Get Started Sign In

Privacy Policy

Last Updated: 1 July 2026

1 Purpose and Scope

1.1 This Privacy Policy ("Policy") describes how Axi Labs AG, a company incorporated under the laws of Switzerland and registered in the Commercial Register under company number CHE-299.451.950 ("Axi", "Company", "we", "us", or "our"), collects, processes, stores, transfers, discloses, and otherwise handles personal data in connection with its business activities, website, platform, systems, services, and related operations.

1.2 Axi provides financial intermediary, transaction, liquidity, settlement, and related technology services for institutional and corporate clients, including money service businesses, payment service providers, financial institutions, and other commercial counterparties. In the course of providing such services, Axi may process personal data relating to natural persons associated with those entities, transactions, payment instructions, settlement flows, compliance reviews, or business relationships.

1.3 This Policy applies to personal data processed by Axi in connection with, including but not limited to:

1.4 This Policy may apply to personal data relating to, among others:

1.5 This Policy does not apply to information that has been irreversibly anonymised so that no natural person can be identified, directly or indirectly.

1.6 Certain products, services, counterparties, jurisdictions, financial partners, or regulated payment systems may impose additional privacy, confidentiality, banking secrecy, payment transparency, travel rule, or data handling requirements. In such cases, those specific requirements shall apply in addition to this Policy.

2 Data Controller and Contact

2.1 Unless otherwise expressly stated, Axi Labs AG is the controller of personal data processed under this Policy and determines the purposes and means of such processing.

Axi Labs AG
Baarerstrasse 12
6300 Zug
Switzerland
Company Registration Number: CHE-299.451.950

Data protection enquiries and data subject requests may be submitted to:
Email: compliance@axiym.io

2.2 Axi may request additional information to verify the identity, authority, and entitlement of any person submitting a data protection request.

2.3 In certain circumstances, Axi may process personal data jointly with, or in parallel to, regulated counterparties, banking partners, payment institutions, service providers, or other financial intermediaries. Where another entity determines the purposes and means of processing independently, such entity may act as an independent controller with respect to the relevant processing activities.

3 Applicable Legal Framework

3.1 Axi processes personal data in accordance with applicable data protection, confidentiality, and regulatory obligations, including, where relevant:

3.2 Because Axi operates within regulated financial, cross-border payment, settlement, and digital asset environments, certain legal obligations concerning recordkeeping, transaction transparency, sanctions controls, payment messaging, law enforcement cooperation, fraud prevention, and regulatory reporting may limit or override certain privacy-related rights otherwise available under general data protection law.

3.3 Nothing in this Policy shall be interpreted as limiting any statutory obligation imposed upon Axi by applicable law, financial regulation, supervisory requirements, court order, governmental instruction, sanctions obligation, or lawful regulatory request.

4 Categories of Personal Data Processed

4.1 Depending on the nature of the business relationship, services provided, regulatory obligations, and transaction flows involved, Axi may process different categories of personal data.

4.2 Identity and Verification Data. Personal data used to identify, verify, authenticate, or validate the identity of individuals associated with clients, counterparties, transactions, or business relationships. This may include full name, date of birth, place of birth, nationality, citizenship, residential address, government-issued identification documents, passport or national identification information, residence permit information, photographs, identity verification materials, signature specimens, authorised signatory information, and other identification information required to satisfy legal, contractual, regulatory, or operational obligations.

4.3 Corporate and Relationship Data. Personal data relating to an individual's role, authority, ownership, control, or relationship to a corporate entity, organisation, or commercial counterparty. This may include employer or affiliated entity, job title, function, authority to represent or bind an entity, shareholding or ownership information, beneficial ownership or controlling person status, board membership, executive responsibilities, governance role, relationship history, and account status.

4.4 Contact Data. Personal data used for communication, relationship management, operational coordination, or service delivery. This may include business email address, telephone or mobile number, mailing or business address, communication preferences, and correspondence records.

4.5 Transaction and Settlement Data. Personal data contained in or associated with financial transactions, liquidity operations, settlement activities, account movements, payment-related services, digital asset transfers, or related operational workflows. This may include transaction identifiers, reference numbers, transaction timestamps, transaction amount and currency, exchange rate and foreign exchange details, settlement instructions, account numbers, IBANs, virtual account identifiers, wallet addresses, blockchain-related transaction identifiers, payout or settlement destinations, payment references, transaction history, reconciliation records, and settlement logs.

4.6 Payment Messaging and Travel Rule Data. Personal data contained in payment messages, settlement instructions, funds transfer records, digital asset transfer records, or regulated payment messaging standards, including information processed for payment transparency, sanctions screening, travel rule, interoperability, and payment compliance purposes. This may include originator information, beneficiary information, customer identifiers, account or wallet identifiers, address or jurisdiction information where required, receiving institution information, destination jurisdiction, payment purpose, structured remittance data, routing data, intermediary institution data, correspondent data, message validation results, and screening results.

4.7 Compliance and Risk Data. Personal data processed for financial crime prevention, legal compliance, internal governance, and risk management. This may include sanctions screening results, politically exposed person ("PEP") screening results, adverse media or reputational screening results, anti-money laundering risk assessments, fraud indicators, suspicious activity markers, source-of-funds or source-of-wealth information, internal risk classifications, flags, scores, escalation records, investigation records, case notes, audit findings, regulatory reporting records, and law-enforcement or regulatory correspondence.

4.8 Technical and Usage Data. Personal data generated through interaction with Axi websites, systems, platforms, APIs, applications, or technical infrastructure. This may include IP address, device identifiers, browser and operating system information, authentication and login records, session logs, API access logs, system usage metadata, cookies or similar technical identifiers, diagnostic logs, performance logs, security logs, and audit logs.

4.9 Communications and Business Records. Personal data contained in communications, records, files, and business documentation created or maintained in the ordinary course of business. This may include emails, written correspondence, meeting notes, call records where lawfully maintained, contractual records, onboarding documentation, support or service requests, and internal operational records.

4.10 Website, Marketing, and Preference Data. Where applicable, Axi may process website usage information, newsletter preferences, marketing communication preferences, event participation information, opt-in and opt-out records, and similar business contact information. KYC, AML/CFT, sanctions screening, identity documents, and transaction compliance records are not used for general marketing purposes.

5 Sources of Personal Data and Third-Party Personal Data

5.1 Axi may collect personal data directly from data subjects or indirectly through clients, counterparties, service providers, public sources, regulated financial institutions, payment systems, digital asset infrastructure, or other lawful third-party sources.

5.2 Data Provided Directly by Data Subjects. Axi may collect personal data directly from individuals when such individuals communicate with Axi, submit documentation, access Axi systems, use Axi services, or otherwise interact with Axi. This may include data provided during onboarding, due diligence, contractual negotiations, service implementation, regulatory or compliance-related communications, account setup, authentication processes, and ongoing operational or commercial interactions.

5.3 Data Provided by Clients and Counterparties. Because Axi primarily operates on a business-to-business basis, a substantial portion of personal data processed by Axi may be received from corporate clients, regulated counterparties, payment institutions, financial intermediaries, banking partners, or other authorised third parties. Such data may relate to authorised representatives, directors, officers, beneficial owners, controlling persons, shareholders, originators, beneficiaries, remitters, recipients, and other individuals associated with payment, settlement, liquidity, digital asset, or other transactions.

5.4 Transaction, Payment, Settlement, and Digital Asset Infrastructure. Personal data may be generated, transmitted, or received through banking and payment rails, settlement and reconciliation systems, API integrations, payment messaging systems, ISO 20022, SWIFT, blockchain or distributed ledger infrastructure, transaction monitoring systems, and internal operational workflows.

5.5 Public, Regulatory, and Commercial Sources. Axi may obtain personal data from publicly available, regulatory, or commercial information sources where necessary for compliance, verification, due diligence, fraud prevention, sanctions screening, adverse media screening, or risk assessment. Such sources may include commercial registries, sanctions lists, PEP databases, watchlists, regulatory notices, court records, insolvency records, adverse media databases, and other lawfully accessible sources.

5.6 Service Providers and Third Parties. Axi may receive personal data from service providers, technology vendors, screening providers, infrastructure providers, advisers, professional service firms, or financial partners engaged in connection with Axi's operations.

