This Privacy Policy describes the processing of personal data carried out by BT SA in the context of the operation of the XBTM portal (https://xbtm.net), of the offering of custody and trading services relating to physical gold and silver, and of the associated GLD NFT and SLV NFT digital representations.
Data Controller: BT SA, Microcity, Rue de la Pierre-à-Mazel 39, 2000 Neuchâtel, Switzerland.
Data Protection correspondence: CS@XBTM.NET.
Applicable law: Regulation (EU) 2016/679 (GDPR), Swiss Federal Act on Data Protection (revFADP / nFADP) and other applicable national data-protection laws.
BT SA, a company incorporated under Swiss law with registered seat at Microcity, Rue de la Pierre-à-Mazel 39, 2000 Neuchâtel, Switzerland, acts as Data Controller for the processing of personal data carried out through the XBTM portal and in the performance of the contractual relationship with its clients and business contacts. All privacy-related correspondence, including requests by data subjects, complaints and designations of contacts, shall be addressed to CS@XBTM.NET or, by registered mail, to BT SA at its registered office above.
BT SA has appointed a dedicated internal data-protection function, which oversees compliance with the applicable framework and handles all data-subject requests and data-protection-related correspondence. Where BT SA is legally required to appoint a representative in a specific jurisdiction, the corresponding contact details are communicated, upon request, to data subjects and to the competent supervisory authority in that jurisdiction.
Personal data are processed under the EU GDPR where its territorial scope applies, under the Swiss Federal Act on Data Protection (revised / new FADP) where such act is applicable, and under the relevant national data-protection laws of other jurisdictions to the extent their application is mandatory. The fact that the physical Metals are held in custody in Switzerland does not, by itself, determine the data-protection framework applicable to a specific processing operation or category of data subjects.
The following categories of personal data are processed by BT SA in connection with the XBTM portal and services:
Personal data are collected from the data subject directly; from persons duly authorised to represent the data subject; from payment service providers, identity-verification providers and screening providers formally appointed by BT SA; from public registers where this is permitted by applicable law; and, where lawful and necessary, from fraud-prevention, sanctions-screening and compliance sources in the context of BT SA's statutory and contractual obligations. Where data are collected from sources other than the data subject, BT SA provides any additional information required under the applicable law. Payment-card data are processed under the responsibility of the PCI-DSS-compliant payment service provider appointed by BT SA and in accordance with the applicable architecture and controls.
The following table sets out the main processing purposes carried out by BT SA, the corresponding GDPR legal basis where the GDPR applies, and the consequences of a refusal by the data subject to provide the data in question, where such consequences are relevant.
| Purpose | GDPR legal basis (if applicable) | Consequences of refusal |
|---|---|---|
| Client registration, account management, execution of purchase and sale orders, custody operations, payment processing, withdrawals and client support. | Performance of a contract to which the data subject is a party, or pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR); in respect of representatives and business contacts, a legitimate interest properly weighed and documented by BT SA (Article 6(1)(f) GDPR). | Refusal prevents the opening of the account and the performance of the contractual services. |
| Bookkeeping, invoicing, tax compliance, and anti-money-laundering, counter-terrorist-financing and sanctions-screening controls legally imposed on BT SA. | Compliance with a legal obligation to which BT SA is subject (Article 6(1)(c) GDPR), read together with the specific statutory provision that requires the processing. | Mandatory whenever the applicable law requires the processing. |
| Information security, fraud and abuse prevention, detection and investigation, and the establishment, exercise or defence of BT SA's legal rights in judicial, administrative or out-of-court proceedings. | A legitimate interest properly weighed and documented by BT SA or by a third-party recipient (Article 6(1)(f) GDPR); alternatively, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR). | Required for the security and integrity of the service and for BT SA's rights protection. |
| Commercial information, newsletters and promotional offers concerning XBTM Gold and Silver products and services. | The explicit, freely given, specific and revocable consent of the data subject (Article 6(1)(a) GDPR), unless a specific statutory exception applicable to existing-customer marketing applies in the jurisdiction concerned. | Optional; refusal has no effect on core contractual services. |
| Statistical analyses and non-essential performance and usage tracking aimed at service-quality improvement. | Consent where required by the EU ePrivacy Directive or its national implementing laws; alternatively, a legitimate interest properly weighed and documented by BT SA after a full legitimate-interest assessment. | Optional; refusal has no effect on core contractual services. |
Where processing is based on a legal obligation or on a legitimate interest, BT SA internally documents the specific statutory provision relied upon or the legitimate interest pursued, and may disclose such documentation, where appropriate, to the competent supervisory authority. Where processing is based on consent, the data subject may withdraw such consent at any time, without affecting the lawfulness of processing performed before the withdrawal.
Personal data may be disclosed, strictly to the extent necessary for the purposes listed in Article 3 and subject to all applicable legal safeguards, to the following categories of recipients:
Any recipient formally acting as a Processor within the meaning of the GDPR or of the equivalent provisions of Swiss law is bound by a written data-processing agreement that satisfies the statutory requirements applicable thereto. Any party that independently determines the purposes and means of processing operates as a separate and autonomous Controller. Marketing data are disclosed to third-party marketing recipients only where a separate and valid legal title exists.
The payment rails and technical framework adopted by XBTM involve the following public or permissionless networks: the Ethereum network (for GLD NFT and SLV NFT related operations and for ERC-20 funding such as USDT ERC20), the Bitcoin network (for BTC funding in Bech32 format) and the Tron network (for USDT TRC20 funding). As a consequence of the operations performed by or on behalf of the Client, wallet addresses, token identifiers, transfer quantities and signed transaction data may be publicly visible and globally replicated on the corresponding network.
Data recorded on a public blockchain, even if apparently pseudonymised, may in certain cases be re-associated with an identified or identifiable natural person through contextual information obtained from other sources. The immutability properties of the networks concerned may prevent any material modification or deletion of a public on-chain record.
BT SA's architecture is designed so that names, identity documents, contact details and other directly identifying personal data are not, in the ordinary course of operations, recorded on any public blockchain. For each operation that produces an on-chain record, BT SA informs the Client, before confirmation, of the specific data elements that will be recorded and of the corresponding consequences. The rights of data subjects continue to apply within the limits of applicable law; the technical characteristics of a public blockchain do not, by themselves, justify a general derogation from the right to erasure or other applicable rights. BT SA implements data-minimisation techniques and keeps any data that are not strictly required to be public outside the public network.
The core processing activities of BT SA are primarily carried out in the European Economic Area and in Switzerland, where BT SA and its appointed primary infrastructure, hosting and custody providers maintain their main operations. Transfers of personal data to third countries outside the EEA and Switzerland may, in strictly limited circumstances and only to the extent necessary for the relevant purpose, take place under a valid legal basis: an applicable adequacy decision by the European Commission or by the competent Swiss authority, or — as the case may be — appropriate safeguards such as the EU Standard Contractual Clauses or equivalent instruments, together with any required supplementary technical and organisational measures.
Any transfer required by law or by a binding order of a competent court or authority is carried out in accordance with the applicable formalities and safeguards. The general acceptance of this Privacy Policy does not, by itself, replace the specific safeguards required by applicable law for systematic international transfers. The dissemination of data through publication on a public blockchain is addressed separately in Article 5.
