Privacy Policy
Last Updated: January 1, 2026
1. Introduction
This Privacy Policy explains how PALFA AB, registration number 5590353669 ("PALFA AB", "PALFA", "we", "us", or "our"), collects, uses, stores, shares, and otherwise processes personal information when you access or use the PALFA website, platform, applications, accounts, and related services (collectively, the "Services").
PALFA is a financial technology platform operated by PALFA AB.
We are committed to protecting your privacy and processing personal data in accordance with applicable data protection laws, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable privacy and data protection legislation.
This Privacy Policy applies to visitors to our website, registered users, prospective users, representatives and beneficial owners of business customers, and other individuals whose personal information we process in connection with the Services.
By accessing or using PALFA, you acknowledge that your personal information will be processed as described in this Privacy Policy.
2. Data Controller
For personal data processed in connection with the operation of the PALFA platform, the data controller is:
PALFA AB
Registration No.: 5590353669
Registered Office: c/o YourOffice, Bror Nilssons gata 5, 417 55 Göteborg, Sweden
Website: palfa.se
Email: support@palfa.se
Depending on the service you use, certain regulated financial institutions, payment service providers, digital asset service providers, identity verification providers, compliance providers, banking infrastructure providers, or other third-party service providers may process your personal information as independent data controllers or processors in accordance with their own legal and regulatory obligations.
3. Personal Information We Collect
The information we collect depends on how you interact with PALFA and which Services you use.
3.1 Account and Contact Information
We may collect:
- full name;
- email address;
- telephone number;
- residential or business address;
- country of residence;
- nationality;
- date of birth;
- account username and identifiers;
- language and communication preferences;
- account type and profile information.
3.2 Identity Verification Information
Where identity verification is required, we or our verification and compliance service providers may collect and process:
- passport;
- national identity card;
- driving licence;
- photograph or selfie;
- proof of residential address;
- date and place of birth;
- nationality and citizenship information;
- tax identification information where required;
- identity verification results;
- information required for KYC, KYB, AML and sanctions screening.
Where permitted or required by applicable law, identity verification processes may involve biometric information derived from photographs, facial images or identity documents for the purpose of verifying identity and preventing fraud.
Where biometric or other special-category personal data is processed, such processing will be carried out only where an appropriate legal basis and any additional condition required by applicable law applies.
3.3 Business Customer Information
For business accounts, we may collect:
- company name;
- registration number;
- registered address;
- business address;
- incorporation documents;
- ownership and corporate structure;
- directors and authorised representatives;
- shareholders and ultimate beneficial owners;
- nature of business;
- expected account activity;
- source of funds and source of wealth information where required;
- licences or regulatory information where applicable;
- corporate bank or financial information;
- other documentation required for KYB and compliance purposes.
3.4 Financial and Transaction Information
When you use financial functionality available through PALFA, we may process information including:
- virtual account and IBAN information;
- account identifiers;
- balances made available to the platform;
- payment instructions;
- beneficiaries and counterparties;
- transaction amounts;
- currencies;
- payment references;
- transaction dates and status;
- SEPA and international payment information;
- exchange transactions;
- digital asset transactions;
- wallet addresses;
- blockchain transaction identifiers;
- fiat-to-digital-asset and digital-asset-to-fiat transactions;
- transaction history;
- fees and exchange information.
We may receive some of this information directly from financial, payment, banking infrastructure, digital asset or other service providers connected to the Services.
3.5 Digital Asset Information
Where you use digital asset functionality, we may process:
- cryptocurrency or stablecoin wallet addresses;
- supported digital assets;
- transaction amounts;
- blockchain network information;
- transaction hashes;
- deposit and withdrawal information;
- conversion information;
- blockchain analytics and risk indicators.
Information recorded on public blockchains may be publicly accessible and cannot necessarily be modified or deleted by PALFA.
3.6 Technical and Device Information
When you access PALFA, we may automatically collect:
- IP address;
- browser type and version;
- operating system;
- device identifiers;
- device type;
- language settings;
- login timestamps;
- session information;
- pages viewed;
- referral information;
- security events;
- cookies and similar technologies;
- approximate location derived from IP address.
We use this information to operate the platform, maintain security, prevent fraud, troubleshoot technical issues and improve the Services.
3.7 Communications and Support
When you contact us, we may process:
- emails;
- support requests;
- chat communications;
- complaints;
- documents or information submitted to support;
- records of communications with us.
4. How We Collect Personal Information
We may collect personal information:
- directly from you when you register or use PALFA;
- when you complete KYC or KYB procedures;
- when you initiate or receive transactions;
- when you communicate with us;
- automatically through your use of our website or platform;
- from identity verification and compliance providers;
- from regulated financial and payment service providers;
- from banking infrastructure providers;
- from digital asset and blockchain service providers;
- from fraud prevention and cybersecurity providers;
- from public databases, sanctions lists, PEP databases and regulatory sources;
- from blockchain networks and blockchain analytics services;
- from corporate registries and other publicly available sources;
- from counterparties involved in transactions;
- from other service providers where permitted by applicable law.