5.7 Where a client, counterparty, or other third party provides personal data relating to another individual, including a beneficial owner, director, officer, employee, authorised signatory, representative, originator, beneficiary, remitter, recipient, account holder, wallet holder, or controlling person, that client, counterparty, or third party is responsible for ensuring that the relevant individual has been appropriately informed that their personal data may be provided to Axi for onboarding, KYC/AML/CFT, sanctions screening, transaction processing, settlement, regulatory compliance, fraud prevention, and related purposes. Where required by applicable law, that client, counterparty, or third party must obtain any necessary consent, authority, or other valid basis before providing such personal data to Axi.

6 Purposes of Processing

6.1 Axi processes personal data only for specified, legitimate, and lawful business, regulatory, operational, security, and compliance purposes.

6.2 Client Onboarding and Due Diligence. Personal data may be processed to establish, assess, approve, and maintain business relationships with clients, counterparties, service providers, and commercial partners. This includes client identification and verification, KYB and KYC procedures, beneficial ownership verification, authority verification, risk assessment, onboarding approval, contractual relationship establishment, and ongoing due diligence.

6.3 Transaction Execution and Settlement. Personal data may be processed to facilitate transaction processing, liquidity operations, foreign exchange, digital asset transfers, settlement, reconciliation, payment messaging, account administration, and associated operational services. This includes transaction initiation, validation, routing, monitoring, settlement processing, liquidity allocation, exception handling, support, and reconciliation.

6.4 Regulatory Compliance and Financial Crime Prevention. Personal data may be processed to comply with legal and regulatory obligations relating to anti-money laundering, sanctions, counter-terrorist financing, fraud prevention, travel rule obligations, payment transparency, tax, recordkeeping, regulatory reporting, and financial crime prevention. This includes AML screening, sanctions screening, PEP screening, adverse media screening, suspicious activity detection, fraud detection, regulatory reporting, internal investigation, and cooperation with competent authorities.

6.5 Risk Monitoring and Operational Control. Personal data may be processed for internal governance, risk management, security monitoring, anomaly detection, operational oversight, escalation, and control purposes. This includes risk classification, transaction monitoring, exception management, fraud and abuse detection, operational risk management, and internal escalation procedures.

6.6 Corporate Administration and Business Operations. Personal data may be processed for lawful business administration and corporate operational purposes, including relationship management, communications, governance, internal reporting, audit support, legal and contractual administration, financial administration, and dispute management.

6.7 Technology, Security, and Service Improvement. Personal data may be processed to operate, secure, maintain, improve, and monitor Axi systems, infrastructure, APIs, digital services, and technical environments. This includes cybersecurity monitoring, access control, incident detection, authentication, system diagnostics, infrastructure maintenance, service performance optimisation, backup, logging, and operational resilience.

6.8 Communications and Marketing. Axi may process business contact data to communicate with clients, counterparties, service providers, and other business contacts, including for service updates, operational notices, regulatory communications, relationship management, events, and marketing communications where permitted by applicable law. Individuals may object to or opt out of marketing communications where required by applicable law.

6.9 Legal Claims and Protection of Rights. Personal data may be processed to establish, exercise, defend, enforce, or protect legal rights, contractual rights, regulatory rights, security interests, or claims, and to respond to disputes, investigations, legal proceedings, regulatory enquiries, or enforcement actions.

6.10 Axi shall not process personal data for purposes materially incompatible with those described in this Policy unless otherwise permitted or required by applicable law.

7 Legal Basis and Justification for Processing

7.1 Where required under applicable law, Axi processes personal data on one or more lawful grounds or justifications.

7.2 Such lawful grounds or justifications may include:

7.3 Where consent constitutes the legal basis for processing, such consent may be withdrawn at any time, subject to legal, regulatory, contractual, operational, or evidentiary limitations and without affecting the lawfulness of prior processing.

8 Automated Processing, AI-Supported Tools, Profiling, and Monitoring

8.1 Axi may use automated systems, rule-based controls, analytical tools, machine-learning tools, artificial intelligence systems, or AI-supported tools to support compliance, risk management, fraud prevention, transaction monitoring, sanctions screening, operational oversight, cybersecurity, service administration, and internal reporting.

