Privacy Policy

Version 2.6 — Effective September 12, 2026 · Governed strictly by the Swiss Federal Act on Data Protection (FADP / revDSG) and the EU General Data Protection Regulation (GDPR).

This Privacy Policy explains what personal data LuxuryBroker.com collects, why we collect it, how it is processed, and what rights you have regarding your data. It applies alongside our Terms of Service.

1. Data Controller and Contact Information
The data controller responsible for processing your personal data under this policy is:
Alexander Baum, trading as LuxuryBroker.com, c/o RA Matutis, Rheinstrasse 71, CH-7012 Felsberg, Switzerland.
• General Enquiries: [email protected] 
• Security & Data Protection Enquiries: [email protected] 
• Website: https://www.luxurybroker.com

1.1 EU Representative / DSGVO-Vertreter (Art. 27 EU GDPR)
Pursuant to Article 27 of the EU General Data Protection Regulation (GDPR), our designated representative for data protection matters and inquiries from individuals or supervisory authorities within the European Union (EU / EEA) is:
Kanzlei Matutis, Berliner Straße 57, D-14467 Potsdam, Germany
• E-Mail: [email protected] 
• Website: https://dsgvo-vertreter.eu / https://matutis.de

2. Applicable Legal Frameworks
LuxuryBroker.com is established and operated strictly out of Switzerland. Our data processing activities are primarily governed by the Swiss Federal Act on Data Protection (FADP / revDSG).
Where our B2B platform and services are accessed by or directed at users located within the European Economic Area (EEA), processing also complies with the applicable provisions of the EU General Data Protection Regulation (GDPR).

3. Categories of Individuals Concerned
We process personal data relating to:
• Members & Authorized Representatives: Licensed brokers, dealerships, corporate advisory firms, and individuals acting on their behalf who maintain an active account.
• Applicants: Individuals and corporate entities submitting documentation for accreditation.
• Visitors & Private Clients: Individuals browsing public pages of the Platform, submitting direct asset inquiries, or submitting a buying or placement request through our Off-Market Desk.
• Third Parties Named in Materials: Individuals whose names or details appear in listing documentation provided by a Member.

4. What We Process, Purposes, and Legal Basis
4.1 Zero-Cookie & No-Client-Tracking Architecture
• Policy: We do not use cookies beyond those strictly necessary to operate the Platform, and we do not use tracking pixels, fingerprinting scripts, or any web analytics tools.
• Consent Banner: Because we do not deploy any non-essential cookies or tracking mechanisms, no cookie consent banner is required.

4.2 Web Hosting, Server Logfiles & Local Asset Delivery (Self-Hosted Fonts)
• Local Asset Hosting: All application assets, images, and typography files (Web Fonts) are hosted exclusively on our dedicated hosting infrastructure in Switzerland. We do not load external fonts from third-party networks (e.g., Google Fonts or Adobe Typekit), preventing unauthorized transmission of your IP address to foreign third parties.
• Server Log Data: When you access our website, the web server operated by our hosting provider automatically records technical connection data in server log files:
  - IP address of the requesting device
  - Date and time of access
  - Requested resource / URL
  - Referrer URL (previously visited page)
  - Browser type, operating system, and HTTP status code
• Purpose: Provision of website content, system stability, diagnostics, and defense against malicious attacks or scraping.
• Evaluation: We do not evaluate server log data for marketing or profiling purposes, nor do we combine this data with other personal data sources.
• Legal Basis: Legitimate interest in the secure, stable, and reliable operation of our online infrastructure (Art. 31(1) Swiss FADP; Art. 6(1)(f) EU GDPR).

4.3 Accreditation and Account Administration
• Data Collected: Name, business position, corporate contact details, evidence of active commercial trading (which may include a commercial register extract or broker licence), identity of authorized representatives, and hashed login credentials.
• Purpose: To verify accreditation eligibility, establish and maintain B2B accounts, and enforce platform integrity.
• Legal Basis: Performance of a contract / pre-contractual measures (Art. 31(2)(a) Swiss FADP; Art. 6(1)(b) EU GDPR) and legitimate interest in maintaining a verified member ecosystem.

4.4 Sanctions and Compliance Screening
• Data Collected: Company name, names of corporate directors, and ultimate beneficial owners (UBOs) where applicable, cross-referenced against official sanctions databases.
• Purpose: To verify that published listings and transactions do not violate Swiss (SECO) or applicable international trade embargos.
• Legal Basis: Compliance with legal obligations under Swiss sanctions law and legitimate interest in avoiding unlawful trade activity.

4.5 Listing Media & Data Sovereignty
• Data Collected: Photographs, video, floor plans, technical specifications, and brochures uploaded by Members when publishing a listing, or sent to us by email where a Member requests formatting assistance.
• Purpose: To publish and host asset listings on the Platform.
• Roles: Members act as independent controllers for any third-party personal data contained within submitted materials. The Operator processes these materials on behalf of the Member to format and publish the listing live. Members retain 24/7 dashboard authority to edit, modify, or unpublish listings.

