PRIVACY POLICY

Krabiq AG

Last updated: 17.02.2026

Information in this Privacy Policy

In this Privacy Policy, we explain how we collect, use, and otherwise process personal data when you access our website at www.krabiq.com (the “Website”), interact with our social media channels, contact us, use our services as a client, or make inquiries about our services as a prospective customer.

Why we collect your Data?

We collect and process Users’ personal data to provide, maintain, and improve our crypto exchange services in a secure and compliant manner. This includes verifying identity, fulfilling regulatory obligations such as AML/CTF and sanctions compliance, facilitating transactions, preventing fraud and financial crime, safeguarding platform security, providing customer support, and ensuring the proper performance of our contractual obligations.
Personal data is collected only to the extent necessary for these legitimate business and legal purposes and the way we process any collected personal data is governed by Switzerland’s Federal Act on Data Protection.

What Personal Data do we collect?

Below, we have listed the main categories of personal data we process, together with some examples.

Security of Your Data

In order to keep your personal data secure, we have implemented a number of physical, technical, organisational and procedural protective measures to minimise the risk that unauthorised parties will be able to access your personal data. We store and process your personal data primarily in Switzerland and the EU in accordance with the applicable regulations.
These measures include:
1. Securing our operating environments that are only accessible to our employees, agents and contractors on a need-to know basis
1. Encrypting all sensitive financial information processed to carry out transactions over our Sites. This security is documented by the use of the secure “https” protocol and the padlock in the URL bar.
1. Verifying your identity before you can access, use or make changes to your account so as to prevent any unauthorized access.

With whom we Share your Personal Data

In order to achieve the purposes described in this Privacy Notice, it may be necessary for us to share your personal data with third parties. These are the following categories of recipients:
1. External service providers (KYC, Transaction monitoring, Compliance tools);

Your rights in relation to your Personal Data

You have the following rights in relation to personal data concerning you:
1. The right to obtain information about what personal data we store about you and how we process it;
1. The right to receive or transfer a copy of your personal data in a common format;
1. The right to have your personal data corrected;
1. The right to have your personal data deleted;
1. The right to object to the processing of your personal data.

How we can change this Privacy Notice

We reserve the right to amend or update this Privacy Notice at any time, particularly where our data processing activities change or where new legal or regulatory requirements apply.
If you wish to obtain information regarding the personal data we hold about you on our platform, please contact the support team of Krabiq AG for assistance.

Information for persons Subject to the EU GDPR

For individuals residing in the European Union, we comply with applicable EU data protection legislation. In this section, the term Personal Data has the meaning assigned to it under the General Data Protection Regulation (GDPR).
Where the GDPR applies, we process Personal Data on one or more of the following legal bases:

i. Compliance with Legal Obligations

We process Personal Data where necessary to meet our legal and regulatory duties. This includes compliance with applicable laws and supervisory requirements, such as know-your-customer (KYC) obligations under anti-money laundering and counter-terrorist financing regulations, financial crime prevention measures, sanctions screening, suspicious activity reporting, responding to lawful requests from public authorities, conducting customer due diligence, carrying out audits and risk assessments, preparing tax documentation, fulfilling statutory record-keeping requirements, and establishing, exercising, or defending legal claims.

ii. Performance of a Contract

We process Personal Data where it is necessary to perform our contractual obligations under our Terms of Service. This includes providing access to our Services, delivering customer support, administering user accounts, and maintaining, improving, and optimizing the functionality of our Website and platform.

iii. Consent

In certain circumstances, we rely on your consent to process Personal Data, including for the provision and marketing of our Services. You may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to such withdrawal.

iv. Legitimate Interests

We may process Personal Data where it is necessary for our legitimate interests, provided that such interests are not overridden by your fundamental rights and freedoms. These interests may include monitoring and analyzing usage of the Website, preventing fraud, ensuring network and information security, conducting automated and manual security checks, engaging in direct marketing activities, and safeguarding our legal rights. When relying on this legal basis, we carefully assess and balance our interests against your data protection rights.

Your Rights Under GDPR

You have the following rights regarding your personal data: