Legal
Imprint, terms, privacy and cookies
Imprint
Operator of this website
FE Swiss Financial AG, dba as XEROF. Gubelstrasse 11, 6300 Zug, Switzerland.
Commercial register number: CHE-353.710.248.
VAT number: CHE-353.710.248 MWST.
LEI number: 506700144F83873DIA68.
D-U-N-S® number: 48-055-8306.
Email: middleoffice@xerof.com.
Regulatory status
FE Swiss Financial AG is a financial intermediary under the Swiss Anti-Money Laundering Act, regulated through its membership of VQF (No. 100954), for VASP, Payments and Custody activities, VQF is a self-regulatory organisation recognised and supervised by FINMA.
Disclaimer
The information on this website is provided for general information only and does not constitute an offer, solicitation or investment advice. Prices shown are indicative. Rates are confirmed in writing at account opening.
Terms of use
Last updated 15 April 2026.
Preamble
WHEREAS, Xerof is an online exchange and money transmitting business provided by FE Swiss Financial AG, with legal seat in Zug designed to:
- enable Users to settle the purchase price or part of the purchase price of goods, services or contributions in Digital Assets and the Recipient to receive the purchase price or part of the purchase price in FIAT ("Xerof Transaction Services");
- enable Users to exchange Digital Assets to FIAT and vice versa ("Xerof OTC Exchange Services");
- enable Users to store Digital Assets ("Xerof Custodial Services") (Xerof Transaction Services, Xerof OTC Exchange Services and Xerof Custodial Services in the following together "Xerof Services").
WHEREAS, User is a legal entity or individual person who desires to use the Xerof Services.
By accessing the Xerof Website and using the Xerof Services User agrees and accepts these Terms.
1. Definitions
"Digital Assets" shall mean digital assets registered on a blockchain or another distributed and encryption-based ledger or based on similar technology.
"Exchange" shall mean the exchange of Digital Assets to FIAT and vice versa provided by Xerof to User.
"Exchange Fee" shall mean the fee for the Exchange charged by Xerof to User as indicated in the Welcome Letter.
"Welcome Letter" shall mean the letter sent by Xerof to User consisting of the information as indicated in clause 8.
"Recipient" shall mean the designated recipient of the Transaction.
"Recipient Bank Account" shall mean the bank account of the Recipient designated by User.
"Terms" shall mean these terms of service.
"Transaction" shall mean the transaction from User to Recipient for the purpose of settlement of a purchase price or part of the purchase price of goods, services or contributions provided by the Recipient to the User.
"Transaction Information" shall mean the information provided by User to Xerof necessary to perform the Transaction as requested by Xerof (such as amount and type of User Digital Assets which shall be used for the Transaction, PUK of the User from which the User Digital Assets will be transferred to Xerof, contact details from Recipient, information regarding the underlying purchase, Recipient Bank Account details and FIAT currency in which the Recipient should receive the funds).
"Transaction Fee" shall mean the fee for the Transaction charged by Xerof to User as indicated in the Welcome Letter.
"User Account" shall mean the account of the User accessible via the Xerof Website.
"User Bank Account" shall mean the bank account of a User connected to a User Account.
"User Account Access Data" shall mean information and data necessary to log-in to User Account.
"User Digital Assets" shall mean Digital Assets of the User used to execute the Transaction or the Exchange.
"User Custodial Assets" shall mean Digital Assets of the User in custody with Xerof as part of the Xerof Custodial Services.
"User Information" shall mean the information requested on the Xerof Website to create a User Account.
"Xerof Bank Account" shall mean a bank account in the name of Xerof.
"Xerof User Wallet" shall mean an individual and on-chain segregated wallet held by Xerof for a User.
"Xerof Wallet" shall mean a wallet held by Xerof used to perform the Exchange.
"Xerof Website" shall mean the website www.xerof.com.
2. Xerof Services
- Xerof provides a simple and convenient way to:
- settle the purchase price of goods, services or contributions provided by the Recipient to the User ("Xerof Transaction Services");
- exchange Digital Assets to FIAT and vice versa ("Xerof OTC Exchange Services");
- enable Users to store Digital Assets ("Xerof Custodial Services")
-
Only Digital Assets which qualify as Utility or Payment Token according to the guidelines of the Swiss Financial Market Supervisory Authority ("FINMA") of 16 February 2018 for subordination requests concerning Initial Coin Offerings will be accepted for Xerof Services.
-
XEROF is a company incorporated under Swiss law and is not authorized under the Markets in Crypto-Assets Regulation (MiCA) or by any financial supervisory authority of the European Union or European Economic Area. The services described are not offered to EU/EEA residents or entities except under the reverse solicitation exemption as defined in Article 61 of MiCA.
-
XEROF does not offer or market its services to entities, residents or citizens of the European Union (EU) or European Economic Area (EEA), unless the client has initiated contact entirely on their own initiative. Users from jurisdictions where XEROF is not authorized should not use the services.
3. Onboarding as a User
3.1 Setting up a User Account
- In order to use the Xerof Services, User needs to set up a User Account by providing User Information on the login interface on the Xerof Website and accepting these Terms.
3.2 KYC/AML Process
-
Once User has submitted User Information User must complete certain verification procedures ("KYC-Check") which will be conducted by Xerof or a KYC/AML partner of Xerof ("KYC Service Provider"). Additional KYC-Checks may be performed before each transaction.
-
User acknowledges that pursuant to any applicable anti-money laundering, anti-terrorist financing, government sanction and "KYC"-laws, whether within Switzerland or elsewhere (collectively, including any guidelines or orders thereunder, the "AML Legislation"), Xerof or its KYC Service Provider may be required to obtain, verify and record information regarding User, User's directors, User's partners or User's authorized signing officers and the transaction (e.g. source of funds) contemplated by these Terms.
-
User undertakes to promptly provide or cause to be provided to Xerof or to KYC Service Provider all required information, including supporting documentation and other evidence, as may be reasonably requested by Xerof or its KYC Service Provider, in order to complete Xerof's or the Service Provider's KYC-Check to ensure compliance with applicable AML Legislation, whether now or hereafter in existence. The same applies in case one of Xerof's bank or Recipient Bank requires additional information regarding the source of funds of deposits/transactions made or intended to be made by Xerof.
-
User understands that the outcome of the KYC-Check, e.g. the non-admission of a transaction, or the exclusion at any time later, lies in the sole discretion of Xerof and/or the KYC Service Provider. User further understands that the amount of information requested to provide as part of the KYC-Check may be subject to change over time and that you may at a later point in time be required to provide additional documents and/or information, based on which your transaction may be rejected.
-
Xerof or the KYC Service Provider may designate the KYC-Check process to a KYC Service Provider. All documents and information submitted by the User may be sent to one or more KYC Service Provider for review.
3.3 Login Details for User Account and Transaction Fee
-
If the initial KYC-Check was successful, User will receive User Account Access Data and information regarding the Transaction Fee, Exchange Fee and/or Custodial Fees applicable for the User ("Welcome Letter").
