Privacy policy of Fanpla AG

Version 1.0 – 30 January 2026


About us

This privacy policy (“Privacy Policy”) explains how we process and protect your personal data when you use this Website or our services provided via www.fanpla.ch (together, the “Services”).
These Services are operated by Fanpla AG, Dammstrasse 16, 6300 Zug, Switzerland (the “Company”, “we”, “our”, or “us”). The Company is the controller for the data processing described below.
Unless otherwise defined in this Privacy Policy, the definitions used in this Privacy Policy have the same meaning as in the Swiss Federal Act on Data Protection (FADP) or the EU General Data Protection Regulation (GDPR).

1.Personal data we collect

We may collect or receive personal information for a number of purposes connected with our business operations when you use our Services, namely:
-Usage and analytics information (e.g., identifiers, numbers of clicks, tracking data)
-Contact details (e.g., name, address, phone number, birth date)
-Geolocation (e.g., your actual location, GPS data)
-Login details (e.g., password, username, session)
-Payment details (e.g., billing information, credit card details)
-Request details (e.g., details and content of your inquiries)
-Website visitor details (e.g., IP address, logfiles, terminal ID)
-Public wallet addresses (e.g. telephone numbers, birthdates, purchase history, member history)
There is no obligation to provide your personal data. However, please note that our Services cannot be provided if you do not provide the required data strictly necessary for performing the contract between you and us.

2.How we collect personal data

We collect information about our users when they use our Services, including taking certain actions within it.
Directly
-Via our Website and electronic communication
-When you use our Services
-When you provide services to us
-When you correspond with us by electronic means using our Services
-When you browse, complete a form or make an inquiry while using our Services
Indirectly
-Through public sources
-From public registers (such as commercial registers), news articles and internet searches
-When our business customers engage us to perform professional services which involve them sharing personal data they control with -us as part of that engagement
-From external Service Providers (see section 5)

3.Legal Basis and purposes

Our legal basis for collecting and using the personal data described in this Privacy Policy depends on the personal data we collect and the specific purposes for which we collect it.
Contract: To perform our contractual obligations or take steps linked to a contract with you. In particular:
-To provide you with customer support
-To set up and manage your account, as well as to verify your credentials when logging in
-To provide our Services
Legitimate interests: We rely on legitimate interests based on our assessment that the processing is fair and reasonable and does not override your interests or fundamental rights and freedoms. In particular:
-To place essential cookies and other tools on your browser that are technically necessary for our Services
-To develop new services
-To maintain and improve our Services, as well as to detect, prevent, and address security threats
Necessity for compliance with legal obligations: To meet regulatory and public interest obligations. In particular:
-To notify you about changes to our Services and our Privacy Policy
-To comply with applicable regulations and legislation.
-For the legal enforcement of claims and rights.

4.Data retention

We retain personal data for so long as it is needed for the purposes for which it was collected and in line with legal and regulatory requirements or contractual arrangements. After this period, we delete or fully anonymize your personal data.

5.Data recipients

We engage third-party companies (“Service Providers”) to facilitate the operation of our Services, assist in analysing the usage of the Services, or perform necessary services, such as payment and the provision of IT services. These third parties have access to your personal data only to the extent necessary to perform these tasks.
Type(s) of Service Providers who might access your personal data:
-Third parties that are engaged in the course of your matter, such as counsels, banks and other payment providers, KYC/AML service providers, and postal or courier providers
-Other group entities that are involved in your matter
-Third parties who provide IT and software services
-Third parties who help us with client insights and marketing

6.Data transfers

We and/or our Service Providers may transfer your personal data to and process it in the following countries:
-EU
We may use Service Providers partly located in so-called third countries (outside the European Union or the European Economic Area or Switzerland) or process personal data there, i.e., countries whose level of data protection does not correspond to that of the EU or Switzerland.
We safeguard your personal data per our contractual obligations and applicable data protection legislation when transferring data abroad.
Such safeguards may include:
-The transfer to countries that have been deemed to provide an adequate level of protection according to the Federal Council, as well as to countries where there is an adequacy decisions by the European Commission in place
-Applying standard data protection model clauses, binding corporate rules or other standard contractual obligations that provide appropriate data protection

If a third country transfer takes place and there is no adequacy decision or appropriate safeguards, it is possible and there is a risk that authorities in the third country (e.g. intelligence services) can gain access to the transferred data and that the enforceability of your data subject’s rights cannot be guaranteed.

7.Data disclosure

We may disclose your personal data in the good faith belief that such action is necessary:
-To comply with a legal obligation (i.e., if required by law or in response to valid requests by public authorities, such as a court or government agency)
-To protect the security of our Services and defend our rights or property
-To prevent or investigate possible wrongdoing in connection with us

8.Data on the blockchain

When using our Services or using any applicable blockchain in relationship with our Services, you should be aware that any transactions will be publicly and irrevocably archived on the applicable blockchain once you sign them and send them to the network. These transactions typically include information about how many tokens have been bought, sold, transferred or otherwise interacted with, a timestamp, and the involved addresses. They do not include data such as your name or e-mail address. Nonetheless, once someone knows that a particular address belongs to you, they can connect all the transactions involving that address to you.

9.Data security

We take reasonable technical and organisational security measures that we deem appropriate to protect your stored data against manipulation, loss, or unauthorised third-party access. Our security measures are continually adapted to technological developments.
We also take internal data privacy very seriously. Our employees and the service providers that we engage are required to maintain secrecy and comply with applicable data protection legislation. In addition, they are granted access to personal data only insofar as this is necessary for them to carry out their respective tasks or mandate.
The security of your personal data is important to us but remember that no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security. We recommend using antivirus software, a firewall, and other similar software to safeguard your system.

