Back to site

Policy Pages

Privacy Policy

How we collect, use, protect, and disclose personal information.

Privacy Policy


Last Updated: January 1, 2026



1. Introduction


This Privacy Policy explains how PALFA AB, registration number 5590353669 ("PALFA AB", "PALFA", "we", "us", or "our"), collects, uses, stores, shares, and otherwise processes personal information when you access or use the PALFA website, platform, applications, accounts, and related services (collectively, the "Services").


PALFA is a financial technology platform operated by PALFA AB.


We are committed to protecting your privacy and processing personal data in accordance with applicable data protection laws, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and other applicable privacy and data protection legislation.


This Privacy Policy applies to visitors to our website, registered users, prospective users, representatives and beneficial owners of business customers, and other individuals whose personal information we process in connection with the Services.


By accessing or using PALFA, you acknowledge that your personal information will be processed as described in this Privacy Policy.



2. Data Controller


For personal data processed in connection with the operation of the PALFA platform, the data controller is:


PALFA AB

Registration No.: 5590353669

Registered Office: c/o YourOffice, Bror Nilssons gata 5, 417 55 Göteborg, Sweden

Website: palfa.se

Email: support@palfa.se


Depending on the service you use, certain regulated financial institutions, payment service providers, digital asset service providers, identity verification providers, compliance providers, banking infrastructure providers, or other third-party service providers may process your personal information as independent data controllers or processors in accordance with their own legal and regulatory obligations.



3. Personal Information We Collect


The information we collect depends on how you interact with PALFA and which Services you use.


3.1 Account and Contact Information


We may collect:


- full name;

- email address;

- telephone number;

- residential or business address;

- country of residence;

- nationality;

- date of birth;

- account username and identifiers;

- language and communication preferences;

- account type and profile information.


3.2 Identity Verification Information


Where identity verification is required, we or our verification and compliance service providers may collect and process:


- passport;

- national identity card;

- driving licence;

- photograph or selfie;

- proof of residential address;

- date and place of birth;

- nationality and citizenship information;

- tax identification information where required;

- identity verification results;

- information required for KYC, KYB, AML and sanctions screening.


Where permitted or required by applicable law, identity verification processes may involve biometric information derived from photographs, facial images or identity documents for the purpose of verifying identity and preventing fraud.


Where biometric or other special-category personal data is processed, such processing will be carried out only where an appropriate legal basis and any additional condition required by applicable law applies.


3.3 Business Customer Information


For business accounts, we may collect:


- company name;

- registration number;

- registered address;

- business address;

- incorporation documents;

- ownership and corporate structure;

- directors and authorised representatives;

- shareholders and ultimate beneficial owners;

- nature of business;

- expected account activity;

- source of funds and source of wealth information where required;

- licences or regulatory information where applicable;

- corporate bank or financial information;

- other documentation required for KYB and compliance purposes.


3.4 Financial and Transaction Information


When you use financial functionality available through PALFA, we may process information including:


- virtual account and IBAN information;

- account identifiers;

- balances made available to the platform;

- payment instructions;

- beneficiaries and counterparties;

- transaction amounts;

- currencies;

- payment references;

- transaction dates and status;

- SEPA and international payment information;

- exchange transactions;

- digital asset transactions;

- wallet addresses;

- blockchain transaction identifiers;

- fiat-to-digital-asset and digital-asset-to-fiat transactions;

- transaction history;

- fees and exchange information.


We may receive some of this information directly from financial, payment, banking infrastructure, digital asset or other service providers connected to the Services.


3.5 Digital Asset Information


Where you use digital asset functionality, we may process:


- cryptocurrency or stablecoin wallet addresses;

- supported digital assets;

- transaction amounts;

- blockchain network information;

- transaction hashes;

- deposit and withdrawal information;

- conversion information;

- blockchain analytics and risk indicators.