-
User shall not be permitted to make these User Account Access Data available to third parties and User is responsible for any use and activities in connection with the User Account. User shall inform Xerof immediately if User becomes aware of any an unauthorised access to his User Account.
4. Xerof Transaction Services
4.1 Performance of the Transaction
-
In order to perform a Transaction, User shall designate the type of transaction which should be processed by Xerof by providing the Transaction Information in the respective form in its User Account ("Transaction Order"). Xerof may perform an additional KYC-Check for each and every Transaction Order.
-
Upon successful completion of the KYC-Check the User shall transfer Digital Assets to the Xerof User Wallet. Xerof will confirm receipt of the funds by displaying them in the respective User Account. Before performing the exchange of the Digital Assets Xerof in the FIAT currency as defined in the Transaction Order, Xerof will propose to the User when, how, to what conditions the exchange shall be performed ("Exchange Offer"). The User shall confirm the Exchange Offer ("Exchange Confirmation"). By providing the Exchange Confirmation the User authorizes Xerof to execute the Exchange Offer and charge the User any applicable fees (as described in Section 4.2). Xerof will perform the exchange and transfer the FIAT amount to the Recipient Bank Account, whereas the actual exchange rate may be different from the prevailing rate indicated via the Exchange Offer. If the exchange rate from the Exchange Offer deviates, to the User's detriment, substantially from the exchange rate when the exchange may be executed (at least 1 %) Xerof will not execute the exchange ("Failed Exchange"). In such case Xerof informs User accordingly and provides a new Exchange Offer.
4.2 Fees
-
The fee to be paid by User to Xerof for performance of the Transaction will be calculated as a percentage of the transaction amount ("Transaction Fee") and becomes due and payable upon placing the Transaction Order. By placing the Transaction Order the User accepts the Transaction Fee as designated by Xerof.
-
In addition to the Transaction Fees, additional expenses, interests, charges, commissions, mark-ups or taxes may occur for the execution of the Transaction ("Third Party Fees"). Xerof will inform User in advance about such Third Party Fees.
-
User authorizes Xerof and Xerof's designated payment processor to deduct the Transaction Fee and any applicable Third Party Fees from the transaction amount before transferring the exchanged FIAT of the Digital Assets to the Recipient Bank Account.
-
Once the Transaction is executed a confirmation of the Transaction will be electronically made available via the User Account detailing the particulars of the Transaction (in particular all relevant fees).
4.3 Cancellation of the Transaction
-
Both parties may, at any time before the exchanged FIAT of the Digital Assets is transferred to the Recipient Bank Account, cancel the Transaction without any reasons.
-
If the Transaction is cancelled by one of the parties or the Transaction may not be successfully executed for any other reason (e.g. any of the involved banks refuses the Transaction) the Transaction shall be reversed. If the Digital Assets have at the time of cancellation already been exchanged, the FIAT amount will be exchanged to the same currency of the Digital Assets again before the assets are provided to the User, whereas Xerof may in its own discretion decide when the exchange shall be executed.
-
Xerof shall not be liable for any currency lost, Third Party Fees or costs of additional transactions of a reversed transaction unless Xerof has cancelled the Transaction without valid reasons. In all other cases User shall carry any and all costs and losses (e.g. currency losses) of the cancelled transaction and Xerof is entitled to deduct all such costs before transferring the remaining Digital Assets to User.
-
If the Transaction is cancelled by Xerof without valid reasons, no Transaction Fee is due. If the Transaction is cancelled by Xerof for valid reasons, the Transaction is cancelled by User or the Transaction is not successfully executed for any other reason a reduced Transaction Fee of 50 % of the Transaction Fee ("Reduced Transaction Fee") is due and Xerof shall be entitled to deduct this Reduced Transaction Fee from the Digital Assets before the Transaction shall be reversed.
5. Xerof OTC Exchange Services
5.1 Performance of the Exchange
-
In order to perform an Exchange, User shall designate the type of exchange which should be processed by Xerof by providing the Exchange Information in the respective form in its User Account ("Exchange Order"). Each Exchange Order requires at least the User to specify the amount of Fiat currency or Digital Assets the User intends to sell ("Purchase Funds") and the Fiat currency or Digital Assets equivalent to be bought with the Purchase Funds ("Target Funds"). Xerof may perform an additional KYC-Check for each and every Exchange Order.
-
Upon successful completion of the KYC-Check the User shall transfer the designated Digital Assets to the Xerof Wallet or to Xerof Bank Account. Before performing the exchange as defined in the Exchange Order, Xerof will propose to the User the applicable exchange rate and the conditions of the exchange ("Exchange Offer"), which is an indicative offer. The final exchange rate will be determined at the time Xerof executes the Users Exchange Order at Xerof's sole discretion and based on a best effort basis ("Final Exchange Rate").
-
The User shall confirm the Exchange Offer ("Exchange Confirmation"). By providing the Exchange Confirmation the User authorizes Xerof to execute the Exchange Offer and charge the User any applicable fees (as described in section 5.2). Xerof will perform the exchange and transfer the FIAT amount to the User Bank Account or the Digital Assets to the designated wallet of the User, whereas the actual exchange rate may be different from the prevailing rate indicated via the Exchange Offer. If the exchange rate from the Exchange Offer deviates, to the User's detriment, substantially from the exchange rate when the exchange may be executed (at least 1 %) Xerof will not execute the exchange ("Failed Exchange"). In such case Xerof informs User accordingly and provides a new Exchange Offer. In case no successful exchange can be performed within 60 days upon the inflow of the assets to Xerof, Xerof will retransfer the Digital Assets or the FIAT amount to the User.
5.2 Fees
-
The fee to be paid by User to Xerof for performance of the Exchange will be calculated as a percentage of the Exchange Amount ("Exchange Fee") and becomes due and payable upon placing the Exchange Order. By placing the Exchange Order the User accepts the Exchange Fee as designated by Xerof.
-
In addition to the Exchange Fees, additional expenses, interests, charges, commissions, mark-ups or taxes may occur for the execution of the Exchange ("Third Party Fees"). Xerof will inform User in advance about the range of such Third Party Fees.
-
User authorizes Xerof and Xerof's designated payment processor to deduct the Exchange Fee and any applicable Third Party Fees from the Exchange Amount before transferring the Exchange Amount to the User Bank Account or the designated wallet of the User.
-
Once the Exchange is executed a confirmation of the Exchange will be electronically made available via the User Account detailing the particulars of the Exchange (in particular all relevant fees).
6. Xerof Custodial Services
6.1 Custody Set-Up for Digital Assets
-
The types of Digital Assets covered by the Xerof Custodial Services are defined by Xerof upon opening of a User Account and further Digital Assets can be supported in accordance with the provision in section 11 below.
