Legal

Privacy Policy

CivicBond AG is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information in accordance with the Swiss Federal Act on Data Protection (nDSG, in force September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR).

Last updated: May 2026Swiss nDSG & GDPR compliant

1.Who We Are

CivicBond AG is a Swiss fintech company operating a digital platform for Swiss public infrastructure financing. We act as the data controller for personal data collected through our website and platform services.

Registered address: CivicBond AG, St. Gallen, Switzerland

Data protection contact: privacy@civicbond.ch

2.Data We Collect

Data CategoryExamplesSource
Identity dataFull name, job title, organisationYou provide directly
Contact dataEmail address, phone numberYou provide directly
Professional dataAUM range, investment mandate, roleYou provide via forms
Usage dataPages visited, time on site, clicksCollected automatically
Communication dataDemo requests, enquiries, messagesYou provide directly
Technical dataIP address, browser type, deviceCollected automatically

We do not collect special categories of personal data and do not knowingly collect data from individuals under 18.

3.How We Use Your Data

  • To respond to demo requests and investor access applications.
  • To assess eligibility of municipalities and institutional investors for platform access.
  • To send platform-related communications.
  • To improve the website and platform through aggregated usage analytics.
  • To comply with legal and regulatory obligations under Swiss financial market law.
  • To manage our business relationship with complementor partners.

4.Legal Basis for Processing

Contractual Necessity (Art. 6(1)(b) GDPR / nDSG)

Processing required to fulfil our contract with you or take steps at your request before entering a contract.

Legitimate Interests (Art. 6(1)(f) GDPR / nDSG)

Processing necessary for our legitimate business interests, including improving our platform and preventing fraud.

Legal Obligation (Art. 6(1)(c) GDPR / nDSG)

Processing required to comply with Swiss financial market law, FINMA regulations, and AML obligations.

5.Data Sharing & Third Parties

We share personal data only where necessary and with appropriate safeguards. We never sell your personal data.

RecipientPurposeSafeguard
Rating agency partnersCredit assessmentData processing agreement
Legal-tech partnersSecuritisation documentationData processing agreement
Custodian bank partnersAsset custody and settlementSwiss banking secrecy + DPA
Cloud infrastructure providerPlatform hosting (Swiss data residency)ISO 27001 certified
Analytics provider (Plausible)Privacy-respecting website analyticsNo cookies, no personal data

6.International Transfers

CivicBond stores all personal data on servers located in Switzerland. We do not transfer personal data outside Switzerland or the EEA without ensuring adequate data protection.

Swiss data residency guaranteed. All CivicBond platform data remains on Swiss-domiciled servers at all times.

7.Data Retention

  • Account and platform data: retained for the duration of the contractual relationship plus 10 years.
  • Demo requests and enquiries: 24 months from last contact.
  • Usage and analytics data: aggregated and anonymised.
  • Legal and compliance records: retained as required by FINMA (typically 10 years).

8.Your Rights

Right of Access

Request a copy of personal data we hold.

Right to Rectification

Ask us to correct inaccurate data.

Right to Erasure

Request deletion where no compelling reason for processing exists.

Right to Restriction

Ask us to restrict processing in certain circumstances.

Right to Data Portability

Receive your data in a machine-readable format.

Right to Object

Object to processing based on legitimate interests.

To exercise any right, contact privacy@civicbond.ch. We respond within 30 days. You may also lodge a complaint with the FDPIC at www.edoeb.admin.ch.

9.Cookies & Analytics

CivicBond uses Plausible Analytics — a privacy-respecting tool that does not use cookies and does not collect personal data. No cookie consent banner is required. We do not use Google Analytics, Meta Pixel, or any other tracking technology.

10.Security

  • All data encrypted in transit (TLS 1.3) and at rest (AES-256).
  • ISO 27001-certified infrastructure.
  • Regular third-party penetration testing.
  • Role-based access controls, principle of least privilege.
  • Swiss data residency — no data leaves Switzerland.
  • Incident response plan aligned with nDSG breach notification obligations.

11.Changes to This Policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email and update the Last updated date. We encourage you to review this page periodically.

12.Contact & Data Protection

Data Protection Contact

Email: privacy@civicbond.ch

Address: CivicBond AG, St. Gallen, Switzerland

We aim to respond to all data protection enquiries within 5 business days.

Send a Privacy Request

This Privacy Policy is provided for informational purposes. It does not constitute legal advice.