5. How We Use Personal Information
We may process personal information for the following purposes.
5.1 Providing and Operating the Services
To:
- create and administer your PALFA account;
- authenticate users;
- provide access to your dashboard;
- facilitate access to virtual accounts and payment functionality;
- facilitate payments and transfers;
- process transaction instructions;
- display account and transaction information;
- provide currency exchange functionality;
- facilitate digital asset transactions;
- provide fiat on-ramp and off-ramp functionality;
- maintain transaction history;
- provide customer support.
5.2 Identity Verification and Regulatory Compliance
To:
- verify identities;
- verify businesses and beneficial owners;
- conduct KYC and KYB checks;
- perform AML and counter-terrorist financing checks;
- screen against sanctions lists;
- identify politically exposed persons where required;
- conduct fraud and financial crime prevention;
- assess transaction risk;
- monitor transactions where required;
- comply with requests from competent authorities;
- comply with applicable financial crime and regulatory obligations.
Some compliance procedures may be performed directly by third-party regulated service providers or specialised compliance providers.
5.3 Security and Fraud Prevention
We may process information to:
- detect unauthorised account access;
- protect user accounts;
- prevent fraud;
- identify suspicious behaviour;
- protect our infrastructure;
- investigate security incidents;
- enforce account restrictions;
- protect PALFA, our users and service providers.
5.4 Communications
We may use your contact information to:
- provide service notifications;
- send security alerts;
- provide transaction notifications;
- respond to support requests;
- provide information about changes to the Services;
- communicate important legal or regulatory information.
5.5 Improving the Platform
We may analyse usage and technical information to:
- improve functionality;
- troubleshoot problems;
- understand how users interact with PALFA;
- develop new functionality;
- improve performance and security.
5.6 Marketing
Where permitted by applicable law, we may use your contact information to send information about PALFA products, features, promotions or updates.
Where consent is required, we will obtain your consent before sending such communications.
You may withdraw your marketing consent or unsubscribe from marketing communications at any time.
6. Legal Bases for Processing
Where the GDPR, UK GDPR or similar legislation applies, we process personal data under one or more of the following legal bases:
Performance of a Contract
Processing necessary to:
- create and maintain your account;
- provide requested Services;
- process instructions and transactions;
- provide customer support;
- administer our contractual relationship with you.
Legal Obligations
Processing necessary to comply with applicable laws and regulatory requirements, including where applicable:
- identity verification;
- financial crime prevention;
- AML requirements;
- sanctions requirements;
- fraud prevention;
- record-keeping;
- regulatory or lawful authority requests.
Legitimate Interests
We may process personal data where necessary for legitimate interests pursued by us or a third party, including:
- maintaining platform security;
- preventing fraud and abuse;
- protecting our legal rights;
- improving the Services;
- managing business operations;
- managing risks;
- establishing, exercising or defending legal claims.
We consider the impact on your rights and interests before relying on legitimate interests.
Consent
Where required, we may rely on your consent, including for certain:
- marketing communications;
- cookies and similar technologies;
- processing of information requiring explicit consent under applicable law.
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
7. KYC, KYB, AML and Compliance Processing
Access to certain PALFA functionality may require identity or business verification.
Personal information may therefore be shared with or processed by identity verification, compliance, regulated financial, payment and digital asset service providers for purposes including:
- KYC;
- KYB;
- AML screening;
- sanctions screening;
- PEP screening;
- fraud prevention;
- transaction monitoring;
- risk assessment;
- regulatory compliance.
These providers may request additional documentation or information directly from you.
Successful registration with PALFA does not guarantee approval for any particular financial service. Access to certain functionality may depend on successful verification, eligibility requirements, jurisdiction and approval by the relevant service provider.
8. Automated Processing and Risk Assessment
Certain verification, security, fraud prevention and compliance processes may involve automated tools or risk-scoring systems.
These systems may analyse information such as:
- identity verification results;
- account activity;
- transaction information;
- device information;
- geographic indicators;
- sanctions or PEP screening results;
- fraud indicators;
- blockchain transaction information;
- other relevant risk indicators.
Automated tools may flag an account or transaction for additional review.
Where a decision producing legal or similarly significant effects is based solely on automated processing and applicable law provides specific rights in relation to that decision, we or the relevant service provider will provide those rights as required by applicable law.
9. How We Share Personal Information
We do not sell personal information.
We may share personal information where necessary with the following categories of recipients.
Financial and Payment Service Providers
Including regulated financial institutions, payment institutions, electronic money institutions, banking infrastructure providers, payment processors and other financial service providers involved in providing functionality available through PALFA.
Digital Asset Service Providers
Including providers supporting digital asset wallets, stablecoins, fiat-to-digital-asset conversions, digital-asset-to-fiat conversions, transfers or related infrastructure.
Identity and Compliance Providers
Including providers of:
- KYC and KYB verification;
- AML screening;
- sanctions screening;
- fraud prevention;
- PEP screening;
- transaction monitoring;
- blockchain analytics.
