This notice explains how Trillion Digital handles personal information about website visitors, people making enquiries, introducers, applicants, counterparties, and their representatives and beneficial owners. It covers personal information collected through our website and in connection with our trading and onboarding services.
1. Who is responsible for your information
Trillion Capital Markets Inc. operates this website. Trillion Capital Markets Inc. and Trillion Capital Markets AG, each trading as Trillion Digital, process information in connection with their respective services. The entity handling your enquiry or providing your service is responsible for the processing it determines. Your signed agreement identifies your contracting entity; see Regulatory Information for entity details.
The entities share client information within the group for permitted service and compliance purposes. Each remains responsible for its own legal obligations. This notice does not make the entities interchangeable or change your contracting party. For U.S. consumer financial information, read the GLB Privacy Notice alongside this policy; its specific sharing disclosures apply to that information.
2. Information we collect and its sources
Information you provide may include your name, business contact details, role, organisation, enquiry, and communications with us. Onboarding and ongoing due diligence may also require identity documents, residential address, date of birth, nationality, tax identifiers, ownership and control information, and evidence of source of funds or wealth.
When relevant to your services, we process bank and wallet details, payment instructions, quotes, trade and settlement records, and supporting financial information. Representatives or introducers may supply information about you. We may obtain information from identity-verification providers, public registers, sanctions sources, and blockchain records.
Website and security systems process technical information such as IP addresses, browser and device information, request activity, security signals, and consent preferences. Optional analytics and performance measurement are described in our Cookies Policy. Please do not send identification documents or sensitive financial records through a general enquiry form; use the secure channel provided during onboarding.
3. Why we use information
We use information to respond to enquiries, assess and onboard counterparties, communicate about services, execute and settle agreed transactions, maintain records, and resolve service issues. We also use it to meet identity-verification, sanctions, anti-money-laundering, reporting, and other applicable legal obligations.
We process security information to prevent fraud, impersonation, automated abuse, and unauthorised access, and to investigate technical problems. Our public forms use Vercel BotID browser verification. A failed check may prevent submission; contact us if you need help. This is separate from optional analytics consent.
Where we send marketing communications, you may ask us to stop. This does not stop necessary service, security, or legal communications. We do not sell or rent your personal information.
4. Applicable privacy law and legal grounds
The rights and requirements that apply depend on the entity, processing, and applicable law. Swiss processing is subject to the Swiss Federal Act on Data Protection where applicable. EU GDPR and UK GDPR requirements are considered separately where their territorial scope applies; residence alone does not determine every applicable rule.
Where GDPR or UK GDPR requires a legal basis, we rely, as appropriate, on steps requested before a contract or performance of a contract with you; applicable legal obligations; legitimate interests in operating and securing our business, subject to your rights; or consent where required. Processing a corporate representative's information may rely on legitimate interests rather than a contract with that individual. Withdrawing consent does not affect earlier lawful processing or processing supported by another valid basis.
5. Who receives information
We share information within the Trillion group where necessary and permitted for service delivery, administration, risk management, or compliance. Access is limited according to the purpose and applicable restrictions. The U.S. GLB notice explains the sharing choices for information within its scope.
Recipients may include hosting and communications providers, onboarding and verification providers, professional advisers, and banks or transaction providers involved in delivering your service. They receive information needed for their role, subject to applicable confidentiality, security, and data-protection requirements. Authorities, courts, auditors, and supervisors may receive information where disclosure is required or permitted by law.
A transaction may require originator, beneficiary, or other transfer information to be provided to another financial intermediary. We do not promise to notify you of disclosures where doing so is prohibited by law. Public blockchain transactions may be visible to others and cannot generally be removed by us.
6. International processing
Information may be processed outside your country, including between our U.S. and Swiss entities and by service providers. Applicable transfer requirements depend on the origin, destination, recipient, and type of information. Transfers requiring safeguards must have an appropriate legal basis, such as an applicable adequacy decision, recognised contractual safeguards, or a permitted statutory exception.
For information about the destination countries and safeguards relevant to your relationship, or to request a copy of applicable safeguards, contact compliance@trilliondigital.io. A provider's location or a group relationship does not by itself establish that a transfer is protected.
7. Retention and security
We retain information for the period needed for its purpose and applicable legal obligations. Retention depends on the record category, entity, relationship, and relevant legal trigger; there is no single period for all data. Enquiries, security records, customer due-diligence files, and transaction records may have different schedules. Legal holds, investigations, disputes, and reporting duties can require longer retention.
Closing an account or requesting deletion does not override mandatory recordkeeping. When information is no longer needed and no retention obligation applies, it should be deleted or anonymised under the applicable retention process. Ask us for the period or criteria applicable to a particular record.
We use technical and organisational safeguards appropriate to the information and processing, including access restrictions and protected transmission. No system or communication method is completely secure. Protect your own credentials and verify unexpected requests for documents or changes to settlement instructions.
8. Your rights and choices
Depending on applicable law, you may request access, correction, erasure, restriction, or information about processing, and object to certain processing. Where applicable, portability covers information you provided that is processed by automated means on the basis of consent or a contract. You may withdraw consent and object to direct marketing.
Send requests to compliance@trilliondigital.io. We may need proportionate identity verification. Requests are handled within the applicable statutory deadline and ordinarily without charge; any fee, extension, restriction, or refusal must have a lawful basis. We will explain our response to the extent permitted by law.
You may also complain to the competent data-protection authority, including the Swiss FDPIC, the UK ICO, or the relevant EU supervisory authority where applicable. You do not need to contact us first to exercise that right. Rights may be limited by mandatory retention, reporting confidentiality, or the rights of others.
9. Updates and contact
We will update the revision date when this notice changes and provide additional notice where required by law. A new website notice does not itself supply consent for a use that requires consent.
For privacy questions, requests, or concerns about either entity, email compliance@trilliondigital.io. Identify the service or entity involved where possible so the request can be routed correctly.