4.6 Direct Listing Inquiries, Lead Forwarding & E-Mail Relay
• Data Collected: Full name, email address, telephone number (optional), message content, and listing reference (Asset ID/Title).
• Processing Mechanism (E-Mail Relay): When you submit an inquiry through a contact form on an asset listing page, our system automatically processes your message via our secure Swiss mail server infrastructure (Novatrend) and forwards it directly via email to the respective listing seller, broker, or dealer (Listing Member).
• Independent Controllership: 
  - LuxuryBroker.com acts as the initial controller solely for the collection and automated technical forwarding of the inquiry.
  - Upon receipt of the forwarded email, the respective seller/broker becomes an independent data controller for all subsequent communications, follow-ups, and data storage under their own privacy policies.
• Cross-Border Data Transmission: Depending on the location of the listed asset or the seller's registered office, the forwarded inquiry email may be transmitted to recipients located outside Switzerland or the European Economic Area (EEA). By submitting the inquiry form, you acknowledge that this data transmission is necessary for the implementation of pre-contractual measures taken at your direct request (Art. 17(1)(b) Swiss FADP; Art. 49(1)(b) EU GDPR).
• No Commercial Monetization: LuxuryBroker.com does not sell, rent, or trade your contact details or inquiry history to unrelated third-party advertisers.
• Legal Basis: Performance of a contract or pre-contractual measures initiated by the user (Art. 31(2)(a) Swiss FADP; Art. 6(1)(b) EU GDPR).

4.7 WhatsApp Business Communication
• Data Collected: Sender name, phone number / WhatsApp profile details, message history.
• Processing: If you contact us via WhatsApp Business, communications are processed via Meta Platforms Ireland Ltd. Content data is end-to-end encrypted; metadata (e.g., phone numbers, time, routing data) may be processed on servers in the United States. Communication via WhatsApp is voluntary; alternative contact channels (e.g., standard email) are available at all times.
• Legal Basis: Pre-contractual communication / contract fulfillment (Art. 31(2)(a) Swiss FADP; Art. 6(1)(b) EU GDPR).

4.8 Traffic Analysis (Cloudflare)
• Data Collected: Aggregated request data recorded by our CDN and security provider, including country of origin, browser type, requested resource and HTTP status.
• No Cookies / No Fingerprinting: This analysis takes place on the server side. No script is placed on your device, and no cookies or localStorage are used.
• Purpose: Security, performance monitoring and diagnostics.
• Legal Basis: Legitimate interest in operating a secure and performant platform (Art. 31(1) Swiss FADP; Art. 6(1)(f) EU GDPR).

4.9 Business B2B Outreach
• Data Collected: Professional contact details sourced from official public registers, corporate websites, or professional directories.
• Purpose: Direct B2B outreach to introduce platform infrastructure to qualified luxury brokers and dealerships.
• Right to Object: Recipients may object to direct B2B marketing at any time by emailing [email protected].

4.10 Off-Market Requests
• Data Collected: Name, contact details, and the parameters of the asset sought or offered, as provided by you via email or WhatsApp.
• Processing: Your request is forwarded to Members active in the relevant asset category and market. Unless you expressly ask us to disclose your identity, requests are forwarded with the asset parameters only, without your name or contact details. A direct introduction is made only once both parties agree.
• Recipients: Requests may be forwarded to Members located outside Switzerland or the European Economic Area where the asset or the Member is based there. By submitting a request you acknowledge that this transmission is necessary for pre-contractual measures taken at your direct request (Art. 17(1)(b) Swiss FADP; Art. 49(1)(b) EU GDPR).
• Legal Basis: Pre-contractual measures initiated by you (Art. 31(2)(a) Swiss FADP; Art. 6(1)(b) EU GDPR).

5. Social Media Presence, External Links & Sharing Buttons

5.1 Static External Social Links
Our website includes static external hyperlinks to our official business profiles:
• WhatsApp Business (Meta Platforms Ireland Ltd.)
• YouTube (Google Ireland Limited / Google LLC)
• Instagram (Meta Platforms Ireland Ltd.)
• TikTok (TikTok Technology Limited / ByteDance Ltd.)

5.2 Privacy-Compliant Social Sharing Buttons (Direct Share Links)
Our asset listing pages provide static sharing links that allow users to voluntarily share listings via:
• Facebook (Meta Platforms Ireland Ltd.)
• X / Twitter (X Corp.)
• WhatsApp (Meta Platforms Ireland Ltd.)
• Telegram (Telegram FZ-LLC)
• E-Mail (Default local mail client via mailto link)

No Tracking Plugins or Automatic Data Transfer:
We do not use dynamic social media JavaScript plugins, tracking pixels, or embedded feeds. Visiting LuxuryBroker.com or viewing listings does NOT transmit personal data or IP addresses to these third-party operators. Data transmission only occurs if you actively click on a sharing button, redirecting you to the external service.