Information recorded on public blockchains may be publicly accessible and cannot necessarily be modified or deleted by PALFA.


3.6 Technical and Device Information


When you access PALFA, we may automatically collect:


- IP address;

- browser type and version;

- operating system;

- device identifiers;

- device type;

- language settings;

- login timestamps;

- session information;

- pages viewed;

- referral information;

- security events;

- cookies and similar technologies;

- approximate location derived from IP address.


We use this information to operate the platform, maintain security, prevent fraud, troubleshoot technical issues and improve the Services.


3.7 Communications and Support


When you contact us, we may process:


- emails;

- support requests;

- chat communications;

- complaints;

- documents or information submitted to support;

- records of communications with us.



4. How We Collect Personal Information


We may collect personal information:


- directly from you when you register or use PALFA;

- when you complete KYC or KYB procedures;

- when you initiate or receive transactions;

- when you communicate with us;

- automatically through your use of our website or platform;

- from identity verification and compliance providers;

- from regulated financial and payment service providers;

- from banking infrastructure providers;

- from digital asset and blockchain service providers;

- from fraud prevention and cybersecurity providers;

- from public databases, sanctions lists, PEP databases and regulatory sources;

- from blockchain networks and blockchain analytics services;

- from corporate registries and other publicly available sources;

- from counterparties involved in transactions;

- from other service providers where permitted by applicable law.



5. How We Use Personal Information


We may process personal information for the following purposes.


5.1 Providing and Operating the Services


To:


- create and administer your PALFA account;

- authenticate users;

- provide access to your dashboard;

- facilitate access to virtual accounts and payment functionality;

- facilitate payments and transfers;

- process transaction instructions;

- display account and transaction information;

- provide currency exchange functionality;

- facilitate digital asset transactions;

- provide fiat on-ramp and off-ramp functionality;

- maintain transaction history;

- provide customer support.


5.2 Identity Verification and Regulatory Compliance


To:


- verify identities;

- verify businesses and beneficial owners;

- conduct KYC and KYB checks;

- perform AML and counter-terrorist financing checks;

- screen against sanctions lists;

- identify politically exposed persons where required;

- conduct fraud and financial crime prevention;

- assess transaction risk;

- monitor transactions where required;

- comply with requests from competent authorities;

- comply with applicable financial crime and regulatory obligations.


Some compliance procedures may be performed directly by third-party regulated service providers or specialised compliance providers.


5.3 Security and Fraud Prevention


We may process information to:


- detect unauthorised account access;

- protect user accounts;

- prevent fraud;

- identify suspicious behaviour;

- protect our infrastructure;

- investigate security incidents;

- enforce account restrictions;

- protect PALFA, our users and service providers.


5.4 Communications


We may use your contact information to:


- provide service notifications;

- send security alerts;

- provide transaction notifications;

- respond to support requests;

- provide information about changes to the Services;

- communicate important legal or regulatory information.


5.5 Improving the Platform


We may analyse usage and technical information to:


- improve functionality;

- troubleshoot problems;

- understand how users interact with PALFA;

- develop new functionality;

- improve performance and security.


5.6 Marketing


Where permitted by applicable law, we may use your contact information to send information about PALFA products, features, promotions or updates.


Where consent is required, we will obtain your consent before sending such communications.


You may withdraw your marketing consent or unsubscribe from marketing communications at any time.



6. Legal Bases for Processing


Where the GDPR, UK GDPR or similar legislation applies, we process personal data under one or more of the following legal bases:


Performance of a Contract


Processing necessary to:


- create and maintain your account;

- provide requested Services;

- process instructions and transactions;

- provide customer support;

- administer our contractual relationship with you.


Legal Obligations


Processing necessary to comply with applicable laws and regulatory requirements, including where applicable:


- identity verification;

- financial crime prevention;

- AML requirements;

- sanctions requirements;

- fraud prevention;

- record-keeping;

- regulatory or lawful authority requests.


