Privacy
Privacy policy
Privacy policy · As of 28 September 2026 · Version 2.1 (PoC / live operation) · English translation for convenience; only the German version is legally binding.
Protecting your personal data is a central concern for STATELY AG. We always process your personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR), the Liechtenstein Data Protection Act (DSG) and the relevant special statutory provisions, in particular the Liechtenstein Due Diligence Act (SPG).
1. Controller and data protection
Controller within the meaning of the GDPR:
STATELY AG
Landstrasse 123
9495 Triesen
Principality of Liechtenstein
Commercial register no.: FL-0002.756.745-6
Email: [email protected] / [email protected]
Website: www.statelyassets.com
Data protection coordination / data protection requests:
Email: [email protected]
2. Purposes and legal bases of processing
We process personal data for the following purposes and on the following legal bases:
Provision and operation of the platform: To fulfil contractual obligations and pre-contractual measures (Art. 6(1)(b) GDPR).
Identity verification, anti-money-laundering & compliance (KYC/AML): To fulfil statutory due diligence obligations under the Liechtenstein Due Diligence Act (SPG) and international sanctions provisions (Art. 6(1)(c) GDPR in conjunction with the SPG).
Payment processing and transaction management: To carry out deposits, payouts and interest credits (Art. 6(1)(b) GDPR).
Communication and support: To answer enquiries and provide contract-relevant information (Art. 6(1)(b) and (f) GDPR).
Web analytics and platform optimisation: To analyse user behaviour and detect errors on the basis of your voluntary consent (Art. 6(1)(a) GDPR).
IT security and abuse prevention: To ensure stability and defend against cyber attacks (Art. 6(1)(f) GDPR).
3. Hosting, infrastructure and data backup
To operate our systems we use specialised service providers with whom data processing agreements pursuant to Art. 28 GDPR have been concluded: Web hosting, domains & databases (World4You): We use web hosting and database services of World4You Internet Services GmbH, Hafenstraße 35, 4020 Linz, Austria. Data processing takes place in ISO-certified data centres in Austria (EU). Platform and server operation (STRATO): To operate our platform components we use servers (Linux environment) of STRATO AG, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. The data centres are located in Germany and are ISO 27001 certified. Cloud infrastructure & backup systems (Amazon Web Services, AWS): For redundant system backups (under Linux) and hosting functions we use services of Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg (parent company: Amazon.com, Inc., USA). Server location: exclusively data centres within the European Union (Frankfurt am Main region). Amazon.com, Inc. is certified under the EU-U.S. Data Privacy Framework; standard contractual clauses (SCCs) apply in addition.
4. Tag management, web analytics and cookies
Google Tag Manager: We use Google Tag Manager of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Tag Manager serves to embed and manage code segments (tags) on our website centrally. The service itself does not set cookies and does not process user profiles; however, your IP address is transmitted to Google when the scripts are loaded.
Legal basis: Legitimate interest in the efficient technical control of our platform (Art. 6(1)(f) GDPR).
Google Analytics: Where you have consented via our cookie banner (Art. 6(1)(a) GDPR), we use Google Analytics of Google Ireland Limited. Google Analytics uses cookies to analyse the use of the website. We use the anonymizeIp function, which shortens your IP address within the EEA. Transfer to Google LLC in the USA takes place on the basis of the EU-U.S. Data Privacy Framework. Microsoft Clarity: Where you have given your consent (Art. 6(1)(a) GDPR), we use the analytics service Microsoft Clarity of Microsoft Ireland Operations Ltd., One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (parent company: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA). Clarity creates pseudonymised session recordings, click and scroll heatmaps and error analyses to improve the usability of the platform. Sensitive input fields (such as passwords, addresses or payment data) are masked by Microsoft by default before transmission. Microsoft Corporation is certified under the EU-U.S. Data Privacy Framework. Withdrawal of cookie consent: You can withdraw consent to analytics cookies at any time with effect for the future by opening and adjusting the cookie settings via the link in the footer of our website.
5. Identity verification, compliance and disclosure to the partner bank
Identity and address verification via didit.me: For the legally required verification of identity and residence (KYC), document checks and sanctions list screening, we use the specialised service didit.me (Didit Technologies). Identity document data, photographs, registration data and biometric verification data are recorded and checked in encrypted form.
