Regula Privacy Policy
Version 1.0.0 · Effective from 1 October 2026 · Zug, Switzerland
Document key: privacy · Scope: all users · Language: English (authoritative)
Controller: KROIN AG, Ahornstrasse 6, 6300 Zug, Switzerland (CHE-498.889.894). Data-protection contact: privacy@kroin.net.
Framework: Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR).
Read together with the Regula Terms of Service and, for organisations, the Regula Data Processing Agreement, each version 1.0.0.
1. What this Policy covers
KROIN AG is the controller of the personal data described here, processed to provide the Regula identity wallet, HumanSigned, Login with Regula and the Entity services. Regula is built so that most of what you store is unreadable to us: we hold ciphertext, one-way lookup tokens and cryptographic fingerprints. The one category we can read, because the law requires us to be able to, is your identity dossier; Section 7 describes exactly how it is protected.
2. What we process
| Category | What | How it is held |
|---|---|---|
| Account | e-mail address, mobile number, password | encrypted; a keyed one-way index lets us find your account and prevent duplicates without storing the value readably |
| Wallet | public wallet address, Level attestations signed by KROIN AG | in clear (they are public by nature) |
| Content you store | address book, documents, transaction vault, files you sign | encrypted on your device; we cannot read it |
| Identity dossier (Level 1 and 2) | document data, second-document data, proof of address, face-match result, screening result (sanctions, politically-exposed persons, adverse media), images, timestamps, provider reference | encrypted at rest; Section 7 |
| Acts | signed messages (acceptance of documents, signatures, grants, entity and member acts), their fingerprints, anchoring references | in clear, without personal content beyond your address |
| Entity data | organisation data and documents submitted by an Owner; members' roles, statuses and the reasons for role changes | documents encrypted; reasons encrypted, readable only by the affected member and the Entity's authorised auditors |
| Technical | push-notification token, security logs (no readable parameters), abuse-protection signals | in clear, minimal |
| Payment | payment reference from our processor | no card data |
| Agreements | which version of each document you signed, when, with which signature | in clear, append-only |
3. Why, and on what legal basis
- To provide the service you asked for (wallet, signatures, sharing, entities): performance of a contract.
- Identity verification and the identity dossier: your consent to the verification and, for the dossier's retention, our legal obligations (anti-money-laundering and record-keeping law) and our legitimate interest in the integrity of the attestations we sign.
- Login with Regula: your explicit consent, given for each share.
- Entity and member records: performance of the contract with the Owner and members, and the Entity's legitimate interest in an auditable record of mandates.
- Security and abuse prevention: legitimate interest and, where applicable, legal obligation.
- Payments, accounting, tax: legal obligation.
We do not use your data for advertising, profiling or cross-site tracking, and we make no automated decision with legal effect on you other than the outcome of identity verification, which you can contest by contacting us (Section 9).
4. Identity verification: how the data flows
- You submit your document, a live face capture and, for Level 2, a second document and a proof of address through the app to Shufti Pro Ltd., our processor, which performs the checks and the sanctions/PEP screening.
- On completion, KROIN AG retrieves the full result from Shufti Pro, seals it into your identity dossier (Section 7), signs your Level attestation, and instructs Shufti Pro to delete the verification data from its systems. Shufti Pro deletes within the period stated in its own retention policy.
- From then on, only the sealed dossier and the attestation exist. Because we do not keep readable identity data at hand, re-verification requires your participation (Terms, Section 4.4); there is no continuous monitoring of your name against sanctions lists between verifications. Screening is repeated each time you re-verify.
Your proof of address and your Entity documents are signed and anchored before they are uploaded; the upload is encrypted.
5. Who receives your data
- Shufti Pro Ltd. (United Kingdom): identity verification, as our processor, under our instructions and a data-processing agreement.
- Relying Parties you log in to: only the fields you chose to share, with your signed consent. Each becomes an independent controller of what you disclosed.
- Entities you are a member of: your public address, your role, your Level (as a badge) and the record of acts that concern you. The Owner and authorised auditors of the Entity read the reasons written about you; so do you.