-
All Users Digital Assets held in custody by Xerof for a User ("User Custodial Assets") will be held in Xerof User Wallets. For each User Xerof will hold an on-chain segregated Xerof User Wallet. Such Xerof User Wallet only contain Digital Assets which belong to the User. A pooling with the Digital Assets of other User may only take place if User uses the Xerof OTC Exchange Services as described in section 5 above. Access to such Xerof User Wallets is based on a multi-signature approach according to which every on-chain transaction from a Xerof User Wallet needs to be signed by Xerof who controls the respective private key/private key shard ("Xerof User Wallet Private Key"). Xerof will only sign transaction upon receipt of an instruction by the User within the User Account.
-
Xerof assures that the Digital Assets of the User will at all times be individualised in the books of Xerof as assets in the property of User.
6.2 Deposits and Withdrawals
- The User may make deposits to (transfer-in) and withdrawals from (transfer-out) the User Custodial Assets balances in accordance to the respective process specified in the User Account.
- Deposits of Digital Assets: Xerof may verify the Users control over the sender wallet(s) used applying any method determined at the discretion of Xerof. If Digital Assets are being deposited from a third-party sender wallet, Xerof only accepts such a transaction if the respective third-party successfully passes a KYC/AML check as determined at the sole discretion of Xerof.
- Withdrawals of Digital Assets: Xerof does accept withdrawals from the Xerof User Wallets to external accounts or wallets under control by any person other than the User only, if such third party successfully passes a KYC/AML check determined at the sole discretion of Xerof. Xerof may verify the User's control over the receiving wallet(s) used applying any method determined at the discretion of Xerof.
- The User understands and accepts that:
- Any transfer-in and transfer-out Instructions by the User are subject to the required compliance checks according to the anti-money laundering directive of Xerof as a regulated Swiss financial intermediary and can be rejected at its sole discretion. Xerof is not obliged to provide any reasons for its decision.
- Xerof does not guarantee any maximum duration for the processing of transfer-in and transfer-out transactions/instructions and disclaims any liability for losses or damages caused by delays in the processing of such transactions/instructions.
- The User bears the full risk for the accuracy of the provided recipient addresses for transfer-out Instructions as well as for initiating the correct transaction to the wallet address Xerof has provided for the transfer-in transactions. Xerof disclaims any liability for losses or damages caused by the User using or providing incorrect wallet addresses in this regard.
6.3 Ownership of Digital Assets
- Xerof hereby acknowledges and agrees that it is a custodian of the User Custodial Assets which always remain in the property of the User and that Xerof has no right, interest, or title in such User Custodial Assets. Xerof hereby confirms that the User Custodial Assets do not constitute an asset on the balance sheet of Xerof and that the User Custodial Assets will at all times be identifiable in Xerof's database as being stored on behalf of Customer (via an on-chain segregation).
6.4 Safekeeping of User Custodial Assets
- Xerof shall use commercially reasonable efforts to keep in safe custody on behalf of the User all User Custodial Assets received by Xerof. All User Custodial Assets connected to the User Account shall be held in the related Xerof User Wallets at all times – except for explicit transaction instructions made by User. Xerof will use commercially reasonable efforts to keep its keys to the Xerof User Wallets secure, to prevent unauthorized access to or use of the keys to the Xerof User Wallet and shall maintain at least one (1) backup key to use as a replacement.
6.5 Reporting and Valuation of Custodied Digital Assets
-
Xerof shall provide User with periodic reports, transaction notices and/or statements of accounts relating to the User Custodial Assets. Xerof shall provide such statements of accounts on a monthly basis and ensures on a best effort basis that User can obtain such data as required for income and/or wealth tax purposes of the User.
-
The User will have thirty (30) days to file any written objections or exceptions with Xerof after respective account statement has been made available via the User Account or other pre-agreed communication channel. If the User does not file any objections or exceptions within the thirty (30) day period, this shall indicate the User's approval of the statement and will preclude the User from making future objections or exceptions regarding the information contained in the statement. Such approval by the User shall be full acquittal and discharge of User regarding the transactions and information on such statement.
6.6 Record Keeping
- User shall have access to the books and records pertaining to User Custodial Assets, which are in the possession or under the control of Xerof at all times during Xerof's normal business hours. Upon the reasonable request of Xerof, copies of any such books and records shall be provided by Xerof to the User, at the User's expense. All records maintained pursuant to this provision shall be retained by User for such period as required by applicable law, but in no event for less than ten (10) years, after which retention of such records shall be at Xerof's discretion.
7. Audit Rights
- If the provision of the Xerof Services is part of an outsourcing Agreement due to which User outsources own activities to Xerof (in the sense of the FINMA Outsourcing Circular 2018/3 or similar provision), which Xerof needs to be informed in writing about, the User, its audit firm as well as any regulatory body under whose licensing regime the User operates shall have the right – at the User's expense – to inspect and audit all information relating to the outsourced function at any time without restriction.
8. Use of Subcontractors
- The Customer understands that Xerof may perform any of its duties or obligations under this Agreement through subcontractors, agents or sub-custodians (including affiliates), whenever and on such terms and conditions as Xerof, in its sole discretion, deems necessary or appropriate to perform such duties or obligations or liabilities; provided that no arrangement with such subcontractor, agent or sub-custodian shall discharge Xerof from its duties and obligations for the selection and instruction of such subcontractor, agent or sub-custodian.
9. Suspension Due to Market Disruption
- The User agrees and understands that in the event of a market disruption, Xerof may, in its sole discretion, do one or more of the following: (i) suspend access to the Xerof Services; or (ii) prevent the User from completing any actions via the Xerof Services. It can do so itself or via its sub-contractors. Xerof is not liable for any losses suffered by the User resulting from such actions. Following such an event, when Xerof Services resume, the User agrees and understands that the prevailing market prices may differ significantly from the prices prior to such event.
10. No Asset Management or Investment Advice
-
Xerof is not acting under this Agreement as manager or investment adviser to the User, and responsibility for the selection, acquisition and disposal of the User Custodial Assets or execution of any exchange or transaction remains with the User all times. Xerof shall have no obligation to explain or warn of any risks taken or to be taken by the User. In particular Xerof has no duty to inform the User of any information on an asset in the User Account which Xerof may have learned in connection with another User Account or User or from any source other than in the operation of the User Account.
-
The information on the User Account or provided via other communication channels does not constitute legal, financial or investment advice and is not intended as a recommendation for buying, trading or selling Digital Assets or Fiat currencies. Xerof recommends seeking advice of legal and financial experts before starting to buy, trading or selling Digital Assets. Digital Assets are volatile. Buying and selling of Digital Assets carries with it a high degree of risk. The Customer should be fully aware of the level of risk involved before trading. Any loss of data, Digital Assets or profit is on the User's sole responsibility. Xerof will not be responsible for the consequences of reliance upon any opinion or statement contained herein or for any omission.
11. Fork and Airdrop Policy / Digital Asset Support
-
In the event of a Fork, the User can only claim the version of that Digital Asset which is deemed the official/prevailing one at the sole discretion of Xerof.
-
Any Airdrops Xerof as custody service provider receives related to the Digital Assets of the User shall become part of the User Custodial Assets of such User as well, if Xerof supports the Digital Asset created in the course of such Airdrop. User understands and accepts that it lies in Xerof's sole discretion whether to support a Digital Asset, respectively the related Airdrop procedure and that Xerof, if not doing so, still might keep the related Airdrops as its own exclusive property.
-
For which Digital Assets Xerof provides the Xerof Services lies at the sole discretion of Xerof and Xerof can add or remove support towards certain Digital Assets without being obliged to explain such a decision. Which Digital Assets are supported towards a specific User is being agreed between such User and Xerof. User shall not expect that Xerof supports any other Digital Assets as explicitly stated by Xerof via its website or any other pre-agreed communication channel. This means, in particular and without limitation, User should not attempt to receive, request, send, store, or engage in any other type of transaction involving any Digital Asset unless expressly supported by Xerof. Xerof will have no responsibility or liability if customer loses, burns, or otherwise cannot access or control any digital assets that Xerof does not support.
12. Risks
- The User understands and accepts the risks connected to Digital Assets, the Transaction, the Exchange and any other services provided by Xerof as part of this Agreement. In particular, but not exhaustively, the User understands the inherent risks listed hereinafter:
- Risk of Theft: The Client understands and accepts that the Digital Assets used for the Transaction, Exchange or Custody may be exposed to attacks by hackers or other individuals that could result in theft or complete loss of the Digital Assets of the User.
- Risk of Mining Attacks: The User understands and accepts that, the blockchain is susceptible to attacks, including but not limited to denial of service attacks, exploits of consensus nodes, and byzantine attacks on the consensus nodes. Any successful attacks present a risk to the performance of the Xerof Services.
- Risk of Transaction Verification: The User understands and accepts that the Transaction, Exchange or Custody may be delayed or not be executed due to the transaction volume on the respective blockchain, mining attacks and/or similar events.
- Risk of Delayed FIAT Transaction: The User understand accept that the Transaction, Exchange or Custody may be delayed due to a delay of execution of the FIAT transaction by the involved banks (due to bank holidays, fraud prevention procedures or other compliance issues).
- Risk of Software Weaknesses: The User understands and accepts that the relevant blockchain, the underlying software application, and software platform may still be in an early developmental stage and unproven. The User acknowledges that there is an inherent risk that the software could contain weaknesses, vulnerabilities or bugs causing, inter alia, a complete loss of the Digital Assets for the Xerof Services.
- Prices and Availability: The User understands and accepts that all prices during the Suggested Exchange reflect the exchange rates of Broker/Exchange applicable to the sale of the Digital Assets. Particularly during periods of high volume, illiquidity, fast movement or volatility in the marketplace for any Digital Assets, the actual market rate at which the exchange is executed may be different from the prevailing rate indicated via the Exchange Offer.
13. Warranties of User
- By accepting these Terms, User represents and warrants that:
- he/she is the sole legal and ultimate beneficial owner of the Digital Assets used for the Xerof Services;
- he/she may only use the User Account and the Xerof Services for the contractually agreed purpose, which is the settlement of a purchase price of goods, services or contributions provided by the Recipient to the User. In particular, using the User Account and the Xerof Services for currency exchange services (this includes the exchange of fiat money into Digital Assets and vice versa) and any transfer of money and assets not serving as a payment by the User to Recipient for goods, services or contributions rendered by the Recipient to the User is strictly forbidden;
- he/she will use the Xerof Services and User Account only for himself/herself, and not on behalf of any third party, unless you have obtained prior approval from Xerof. Each User may register only one User Account;
- he/she is fully responsible for all activity that occurs under the User Account. Xerof may, in its sole discretion, refuse to open a User Account for a User, or fully or partially suspend or terminate any User Account;
- he/she is not using Xerof Services for any illegal purposes;
- he/she has a deep understanding of the functionality and transmission mechanisms of blockchain-based software Digital Assets;
- that all information provided within any registration or KYC-Check linked to his User Account is true and accurate;
- the Digital Assets used for the Xerof Services are (i) good, clean, clear and are of non-criminal origin; (ii) completely free and clear of any liens or encumbrances of any kind of any rights of third-party interests; and (iii) have no origins that may be connected to any breach of money laundering regulations whatsoever, as defined in the jurisdiction of origin, or internationally;
- he/she is not being listed, or associated with any person or legal entity being listed, on any of the US Department of Commerce's Denied Persons or Entity List, the US Department of Treasury's Specially Designated Nationals or Blocked Persons Lists, the US Department of State's Debarred Parties List, the EU Consolidated List of Persons, Groups and Entities Subject to EU Financial Sanctions or the Swiss SECO's Overall List of Sanctioned Individuals, Entities and Organizations;
- he/she is not a citizen or resident of the United States of America, nor a person subject to US taxation based on the Foreign Account Tax Compliance Act (FATCA), nor resident of, citizen of or located in a geographic area that is subject to UN-, US-, EU-, Swiss or any other sovereign country sanctions or embargoes;
- if he/she is a natural person who is a resident or citizen of the European Union (EU) or European Economic Area (EEA), or if he/she is a legal entity established or registered in the EU/EEA, he/she confirms that he/she is engaging with Xerof entirely at his/her own initiative and not as a result of any direct or indirect marketing, solicitation, or advertising by Xerof or any of its representatives. He/she further acknowledges that Xerof's services are made available to him/her solely under the reverse solicitation exemption as defined in Article 61 of the Markets in Crypto-Assets Regulation (MiCA).
14. Warranties of Xerof
-
Xerof is a company duly organized, validly existing and in good standing under the laws of Switzerland and has all requisite corporate power and authority to carry on its statutory purpose and operation as now conducted and as presently proposed to be conducted.
-
Xerof has all requisite power and authority to execute and deliver the obligations under these Terms.
15. Liability
-
Xerof carries out the Xerof Service with reasonable care.
-
The liability of Xerof is limited to acts of intent and gross negligence and direct damages. Any liability for indirect damage or consequential damage including loss of profit is excluded. In particular, Xerof shall in particular not be liable for damages resulting from delayed or non-executed processing of Transaction or Exchange Orders or from transfers of the User of Digital Assets on non-notified block chain addresses.
-
Xerof cannot guarantee that the Xerof Website and Xerof Services may be available all the time. Xerof Website and Xerof Services may be unavailable for various reasons, including routine maintenance. The User accepts that due to circumstances within or outside the control of Xerof the use of the Xerof Service may be interrupted, suspended or terminated. Xerof expressly excludes any liability for damages due to such circumstances. Xerof shall not be liable for any Failed Exchange and in particular any adverse exchange rates due to a Failed Exchange.
-
Xerof shall be liable for the acts or omissions of their subcontractors in the same way as for itself.
16. Confidentiality
-
The Parties agree to hold each other's "Confidential Information" confidential for a period of three (3) years following the termination of the contractual relationship. The Parties agree, that unless required by law or required by a service provider (e.g. KYC Service Provider), they shall not make each other's Confidential Information available in any form to any third party or to use each other's Confidential Information for any purpose other than the implementation of these Terms. Each Party agrees to take all reasonable steps to ensure that Confidential Information is not disclosed or distributed by its employees or agents in violation of these Terms.
