Privacy Policy
Last updated:
This English translation is provided for convenience. The German version is authoritative.
1. Introduction and scope
Digital Estate Group AG (hereinafter "we", "us" or "controller") takes the protection of your personal data very seriously. This privacy policy informs you about which personal data we collect, process and use in the course of our business activities – in particular in the areas of crypto asset management, wealth architecture and tax optimisation.
This privacy policy applies to the use of our website(s), our client relationships, advisory mandates, crypto asset management and all related services.
Our services are aimed at clients in Switzerland and in the European Union (EU), in particular in Germany. We therefore comply both with the Swiss Federal Act on Data Protection (FADP, in force since 1 September 2023) and – where applicable – with the EU General Data Protection Regulation (GDPR).
2. Controller
The controller responsible for data processing within the meaning of the FADP and the GDPR is:
Digital Estate Group AG Baarerstrasse 43, 6300 Zug Switzerland Email: info@digitalestategroup.ch
3. Principles of data processing
We process personal data in accordance with the principles of lawfulness, good faith, proportionality, transparency, purpose limitation and accuracy. We take appropriate technical and organisational measures to ensure the security of the data.
4. Legal bases for processing (GDPR)
Where the GDPR applies, we base the processing of your personal data on the following legal bases:
- •Consent (Art. 6(1)(a) GDPR): where you have given us your consent to the processing.
- •Performance of a contract (Art. 6(1)(b) GDPR): where the processing is necessary for the performance of a contract or of pre-contractual measures, in particular in the context of asset management mandates, advisory agreements and wealth architecture.
- •Legal obligation (Art. 6(1)(c) GDPR): where we are subject to a legal obligation, e.g. in the area of anti-money laundering (AMLA), tax law or regulatory duties.
- •Legitimate interests (Art. 6(1)(f) GDPR): where the processing is necessary to safeguard our legitimate interests, e.g. for asserting claims, IT security or direct marketing.
Under the Swiss FADP, no specific legal basis is generally required for the processing of personal data, provided there is no justification against the processing (e.g. missing consent for sensitive personal data).
5. Categories of personal data
In the course of our business activities, we process in particular the following categories of personal data:
5.1 Master and contact data
Surname, first name, salutation, date of birth, address, email address, telephone number, nationality, tax residence.
5.2 Financial and asset data
Bank details, crypto wallet addresses, account statements, portfolio data, trading history, performance data, investment strategies, asset overviews, tax information, details of trading accounts with third-party platforms.
5.3 Identification data (KYC/AML)
Copies of identity documents, proof of residence, beneficial owners, source of assets, PEP status and further information in the context of the due diligence obligations under the Anti-Money Laundering Act (AMLA).
5.4 Communication data
Emails, telephone notes, chat messages, meeting minutes, correspondence with tax advisors, lawyers and other partners.
5.5 Contract data
Mandate agreements, board of directors mandates, shareholder agreements, domicile agreements, powers of attorney, fee agreements.
5.6 Technical data (website)
IP address, browser type and version, operating system, access times, referrer URL, pages visited and other technical log data.
6. Purposes of data processing
We process your personal data for the following purposes:
- •Provision of our services in the areas of crypto asset management, wealth architecture, tax optimisation and strategic advisory, marketing
- •Execution and settlement of trading mandates
- •Incorporation, administration and domiciliation of companies in Switzerland
- •Preparation of client reports (quarterly and annual reports)
- •Calculation and invoicing of fees
- •Compliance with legal and regulatory obligations (KYC/AML, tax law, commercial law)
- •Communication with you, your tax advisors, lawyers and other third parties instructed by you
- •Arrangement of PV direct investments
- •Organisation of investor events and referral programmes
- •Operation and security of our website and IT infrastructure
- •Assertion, exercise or defence of legal claims
7. Recipients and disclosure of personal data
We only disclose your personal data where this is necessary for the stated purposes, where there is a legal obligation or where you have given your consent. Recipients may in particular be:
- •Crypto exchanges and trading platforms for the execution of trading orders
- •Tax advisors, auditors and lawyers in the course of handling mandates
- •Banks and financial intermediaries
- •Swiss commercial register offices and tax authorities
- •Other financial authorities (where required by law)
- •IT service providers and hosting providers
- •Partners for PV direct investments
- •Notaries, trustees and other specialists involved
When selecting service providers, we ensure that appropriate data protection standards are observed. Where necessary, we conclude data processing agreements (DPAs).