Legitimate Interests


We may process personal data where necessary for legitimate interests pursued by us or a third party, including:


- maintaining platform security;

- preventing fraud and abuse;

- protecting our legal rights;

- improving the Services;

- managing business operations;

- managing risks;

- establishing, exercising or defending legal claims.


We consider the impact on your rights and interests before relying on legitimate interests.


Consent


Where required, we may rely on your consent, including for certain:


- marketing communications;

- cookies and similar technologies;

- processing of information requiring explicit consent under applicable law.


You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.



7. KYC, KYB, AML and Compliance Processing


Access to certain PALFA functionality may require identity or business verification.


Personal information may therefore be shared with or processed by identity verification, compliance, regulated financial, payment and digital asset service providers for purposes including:


- KYC;

- KYB;

- AML screening;

- sanctions screening;

- PEP screening;

- fraud prevention;

- transaction monitoring;

- risk assessment;

- regulatory compliance.


These providers may request additional documentation or information directly from you.


Successful registration with PALFA does not guarantee approval for any particular financial service. Access to certain functionality may depend on successful verification, eligibility requirements, jurisdiction and approval by the relevant service provider.



8. Automated Processing and Risk Assessment


Certain verification, security, fraud prevention and compliance processes may involve automated tools or risk-scoring systems.


These systems may analyse information such as:


- identity verification results;

- account activity;

- transaction information;

- device information;

- geographic indicators;

- sanctions or PEP screening results;

- fraud indicators;

- blockchain transaction information;

- other relevant risk indicators.


Automated tools may flag an account or transaction for additional review.


Where a decision producing legal or similarly significant effects is based solely on automated processing and applicable law provides specific rights in relation to that decision, we or the relevant service provider will provide those rights as required by applicable law.



9. How We Share Personal Information


We do not sell personal information.


We may share personal information where necessary with the following categories of recipients.


Financial and Payment Service Providers


Including regulated financial institutions, payment institutions, electronic money institutions, banking infrastructure providers, payment processors and other financial service providers involved in providing functionality available through PALFA.


Digital Asset Service Providers


Including providers supporting digital asset wallets, stablecoins, fiat-to-digital-asset conversions, digital-asset-to-fiat conversions, transfers or related infrastructure.


Identity and Compliance Providers


Including providers of:


- KYC and KYB verification;

- AML screening;

- sanctions screening;

- fraud prevention;

- PEP screening;

- transaction monitoring;

- blockchain analytics.


Technology Providers


Including:


- cloud infrastructure providers;

- hosting providers;

- cybersecurity providers;

- email and communications providers;

- analytics providers;

- customer support technology providers.


Professional Advisers


Including lawyers, accountants, auditors, consultants and other professional advisers where necessary.


Authorities and Regulators


We may disclose information where required or permitted by law to:


- courts;

- law enforcement authorities;

- financial intelligence units;

- regulators;

- tax authorities;

- sanctions authorities;

- other competent governmental bodies.


Corporate Transactions


Personal information may be disclosed in connection with a merger, acquisition, restructuring, financing, sale of assets or similar corporate transaction, subject to appropriate confidentiality and data protection safeguards.



10. International Data Transfers


PALFA operates internationally and some of our service providers may process personal information in countries outside your country of residence.


Where personal data protected by the GDPR or UK GDPR is transferred internationally, we take steps designed to ensure that the transfer is made using an appropriate lawful transfer mechanism where required.


Depending on the circumstances, these mechanisms may include:


- an adequacy decision issued by the European Commission or relevant authority;

- Standard Contractual Clauses;

- the UK International Data Transfer Agreement or applicable UK transfer addendum;

- other safeguards permitted under applicable data protection legislation.


You may contact us for further information regarding safeguards applicable to international transfers of your personal data.



11. Data Retention


We retain personal information only for as long as reasonably necessary for the purposes for which it was collected and to satisfy applicable legal, regulatory, accounting, compliance and security requirements.


