Privacy Policy

Last updated: 22 July 2026

1. Scope

This Privacy Policy explains how ReWallet AG processes personal data when you visit our website at rewallet.com, contact us, or use our services.

Our processing is primarily governed by the Swiss Federal Act on Data Protection and the related Data Protection Ordinance. Where the European Union General Data Protection Regulation (GDPR) applies to a particular processing activity, we also comply with its requirements.

2. Controller

ReWallet AG
Baarerstrasse 8
6300 Zug
Switzerland

Email: team@rewallet.com

3. Purposes and legal bases

We process personal data in particular for the following purposes:

  • providing, operating, and securing our website;
  • handling and assessing contact and service enquiries;
  • preparing, performing, and managing customer relationships;
  • providing our wallet recovery services;
  • communication and appointment scheduling;
  • complying with legal obligations;
  • establishing, exercising, or defending legal claims.

Where the GDPR applies, depending on the processing activity, we rely in particular on steps taken before entering into a contract and performance of a contract, legal obligations, consent, or legitimate interests. Our legitimate interests include the secure and efficient operation of our website and services, the handling of enquiries, and the protection of legal claims.

We do not make decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them.

4. Personal data processed

Depending on how you use our website, communicate with us, and engage our services, we process in particular:

  • contact details such as name, email address, and a voluntarily provided telephone number;
  • the content of messages and correspondence;
  • general information about the reported wallet issue;
  • contract, case, and administrative data;
  • technical and engagement-specific data, files, documents, and information provided to us after entering into a contract;
  • identity and authority documentation where required to handle an enquiry;
  • technical connection data, in particular IP address, time of access, and browser and device information.

Information required to assess an enquiry or perform a contract must be provided for those purposes. Without such information, we may be unable to assess an enquiry or provide an agreed service.

5. Contact forms

When you use a contact form, we process the information you enter to assess and respond to your enquiry and, where applicable, prepare a customer relationship.

Please do not submit seed phrases, private keys, recovery words, wallet passwords, or comparable confidential access information through the general contact form or by ordinary email.

The information entered in the contact form is transmitted through a technical interface directly to a system used by us in Switzerland, where it is stored for the purpose of processing your enquiry. The service provider involved in the transmission is used solely for technical forwarding and does not store the form contents. The form data is not additionally transmitted by email.

6. Wallet recovery services

As part of our services, we process the technical and engagement-specific data, files, documents, and information provided to us after entering into a contract for the assessment and handling of a wallet case.

We process this data exclusively to perform the relevant engagement, communicate, and maintain necessary documentation. We request only data required for the specific case.

Where enquiries are submitted by heirs or other authorised representatives, we process the data and documents required to assess the claimed authority.

Because engagement-specific data is particularly confidential, before it is submitted, or at the latest when the contract is entered into, we provide customers with additional information about the specific processing, designated secure transmission channels, and retention and deletion.

7. Website operation and technical service providers

We use hosting and infrastructure service providers to operate and secure our website and to transmit contact enquiries. In this context, technically necessary connection, operational, error, and security data may be processed.

8. Email, appointments, and video conferences

We use Google Workspace for email communication, appointment management, and video conferences. In this context, contact details, communication content, appointment data, and technical connection data may be processed.

Engagement-specific wallet data should not be provided by ordinary email, but only through the secure transmission channels designated for this purpose.

9. Website Analytics

We use data-minimising website analytics to measure aggregated website usage and to improve the technical operation of our website. The analytics system is operated by us on our own infrastructure in Switzerland. Analytics data is not disclosed to an external analytics provider.

The analytics do not use persistent user identifiers and are not used for cross-site tracking, profiling or personalised advertising. Raw IP addresses are not stored in the analytics database.

10. Cookies and similar technologies

We use technically necessary cookies and similar storage technologies to provide essential website functions. These include remembering the selected language and entry page and supporting the consistent and error-free display of the website.

These technologies are not used for personalised advertising or cross-site tracking. Depending on their purpose, the stored settings are retained for the duration of the session or until they are changed or deleted.

11. Recipients

We disclose personal data only to the extent necessary for the purposes described in this Privacy Policy. Recipients may include in particular:

  • Vercel for website operation;
  • DigitalOcean for technical infrastructure;
  • Google for email communication, appointment management, and video conferences;
  • public authorities, courts, and external advisers where required to comply with legal obligations or protect legal claims.

Our website analytics are operated by us on our own infrastructure in Switzerland. Analytics data is therefore not disclosed to an external analytics provider.

12. Disclosure of personal data abroad

We process personal data primarily in Switzerland and Germany. In connection with the service providers we use, personal data may also be processed in Ireland, the United States or other countries in which these service providers or their subprocessors operate.

Current subprocessors and processing locations can be found in the providers' publicly available lists:

Where personal data is transferred to countries without a recognised adequate level of data protection, we ensure the required protection through appropriate legal safeguards. These safeguards include, in particular, the Swiss-U.S. Data Privacy Framework for appropriately certified recipients, recognised standard contractual clauses and, where required, additional protective measures.

13. Retention and deletion

We retain personal data depending on the category of data, the purpose of processing, and legal requirements. The following principles apply in particular:

  • contact and enquiry data that does not lead to a contract is generally deleted no later than 24 months after the last substantive contact;
  • data relating to an existing customer relationship is retained for as long as required to prepare, perform, and document the relevant engagement;
  • engagement-specific working data is deleted after completion or termination of the engagement as soon as it is no longer required;
  • contractual, business, and accounting records subject to statutory retention requirements may generally be retained for up to ten years.

Data may be retained for longer where required to comply with legal obligations or to establish, exercise, or defend legal claims.

14. Data security

We implement appropriate technical and organisational security measures to protect personal data, according to the relevant risk, against loss, misuse, unauthorised access, disclosure, and alteration. Particularly confidential engagement-specific data is received through separate secure transmission channels.

15. Rights of data subjects

Within the scope of applicable data protection law, you may in particular exercise the following rights:

  • access to the personal data processed by us;
  • rectification of inaccurate or incomplete data;
  • deletion of personal data where there is no obligation or entitlement to retain it;
  • provision or transfer of certain personal data in a commonly used electronic format where the legal requirements are met;
  • withdrawal of consent with effect for the future;
  • objection to certain processing activities where provided by applicable law.

Where the GDPR applies, additional rights may include in particular restriction of processing, data portability, and the right to lodge a complaint with a competent data protection supervisory authority.

To exercise your rights, you may contact us at team@rewallet.com. We may request appropriate proof of your identity.

You may report a suspected infringement of data protection law to the Swiss Federal Data Protection and Information Commissioner (FDPIC). The FDPIC does not enforce individual claims on your behalf. Rights such as access, rectification or deletion must first be exercised against ReWallet. Civil claims, including claims for injunctive relief or damages, may be pursued before the competent civil court. edoeb.admin.ch

16. Changes to this Privacy Policy

We may amend this Privacy Policy if our processing activities, services, or legal requirements change. The version published on our website with the date stated there applies.