6. Third-Party Service Providers and Processors
We engage vetted infrastructure providers bound by data processing agreements in compliance with Swiss FADP and EU GDPR standards:

6.1 Swiss Web Hosting & E-Mail Infrastructure (Novatrend Services GmbH)
Our complete website infrastructure, application databases, local assets (including fonts), and outgoing email routing services are hosted by:
Novatrend Services GmbH, Richtiarkade 18, CH-8304 Wallisellen / Baar, Switzerland.
• Data Location: Certified, high-security data centres located in Switzerland (Zurich / Aargau).
• Data Processing: Novatrend acts as data processor under a formal Data Processing Agreement (DPA).

6.2 Global Security & Content Delivery (Cloudflare Inc.)
DNS management, Web Application Firewall (WAF), and DDoS mitigation are provided by Cloudflare Inc. (USA / Global Edge Network).

6.3 Payment Processing (Stripe Payments)
Where membership fees are charged, payment infrastructure, billing and subscription management are provided by Stripe Payments Europe, Ltd. (Ireland) / Stripe, Inc. (USA). No payment data is processed while access is complimentary.

6.4 Map Integration & Content Delivery (OpenStreetMap & Fastly)
To display interactive geographical maps for asset locations without invasive tracking, we integrate map tiles from OpenStreetMap (OpenStreetMap Foundation, UK) delivered via Fastly CDN (Fastly Inc., USA).
• Data Processed: Your IP address and technical HTTP headers are processed solely to transmit map tiles. OpenStreetMap does not deploy tracking cookies or commercial profiling.

7. International Data Transfers
Primary application data and databases reside exclusively on secured servers located within Switzerland.
Where network edge delivery or specialized third-party services (such as Cloudflare, Fastly, or Stripe) route traffic globally, transfers outside Switzerland or the EEA are conducted on the basis of:
• Adequacy decisions recognized by the Swiss FDPIC and European Commission, or
• Standard Contractual Clauses (SCCs) adapted for Swiss law, supplemented by technical safeguards and recognized Data Privacy Framework certifications.

8. Data Retention Periods
• Server & Security Logs: Retained for up to 90 days, then deleted or anonymized.
• Member Account & Transaction Records: Retained for active Membership duration and up to 10 years following account closure pursuant to statutory record-keeping obligations under Art. 958f of the Swiss Code of Obligations (CO).
• Unpublished Listing Media: Deleted within 90 days of account termination or asset deletion.
• Off-Market Requests & Asset Inquiries: Retained for up to 12 months, unless required longer for contract execution or legal defense.
• Marketing Opt-Out Records: Retained indefinitely on a suppression list to honor objection requests.

9. Your Data Protection Rights
Under the Swiss FADP (and EU GDPR where applicable), you have the right to:
• Access: Request confirmation and copies of personal data held about you.
• Rectification: Request correction of inaccurate or incomplete data.
• Erasure: Request deletion of your personal data, subject to statutory retention obligations.
• Restriction & Objection: Object to data processing based on legitimate interests or request processing restrictions.
• Data Portability: Request delivery or transfer of data you provided in a structured, machine-readable format.

To exercise any of these rights, contact us at [email protected].

Supervisory Authorities:
• In Switzerland: The Federal Data Protection and Information Commissioner (FDPIC / EDÖB), Feldeggweg 1, CH-3003 Bern (https://www.edoeb.admin.ch).
• In the European Union: You may lodge a complaint with your local national Data Protection Authority (DPA) or contact our designated EU Representative under Art. 27 GDPR.

10. Security Safeguards & Infrastructure Defense
We implement state-of-the-art technical and organizational measures (TOMs) to safeguard system integrity and confidentiality:
• Edge Security & WAF: Cloudflare Web Application Firewall (WAF) and automated DDoS mitigation.
• Host-Level Defense: Multi-layered server security via Novatrend infrastructure, including Imunify360 intrusion prevention, Monarx real-time malware monitoring, and SpamExperts automated email filtering.
• Transport & Access Security: TLS transport encryption for all connections to the Platform.

11. Automated Decision-Making and AI Usage
• We do not engage in automated decision-making or profiling producing legal effects concerning individuals.
• AI Usage: Where we assist a Member in formatting a listing, text descriptions may be prepared with the assistance of generative AI tools.

12. Updates to This Policy
The current version is always available at https://www.luxurybroker.com/post/privacy.

Last Updated: September 12, 2026
Operator: Alexander Baum, Felsberg, Switzerland
Contact: [email protected]