8.2 Such tools may be used to assist with:

8.3 AI-supported tools may process personal data contained in onboarding documents, identification materials, corporate documents, ownership and control information, transaction records, payment messages, wallet or account information, communications, screening results, risk assessments, and other information described in this Policy.

8.4 Axi uses automated and AI-supported outputs as decision-support tools. Such outputs are intended to assist human review, compliance assessment, operational control, and risk management. Axi does not rely solely on automated or AI-generated outputs to make decisions that produce legal effects or similarly significant effects for an individual, unless such automated processing is permitted or required by applicable law, regulation, sanctions obligations, security requirements, or other lawful grounds.

8.5 Where Axi makes an automated individual decision that produces legal effects or similarly significant effects for an individual, Axi will provide the information and rights required under applicable law, subject to legal, regulatory, security, AML/CFT, sanctions, fraud-prevention, confidentiality, and other lawful limitations.

8.6 Axi does not use KYC/AML/CFT documents, identity documents, or transaction data to train public AI models. Where Axi uses third-party AI or technology service providers, Axi applies appropriate contractual, confidentiality, security, access control, and data protection safeguards. Where personal data is transferred to or accessed from a country that does not provide an adequate level of data protection, Axi will apply appropriate safeguards as required under applicable Swiss data protection law, unless an exception under applicable law applies.

9 Cookies, Analytics, and Similar Technologies

9.1 Axi websites and digital services may use cookies, analytics tools, log files, pixels, tags, and similar technologies to operate the website, maintain security, remember user preferences, analyse usage, improve functionality, monitor performance, and, where applicable, support communications or marketing.

9.2 Cookies may include essential cookies required for the operation and security of the website, functionality cookies used to remember preferences, analytics or performance cookies used to understand how the website is used, and marketing or communication cookies where applicable.

9.3 Where required by applicable law, Axi will request consent before placing non-essential cookies or similar technologies. Users may manage or disable cookies through their browser settings or, where available, through cookie preference tools made available on the website. If cookies are disabled, certain website functions may not operate correctly.

9.4 Axi may use Google Analytics or similar web analytics services. Such providers may process technical and usage data, such as IP address, device identifiers, browser information, pages visited, date and time of access, referring websites, and interaction data. Where applicable, Axi will use available privacy settings, such as IP anonymisation or similar measures, and will apply applicable data protection requirements.

9.5 Axi may use tracking technologies in newsletters or marketing emails to understand whether communications have been opened or interacted with, where permitted by applicable law. Recipients may opt out of marketing communications where required by applicable law.

10 Disclosure and Sharing of Personal Data

10.1 Axi may disclose personal data where reasonably necessary for legitimate business purposes, service delivery, transaction processing, settlement, regulatory compliance, security, audit, legal obligations, or other purposes described in this Policy.

10.2 Personal data may be shared with:

10.3 Axi requires service providers processing personal data on its behalf to implement appropriate confidentiality, security, and data protection safeguards.

10.4 Axi may disclose personal data without prior notice where required or permitted by applicable law, regulation, sanctions obligation, court order, supervisory request, law enforcement request, contractual arrangement, or compliance requirement.

11 International Data Transfers

11.1 Due to the international nature of Axi's business, personal data may be processed, accessed, transferred, or stored outside Switzerland or the jurisdiction in which the data originated.

11.2 Such transfers may occur in connection with cross-border payments, settlement activities, banking or financial infrastructure, payment messaging, digital asset transfers, KYC/AML screening providers, sanctions screening providers, IT and cloud service providers, professional advisers, regulatory cooperation, or other operational requirements.

11.3 Depending on the relevant business relationship and service flow, personal data may be processed in Switzerland and in other countries where Axi's service providers, financial partners, counterparties, regulators, or authorities operate, including [insert actual destination countries before publication, e.g. United Kingdom, European Economic Area countries, United States, Singapore, United Arab Emirates, or other relevant jurisdictions, if applicable].

11.4 Where personal data is transferred to or accessed from a country that does not provide an adequate level of data protection, Axi will apply appropriate safeguards as required under applicable Swiss data protection law, such as recognised standard contractual clauses, contractual safeguards, binding internal rules, or another legally permitted transfer mechanism, unless an exception under applicable law applies.

12 Data Retention

12.1 Axi retains personal data only for as long as necessary to fulfil the purposes described in this Policy or to satisfy legal, contractual, regulatory, operational, audit, security, or evidentiary requirements.

12.2 Retention periods may vary depending on the data category, purpose of processing, applicable regulations, dispute risk, legal obligations, and operational requirements.

12.3 Operational data may be retained for business continuity, service delivery, reconciliation, governance, audit, security, support, and operational purposes.

12.4 Onboarding, KYC/AML/CFT, sanctions screening, transaction, settlement, payment messaging, digital asset transfer, and related compliance records are retained for as long as required under applicable legal and regulatory obligations, including, where applicable, for at least ten years after the end of the business relationship or completion of the relevant transaction.

12.5 Personal data may be retained for longer periods where necessary or permitted for litigation, investigations, disputes, regulatory enquiries, audits, enforcement actions, legal holds, or the establishment, exercise, or defence of legal claims.

12.6 Upon expiry of applicable retention requirements, personal data may be securely deleted, destroyed, anonymised, or otherwise rendered inaccessible, unless further retention is legally required or permitted.

13 Data Security and Operational Resilience

13.1 Axi implements appropriate technical, organisational, administrative, and operational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, misuse, or unauthorised access.

13.2 Such measures may include governance controls, confidentiality obligations, access restrictions, role-based permissions, personnel training, authentication controls, encryption where appropriate, logging, monitoring, network security controls, security testing, backup and recovery measures, and incident response procedures.

13.3 Axi maintains backup, recovery, and resilience measures designed to preserve the confidentiality, integrity, and availability of critical systems and data.

13.4 Axi maintains procedures for security incident detection, escalation, investigation, containment, remediation, recovery, and regulatory notification where required by applicable law.

13.5 No technical or organisational security measure can guarantee absolute security. Ordinary email and internet transmission may carry inherent security risks. Axi may therefore request documents through secure channels, encrypted or password-protected attachments, or another secure method agreed between the parties.

14 Rights of Data Subjects

14.1 Subject to applicable law, individuals may have certain rights regarding personal data processed by Axi.

14.2 Such rights may include:

14.3 Where the GDPR applies, individuals may also have rights under the GDPR and may lodge complaints with a competent EU or EEA supervisory authority.

14.4 Requests may be submitted to compliance@axiym.io. Axi may require identity verification and sufficient information to process the request.

14.5 Axi may refuse, limit, or defer requests where permitted or required by law, including where necessary for AML/CFT, sanctions, fraud prevention, regulatory reporting, transaction monitoring, security, legal privilege, confidentiality, litigation, investigation, audit, or recordkeeping obligations.

15 Regulatory Recordkeeping and Legal Limitations

15.1 As a financial intermediary operating in regulated environments, Axi is subject to legal and regulatory obligations that may require the retention, monitoring, disclosure, preservation, or restricted handling of personal data.

15.2 Such obligations may arise under laws or regulations relating to anti-money laundering, sanctions compliance, counter-terrorist financing, fraud prevention, financial crime investigations, payment transparency, travel rule requirements, transaction monitoring, regulatory reporting, tax reporting, audit, and law enforcement cooperation.

15.3 Accordingly, certain rights otherwise available under general data protection law, including rights relating to deletion, objection, restriction, portability, disclosure, or access, may be limited, deferred, or unavailable where such rights conflict with Axi's legal or regulatory obligations, third-party rights, confidentiality duties, security requirements, or lawful interests.

16 Third-Party Websites and External Services

16.1 Axi websites, systems, or communications may contain links to third-party websites, services, platforms, or resources.

16.2 Axi is not responsible for the privacy, security, or data handling practices of third parties not controlled by Axi.

16.3 Individuals are encouraged to review applicable third-party privacy notices before submitting personal data to such third parties.

17 Changes to this Privacy Policy

17.1 Axi may amend, update, or revise this Policy from time to time to reflect changes in law, regulation, operational practices, services, infrastructure, technology, or business activities.

17.2 The latest version of this Policy shall supersede prior versions and becomes effective upon publication or other formal adoption by Axi.

17.3 Material changes may be communicated through appropriate channels where required by law or considered appropriate by Axi.