-
Confidential Information shall mean all material and information that has or will come into possession or knowledge of the other Party in connection with its performance hereunder and which in the ordinary course of business is considered to be treated confidential. A Party's Confidential Information shall not include information that: (a) is or becomes a part of the public domain through no act or omission of the other Party; (b) was in the other Party's lawful possession prior to the disclosure and had not been obtained by the other Party either directly or indirectly from the disclosing Party; (c) is lawfully disclosed to the other Party by a third party without restriction on disclosure; (d) is independently developed by the other Party; or (e) is required to be disclosed by law or governmental regulation or by any competent body or authority provided that the recipient shall inform the disclosing Party of its obligation to disclose information, of the information to be disclosed and of the circumstances in which the disclosure is alleged to be required) as early as reasonably possible before such disclosure must be made and shall take all reasonable actions to avoid and limit such disclosure. The Parties agree that the information duty under (e) shall not apply to disclosures towards tax authorities.
This document is confidential and is intended only for persons or legal entities who have contacted Xerof at their own initiative. It may not be copied, distributed, published, or shared—particularly in jurisdictions such as the European Union (EU) or European Economic Area (EEA), where Xerof does not offer or advertise its services.
17. Data Protection
- Any use of your personal data is governed by our Privacy Policy which can be accessed in its most current version on the Xerof Website.
18. Intellectual Property
- User accepts that any and all rights (including copyrights, design rights and/or other intellectual property rights) of Xerof (in particular but not exclusively in the Xerof Website and the Xerof Services) shall remain in the sole property of Xerof. Xerof does not assign any right, title and interest in any and all work results created or developed by Xerof under this Agreement, including, but without limitation, all patents, copyrights, trade secrets and other proprietary rights.
19. Applicable Law and Jurisdiction
- These Terms shall be governed by and construed in accordance with Swiss law, excluding the Swiss conflict of law rules. The application of the United Nations Convention for Contracts for the International Sales of Goods is hereby expressly excluded.
Any dispute, controversy or claim arising out of or in connection with this Agreement or the breach, termination, existence, legal competence or invalidity thereof, shall be exclusively settled by the courts of Zug, Switzerland.
20. Miscellaneous
-
These Terms do not create a principal or agent, employer or employee partnership, joint venture, or any other relationship except that of independent contractors between the Parties. Nothing contained herein shall be construed to create or imply a joint venture, principal and agent, employer or employee, partnership, or any other relationship except that of independent contractors between the parties, and neither party shall have any right, power or authority to create any obligation, express or implied, on behalf of the other in connection with the performance hereunder.
-
No modification, amendment, supplement to or waiver of these terms, including this Section, shall be binding upon the parties hereto unless made in writing and duly signed by both parties.
-
The representations and warranties in these Terms are final. Apart from these representations and warranties there are no express or implied representations or warranties respecting these Terms and/or Xerof Services.
-
Neither Party shall have the right to assign or transfer these rights and obligations under these Terms, in full or in part, to any third party without the prior written and express consent of the other Party. The Parties agree that any assignment or transfer in violation of this Section shall be null and void.
-
Xerof shall be entitled to use subcontractors to perform the obligations under these Terms.
-
Xerof reserves the right to change these Terms at any time, effective immediately upon accepted by the User upon the next login to the User Account.
-
These Terms contain the entire agreement between the parties regarding the subject matter hereof and supersedes all understandings and agreements whether written or oral.
-
If any provision of these Terms should be invalid in any jurisdiction under applicable law, the legality and enforceability of the remaining provisions hereof shall not in any way be affected or impaired thereby. In such an event, the Parties commit themselves to compose a legally valid replacement rule which approaches the invalid provision as closely as possible within the economic intent of this Agreement. With this in mind, these Terms will be interpreted as though the invalid clause had been omitted from the outset.
-
If any Party waives the enforcement or exercise of its contractual right in a particular case, this may not be considered a general waiver of the respective right or any other contractual right or the exercise and enforcement thereof.
FE Swiss Financial AG
last updated 15 Apr 2026
Privacy policy
Last updated 15 April 2026.
I. General Information
1. Name and Address of the Controller
The controller within the meaning of the Swiss Data Protection Act ("FADP"), EU General Data Protection Regulation ("GDPR") (if applicable) and other national data protection laws and regulations that determine the purposes and means of processing personal data is:
FE Swiss Financial AG
Gubelstrasse 11
6300 Zug
Switzerland
The data protection coordinator of the controller can be contacted at:
E-mail address: privacy@xerof.ch
2. Scope of Processing of Personal Data
We only process personal data if this is necessary to provide a functional website as well as our contents and services. The processing of our users' personal data is normally only carried out with your prior consent, except those cases where prior consent cannot be obtained for factual reasons and the processing of personal data is permitted by law.
3. Legal Basis for Processing (if required)
If the data subject has given his/her consent to the processing of personal data, art. 6 (1) (a) GDPR serves as the legal basis for the processing.
If the processing of personal data is necessary for the performance of a contract to which the data subject is party, art. 6 (1) (b) GDPR serves as the legal basis for the processing. This also applies to processing operations that are necessary to carry out pre-contractual measures.
If the processing of personal data is necessary for compliance with legal obligation to which our company is subject, art. 6 (1) (c) GDPR serves as the legal basis for the processing.
If the processing of personal data is necessary to protect the vital interests of the data subject or another natural person, article 6 (1) (d) GDPR serves as the legal basis for the processing.
If the processing of personal data is necessary for the purposes of the legitimate interests pursued by our company or a third party and where such interests are not overridden by the interests, fundamental rights and freedoms of the data subject which require protection of personal data, art. 6 (1) (f) GDPR serves as the legal basis for the processing.
4. Erasure and Storage of Personal Data
The personal data of the data subject will be erased or blocked as soon as it is no longer necessary in relation of the purpose of storage. Furthermore, personal data may be stored if this has been required by regulations, laws or other provisions to which our company is subject. The personal data will also be blocked or erased if a storage period prescribed by the aforementioned standards expires, unless there is a need for further storage of the data for the conclusion or performance of a contract.
II. Provision of the Website and Creation of Log Files
1. Description and Scope of Processing of Personal Data
Every time you visit our website, our system automatically collects the following data and information from the computer system of the calling computer:
- Information relating to the browser type and version used
- The user's operating system
- The user's Internet service provider
- The user's IP address
- Date and time of access
- Websites from which the user's system reaches our website
- Websites accessed by the user's system via our website
The data is also stored in the log files of our system but is not stored together with other personal data of the user. Not affected by this are the IP addresses of the user or other data that enable the assignment of the data to a user.
2. Legal Basis for Processing (if required)
The legal basis for the temporary storage of personal data and log files is art. 6 (1) (f) GDPR.
3. Purposes of Processing
The temporary storage of the IP address by the system is necessary to enable the website to be delivered to the user's computer. For this, the IP address must remain stored for the duration of the session.
