Privacy Policy
Updated 23rd January 2026
Introduction and scope
This Privacy Policy explains how pfolio GmbH (“Company”, “we”, “us”) processes personal data in connection with the use of its website, digital platform, and related services (collectively, the “Platform”).
We process personal data in accordance with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the General Data Protection Regulation (GDPR). This Privacy Policy applies to website visitors and registered users (“Users”).
Data controller and contact
The data controller is:
pfolio GmbH
Sinserstrasse 67
CH-6330 Cham
Users may contact us regarding data protection matters by email at privacy@pfolio.io.
Categories of personal data
We process the following categories of personal data, depending on how the Platform is used:
- Identification and account data, such as name, email address, and account credentials
- Usage and technical data, such as IP address, device and browser information, pages visited, and interactions with the Platform
- Investor profile data, such as onboarding questionnaire responses, risk tolerance, investment objectives, and portfolio preferences, where applicable.
- Communication data, such as support requests and email correspondence
- Payment and subscription data, such as subscription status and payment identifiers (payment card details are processed by our payment provider and are not stored by the Company)
We do not intentionally process special categories of personal data, unless required by applicable law.
Purposes of processing
We process personal data for the following purposes:
- to operate and provide the Platform and its functionalities
- to register and manage user accounts
- to perform investor profiling and provide investment advisory services, where applicable
- to manage subscriptions and payments
- to communicate with Users, including support and service-related messages
- to send marketing communications, where Users have provided consent
- to analyse and improve the Platform
- to ensure security and prevent misuse
- to comply with legal and regulatory obligations
Legal bases for processing
Personal data is processed in accordance with applicable Swiss data protection law and, where applicable, the GDPR. Processing is based in particular on:
- the performance of a contract or steps taken prior to entering into a contract
- compliance with legal obligations
- the Company’s legitimate interests in operating and improving the Platform
- the User’s consent, where required (for example, for marketing communications)
Marketing emails are sent only where Users have provided consent through a double opt-in process. Users may withdraw their consent at any time.
Cookies and analytics
The Platform uses cookies and similar technologies to ensure basic functionality and to analyse usage.
We use Google Analytics to collect information about how visitors interact with the website, such as pages visited, interactions, and technical information about the device and browser used. This information is used to analyse usage patterns and improve the Platform and user experience.
Users may restrict or disable cookies through their browser settings.
Data sharing and international transfers
Personal data may be shared with service providers acting on our behalf, including:
- Webflow – website hosting and content delivery
- Render – application hosting
- Stripe – payment processing
- SendGrid – email delivery
- Google Analytics – website analytics
Personal data may be processed in Switzerland, the European Union, and, in some cases, in other countries such as the United States. Where personal data is transferred outside Switzerland or the EU/EEA, appropriate safeguards are implemented, including adequacy decisions or standard contractual clauses.
We do not sell personal data.
Data retention and security
Personal data is retained only for as long as necessary to fulfil the purposes described in this Privacy Policy or as required by applicable law.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse. However, no method of transmission or storage is completely secure.
Rights of Users
Users may have the right to:
- access their personal data
- request rectification of inaccurate or incomplete data
- request deletion of personal data, where legally permissible
- request restriction of processing
- receive personal data in a portable format (GDPR, where applicable)
- object to certain processing activities (GDPR, where applicable)
- withdraw consent at any time, where processing is based on consent
Users also have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, with a competent EU supervisory authority.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The current version is published on our website. Material changes will be communicated in an appropriate manner.