
Privacy Policy
Volcanic Glass AG Data Privacy Policy
​
1. Introduction Volcanic Glass AG ("Company," "we," "our," or "us") is committed to ensuring the highest level of data protection in compliance with Swiss and international privacy laws, including the Swiss Federal Act on Data Protection (FADP) and the General Data Protection Regulation (GDPR) where applicable. This Data Privacy Policy outlines our approach to handling personal data, ensuring transparency, security, and compliance with regulatory requirements.
​
2. Scope This policy applies to all personal data processed by Volcanic Glass AG in connection with our operations, including international payments via stablecoins for Latin American companies, over-the-counter (OTC) transactions, market-making, and institutional payment services.
​
3. Legal Basis for Processing Personal Data We process personal data based on the following legal grounds:
-
Contractual necessity: To fulfill our obligations in payment transactions.
-
Legal compliance: To meet Swiss FINMA, VQF, and anti-money laundering (AML) requirements.
-
Legitimate interests: To improve our services, conduct risk assessments, and prevent fraud.
-
Consent: Where explicit consent is required under applicable laws.
​
4. Data Collection and Processing We collect and process the following categories of personal data:
-
Identity information: Name, date of birth, nationality, identification documents (e.g., passport, national ID).
-
Contact details: Address, phone number, email.
-
Financial information: Bank details, cryptocurrency wallet addresses, transaction records.
-
AML/KYC data: Enhanced due diligence (EDD), beneficial ownership details, source of funds.
-
Technical data: IP addresses, device information, and transaction metadata.
​
5. Data Protection Impact Assessment (DPIA) As a financial institution handling sensitive transaction data, we conduct regular Data Protection Impact Assessments (DPIAs) to evaluate and mitigate risks associated with personal data processing. Key aspects of our DPIA include:
-
Identification of risks: Assessing potential risks to data subjects.
-
Mitigation measures: Implementing encryption, secure storage, and access controls.
-
Compliance review: Ensuring alignment with Swiss and international regulations.
-
Ongoing monitoring: Regular audits and updates to security measures.
​
6. Data Security Measures To protect personal data, we implement:
-
Encryption: Secure storage and transmission of sensitive data.
-
Access controls: Role-based access to restrict unauthorized access.
-
Regular audits: Independent security assessments.
-
Incident response: Procedures for managing data breaches.
​​
7. Data Retention We retain personal data only as long as necessary for regulatory compliance, legal obligations, and business purposes. Generally, AML/KYC data is retained for a minimum of 10 years in accordance with Swiss financial regulations.
​
8. Data Sharing and Transfers We do not sell personal data. However, we may share it with:
-
Regulatory authorities: FINMA, VQF, and other competent bodies.
-
Third-party service providers: For compliance, security, and payment processing.
-
International transfers: Ensuring compliance with adequacy decisions or standard contractual clauses (SCCs) when data is transferred outside Switzerland.
​​
9. Data Subject Rights Individuals have the right to:
-
Access their data.
-
Rectify inaccurate data.
-
Request deletion of personal data where legally permissible.
-
Object to processing in specific circumstances.
-
Request data portability.
-
Lodge complaints with the Swiss Federal Data Protection and Information Commissioner (FDPIC).
​​
10. Contact Information For data privacy inquiries, please contact: Volcanic Glass AG Bahnhofstrasse 7, Zug 6300 Switzerland Email: compliance@volcanicglass.io
This policy is subject to periodic updates to reflect regulatory changes and operational improvements. Effective Date: February 28, 2025.
​
​
​