The personal data is stored in log files to ensure the functionality of the website. In addition, the data serves us to optimize the website and to ensure the security of our information technology systems. The data is not evaluated for marketing purposes in this context.
These purposes also represent our legitimate interest in data processing within the meaning of art. 6 (1) (f) GDPR (if required).
4. Period of Storage
The personal data will be erased as soon as it is no longer necessary to achieve the purpose for which it was collected. In the case of the collection of data for the provision of the website, the data will be deleted when the respective session has ended.
If the personal data is stored in log files, it will be deleted after seven days at the latest. Further storage is possible. In this case, the IP addresses of the users are deleted or alienated so that the calling client can no longer be assigned.
5. Possibility of Objection and Erasure
The collection of personal data for the provision of our website and the storage of personal data in log files is necessary for the operation of the website. Consequently, there is no possibility of objection.
III. Use of Cookies
1. Description and Scope of Processing of Personal Data
Our website uses cookies. For further information see our Cookie Policy https://xerof.com/cookie.
When you visit our website, an information banner informs you about the use of cookies for analytical purposes and refers you to this privacy policy. In this context, there is also a note on how the storage of cookies can be prevented.
When accessing our website, the user is informed about the use of cookies for analytical purposes and his or her consent to the processing of the personal data used in this context is obtained.
2. Legal Basis for Processing (if required)
The legal basis for the processing of personal data using technically necessary cookies is art. 6 (1) (f) GDPR.
The legal basis for the processing of personal data using other cookies is art. 6 (1) (a) GDPR.
3. Purpose of Processing
The purpose of using technically necessary cookies is to simplify the use of websites for users. Some functions of our website cannot be offered without the use of cookies. For these functions concerned it is necessary that the browser is recognized even after a page change. These purposes represent also our legitimate interest to process personal data within the meaning of art. 6 (1) (f) GDPR (if required). We do not use these tools to market services to users or entities in the EU/EEA. IP address and geolocation data may be processed to restrict access from jurisdictions where Xerof is not authorized, including the EU/EEA. For more detailed information see our Cookie Policy https://xerof.com/cookie.
The analysis cookies are used to improve the quality of our website and its content. Through the analysis cookies we learn how the website is used and can thus continuously optimize our offer. For more detailed information see our Cookie Policy https://xerof.com/cookie.
IV. Newsletter
1. When Subscribing to Our Newsletter
When you subscribe to our newsletter, we collect personal data via its newsletter service provider MailChimp. This data may include:
- IP address of the calling computer
- Date and time of registration
- Name (first name and surname)
This data is collected and processed for the purpose of subscribing you to and sending you our newsletter with updates as well as ensuring the security and reliability of the newsletter service.
2. Legal Basis for Processing (if required)
The legal basis for this processing is your consent (art. 6 (1) (a) GDPR) as provided in the double opt-in confirmation part of our newsletter sign-up process. This data will be stored as long as we have your consent to send you a newsletter. If you wish to unsubscribe from our newsletter, you can do so by clicking on the link at the end of each newsletter or by sending us an email. You can read more about MailChimp's data access as well as their legitimate interests in and purposes for collecting this data here.
3. When Receiving Our Newsletter
If you have subscribed to our newsletter, each time you receive and open a newsletter, a third-party service provider MailChimp collects data, including:
- Email address
- Date and time you opened the email
- Location, as indicated by your IP address
This data is collected and processed by us for the purpose of ensuring the security and reliability of the newsletter service as well as our legitimate interest in the effectiveness of and general user interest in our newsletter. Because our newsletter service is hosted by MailChimp, you can view more information about the data they collect and their legitimate interests in and purposes for collecting this data here.
4. Period of Storage
The data will be erased as soon as it is no longer necessary to achieve the purpose for which it was collected. The user's email address will therefore be stored for as long as the subscription to the newsletter is active. The other personal data collected during the registration process will generally be deleted after a period of seven days.
5. Possibility of Objection and Erasure
The subscription to the newsletter can be cancelled by the user concerned at any time. For this purpose, there is a corresponding link in every newsletter. This also makes it possible to withdraw the consent to the storage of personal data collected during the registration process.
V. Registration and User KYC/AML Check
1. Description and Scope of Processing of Personal Data
On our website, we offer users the opportunity to register and open a user account by providing personal data. The data entered in the input mask is transmitted to us and stored by us. The data will not be transmitted to third parties. The following personal data is collected during the registration process:
- Title
- Name (first name and surname)
- Company name
- Language
- Address (street, zip code, city, state, country)
- Nationality
- Date of birth
- Phone number
- Email address
- Personal background information regarding professional activity
- Copies of passport, identity card or utility bill
- Contact details from recipient
- Photo of international passport
- Photo of you and your document of identification
- Proof of residency
- Expected trading volume
- Annual income
- Type of assets
- Origin of funds
- Virtual asset address
- Additional information which may be required by AML regulation
- User's consent to this Privacy Policy
At the time of registration, the following data is stored:
- The IP address of the user
- Date and time of registration
2. Legal Basis of Processing (if required)
The data collected during registration serves to perform a contract to which the user is party or to implement pre-contractual measures and to comply with a legal obligation to which we are subject. The legal basis for the processing of the data is therefore art. 6 (1) (b) GDPR and art. 6 (1) (c) GDPR.
3. Purpose of Processing
The registration of the user is necessary for the performance of a contract with the user or for the implementation of pre-contractual measures and to comply with AML regulations.
4. Period of Storage
The data will be erased as soon as it is no longer necessary to achieve the purpose for which it was collected.
Consequently, the personal data collected during the registration process to perform a contract or to carry out pre-contractual measures are erased as soon as it is no longer required for the execution of the contract. Even after conclusion of the contract, it may still be necessary to store personal data of the contractual partner in order to meet contractual or legal obligations.
5. Possibility of Objection and Erasure
As a user you have the possibility to cancel the registration and to change the data stored about you at any time.
If the personal data is necessary to perform a contract or to carry out pre-contractual measures, an early erasure of the data is only possible if neither contractual nor legal obligations prevent a deletion.
VI. Contact Form and E-Mail Contact
1. Description and Scope of Processing of Personal Data
There is a contact form on our website which can be used for electronic contact. If a user takes advantage of this possibility, the following data entered in the contact form will be transmitted to us and will be stored:
- Email address
- Company name
- First name
- Last name
- Phone number
- Address
- Message
At the time the message is sent, the following data is stored in addition:
- IP address of the user
- Date and time of registration
Your consent is obtained for the processing of the personal data within the scope of the sending process and reference is made to this Privacy Policy. Alternatively, you can contact us via the email address provided. In this case, the user's personal data transmitted by email will be stored. In this context, the personal data will not be transmitted to third parties. The data is used exclusively for processing the conversation.
2. Legal Basis for Processing (if required)
The legal basis for the processing of data is art. 6 (1) (a) GDPR if the user has given his consent.
The legal basis for the processing of personal data transmitted in the course of sending an email is art. 6 (1) (f) GDPR. If the e-mail contact aims at the conclusion of a contract, then the additional legal basis for the processing is art. 6 (1) (b) GDPR.
3. Purpose of Processing
The processing of personal data from the contact form serves us only for the treatment of the establishment of contact. The personal data collected in the course of sending an email represent also our legitimate interest in processing of personal data. The other personal data processed during the sending process serve to prevent misuse of the contact form and to ensure the security of our information technology systems.
4. Period of Storage
To offer a good user experience and to safeguard our ability to comply with our contractual obligations, we need to have access to all user communication.
Consequently, the personal data from the contact form or the personal data that is sent by email will be erased not earlier than after 10 years.
5. Possibility of Objection and Erasure
You have the possibility to withdraw your consent to the processing of personal data concerning you at any time. If you contact us by e-mail, you can object to the storage of your personal data at any time. In this case, the conversation cannot be continued. All personal data stored in the course of contacting us will be deleted in this case.
VII. Web Analysis by Google Analytics
1. Scope of processing of personal data
On our website we use Google Analytics, a web analysis service of Google Inc. ("Google"). Google Analytics uses cookies, which are saved on the user's computer and which enable an analysis of the use of the website (for cookies see above). If individual pages of our website are accessed, the following data is stored:
- IP address of the user's calling system
- Anonymized IP address and location (city and country)
- Accessed website
- Website from which the user has accessed the accessed website (referrer)
- Sub-pages accessed from the accessed website
- Browser information
- Time spent on the website
- Frequency with which the website is accessed
- Language settings
- User ID
- Aggregated data (if ads personalization is enabled)
To ensure that any personal reference can be excluded when processing your IP address, we have activated the "_anonymizeIp()" function at Google. As a result, IP addresses are not stored completely and are only processed further in abbreviated form. As far as the data collected about you contains a personal reference, this will be excluded immediately, and the personal data will be deleted immediately.
The information generated by Google's cookies about your use of this website is usually transferred to a Google server in the USA and stored there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide the website operator with other services relating to website and Internet use. Google will shorten the user's IP address within member states of the European Union or in other signatory states to the Agreement on the European Economic Area prior to transmission. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and shortened there. The IP address transmitted by the user's browser within the scope of Google Analytics is not merged with other Google data.
We have concluded a data processing agreement with Google and fully implement the strict requirements of the FDPA and the GDPR (if applicable) for the use of Google Analytics.
2. Legal Basis of Processing (if required)
The legal basis for processing users' personal data is art. 6 (1) (f) GDPR.
3. Purpose of Processing
The processing of users' personal data enables us to analyze the surfing behavior of our users. We are in a position to compile information about the use of the individual components of our website by evaluating the data obtained. This helps us to continuously improve our website and its user-friendliness. For these purposes, it is also in our legitimate interest to process the personal data within the meaning of art. 6 (1) (f) GDPR (if required). By anonymizing the IP address, users' interest in protecting their personal data is sufficiently taken into account.
4. Period of Storage
The data will be deleted as soon as it is no longer needed for our recording purposes.
5. Possibility of Objection and Erasure
Cookies are saved on the user's computer and transmitted to our site. Therefore, your Internet browsers should allow you to control the use of cookies. You can deactivate or restrict the transmission of cookies by changing the settings in your Internet browser. Cookies that have already been saved can be deleted at any time. This can also be done automatically. If cookies are deactivated, it may no longer be possible to use all functions of the website in full.
Information of the third party Google:
- Address: Google Dublin, Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland
- User conditions: https://www.google.com/analytics/terms/de.html
- Overview of data protection: https://www.google.com/intl/de/analytics/learn/privacy.html
- Privacy policy: https://www.google.de/intl/de/policies/privacy
VIII. Tools
We use a variety of technologies, tracking tools, web controlling technologies and analytical tools to help us design and continually improve our website, products and services. Cookies may also be used for this purpose, but only to collect and store data in a pseudonymous form. The data is not used to personally identify the user of the website and is not combined with data about the bearer of the pseudonym.
• HubSpot
On our website, we use functions of the CRM platform HubSpot, which is offered by HubSpot Inc., based in the USA. We have concluded an order data processing contract with HubSpot Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using HubSpot. You can find more information on the handling of personal data in the HubSpot privacy policy: https://legal.hubspot.com/privacy-policy.
• Google Services
In the course of our business activities, we use functions from Google (e.g. Gmail, Google Calendar, Google Chat, Google Meet, Google Drive), which is offered by Google Ireland, based in Ireland. We have concluded an order data processing contract with Google Ireland and fully implement the requirements of the FADP and the GDPR (if applicable) when using the services mentioned above from Google. You can find more information on the handling of personal data in the Google privacy policy: https://policies.google.com/privacy?hl=en-US.
• Telegram
In the course of our business activities, we use functions of the messaging platform Telegram, which is offered by Telegram FZ-LLC, based in Dubai. We have concluded an order data processing contract with Telegram FZ-LLC and fully implement the requirements of the FADP and the GDPR (if applicable) when using Telegram. You can find more information on the handling of personal data in the Telegram privacy policy: https://telegram.org/privacy.
• Cookiebot
On our website, we use functions of the cookie management platform Cookiebot, which is offered by Usercentrics A/S, based in Denmark. We have concluded an order data processing contract with Usercentrics A/S and fully implement the requirements of the FADP and the GDPR (if applicable) when using Cookiebot. You can find more information on the handling of personal data in the Cookiebot privacy policy: https://www.cookiebot.com/en/privacy-policy/.
• Zapier
In the course of our business activities, we use functions of the workflow automation platform Zapier, which is offered by Zapier Inc., based in the USA. We have concluded an order data processing contract with Zapier Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Zapier. You can find more information on the handling of personal data in the Zapier privacy policy: https://zapier.com/privacy.
In the course of our business activities, we use functions of the messaging platform WhatsApp, which is offered by WhatsApp Ireland Limited, based in Ireland. We have concluded an order data processing contract with WhatsApp Ireland Limited and fully implement the requirements of the FADP and the GDPR (if applicable) when using WhatsApp. You can find more information on the handling of personal data in the WhatsApp privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea.
• Tresorit
Cloud storage solution with end-to-end encryption for storing, syncing, and sharing confidential data. In the course of our business activities, we use functions of the content collaboration platform Tresorit, which is offered by Tresorit AG, based in Switzerland. We have concluded an order data processing contract with Tresorit AG and fully implement the requirements of the FADP and the GDPR (if applicable) when using Tresorit. You can find more information on the handling of personal data in the Tresorit privacy policy: https://tresorit.com/legal/privacy-policy.
• Zoom
In the course of our business activities, we use functions of the communication and collaboration platform Zoom, which is offered by Zoom Video Communications Inc., based in the USA. We have concluded an order data processing contract with Zoom Video Communications Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Zoom. You can find more information on the handling of personal data in the Zoom privacy policy: https://explore.zoom.us/en/privacy/.
