XBTM GOLD XBTM GOLD BT SA · SWISS
🛒 Catalog ✨ Register 🔑 Login
GDPR
EU GDPR · Swiss FADP · BT SA Data Controller

Privacy Policy

Effective date: 2 October 2026 · Version 1.0

This Privacy Policy describes the processing of personal data carried out by BT SA in the context of the operation of the XBTM portal (https://xbtm.net), of the offering of custody and trading services relating to physical gold and silver, and of the associated GLD NFT and SLV NFT digital representations.

Data Controller: BT SA, Microcity, Rue de la Pierre-à-Mazel 39, 2000 Neuchâtel, Switzerland.
Data Protection correspondence: CS@XBTM.NET.
Applicable law: Regulation (EU) 2016/679 (GDPR), Swiss Federal Act on Data Protection (revFADP / nFADP) and other applicable national data-protection laws.

1. Controller and Applicable Legal Framework

BT SA, a company incorporated under Swiss law with registered seat at Microcity, Rue de la Pierre-à-Mazel 39, 2000 Neuchâtel, Switzerland, acts as Data Controller for the processing of personal data carried out through the XBTM portal and in the performance of the contractual relationship with its clients and business contacts. All privacy-related correspondence, including requests by data subjects, complaints and designations of contacts, shall be addressed to CS@XBTM.NET or, by registered mail, to BT SA at its registered office above.

BT SA has appointed a dedicated internal data-protection function, which oversees compliance with the applicable framework and handles all data-subject requests and data-protection-related correspondence. Where BT SA is legally required to appoint a representative in a specific jurisdiction, the corresponding contact details are communicated, upon request, to data subjects and to the competent supervisory authority in that jurisdiction.

Personal data are processed under the EU GDPR where its territorial scope applies, under the Swiss Federal Act on Data Protection (revised / new FADP) where such act is applicable, and under the relevant national data-protection laws of other jurisdictions to the extent their application is mandatory. The fact that the physical Metals are held in custody in Switzerland does not, by itself, determine the data-protection framework applicable to a specific processing operation or category of data subjects.

2. Categories of Personal Data and Sources

The following categories of personal data are processed by BT SA in connection with the XBTM portal and services:

  • Identification and contact data: first name, last name, postal address, electronic mail address, telephone number, date of birth, nationality, country of residence or domicile, identification documents, and, where relevant, information on legal representatives and beneficial owners;
  • Authentication data and credentials: hashed passwords, second-factor references, authentication event logs, login session identifiers and security events;
  • Tax, financial and compliance data: tax identification or reference data where applicable, information on the source of wealth and source of funds, and records generated in the context of anti-money-laundering, counter-terrorist-financing and sanctions-screening controls;
  • Contractual, transactional and position data: order records, trade confirmations, allocation records, metal position statements, balances, deposits and withdrawals, and payment references;
  • Crypto-asset and distributed-ledger data: client-designated receiving addresses used for funding purposes, GLD NFT and SLV NFT identifiers, and on-chain transaction hashes relevant to the client's own operations;
  • Correspondence and relationship data: support and client-service correspondence, ticket records, complaint files and records of communications with the assigned consultant or BT SA personnel;
  • Technical and log data: Internet protocol (IP) addresses, user-agent strings, device and browser information, timestamped security events, and cookie and consent preferences as further described in the Cookie Policy.

Personal data are collected from the data subject directly; from persons duly authorised to represent the data subject; from payment service providers, identity-verification providers and screening providers formally appointed by BT SA; from public registers where this is permitted by applicable law; and, where lawful and necessary, from fraud-prevention, sanctions-screening and compliance sources in the context of BT SA's statutory and contractual obligations. Where data are collected from sources other than the data subject, BT SA provides any additional information required under the applicable law. Payment-card data are processed under the responsibility of the PCI-DSS-compliant payment service provider appointed by BT SA and in accordance with the applicable architecture and controls.

3. Purposes of Processing and Legal Bases

The following table sets out the main processing purposes carried out by BT SA, the corresponding GDPR legal basis where the GDPR applies, and the consequences of a refusal by the data subject to provide the data in question, where such consequences are relevant.

Purpose GDPR legal basis (if applicable) Consequences of refusal
Client registration, account management, execution of purchase and sale orders, custody operations, payment processing, withdrawals and client support. Performance of a contract to which the data subject is a party, or pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR); in respect of representatives and business contacts, a legitimate interest properly weighed and documented by BT SA (Article 6(1)(f) GDPR). Refusal prevents the opening of the account and the performance of the contractual services.
Bookkeeping, invoicing, tax compliance, and anti-money-laundering, counter-terrorist-financing and sanctions-screening controls legally imposed on BT SA. Compliance with a legal obligation to which BT SA is subject (Article 6(1)(c) GDPR), read together with the specific statutory provision that requires the processing. Mandatory whenever the applicable law requires the processing.
Information security, fraud and abuse prevention, detection and investigation, and the establishment, exercise or defence of BT SA's legal rights in judicial, administrative or out-of-court proceedings. A legitimate interest properly weighed and documented by BT SA or by a third-party recipient (Article 6(1)(f) GDPR); alternatively, where applicable, compliance with a legal obligation (Article 6(1)(c) GDPR). Required for the security and integrity of the service and for BT SA's rights protection.
Commercial information, newsletters and promotional offers concerning XBTM Gold and Silver products and services. The explicit, freely given, specific and revocable consent of the data subject (Article 6(1)(a) GDPR), unless a specific statutory exception applicable to existing-customer marketing applies in the jurisdiction concerned. Optional; refusal has no effect on core contractual services.
Statistical analyses and non-essential performance and usage tracking aimed at service-quality improvement. Consent where required by the EU ePrivacy Directive or its national implementing laws; alternatively, a legitimate interest properly weighed and documented by BT SA after a full legitimate-interest assessment. Optional; refusal has no effect on core contractual services.

Where processing is based on a legal obligation or on a legitimate interest, BT SA internally documents the specific statutory provision relied upon or the legitimate interest pursued, and may disclose such documentation, where appropriate, to the competent supervisory authority. Where processing is based on consent, the data subject may withdraw such consent at any time, without affecting the lawfulness of processing performed before the withdrawal.

4. Recipients of Personal Data

Personal data may be disclosed, strictly to the extent necessary for the purposes listed in Article 3 and subject to all applicable legal safeguards, to the following categories of recipients:

  • Authorised personnel of BT SA, acting under principles of least privilege and bound by appropriate obligations of professional confidentiality;
  • Hosting, cloud and information-technology service providers acting as processors on behalf of BT SA;
  • Identity-verification, sanctions-screening and KYC / AML service providers formally appointed by BT SA;
  • Banks, payment institutions, card acquirers and other payment-service providers, including the operators of the fiat and crypto-asset payment rails made available through the Portal;
  • Swiss custodians, vault operators, metal refiners and logistics operators, strictly limited to the data necessary for custody, allocation, insurance and physical redemption;
  • Blockchain-network infrastructure providers, block explorers and protocol-level services, where strictly required for the contractual or technical operation of the services; it being understood that data recorded on a public blockchain are public by design and accessible to any third party;
  • External auditors, tax advisors, legal advisors, insurers and insurance brokers, acting under appropriate duties of confidentiality;
  • Judicial, administrative or law-enforcement authorities, solely to the extent required by a binding and lawful request or by a directly applicable rule of law.

Any recipient formally acting as a Processor within the meaning of the GDPR or of the equivalent provisions of Swiss law is bound by a written data-processing agreement that satisfies the statutory requirements applicable thereto. Any party that independently determines the purposes and means of processing operates as a separate and autonomous Controller. Marketing data are disclosed to third-party marketing recipients only where a separate and valid legal title exists.

5. Blockchains and Public On-Chain Records

The payment rails and technical framework adopted by XBTM involve the following public or permissionless networks: the Ethereum network (for GLD NFT and SLV NFT related operations and for ERC-20 funding such as USDT ERC20), the Bitcoin network (for BTC funding in Bech32 format) and the Tron network (for USDT TRC20 funding). As a consequence of the operations performed by or on behalf of the Client, wallet addresses, token identifiers, transfer quantities and signed transaction data may be publicly visible and globally replicated on the corresponding network.

Data recorded on a public blockchain, even if apparently pseudonymised, may in certain cases be re-associated with an identified or identifiable natural person through contextual information obtained from other sources. The immutability properties of the networks concerned may prevent any material modification or deletion of a public on-chain record.