Legal basis: Fulfilment of legal obligations under the Due Diligence Act (Art. 6(1)(c) GDPR in conjunction with the SPG).
Disclosure to the partner bank (Bank Frick & Co. AG): We hold our business accounts with Bank Frick & Co. AG, Landstrasse 14, 9496 Balzers, Principality of Liechtenstein. For the regulatory processing of payment flows and compliance with banking supervisory due diligence obligations, we transmit the verified identification and transaction documents to Bank Frick. Bank Frick processes this data as an independent controller to fulfil its obligations under banking law.
6. Payment processing
Payment service provider Stripe: Payment transactions are processed via Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland (or Stripe, Inc., USA). Your payment details (card data, IBAN, amount, timestamp) are transmitted directly to Stripe via an encrypted connection. STATELY never stores complete card data. Stripe Inc. is certified under the EU-U.S. Data Privacy Framework. Bank transfers: For manual bank transfers, we process the account information contained in the payment advice to allocate your investment on our account with Bank Frick.
7. Communication, email delivery and newsletter
Transactional emails via Resend: For the automated sending of contract- and security-relevant emails (e.g. registration confirmations, order receipts, investment confirmations, 2FA codes) we use Resend (Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA). The data transfer is based on standard contractual clauses (SCCs).
Legal basis: Performance of the contract and legitimate interest (Art. 6(1)(b) and (f) GDPR).
Email marketing via Brevo: For information updates, investor relations announcements and platform news we use Brevo (Sendinblue GmbH, Köpenicker Str. 126, 10179 Berlin, Germany, or Brevo SAS, Paris, France). Emails are sent exclusively after your separate consent via a double opt-in procedure (Art. 6(1)(a) GDPR). You can unsubscribe at any time via the unsubscribe link at the end of every email.
8. Social media presences and third-party platforms
We maintain publicly accessible company profiles on external platforms: Links: Icons embedded on our website for external platforms (e.g. LinkedIn, Instagram, YouTube, X/Twitter) are designed as simple external links. Merely visiting our website does not transmit any data to the respective platform operators via these icons. Only by actively clicking the respective icon are you forwarded to the platform. Processing on platforms: When you visit our company profiles (e.g. on LinkedIn of LinkedIn Ireland Unlimited Company or Instagram/YouTube), the platform operators process personal data for market research and advertising purposes (among other things via cookies stored on your device). STATELY has no influence on this processing. For details, please refer to the privacy policies of the respective platforms. Embedded content (catch-all clause): Should content from external services (such as videos or graphics) be embedded directly on our website in exceptional cases, this content is only loaded after your express consent via the cookie banner or via privacy-friendly embedding solutions (e.g. YouTube in privacy-enhanced mode).
9. Storage period and statutory retention obligations
Due Diligence Act (SPG Liechtenstein): All documents and evidence relating to customer identification (KYC), beneficial owners and transactions are retained for at least 10 years from the end of the business relationship in accordance with Art. 28(5) SPG. Accounting and company law periods: Contracts, invoices and accounting records are retained for 10 years in accordance with the provisions of the Persons and Companies Act (PGR) and the Liechtenstein Tax Act (SteG). After the periods have expired, data is deleted or irreversibly anonymised unless other statutory retention obligations preclude this.
10. Your rights as a data subject
Under the GDPR you have the following rights towards STATELY AG: Right of access (Art. 15 GDPR) Right to rectification (Art. 16 GDPR) Right to erasure (Art. 17 GDPR), unless statutory obligations (in particular 10 years under the SPG) preclude this Right to restriction of processing (Art. 18 GDPR) Right to data portability (Art. 20 GDPR) Right to object (Art. 21 GDPR) to processing based on legitimate interests Withdrawal of consent given (Art. 7(3) GDPR) with effect for the future To exercise these rights, an informal email to [email protected] is sufficient.
11. Competent supervisory authority
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Data Protection Authority of the Principality of Liechtenstein (DSS)
Städtle 38
PO Box 684
9490 Vaduz
Principality of Liechtenstein
Phone: +423 236 60 90
Email: [email protected]
Website: www.datenschutzstelle.li