| Data category | Retention period and criteria |
|---|---|
| Client profile, contracts, trade and order records, allocation statements and position history. | Entire duration of the relationship plus 10 years from the date of termination of the relationship, in line with applicable financial, anti-money-laundering and accounting record-keeping requirements, limitation periods and the requirements for the establishment, exercise and defence of legal rights. |
| KYC and identity documents, beneficial-owner records, source-of-funds documentation and AML screening records. | 10 years from the termination of the relationship, or for a longer period where expressly required by a specific anti-money-laundering, tax or regulatory retention rule applicable to BT SA. |
| Accounting, invoicing and tax documentation (invoices, receipts, tax records and supporting ledgers). | 10 years, or such longer period as may be required under the specific tax or commercial retention and limitation rules applicable to BT SA. |
| Security logs, authentication logs, abuse-detection events and infrastructure logs. | 12 months as a standard baseline; extended for up to 2 further years where required because of an ongoing investigation, incident, dispute or claim; at the end of the period, securely deleted or irreversibly anonymised. |
| Support correspondence, ticket records and complaint files. | For the duration of the matter to which they relate plus 3 years from its closure, or longer where the correspondence is relevant to a claim, a limitation period or a regulatory inquiry. |
| Records of consents, opt-ins and opt-outs (marketing, non-essential cookies and analytics). | For the full duration of the validity of the consent, plus up to 1 year from the date of withdrawal, where necessary in order to demonstrate the lawfulness of the processing in the event of a challenge. |
| Marketing contact data and subscriber lists. | Until explicit withdrawal of consent or, in the absence of such withdrawal, until 36 months of complete inactivity from the last meaningful contact or interaction. |
| Cookie identifiers and similar tracking identifiers. | As listed in the Cookie Policy inventory and applicable maximum lifetimes published on the Portal. |
At the expiry of the applicable retention period, the personal data concerned are either securely and irreversibly deleted or irreversibly anonymised for purely statistical purposes where permitted by applicable law. The technical persistence of public on-chain records is separately addressed in Article 5 and does not justify indefinite retention of equivalent personal data outside the blockchain environment.
BT SA implements proportionate technical and organisational security measures appropriate to the nature, scope, context and purposes of the processing and to the risks to the rights and freedoms of data subjects. Such measures include role-based and least-privilege access controls, strong authentication, encrypted communications in transit (TLS 1.2 or higher), encrypted storage where appropriate, regular integrity-checked backups, vulnerability management and patching procedures, incident-response and data-breach notification procedures, and appropriate staff awareness and training. BT SA takes reasonable steps to ensure continuous improvement of its security posture. Personal-data breaches are managed internally and, where required by applicable law, notified to the competent supervisory authority and, where appropriate, to the affected data subjects within the applicable legal timelines and in accordance with the applicable conditions.
BT SA does not currently apply any form of decision-making based solely on automated processing, including profiling, that produces legal effects concerning a data subject or similarly significantly affects the data subject. Should such processing be introduced in the future, BT SA shall provide a dedicated privacy notice setting out the legal basis, the significant logic applied, the envisaged consequences and the applicable procedural safeguards, including the right to human intervention where legally required.
Where applicable under the GDPR, the Swiss Federal Act on Data Protection or any other relevant national regime, the data subject may exercise, against BT SA as Data Controller, the following rights, subject to the conditions and limitations set out in the applicable law:
Requests shall be addressed in writing to CS@XBTM.NET or by registered letter to BT SA's registered office. BT SA proportionally verifies the identity of the requester — typically through authentication in the client dashboard or by means of a signed copy of an official identification document — before disclosing, amending or deleting any personal data. Under the GDPR, the standard response period is one calendar month from receipt of the request, with a possible motivated extension of up to two further months in complex cases, as permitted by the GDPR.
The exercise of the right to erasure or of other rights may be legitimately limited by overriding statutory retention, defence-of-rights or public-interest obligations, without, however, affecting other applicable rights. Without prejudice to any other administrative or judicial remedy, a data subject may lodge a complaint with the competent supervisory authority for data protection, including, where applicable, the Swiss Federal Data Protection and Information Commissioner (FDPIC) or the data-protection authority of the EU or EEA Member State of the data subject's habitual residence, place of work or place of the alleged infringement.
Updated versions of this XBTM Privacy Policy are published on the Portal with a clearly indicated effective date and version number. Material amendments — in particular amendments affecting new processing purposes, new categories of recipients, significant international transfers or new categories of personal data — are communicated to active clients, sufficiently in advance, by durable-medium notice, by in-dashboard notice or by electronic mail, as appropriate. New processing purposes that are incompatible with the original purposes of collection, or new processing operations for which fresh consent is required, are not rendered lawful solely by continued use of the Portal following publication of an updated policy.
XBTM — Gold & Silver Platform
Microcity, Rue de la Pierre-à-Mazel 39
2000 Neuchâtel — Switzerland
— Regulation (EU) 2016/679 (GDPR)
— Swiss Federal Act on Data Protection
— Directive 2002/58/EC (ePrivacy)
— Policy version: 1.0 · 2 October 2026