Privacy Policy

Innovative Concepts AG (trading as SuisseBase™) — Version 3.0, effective 26 September 2026

1. Controller

Innovative Concepts AG, Rue du Mont-Blanc 11, 1201 Geneva, Switzerland, UID CHE-294.772.335, is the controller of personal data processed through suissebase.ch, our client onboarding portal and our services. Contact: through the form at suissebase.ch/contact or by post to the registered seat, marked "Data protection".

2. What we collect

  • Identity data: name, date and place of birth, nationality, gender, identity-document data and images, a live selfie and liveness video, signature.
  • Contact data: postal address, email, telephone, proof-of-address document.
  • Financial and KYC data: occupation, employer, source of funds and wealth, expected volumes, purpose of relationship, bank account and wallet addresses, transaction data, sanctions/PEP screening results, risk classification.
  • Technical data: IP address, device fingerprint, browser and OS, timestamps, geolocation derived from IP, consent records (Terms acceptance reference, device identifier, time).
  • Communications: emails, support tickets, messages to our support channels, call notes.

3. Why we process it and on what basis

Purpose Legal basis (FADP / GDPR)
Client identification, verification, sanctions and PEP screening, ongoing monitoring, record-keeping Legal obligation — Swiss AMLA, AMLO, ARIF regulations, Travel Rule (art. 6(1)(c) GDPR)
Opening and operating accounts and wallets, executing conversions and payments Performance of contract (art. 6(1)(b))
Fraud prevention, security, scam warnings Legitimate interest (art. 6(1)(f))
Service emails: onboarding status, account details, security notices Performance of contract / legal obligation
Marketing emails and newsletters Consent, withdrawable at any time (art. 6(1)(a))
Website analytics and advertising measurement Consent via cookie banner
Complaints, disputes, legal claims Legitimate interest / legal obligation

4. Who receives it

Categories of processors and independent recipients, each under contract or legal duty:

  • Our identity-verification and AML-screening provider
  • The regulated financial institutions that provide client accounts and payment rails
  • Privy, the non-custodial wallet infrastructure provider (which never receives your private key)
  • Our email-delivery, website-hosting and portal-hosting providers
  • Our advertising-measurement provider, only with your cookie consent
  • Professional advisers, auditors, ARIF, FINMA, MROS (Swiss Money Laundering Reporting Office), courts and authorities where the law requires.

A current list of named processors is available on request. We do not sell personal data.

5. International transfers

Data is processed in Switzerland, the EU/EEA, the United Kingdom and the United States. Transfers outside Switzerland and the EEA rely on adequacy decisions of the Federal Council or the European Commission, or on standard contractual clauses (with the Swiss addendum) and, where relevant, the EU–US and Swiss–US Data Privacy Frameworks.

6. Retention

KYC records, transaction records and correspondence are kept for 10 years after the end of the business relationship or the transaction, as required by art. 7 AMLA and art. 958f CO. Marketing data is deleted on withdrawal of consent. Technical logs are kept for 12 months. Consent records are kept for the life of the relationship plus 10 years.

7. Your rights

You may request access to, correction of, deletion of, or a portable copy of your data, object to processing based on legitimate interest, and withdraw consent. Requests: through the form at suissebase.ch/contact, marked "Data protection". We answer within 30 days. Legal retention duties may prevent deletion; we will tell you if so. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, for GDPR matters, your EU supervisory authority.

8. Automated decisions

Identity verification and screening use automated checks. No application is refused solely on an automated basis; a compliance officer reviews every refusal and you may ask for human review.

9. Security

Data is encrypted in transit (TLS) and at rest, access is restricted to staff and processors who need it, and authentication for staff systems requires a second factor. Client documents are stored encrypted with keys held separately from the data.

10. Minors

Our services are for persons aged 18 or over. We do not knowingly collect data from minors.

11. Changes

We update this policy by publishing a new version with a new effective date and, for material changes, by email.