Brunaxe
Legal

Privacy Policy

How we collect, use and protect your personal data.

1. Data Controller

Brunaxe SAS, registered office at 88 Neugutstrasse, 8600 Dübendorf, Zurich, is the controller of your personal data. For any questions about data protection, you can contact our Data Protection Officer at: dpo@brunaxe.com.

2. Data Collected

  • Identification data: name, first name, date of birth, ID document number.
  • Contact data: email address, postal address.
  • Financial data: income, expenses, bank statements, IBAN.
  • Browsing data: IP address, browser type, pages visited, session duration.
  • Document data: supporting documents uploaded to your personal space.
  • Transaction data: repayment history, amounts, due dates.

3. Purposes of Processing

  • Assessment and processing of your loan application.
  • Management of your account and personal space.
  • Fraud prevention and identity verification (KYC/AML compliance).
  • Compliance with legal and regulatory obligations (ECB, EBA, national competent authorities).
  • Improvement of our services and personalization of your experience.
  • Sending communications about your contract or our offers (with your consent).

4. Legal Basis

The processing of your data is based on: (1) performance of the loan contract, (2) compliance with our banking and financial legal obligations, (3) our legitimate interests in fraud prevention, and (4) your explicit consent for marketing communications.

5. Retention Period

  • Active account data: account lifetime + 5 years after closure.
  • Loan file data: 10 years from the end of the contract.
  • KYC data: 5 years after the end of the business relationship.
  • Browsing data and cookies: maximum 13 months.
  • Commercial prospecting data: 3 years after the last contact.

6. Data Sharing

  • Technical service providers (hosting, security) bound by GDPR-compliant contracts.
  • Banking partners for file validation and fund transfer.
  • Competent authorities (ECB, EBA, national financial intelligence units) under anti-money laundering obligations.
  • No sale of your data to third parties for commercial purposes.

7. Your Rights (GDPR)

  • Right of access: obtain a copy of your personal data.
  • Right of rectification: correct inaccurate or incomplete data.
  • Right to erasure: request deletion of your data under certain conditions.
  • Right to restriction: temporarily restrict the processing of your data.
  • Right to portability: receive your data in a structured, machine-readable format.
  • Right to object: object to certain processing based on our legitimate interests.
  • To exercise these rights: dpo@brunaxe.com.

8. Cookies

Brunaxe uses technical cookies necessary for the website to function, analytical cookies to measure audience (with your consent), and no third-party advertising cookies. You can manage your cookie preferences at any time through your browser settings.

9. Security

Brunaxe implements appropriate technical and organizational measures to protect your data: TLS/AES-256 encryption, two-factor authentication, strict access controls and regular security audits. In the event of a data breach, you will be notified within the timeframes required by regulation.

10. Complaints

If you believe your rights are not being respected, you can file a complaint with the data protection supervisory authority in your member state of residence (e.g., CNIL in France, APD in Belgium, AEPD in Spain, Garante in Italy). The full list is available on the European Data Protection Board website: edpb.europa.eu.