BT SA's architecture is designed so that names, identity documents, contact details and other directly identifying personal data are not, in the ordinary course of operations, recorded on any public blockchain. For each operation that produces an on-chain record, BT SA informs the Client, before confirmation, of the specific data elements that will be recorded and of the corresponding consequences. The rights of data subjects continue to apply within the limits of applicable law; the technical characteristics of a public blockchain do not, by themselves, justify a general derogation from the right to erasure or other applicable rights. BT SA implements data-minimisation techniques and keeps any data that are not strictly required to be public outside the public network.

6. International Transfers of Personal Data

The core processing activities of BT SA are primarily carried out in the European Economic Area and in Switzerland, where BT SA and its appointed primary infrastructure, hosting and custody providers maintain their main operations. Transfers of personal data to third countries outside the EEA and Switzerland may, in strictly limited circumstances and only to the extent necessary for the relevant purpose, take place under a valid legal basis: an applicable adequacy decision by the European Commission or by the competent Swiss authority, or — as the case may be — appropriate safeguards such as the EU Standard Contractual Clauses or equivalent instruments, together with any required supplementary technical and organisational measures.

Any transfer required by law or by a binding order of a competent court or authority is carried out in accordance with the applicable formalities and safeguards. The general acceptance of this Privacy Policy does not, by itself, replace the specific safeguards required by applicable law for systematic international transfers. The dissemination of data through publication on a public blockchain is addressed separately in Article 5.

7. Retention Periods

Data category Retention period and criteria
Client profile, contracts, trade and order records, allocation statements and position history. Entire duration of the relationship plus 10 years from the date of termination of the relationship, in line with applicable financial, anti-money-laundering and accounting record-keeping requirements, limitation periods and the requirements for the establishment, exercise and defence of legal rights.
KYC and identity documents, beneficial-owner records, source-of-funds documentation and AML screening records. 10 years from the termination of the relationship, or for a longer period where expressly required by a specific anti-money-laundering, tax or regulatory retention rule applicable to BT SA.
Accounting, invoicing and tax documentation (invoices, receipts, tax records and supporting ledgers). 10 years, or such longer period as may be required under the specific tax or commercial retention and limitation rules applicable to BT SA.
Security logs, authentication logs, abuse-detection events and infrastructure logs. 12 months as a standard baseline; extended for up to 2 further years where required because of an ongoing investigation, incident, dispute or claim; at the end of the period, securely deleted or irreversibly anonymised.
Support correspondence, ticket records and complaint files. For the duration of the matter to which they relate plus 3 years from its closure, or longer where the correspondence is relevant to a claim, a limitation period or a regulatory inquiry.
Records of consents, opt-ins and opt-outs (marketing, non-essential cookies and analytics). For the full duration of the validity of the consent, plus up to 1 year from the date of withdrawal, where necessary in order to demonstrate the lawfulness of the processing in the event of a challenge.
Marketing contact data and subscriber lists. Until explicit withdrawal of consent or, in the absence of such withdrawal, until 36 months of complete inactivity from the last meaningful contact or interaction.
Cookie identifiers and similar tracking identifiers. As listed in the Cookie Policy inventory and applicable maximum lifetimes published on the Portal.

At the expiry of the applicable retention period, the personal data concerned are either securely and irreversibly deleted or irreversibly anonymised for purely statistical purposes where permitted by applicable law. The technical persistence of public on-chain records is separately addressed in Article 5 and does not justify indefinite retention of equivalent personal data outside the blockchain environment.

8. Security Measures and Automated Decision-Making

BT SA implements proportionate technical and organisational security measures appropriate to the nature, scope, context and purposes of the processing and to the risks to the rights and freedoms of data subjects. Such measures include role-based and least-privilege access controls, strong authentication, encrypted communications in transit (TLS 1.2 or higher), encrypted storage where appropriate, regular integrity-checked backups, vulnerability management and patching procedures, incident-response and data-breach notification procedures, and appropriate staff awareness and training. BT SA takes reasonable steps to ensure continuous improvement of its security posture. Personal-data breaches are managed internally and, where required by applicable law, notified to the competent supervisory authority and, where appropriate, to the affected data subjects within the applicable legal timelines and in accordance with the applicable conditions.

BT SA does not currently apply any form of decision-making based solely on automated processing, including profiling, that produces legal effects concerning a data subject or similarly significantly affects the data subject. Should such processing be introduced in the future, BT SA shall provide a dedicated privacy notice setting out the legal basis, the significant logic applied, the envisaged consequences and the applicable procedural safeguards, including the right to human intervention where legally required.

9. Rights of the Data Subject and Complaints

Where applicable under the GDPR, the Swiss Federal Act on Data Protection or any other relevant national regime, the data subject may exercise, against BT SA as Data Controller, the following rights, subject to the conditions and limitations set out in the applicable law:

  • Right of access to the personal data processed by BT SA, together with the categories of information required by the applicable law;
  • Right to rectification of inaccurate or incomplete personal data;
  • Right to erasure (often referred to as the "right to be forgotten"), where the conditions of the applicable law are satisfied;
  • Right to restriction of processing, in the cases provided for by the applicable law;
  • Right to data portability, where the legal conditions are met, of personal data provided by the data subject and processed by automated means on the basis of consent or of a contract to which the data subject is a party;
  • Right to object to processing based on legitimate interests, and in particular an absolute right to object, at any time, to processing carried out for the purposes of direct marketing;
  • Right to withdraw consent previously given, without affecting the lawfulness of processing based on consent and performed before the withdrawal;
  • Where applicable, rights relating to automated decision-making and profiling in accordance with the relevant legal regime.

Requests shall be addressed in writing to CS@XBTM.NET or by registered letter to BT SA's registered office. BT SA proportionally verifies the identity of the requester — typically through authentication in the client dashboard or by means of a signed copy of an official identification document — before disclosing, amending or deleting any personal data. Under the GDPR, the standard response period is one calendar month from receipt of the request, with a possible motivated extension of up to two further months in complex cases, as permitted by the GDPR.

The exercise of the right to erasure or of other rights may be legitimately limited by overriding statutory retention, defence-of-rights or public-interest obligations, without, however, affecting other applicable rights. Without prejudice to any other administrative or judicial remedy, a data subject may lodge a complaint with the competent supervisory authority for data protection, including, where applicable, the Swiss Federal Data Protection and Information Commissioner (FDPIC) or the data-protection authority of the EU or EEA Member State of the data subject's habitual residence, place of work or place of the alleged infringement.

10. Amendments to this Privacy Policy

Updated versions of this XBTM Privacy Policy are published on the Portal with a clearly indicated effective date and version number. Material amendments — in particular amendments affecting new processing purposes, new categories of recipients, significant international transfers or new categories of personal data — are communicated to active clients, sufficiently in advance, by durable-medium notice, by in-dashboard notice or by electronic mail, as appropriate. New processing purposes that are incompatible with the original purposes of collection, or new processing operations for which fresh consent is required, are not rendered lawful solely by continued use of the Portal following publication of an updated policy.

BT SA — Data Controller

XBTM — Gold & Silver Platform

Microcity, Rue de la Pierre-à-Mazel 39

2000 Neuchâtel — Switzerland

CS@XBTM.NET

Legal references

— Regulation (EU) 2016/679 (GDPR)

— Swiss Federal Act on Data Protection

— Directive 2002/58/EC (ePrivacy)

— Policy version: 1.0 · 2 October 2026

XBTM GOLD 🏔️ A brand of BT SA · Switzerland

The simplest, most transparent way to own real LBMA gold and silver bars. Buy from 1 gram, live dashboard, physical redeemable.

🏆 LBMA Quality · Swiss Roots · 10+ years
Metalor & top-tier refinery partners · 1:1 physical backing

Market

  • 🛒 Catalog Oro & Argento
  • 🎯 Apri Conto Gratuito
  • 🔑 Area Clienti
  • ❓ FAQ

Legal

  • 📜 Terms & Conditions
  • 🔒 Privacy Policy
  • 🍪 Cookie Policy
  • ✉️ Segnalazioni

Contact BT SA

  • BT SA · XBTM GOLD
  • 🏔️ Switzerland · 🇨🇭
  • ✉️ Support@xbtm.net
  • 💬 Ask your personal consultant for direct support

Founded in Switzerland, Bity has been operating at the intersection of crypto-assets and regulatory compliance for over 10 years.

We build long-term, trusted relationships with private and institutional clients who value discretion, professionalism, and regulatory clarity.

© 2026 XBTM GOLD · A brand of BT SA · All rights reserved.

Terms Privacy Cookies FAQ