• Mailchimp
On our website, we use functions of the marketing management platform Mailchimp, which is offered by Intuit Inc., based in the USA. We have concluded an order data processing contract with Intuit Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Mailchimp. You can find more information on the handling of personal data in the Mailchimp privacy policy: https://www.intuit.com/privacy/statement/.
• Attio
In the course of our business activities, we use functions of the CRM platform Attio, which is offered by Attio Ltd., based in the UK. We have concluded an order data processing contract with Attio Ltd. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Attio. You can find more information on the handling of personal data in the Attio privacy policy: https://attio.com/legal/privacy.
• Slack
In the course of our business activities, we use functions of the messaging and collaboration platform Slack, which is offered by Salesforce Inc., based in the USA. We have concluded an order data processing contract with Salesforce Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Slack. You can find more information on the handling of personal data in the Slack privacy policy: https://slack.com/trust/privacy/privacy-policy.
• Crymbo
In the course of our business activities, we use functions of the institutional-grade digital asset management infrastructure platform Crymbo, which is offered by Crymbo Ltd., based in the UK. We have concluded an order data processing contract with Crymbo Ltd. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Crymbo. You can find more information on the handling of personal data in the Crymbo privacy policy: https://crymbo.com/privacy-policy.
• HelloSign
In the course of our business activities, we use functions of the electronic signature platform HelloSign, which is offered by Dropbox Inc., based in the USA. We have concluded an order data processing contract with Dropbox Inc. and fully implement the requirements of the FADP and the GDPR (if applicable) when using HelloSign. You can find more information on the handling of personal data in the HelloSign privacy policy: https://www.hellosign.com/privacy.
• Base44
On our website, we use functions of the application development platform Base44, which is offered by Wix.com Ltd. We have concluded an order data processing contract with Wix.com Ltd. and fully implement the requirements of the FADP and the GDPR (if applicable) when using Base44. You can find more information on the handling of personal data in the Base44 privacy policy: https://www.base44.com/privacy.
IX. Social Plug-ins
We do not use social media plug-ins on our website. If our website contains icons of social media providers (e.g. LinkedIn, Twitter, Telegram), we use these only for as passive links to the websites of the respective social media platforms.
X. Disclosure of Data to Third Parties
In order to perform our contracts, fulfil our legal obligations, protect our legitimate interest and the other purposes and legal grounds set out above, we may disclose your data to third parties, in particular to the following categories of recipients:
- Group companies: For internal administrative and operational purposes.
- Offerings of third parties: To facilitate partnerships and joint ventures.
- Third-party wallets: To enable transactions and settlements within the crypto asset ecosystem.
- Service providers: To provide services on our behalf, such as customer support and technical infrastructure.
- Contractual partners including customers: To fulfil our contractual obligations and provide services.
- Legal authorities: To comply with the law and respond to lawful requests.
- Regulatory bodies: To comply with financial regulations and other legal obligations.
- Financial institutions: To facilitate financial transactions, settlements, and other financial activities.
- Auditors and consultants: For audit, compliance, and business optimisation purposes.
- Payment processors: To facilitate payments related to our services.
- Risk assessment agencies: For risk management, including credit risk and fraud prevention.
- Data analytics providers: To analyse usage patterns and improve our services.
- Security service providers: To ensure the security and integrity of our services and data.
- Marketing and advertising partners: To provide targeted offers and promotions, where permitted by law.
- Successors: In the event of a merger, acquisition, bankruptcy, or sale of some or all of our assets.
- Other third parties: As required or permitted by law, including to comply with national security or law enforcement requirements.
XI. Transfer of Data Abroad
As we have explained above, we disclose data to other parties, not all of them located in Switzerland. Your data may be processed in the European Economic Area (EEA) and in exceptional circumstances also in countries outside the EEA and around the world, which includes countries that do not provide the same level of data protection as Switzerland or the EEA and are not recognized as providing an adequate level of data protection. We only transfer data to these countries when it is necessary for the performance of a contract or for the exercise or defence of legal claims, or if such transfer is based on your explicit consent or subject to safeguards that assure the protection of your data, such as the European Commission approved standard contractual clauses (adapted to Switzerland, if applicable).
XII. Profiling and Automated Decision Making
We might analyse aspects of your individual's personality, behaviour, interest and habits make predictions or decisions about them for the purposes laid out above, e.g. to perform statistical analysis or to prevent misuse and security risks. This analysis identifies correlations between different behaviours and characteristics to create profiles for individuals. For example, we may use profiling to determine in which products or services you might be interested. We may also use profiling to assess your creditworthiness. We do not use profiling that can produce legal effects concerning you or similarly significantly affect you without human review.
In certain circumstances, automated decision taking might be necessary for reasons of efficiency and consistency. In such cases, we will inform you accordingly and take the measures required by applicable law.
XIII. Rights of the Data Subject
You have various rights in relation with the processing of your personal data, depending on the applicable data protection law (FDPA, GDPR, other national data protection laws or regulations). Please be aware that we reserve the right to enforce statutory restrictions as required, for example if we are obliged to retain or process certain data, have an overriding interest (insofar as we may invoke such interests) or need the data for asserting claims.
1. Right of Access
You can ask the controller to confirm whether personal data concerning you is being processed by us. You have the right to request a copy of the personal data that we hold about you. There are exceptions to this right, so that access may be denied if, for example, making the information available to you would reveal personal data about another person, or if we are legally prevented from disclosing such information.
2. Right to Rectification
You have the right to obtain from the controller the rectification and/or completion of incorrect or incomplete personal data concerning you. We encourage you to contact us to let us know if any of your personal data is not accurate or changes, so that we can keep your personal data up to date.
3. Right to Restriction of Processing
You have the right to ask us to restrict the processing of your personal information in certain circumstances.
4. Right to Erasure
You have the right to require us to erase your personal data when the personal data is no longer necessary for the purposes for which it was collected, or when, among other things, your personal data have been unlawfully processed.
5. Right to Data Portability
You have the right to receive the personal data concerning you which you have provided to the controller in a structured, commonly used and machine-readable format. In addition, you have the right, under certain conditions, to have the personal data transmitted directly from one controller to another.
6. Right to Withdraw the Consent
You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another legal ground for the processing.
7. Right to Object
Under applicable data protection law, you have the right to object at any time to the processing of personal data pertaining to you under certain circumstances, in particular where your data is processed in the public interest, on the basis of a balance of interests or for direct marketing purposes.
If you like to exercise the above-mentioned rights, please contact us at privacy@xerof.ch or the contact details provided under Section I.1 unless otherwise specified or agreed. Please note that we need to identify you to prevent misuse, e.g. by means of a copy of your ID card or passport, unless identification is possible otherwise.
8. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the state of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of personal data concerning you infringes the FDPA or the GDPR (if applicable).
XIV. Updating and changing this Privacy Notice
Due to continuous development of our website and the contents thereof, changes in law or regulatory requirements, we might need to change this privacy notice from time to time. Our current privacy notice can be found at our website.
FE Swiss Financial AG
last updated 15 Apr 2026