Privacy Policy

Effective Date: 01.05.2025

Last Updated: 25.05.2025

Who We Are

Welcome to Helvetic Broker OÜ (“Helvetic Broker”, “we”, “us”, or “our”). Your privacy is important to us. This Privacy Policy explains how we collect, use, and protect your personal data when you use our app, Helvetic Broker, in compliance with the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR). Helvetic Broker OÜ is the Data Controller responsible for your data. We use third-party processors such as Firebase (Google) and AI/LLM providers solely to provide and improve our services.

Data We Collect

We do not collect or store private keys or wallet seed phrases.

  • Personal Identification Information: First name, last name, email address, phone number

  • User Preferences: Preferred language, preferred fiat currency, LLM model settings

  • Portfolio Information: Cryptocurrency balances, wallet addresses, portfolio transaction history (only transactions initiated by Helvetic Broker), and historical portfolio values

  • API Credentials: API keys provided by you to connect third-party services (e.g., exchanges). These keys are stored encrypted using AES-256 encryption, and used solely for enabling secure read-only access to your external crypto accounts

  • Authentication Data: We use Firebase Authentication, which may collect and process your email address, phone number, and other sign-in credentials in accordance with Google's Privacy Policy

  • Cookies and Tracking: We may use cookies or similar technologies for app functionality, analytics, and improving user experience.

Children’s Privacy

Helvetic Broker is intended for users aged 16 and above. We do not knowingly collect personal data from children under this age. If you believe we have inadvertently collected such data, please contact us immediately at privacy@helveticbroker.com

How We Use Your Data

We use your data exclusively to provide, maintain, and improve the Helvetic Broker app. Specifically, we use it to:

  • Authenticate users securely via Firebase Authentication

  • Display your current and historical portfolio data upon request

  • Generate insights and responses using AI models

  • Personalize your app experience

  • Provide marketing communications if you have consented (you can opt-out at any time)

Legal Basis for Processing

We process your data based on the following legal bases under GDPR and FADP:

  • Performance of a contract (e.g., providing app services)

  • Legitimate interests (e.g., app security, fraud prevention)

  • Consent (e.g., for AI-based insights, marketing communications, and third-party API connections)

You can withdraw consent at any time via your app settings or by contacting us.

Automated Decision-Making

Some services use AI models to generate insights or recommendations. These automated processes do not have a legally binding or significant effect on you. If you have concerns, you may request human review by contacting us.

Data Security

We implement strict security measures, including:

  • AES-256 encryption for sensitive credentials (like API keys)

  • Encryption at rest and in transit

  • Secure authentication via Firebase Authentication

  • Access controls and regular security audits

Data Sharing

We do not sell your data. We may share certain anonymized or pseudonymized data with third-party services under strict agreements:

  • AI/LLM Services: For generating user insights or responses

  • Firebase (Google): For user authentication and session management

All data sharing is limited to the minimum necessary and governed by data processing agreements and privacy safeguards.

International Data Transfers

If any data is transferred outside Switzerland or the EU/EEA (e.g., through Firebase or AI providers), we ensure it is protected via Standard Contractual Clauses or other GDPR-compliant safeguards.

Data Breach Notification

In the unlikely event of a data breach, we will notify affected users and relevant authorities without undue delay and in compliance with GDPR and FADP requirements.

Your Rights

Under GDPR and FADP, you have the right to:

  • Access the personal data we hold about you

  • Request correction or deletion of your data

  • Object to or restrict processing

  • Request data portability

  • Withdraw your consent at any time

To exercise your rights, contact us at: privacy@helveticbroker.com

Liability Disclaimer

Helvetic Broker enables internal cryptocurrency transfers between your linked portfolios. You are solely responsible for verifying all transaction details. We are not liable for any loss of funds or data caused by user errors, misconfigured integrations, or third-party service issues.

Data Retention

We retain your personal data only as long as needed to:

  • Deliver the Helvetic Broker service

  • Comply with legal obligations

When no longer needed, your data is securely deleted or anonymized.

Dispute Resolution and Governing Law

This Privacy Policy and your use of the app are governed by the laws of Estonia. Any disputes will be resolved under Estonian jurisdiction.

Changes to This Policy

We may update this Privacy Policy from time to time. You will be notified of any significant changes via the app or by email. Continued use of the app after such updates implies your acceptance of the revised terms.

Contact Information

For any questions or concerns about this policy or your data:

© 2025 Helvetic Broker OÜ. All rights reserved.