Retention periods may vary depending on:


- the type of information;

- the Services used;

- contractual requirements;

- regulatory requirements;

- AML and financial crime record-keeping requirements;

- potential or actual disputes;

- fraud prevention requirements;

- legal limitation periods;

- requirements imposed on regulated service providers.


Certain KYC, KYB, transaction and compliance records may be retained after an account has been closed where required by applicable law or by a regulated provider's legal obligations.


Where information is no longer required, we will delete, anonymise or otherwise securely dispose of it, subject to applicable legal requirements.



12. Data Security


We implement reasonable technical and organisational measures designed to protect personal information against:


- unauthorised access;

- unlawful processing;

- accidental loss;

- destruction;

- alteration;

- unauthorised disclosure.


Measures may include access controls, authentication mechanisms, encryption where appropriate, logging, monitoring and security controls.


However, no electronic transmission or storage system can be guaranteed to be completely secure.


You are responsible for maintaining the confidentiality of your account credentials and should contact us immediately if you believe your account has been compromised.



13. Your Data Protection Rights


Depending on your location and applicable law, you may have the right to:


- Access your personal data;

- Rectify inaccurate or incomplete personal data;

- Erase personal data in certain circumstances;

- Restrict processing in certain circumstances;

- Object to processing based on legitimate interests;

- Data portability for certain information;

- Withdraw consent where processing is based on consent;

- request information concerning certain automated decisions;

- lodge a complaint with an applicable data protection authority.


These rights are not absolute and may be restricted where applicable law permits or requires continued processing, including for compliance, fraud prevention, AML, legal claims or regulatory obligations.


Your Right to Object


Where we process your personal data on the basis of legitimate interests, you have the right to object to that processing on grounds relating to your particular situation.


You also have the right to object at any time to processing of your personal data for direct marketing purposes.


To exercise your rights, contact:


support@palfa.se


We may need to verify your identity before processing a request.


14. Regulatory Complaints


If you are located in the European Economic Area, you have the right to lodge a complaint with the data protection supervisory authority in the country where you live, work, or where you believe an infringement occurred.


If you are located in the United Kingdom, you may have the right to lodge a complaint with the UK Information Commissioner's Office.


We encourage you to contact us first so that we have an opportunity to address your concerns.



15. Cookies and Similar Technologies


We may use cookies and similar technologies to:


- operate the website;

- maintain sessions;

- remember preferences;

- provide security functionality;

- analyse website performance and usage;

- improve the Services;

- support marketing where permitted.


Where applicable law requires consent for non-essential cookies, such cookies will be used only after the required consent has been obtained.


More information is available in our Cookie Policy.



16. Third-Party Services


PALFA integrates with third-party technology, financial, payment, compliance and digital asset service providers.


When a third party acts as an independent data controller, its processing of personal information may also be governed by its own privacy policy.


We encourage users to review any applicable third-party privacy information presented during the use of a particular service.


PALFA is not responsible for the privacy practices of unrelated third-party websites accessed through external links.



17. Blockchain Information


Certain digital asset transactions occur on public or distributed blockchain networks.


Blockchain transactions may be permanently recorded and publicly visible. Information recorded directly on a blockchain may not be capable of being altered or erased by PALFA.


We do not control public blockchain networks and cannot modify information independently recorded on such networks.



18. Children


PALFA is not intended for individuals under the age of 18.


We do not knowingly provide accounts or financial functionality to children.


If we become aware that personal information has been collected from an individual who is not legally eligible to use the Services, we may delete or restrict that information as appropriate, subject to applicable legal and regulatory requirements.



19. Providing Personal Information


Certain information is necessary for us or our service providers to:


- create and secure your account;

- verify your identity;

- meet compliance requirements;

- process transactions;

- provide requested Services.


If required information is not provided, we or the relevant service provider may be unable to provide some or all functionality.