10.Your rights

You have the below data protection rights. To exercise these rights, you may contact the above address or send an e-mail to: support@fanpla.ch. Please note that we may ask you to verify your identity before responding to such requests.
-Right of access: You have a right to request a copy of your personal data, which we will provide to you in an electronic form.
-Right to amendment: You have the right to ask us to correct our records if you believe they contain incorrect or incomplete information about you.
-Right to withdraw consent: If you have provided your consent to the processing of your personal data, you have the right to withdraw your consent at any time with effect for the future. This includes cases where you wish to opt-out from marketing communications. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you initially consented to unless there is another legal basis for processing.
-Right to erasure: You have the right to request that we delete your personal data when it is no longer necessary for the purposes for which it was collected or when it was unlawfully processed.
-Right to restriction of processing: You have the right to request the restriction of our processing of your personal data where you believe it to be inaccurate, our processing is unlawful, or where we no longer need to process it for the initial purpose, but where we are not able to delete it due to a legal obligation or because you do not want us to delete it.
-Right to portability: You have the right to request that we transmit your personal data to another data controller in a standard format such as Excel, if this is data which you have provided to us and if we are processing it on the legal basis of your consent or to perform our contractual obligations.
-Right to object to processing: Where the legal basis for our processing of your personal data is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have a compelling legal basis for the processing which overrides your interests or if we need to continue to process the personal data for the exercise or defence of a legal claim.
-Right to lodge a complaint with a supervisory authority: You have the right of appeal to a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. The competent data protection authority in Switzerland is the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch/edoeb/en/home.html). In the EU and EEA, you can exercise this right, for example, before a supervisory authority in the Member State of your residence, your place of work or the place of the alleged infringement. You can find a list of the relevant authorities here: https://edpb.europa.eu/about-edpb/board/members_en.

11.Cookies

This website uses cookies and similar technologies (collectively “tools”) provided either by us or by third parties.
A cookie is a small text file that is stored on your device by the browser. Comparable technologies are in particular web storage (local / session storage), fingerprints, tags or pixels. Most browsers are set by default to accept cookies and similar technologies. However, you can usually adjust your browser settings so that cookies or similar technologies are rejected or only stored with your prior consent. If you refuse cookies or similar technologies, you may not be able to use all of our services without problems.
In the following, we list the essential tools we use, whereby we inform you in particular about the providers of the tools, the storage period of the cookies and the transfer of data to third parties.

Essential tools
We use certain tools to enable the basic functions of our website. Without these tools, we could not provide our service. Therefore, these tools are used without consent based on our legitimate interests or to fulfil a contract or to carry out pre-contractual measures.

11.1 WordPress

Our website uses WordPress, a service provided by Automattic Inc, 60 29th Street #343 San Francisco, CA 94110 United States of America, (“Wordpress”). WordPresst is a web content management system. It was originally created as a tool to publish blogs but has evolved to support publishing other web content, including more traditional websites, mailing lists, Internet forums, media galleries, membership sites, learning management systems, and online stores. WordPress is written in the PHP programming language and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
Tools used:
●wpEmojiSettingsSupports (session): To store browser details on emoji support
●wordpress_test_cookie (session): To read if cookies can be placed
●wordpress_logged_in_* (persistent): To store logged in users
●wp-settings-time-1 (1 year): To Save user settings
To know more about WordPress cookie usage, consult its privacy policy and cookie policy.

11.2 Polylang

Our website uses Polylang, a service provided by WP SYNTEX, 8 rue Joseph Cugnot (38307) BOURGOIN JALLIEU, FRANCE (“Polylang”). Polylang is an open-source WordPress plugin enabling you to easily create multilingual pages for posts and static pages.
Tools used:
●pll_language (persistent): To store language setting
For more information, please see Polylang’s privacy policy here.

11.3 Google Fonts

Our website uses Google Fonts, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google Fonts”), to ensure a consistent and visually appealing presentation of fonts. The Google Fonts used on this website are hosted locally on our own servers and integrated via CSS files. As a result, no connection to Google servers is established when you visit our website.
Through the local hosting of Google Fonts, no personal data, in particular IP addresses, are transmitted to Google. No cookies or comparable tracking technologies are used in this context.

12.Social Media

We maintain online presences on social networks to, among other things, communicate with customers and prospective customers and to provide information about our products and Services. If you have an account on the same network, it is possible that your information and media made available there may be seen by us, for example, when we access your profile. In addition, the social network may allow us to contact you. As soon as we transfer personal data into our own system, we are responsible for this independently. This is then done to carry out pre-contractual measures and to fulfil a contract. For the legal basis of the data processing carried out by the social networks under their own responsibility, please refer to their data protection declarations. Below is a list of social networks on which we operate an online presence:
-X: Privacy Policy
-Telegram: Privacy Policy
-LinkedIn: Privacy Policy

13.Changes to this Privacy Policy

We may update our Privacy Policy from time to time. We therefore encourage you to review this Privacy Policy periodically for any changes.
Changes to this Privacy Policy are effective when they are posted on this page.

14.Contact us

If you have any questions about this Privacy Policy, do not hesitate to get in touch with us at:
Fanpla AG,
Dammstrasse 16, 6300 Zug, Switzerland
support@fanpla.ch.

Partnership