8. Transfer of data abroad
In the course of our business activities, personal data may be transferred to the following countries:
- •Germany and other EU/EEA states: these have an adequate level of data protection in accordance with the Swiss FADP.
- •Third countries (e.g. server locations of crypto exchanges): in these cases, we ensure through appropriate safeguards (e.g. EU standard contractual clauses, an adequate level of data protection according to the Federal Council's list) that your data is adequately protected.
The current list of countries with an adequate level of data protection is maintained by the Federal Data Protection and Information Commissioner (FDPIC) and by the European Commission respectively.
9. Retention period
We retain your personal data only for as long as is necessary to fulfil the stated purposes or as required by statutory retention periods. The following periods apply in particular:
- •Business correspondence and contracts: 10 years (Art. 958f CO)
- •Accounting records: 10 years (Art. 958f CO)
- •Tax-relevant records: 10 years or longer in accordance with applicable tax law
- •KYC/AML documentation: 10 years after the end of the business relationship (AMLA)
- •Trading data and performance histories: duration of the mandate plus statutory retention periods
- •Website log data: as a rule, a maximum of 12 months
After the retention periods have expired, your data will be deleted or anonymised, unless overriding interests or legal obligations prevent this.
10. Data security
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse or destruction. These include, among others:
- •Encryption of data transmission (TLS/SSL)
- •Access controls and authorisation concepts
- •Regular security updates and backups
- •Confidentiality obligations for all employees and partners
Despite appropriate security measures, complete security cannot be guaranteed for data transmission over the internet (e.g. by email).
12. Your rights as a data subject
You have the following rights with regard to your personal data:
12.1 Rights under the Swiss FADP
- •Right of access (Art. 25 FADP): you can request information as to whether and which personal data we process about you.
- •Right to data release and portability (Art. 28 FADP): you can request the release of your data in a common electronic format.
- •Right to rectification (Art. 32(1) FADP): you can request the rectification of inaccurate personal data.
- •Right to erasure: under certain conditions, you can request the erasure of your data.
12.2 Additional rights under the GDPR
Where the GDPR applies, you additionally have the following rights:
- •Right to restriction of processing (Art. 18 GDPR)
- •Right to object to processing (Art. 21 GDPR), in particular to direct marketing
- •Right to data portability (Art. 20 GDPR)
- •Right to withdraw consent given (Art. 7(3) GDPR), without affecting the lawfulness of processing carried out before the withdrawal
- •Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
For clients resident in Germany, the competent supervisory authority is generally the data protection authority of the respective federal state. In Switzerland, the Federal Data Protection and Information Commissioner (FDPIC) is responsible.
13. Obligation to provide data
The provision of certain personal data is necessary for the conclusion and performance of our contracts and for compliance with legal obligations (in particular KYC/AML). Without this data, we may not be able to provide our services.
14. Automated individual decisions
Where we use technical indicators and signals in the context of our trading strategies, these are decision aids. The final decision on the execution of trades is always made by a human. No automated individual decisions within the meaning of Art. 22 GDPR or Art. 21 FADP are made that are based solely on automated processing and have legal effect.
16. Contact and enquiries
If you contact us by email, telephone or contact form, we process the data you provide in order to handle your enquiry. This data is deleted as soon as the enquiry has been conclusively dealt with and no statutory retention obligations prevent this.
17. Changes to this privacy policy
We reserve the right to amend this privacy policy at any time, in particular in the event of changes to our services, the applicable laws or our data processing practices. The current version is available on our website. We recommend that you review this privacy policy regularly.
Place, date: 15.03.2026
Digital Estate Group AG
Dominik Schneeberger Chairman of the Board of Directors