Skip to content

Release: develop -> main - #138

Merged
TaprootFreak merged 4 commits into
mainfrom
develop
Aug 14, 2026
Merged

Release: develop -> main#138
TaprootFreak merged 4 commits into
mainfrom
develop

Conversation

@github-actions

Copy link
Copy Markdown

Automatic Release PR

This PR was automatically created after changes were pushed to develop.

Commits: 1 new commit(s)

Checklist

  • Review all changes
  • Verify CI passes
  • Approve and merge when ready for production

TaprootFreak and others added 4 commits August 13, 2026 23:37
* Align privacy policy and terms of service with actual API implementation

Privacy policy (all 4 languages):
- Add Azure as primary hosting provider, downgrade All-Inkl to info site only
- Add data processor disclosures (Sumsub, Sift, Dilisense, Application Insights)
- Add cross-border data transfer table with legal bases per Art. 16/17 DSG
- Correct analytics section to clarify server-side monitoring only
- Fix breach notification wording to match nDSG Art. 24
- Renumber all subsequent sections

Terms of service (all 4 languages):
- Correct daily limit to monthly limit (rolling 30-day period)
- Correct daily sales volume to monthly sales volume
- Remove FrankencoinPay reference (not implemented as payment standard)

* Align Art. 24 notification threshold and analytics wording

Raise the breach-notification threshold to a likely high risk to
personality or fundamental rights, matching Art. 24(1) FADP, and add
the German tracking-pixel exclusion to the EN/FR/IT analytics sections.

* Drop leftover FrankencoinPay fee reference

The collection payment standards list only names OpenCryptoPay. The
currency-conversion fee clause still listed FrankencoinPay as a method;
remove it in all four languages and strip trailing whitespace on the
touched headings.

* State Swiss self-hosting and drop Azure from the privacy policy

API, app and database run on DFX servers in Switzerland. Cloudflare
is the public edge only. Remove Azure, Application Insights and the
transfer table; keep Sumsub, Sift and Dilisense as the processors
that receive personal data.

* Point Art. 24 processor notice at the named processors only

The breach-notification clause said "Sumsub, Sift and others". Replace
that open list with a closed reference to the processors named above.

* Remove unused Sift processor from the privacy policy

Sift is no longer used. Drop it from the processor list in all four
language versions; Sumsub and Dilisense remain.

* Drop exclusive wording from the foreign-transfer sentence

The transfer clause said data left Switzerland only for Cloudflare
and the named processors, then listed banks as well. Name Cloudflare,
the processors and the banks in one sentence without "only".

* Align EN/FR/IT analytics wording with the German text

Match the German scope: no website analytics for tracking user
behaviour, and no comparable services, not a blanket ban on any
analysis tool.

* Host static sites on Cloudflare and keep customer systems in Switzerland

Static websites without customer data, such as dfx.swiss, are hosted
on Cloudflare. The API, app and database stay on DFX servers in
Switzerland, with Cloudflare only as the public edge.

* Spell out that Cloudflare hosts only static pages without customer data

State that those pages have no accounts, transactions or identity
checks. Customer-data systems stay on DFX servers in Switzerland.

* Correct Dilisense seat from EU to Switzerland

Dilisense GmbH is incorporated in Switzerland. Drop the adequacy
decision, which only applies to transfers abroad.

* Name only Sumsub as a foreign processor in the transfer clause

Dilisense is in Switzerland, so the abroad sentence must not fold it
into "the processors named above".

* Limit the terms to KYC buy, sell and swap only

Remove send, custody, referral and collection. Trading is available
only after identity verification; drop the light-KYC path.

* Narrow hosting and transfer wording to the trading platform

Do not claim that every processor of customer data runs in Switzerland.
Scope the abroad sentence to trading-platform data and point social
media transfers to section 10.
* docs: add Swissquote/Yuh payment FAQ entry (de/en/fr/it)

* docs: tighten refund wording in Swissquote/Yuh FAQ entry
)

* Clarify Swissquote block, support form and retention in German

State that Swissquote/Yuh block payments, not DFX. Accept inquiries
only via the support form. Drop credit checks, treat official IDs as
ordinary personal data, and keep IP addresses for 10 years.

* Point German FAQ support links at the form and fix retention numbering
Match support form, Swissquote wording, categories, profiling,
retention including IPs, and Dilisense scope. Keep identical
newline counts across languages.
@TaprootFreak
TaprootFreak merged commit 11a8552 into main Aug 14, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants