Legal

Privacy Policy

This policy explains what personal data Pinnacle Asset Management collects, why we collect it, how long we keep it, who we share it with, and the rights you have over it.

Your privacy is treated with the same seriousness as your capital. This policy is written in plain language so you can understand exactly what happens to your data.

This Privacy Policy describes how Pinnacle Asset Management AG(“Pinnacle Asset Management”, “we”, “us”) collects, uses, discloses, and safeguards your personal data when you use our website and investment platform. It applies to all clients, prospective clients, and visitors. By using our services, you consent to the practices described here.

We are the controller of your personal data for the purposes of applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the Dutch Federal Act on Data Protection. Our registered address is Herengracht 482, 1017 CG Amsterdam, Netherlands.

What we collect

We collect only the personal data necessary to operate your account, comply with our legal obligations, and provide the services you have requested. The categories of data we typically process are:

1. Account information

  • Name, email address, country of residence, and a securely hashed password.
  • KYC documents — government-issued identification and, where required, proof of address.
  • Contact preferences and communication history with our support team.

2. Transaction data

  • Deposit and withdrawal records, including payment method, amount, currency, and transaction references.
  • Investment positions, plan selections, vault deposits, and performance history.
  • Wallet addresses you use for crypto deposits and withdrawals.

3. Usage analytics

  • Device information, browser type, IP address, and approximate location derived from IP.
  • Pages visited, features used, and session duration, used to improve the platform.
  • Cookies and similar technologies, as described below.

How we use your data

We process your personal data for specific, lawful purposes and never for unrelated marketing. The principal purposes are:

  • Service delivery. To create and operate your account, process transactions, and manage your investments.
  • Legal compliance. To meet our KYC, AML, tax reporting, and regulatory obligations under Dutch and applicable international law.
  • Security & fraud prevention. To authenticate you, detect suspicious activity, and protect the platform and its users.
  • Communication. To send you service notifications, performance reports, and responses to your enquiries.
  • Improvement. To analyse usage and improve our services, provided the data is aggregated or pseudonymised wherever possible.

Data retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. KYC records and transaction data are typically retained for the period required by applicable anti-money-laundering law, which may extend beyond the closure of your account. Account information is retained for the life of your account and deleted or anonymised thereafter, subject to legal retention obligations.

Third-party sharing

We do not sell your personal data. We share it only with third parties where necessary to deliver our services or meet legal obligations, and only under terms that require equivalent protection. The principal categories of recipient are:

  • Payment processors. Stripe, NOWPayments, Card2Crypto, and our fiat banking partners process payments on our behalf under their own data protection terms.
  • Email & communications providers. Services that deliver transactional and marketing email on our behalf, subject to your preferences.
  • Custody partners. Institutional custodians that hold client crypto assets under segregated arrangements.
  • Regulators & law enforcement. Where we are legally required to disclose data, including for AML or tax-reporting purposes.

Your rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Netherlands, you have a number of rights regarding your personal data. We will respond to any valid request within the timeframe required by applicable law.

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Ask us to correct inaccurate or incomplete data.
  • Erasure. Request deletion of your data, subject to legal retention obligations.
  • Restriction & objection. Ask us to limit processing or object to specific uses.
  • Portability. Receive your data in a structured, machine-readable format.
  • Withdraw consent. Withdraw consent for processing that relies on it, without affecting processing already carried out.

To exercise any of these rights, contact us at Leunmillard@gmail.com. You also have the right to lodge a complaint with your local data protection authority.

Cookies

We use cookies and similar technologies for essential functionality (such as keeping you logged in), for security (such as fraud prevention), and, with your consent, for analytics and marketing. You can manage your preferences through your browser settings at any time. Essential cookies cannot be disabled as they are required for the platform to function.

International transfers

Because we serve clients in more than 90 countries, your data may be processed in a country other than your own. Where that country does not provide an adequate level of protection under applicable law, we rely on appropriate safeguards such as Standard Contractual Clauses, and we require our partners to do the same.

Contact for privacy requests

Email us

For any privacy question or request, contact our team at Leunmillard@gmail.com.

Response time

We acknowledge privacy requests within 72 hours and respond substantively within the period required by applicable law.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. Material changes will be communicated through the platform or by email. The effective date of the current version is displayed below; continued use of our services after a change constitutes acceptance of the updated policy.

This policy is supplemented by our Terms of Service and Security overview. Last updated: July 2026.