Acertix.Onboarding
09 — Legal

Privacy
Policy.

Effective: 6 July 2026
Last updated: 6 July 2026
Version: 1.0

This Policy explains how Ambrella GmbH processes personal data via the Acertix platform. Aligned with the Swiss Federal Act on Data Protection (FADP) and the EU General Data Protection Regulation (GDPR). Read together with our Terms & Conditions.

1. Controller & contact

The controller for personal data processed via the Acertix platform and the acertix.io / acertix.lovable.app websites is Ambrella GmbH (CHE-303.049.381), Grafenaustrasse 13, 6300 Zug, Switzerland ("Acertix", "we", "us").

Privacy enquiries: privacy@acertix.io — general contact: hello@acertix.io.

2. Scope

This Policy applies to personal data processed through the Acertix platform, the marketing website and the contact form. Acertix is a business-to-business service. For personal data of the Client's own prospects, customers, controlling persons and beneficial owners uploaded to the Platform ("Client Data"), the Client acts as the controller and Acertix acts as processor on the Client's documented instructions.

3. Roles under Swiss FADP / EU GDPR

  • Acertix as controller — for account data, billing data, marketing enquiries, contact-form messages and platform telemetry (logs, usage statistics, security events).
  • Acertix as processor — for Client Data processed on behalf of the Client, including KYC/AML case files, identity documents, screening results, risk assessments, AI-generated compliance memos and EDD outputs. The applicable data processing terms are set out in the Client's order form or Data Processing Addendum.

4. Categories of personal data

  • Account data: name, work email, role, hashed password, tenant assignment, MFA metadata.
  • Billing data: legal entity, address, VAT number, invoice history and payment metadata (card details are handled directly by our payment processor and are not stored on our systems).
  • Usage & security data: IP address, user agent, timestamps, request logs, audit trail entries, session identifiers.
  • Client Data (processor role): identity data of KYC subjects, PEP and sanctions signals, corporate registry extracts, identity documents, source-of-funds evidence, AI-drafted memos and reviewer decisions.
  • Support & marketing data: contact-form messages, demo requests, email correspondence.

5. Purposes & legal bases

We process personal data on the following legal bases (Art. 31 FADP and, where applicable, Art. 6 GDPR):

  • Contract performance — providing and operating the Platform, authenticating users, invoicing, support.
  • Legal obligation — retaining accounting records (Art. 958f CO), assisting Clients with AMLA record-keeping obligations in their processor capacity, responding to lawful requests from authorities.
  • Legitimate interest — platform and account security, fraud and abuse prevention, product analytics on aggregated data, defence of legal claims.
  • Consent — for any optional analytics or marketing communications, which can be withdrawn at any time.

6. How we collect personal data

  • Directly from Client users when they register and use the Platform.
  • From the Client's own prospects and customers via branded intake links operated on the Client's behalf.
  • Automatically through the Platform (logs, security events, usage counters).
  • From third-party providers acting on the Client's instructions (sanctions, PEP, corporate registry, identity verification data).

7. Third-party providers (sub-processors)

Acertix relies on a limited set of specialist providers to deliver the Platform. Providers are described by category; a current list of named sub-processors is available to Clients on request from privacy@acertix.io.

  • Cloud hosting & managed database — an established European cloud infrastructure provider hosting our application and primary database in an EU region (Frankfurt).
  • Large-language-model provider — a leading AI provider used to draft compliance memos and EDD narratives from case inputs.
  • Research-grade search & retrieval provider — used to gather adverse-media and open-source EDD sources for reviewer consideration.
  • Payment processor — for subscription billing; card data is handled directly by the processor.
  • Transactional email provider — for account, security and notification emails.
  • Identity verification & sanctions screening providers — activated per Client configuration; may operate under the Client's own contract (bring-your-own-key).

8. International transfers

Hosting and the primary database are kept within the European Union (Frankfurt) wherever feasible. Certain AI reasoning and search providers may process data outside Switzerland and the EEA. Such transfers rely on safeguards recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) and, for the EU, on the European Commission's Standard Contractual Clauses with the Swiss addendum.

Prompt payloads sent to AI providers are minimised to what is required for the task and, by contract, providers do not use Client inputs to train their models.

9. AI processing specifics

  • Inputs sent to AI reasoning and retrieval providers are limited to the data required for the specific task (compliance memo draft, EDD source gathering, adverse-media summarisation).
  • Providers are contractually barred from using Client inputs or outputs to train their models.
  • All AI outputs are marked as draft. The final compliance assessment, sign-off and any regulatory decision is made by a qualified human compliance officer of the Client. See also our Terms & Conditions, sections on Nature of service and Limitation of liability.

10. Retention

  • Account data: for the duration of the contract and up to 12 months thereafter.
  • Client Data (processor role): according to the Client's documented instructions and, where the Client is subject to AMLA, at least the 10-year statutory period.
  • Contact-form messages: up to 24 months.
  • Platform logs & security events: up to 12 months.
  • Billing records: 10 years (Art. 958f CO).

11. Recipients

Personal data is accessed by authorised Acertix personnel on a need-to-know basis, by the sub-processors listed in section 7, and by authorities where disclosure is required by law. We do not sell personal data and we do not share it for cross-context behavioural advertising.

12. Security

Acertix maintains technical and organisational measures proportionate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control and tenant isolation at the database layer.
  • Immutable, hash-chained audit trail of state-changing actions.
  • Principle of least privilege for staff access, with logging.
  • Regular encrypted backups and documented restore procedures.
  • Documented incident-response process with notification obligations to affected Clients.

13. Your rights

Where Acertix is controller, data subjects may request access, rectification, deletion, restriction, objection, portability and withdrawal of consent. Requests can be sent to privacy@acertix.io.

Where Acertix is processor of Client Data, requests are forwarded to the Client as controller, and Acertix assists the Client in responding within the applicable statutory deadlines.

Data subjects may also lodge a complaint with the FDPIC (Feldeggweg 1, 3003 Bern, Switzerland) or, for EU residents, with their local supervisory authority.

14. Cookies & tracking

The Acertix marketing site and Platform use strictly necessary cookies by default (authentication, session, security, load balancing, and remembering your cookie choice). These are required for the site to function and do not require consent under Swiss FADP or EU GDPR.

Any additional cookies or tracking technologies are opt-in. We ask for your consent through a banner on your first visit. Categories:

  • Essential — always on. Session, CSRF, load balancing, cookie-consent record.
  • Analytics — optional. Aggregate, privacy-preserving usage measurement to improve the product. Off unless you accept.
  • Marketing — reserved for future opt-in. Not currently in use. We do not set advertising cookies and do not engage in cross-site behavioural tracking.

You can change or withdraw your choice at any time via the "Cookie settings" link in the site footer. Your preference is stored locally in your browser under acertix.cookie-consent.v1.

15. Automated decision-making

The Platform assists compliance officers with screening, risk scoring and drafting compliance memos. It does not make final onboarding, offboarding or reporting decisions. Every decision with legal or similarly significant effect on a data subject is taken by a qualified human reviewer of the Client.

16. Children

The Platform and the marketing website are not directed at persons under 18. We do not knowingly collect personal data of minors outside the context of KYC on behalf of Clients where such collection is required by law.

17. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified at least 30 days in advance via in-app notice and email to account administrators. The current version and its effective date are shown at the top of this page.

18. Contact & complaints

Ambrella GmbH
Grafenaustrasse 13
6300 Zug, Switzerland
privacy@acertix.io

Supervisory authority: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, Switzerland.