Technology Providers
Including:
- cloud infrastructure providers;
- hosting providers;
- cybersecurity providers;
- email and communications providers;
- analytics providers;
- customer support technology providers.
Professional Advisers
Including lawyers, accountants, auditors, consultants and other professional advisers where necessary.
Authorities and Regulators
We may disclose information where required or permitted by law to:
- courts;
- law enforcement authorities;
- financial intelligence units;
- regulators;
- tax authorities;
- sanctions authorities;
- other competent governmental bodies.
Corporate Transactions
Personal information may be disclosed in connection with a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, subject to appropriate confidentiality and data protection safeguards.
10. International Data Transfers
PALFA operates internationally and some of our service providers may process personal information in countries outside your country of residence.
Where personal data protected by the GDPR or UK GDPR is transferred internationally, we take steps designed to ensure that the transfer is made using an appropriate lawful transfer mechanism where required.
Depending on the circumstances, these mechanisms may include:
- an adequacy decision issued by the European Commission or relevant authority;
- Standard Contractual Clauses;
- the UK International Data Transfer Agreement or applicable UK transfer addendum;
- other safeguards permitted under applicable data protection legislation.
You may contact us for further information regarding safeguards applicable to international transfers of your personal data.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, regulatory, accounting, compliance and security requirements.
Retention periods may vary depending on:
- the type of information;
- the Services used;
- contractual requirements;
- regulatory requirements;
- AML and financial crime record-keeping requirements;
- potential or actual disputes;
- fraud prevention requirements;
- legal limitation periods;
- requirements imposed on regulated service providers.
Certain KYC, KYB, transaction and compliance records may be retained after an account has been closed where required by applicable law or by a regulated provider's legal obligations.
Where information is no longer required, we will delete, anonymise or otherwise securely dispose of it, subject to applicable legal requirements.
12. Data Security
We implement reasonable technical and organisational measures designed to protect personal information against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure.
Measures may include access controls, authentication mechanisms, encryption where appropriate, logging, monitoring and security controls.
However, no electronic transmission or storage system can be guaranteed to be completely secure.
You are responsible for maintaining the confidentiality of your account credentials and should contact us immediately if you believe your account has been compromised.
13. Your Data Protection Rights
Depending on your location and applicable law, you may have the right to:
- Access your personal data;
- Rectify inaccurate or incomplete personal data;
- Erase personal data in certain circumstances;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests;
- Data portability for certain information;
- Withdraw consent where processing is based on consent;
- request information concerning certain automated decisions;
- lodge a complaint with an applicable data protection authority.
These rights are not absolute and may be restricted where applicable law permits or requires continued processing, including for compliance, fraud prevention, AML, legal claims or regulatory obligations.
Your Right to Object
Where we process your personal data on the basis of legitimate interests, you have the right to object to that processing on grounds relating to your particular situation.
You also have the right to object at any time to processing of your personal data for direct marketing purposes.
To exercise your rights, contact:
support@palfa.se
We may need to verify your identity before processing a request.
14. Regulatory Complaints
If you are located in the European Economic Area, you have the right to lodge a complaint with the data protection supervisory authority in the country where you live, work, or where you believe an infringement occurred.
If you are located in the United Kingdom, you may have the right to lodge a complaint with the UK Information Commissioner's Office.
We encourage you to contact us first so that we have an opportunity to address your concerns.
15. Cookies and Similar Technologies
We may use cookies and similar technologies to:
- operate the website;
- maintain sessions;
- remember preferences;
- provide security functionality;
- analyse website performance and usage;
- improve the Services;
- support marketing where permitted.
Where applicable law requires consent for non-essential cookies, such cookies will be used only after the required consent has been obtained.
More information is available in our Cookie Policy.
16. Third-Party Services
PALFA integrates with third-party technology, financial, payment, compliance and digital asset service providers.
When a third party acts as an independent data controller, its processing of personal information may also be governed by its own privacy policy.
We encourage users to review any applicable third-party privacy information presented during the use of a particular service.
PALFA is not responsible for the privacy practices of unrelated third-party websites accessed through external links.
17. Blockchain Information
Certain digital asset transactions occur on public or distributed blockchain networks.
Blockchain transactions may be permanently recorded and publicly visible. Information recorded directly on a blockchain may not be capable of being altered or erased by PALFA.
We do not control public blockchain networks and cannot modify information independently recorded on such networks.
18. Children
PALFA is not intended for individuals under the age of 18.
We do not knowingly provide accounts or financial functionality to children.
If we become aware that personal information has been collected from an individual who is not legally eligible to use the Services, we may delete or restrict that information as appropriate, subject to applicable legal and regulatory requirements.
19. Providing Personal Information
Certain information is necessary for us or our service providers to:
- create and secure your account;
- verify your identity;
- meet compliance requirements;
- process transactions;
- provide requested Services.
If required information is not provided, we or the relevant service provider may be unable to provide some or all functionality.