- The public: nothing personal. Verification pages show a document's fingerprint, the signer's Level and the time; an Entity's page shows the organisation, not the people.
- Our infrastructure providers, listed in the Data Processing Agreement, Section 5, which handle ciphertext, fingerprints and technical metadata.
- Authorities: only where the law obliges us, under Section 7.
6. Where your data are processed
Our servers and the pilot network are operated on Amazon Web Services in the European Union (Frankfurt). Shufti Pro processes in the United Kingdom, a country whose data protection Switzerland and the EU recognise as adequate. Where any provider processes outside Switzerland or the EEA, we rely on an adequacy decision or on the EU Standard Contractual Clauses with the Swiss addendum, in addition to encryption.
7. The identity dossier: retention and access
This Section describes the one category of data that KROIN AG must be able to open.
7.1 Retention. We keep your identity dossier for ten years after the end of our relationship (closure of your account, or the last Level attestation if the account is not closed), as required by Swiss anti-money-laundering and record-keeping law. It is then destroyed.
7.2 Sealing. The dossier is encrypted with a key that is split into three shares held by KROIN AG, you (in your wallet) and an independent custodian appointed by KROIN AG. Any two shares are needed to open it; KROIN AG alone cannot. The sealed dossier is moved to write-once, offline storage; our online systems keep only its fingerprint and the sealed shares. Transitional note: until the threshold scheme is in operation for your dossier, the dossier is encrypted with a service key, access requires two authorised KROIN AG officers acting together, and every access is logged. The app shows which regime applies to you.
7.3 Who can open it, and why.
- You, with KROIN AG, to exercise your rights (access, portability) or to contest a verification result.
- KROIN AG with the custodian, on a valid order of a competent authority or where the law obliges us to report. We notify you unless the law forbids it.
- Never KROIN AG alone; never a Relying Party; never an Entity.
Every opening is recorded as a signed act stating who opened, when, and on what basis, and that record is anchored.
7.4 Erasure. You may ask us to erase your data (Section 9). We will erase or crypto-shred everything except the sealed dossier during its legal retention period, which we cannot open for that purpose, and the on-chain fingerprints, which contain no personal data and cannot be altered.
8. Retention of everything else
- Account and wallet metadata: while your account is active, then 90 days.
- Content you store: until you delete it or close your account; then crypto-shredded (the key that could decrypt it is destroyed).
- Acts and agreement records: ten years, as evidence of what was signed; they contain your address and fingerprints, not your content.
- Entity and member records: for the life of the Entity and ten years after, as the Entity's record of mandates; reasons stay encrypted for that period.
- On-chain anchors: permanent by design; fingerprints and timestamps only.
- Security logs: 12 months. Backups: encrypted, rotated within 35 days.
9. Your rights
You may ask for access, rectification, erasure, restriction, objection, portability, and you may withdraw consent for the future. In the app you can already download your signed agreements, your acts and — as a member of an Entity — the full record of what concerns you, including the reasons, and you can add a signed statement in reply. Requests: privacy@kroin.net; we answer within 30 days. The limits that follow from the design are these: we cannot read or reproduce content that only you can decrypt; we cannot alter an anchor; and we cannot open the sealed dossier alone. You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, in the EU, to your supervisory authority.
10. Security
Encryption in transit and at rest; content encrypted on your device with keys we do not hold; keyed one-way indexes instead of readable identifiers; a threshold-sealed, offline identity archive; signed, append-only records of acts; access control by role with least privilege; least-data logging; encrypted backups with restore tests; a boot-time check that refuses to start production with placeholder secrets; independent monitoring of the network's certificates. Security incidents affecting you are notified without undue delay.
11. Children
Regula is not intended for persons under 18 and we do not knowingly process their data.
12. Changes
Each version of this Policy has a number and a fingerprint. Material changes are notified thirty days in advance and require your new signature; clarifications are notified in the app. Previous versions remain available.
13. Contact
KROIN AG · Ahornstrasse 6, 6300 Zug, Switzerland · privacy@kroin.net.