02 / Global Legal Layer
Global Privacy Notice
1. About This Privacy Notice
This Global Privacy Notice (the "Notice") applies to personal information processed in connection with an application, onboarding, customer relationship, use of the GOAT Finance Platform or another GOAT Finance service. If you are a business customer, this Notice also applies to personal information relating to individuals connected with that business, such as representatives, owners, directors or other persons whose information is processed for the relationship.
"GOAT Finance" is the commercial and group designation used by a number of separate legal entities. It is not itself a separate legal person. This Notice provides the common privacy framework for those entities and may be presented directly by GOAT Finance or through an approved Introducer, white-label interface, API-connected customer journey or other approved channel.
Section 9 provides additional information for certain jurisdictions. Where a particular service or GOAT Finance entity must provide further privacy information or obtain a specific consent or authorization, that additional notice or action will be provided at the relevant stage. A more specific notice supplements this Notice for the processing it covers. Acknowledging this Notice confirms that it was made available to you; it does not, by itself, constitute consent where the law requires consent to be obtained separately.
For U.S. individuals who establish a personal, family or household customer relationship with Balansas LLC or another applicable U.S. GOAT Finance entity, this Notice also describes the relevant financial privacy practices to the extent required by applicable U.S. financial privacy law.
2. Who Is Responsible for Your Information
Balansas LLC, a Montana limited liability company ("Balansas"), manages the common GOAT Finance onboarding and, for customers within the customer-facing Platform model, acts as the controller responsible for the Global Customer Profile, the master onboarding record and the general Platform relationship. The GOAT Finance entity that is responsible for providing or executing a particular service is referred to in this Notice as the "Applicable Service Entity". Depending on the customer, service and jurisdiction, an Applicable Service Entity may include GOAT Finance LLC in the United States, GOAT Finance LTD in Canada or GOAT Finance SAGL in Switzerland.
When an Applicable Service Entity is activated for a customer, Balansas makes the relevant onboarding information available to that entity so the customer is not required to repeat the same onboarding unnecessarily. The Applicable Service Entity may rely on the common onboarding record, but it remains responsible for deciding whether the information is sufficient for its own service and legal or regulatory obligations and may request additional information or checks where required. Information is not made available to every GOAT Finance entity by default: access is limited to the entity, people and systems that need it for the relevant purpose.
From the point at which an Applicable Service Entity provides a service, that entity is responsible for personal information processed for its own service, transaction, payment, compliance, recordkeeping and other legal or regulatory purposes. Balansas may continue to process the resulting information where needed to operate the Platform, maintain the Global Customer Profile or consolidated operational records, provide security and support, or satisfy its own lawful obligations. Other GOAT Finance entities may also provide shared technology, systems or personnel and may process information under the instructions of the responsible entity. Sharing infrastructure, personnel or information does not make every GOAT Finance entity responsible for every processing activity.
Where a customer must be serviced outside the GOAT Finance Platform, Balansas may collect and assess information for the common onboarding and routing stage and then hand the approved file to the relevant operating company. Under the current model, customers routed to Swiss operations are handed to GOAT Finance SAGL, while customers in the European Union or European Economic Area are handed to GOAT Finance LTD in Canada and remain outside the customer-facing Platform. Following that handoff, the applicable operating company controls the ongoing customer relationship and service processing. Balansas will not maintain a customer-facing Platform relationship for that service and will retain or access information only where it has a separate lawful reason to do so, including applicable onboarding, compliance, security, audit or recordkeeping requirements.
3. Information We Process and How We Obtain It
We process only the categories of information reasonably connected with the relationship, service or legal obligation. These generally fall into three groups:
- Personal and business information: information that identifies or describes you or a business connected with you and is needed to establish, administer or support the relationship.
- Verification, compliance and risk information: information and results used to verify identity or business status, understand the customer and expected activity, assess risk, prevent financial crime and meet legal or regulatory obligations, including risk indicators, summaries and assessments generated through automated or AI-assisted analysis.
- Service, transaction and technical information: information created or received when you use a service, account, wallet, payment or transaction function, together with relevant device, access, security and support records.
We may receive this information directly from you or an authorized representative; from an Introducer or customer-facing partner through an approved onboarding model; from another GOAT Finance entity involved in your relationship; from identity, compliance, banking, payment, wallet, technology or other service providers; from counterparties connected with a requested service or transaction; and from public or other sources that we are legally permitted to use. We may also create records, assessments or results from information obtained through these sources. During onboarding, this information is currently handled through our core onboarding and compliance systems, including Jotform, SumSub and ClickUp. Under the current model, the AI-assisted analysis described in Section 4 is provided by Recomply, Inc., a Delaware corporation established in the United States, which acts as a processor on our documented instructions under a written data-processing addendum. Recomply is granted controlled, read-only access to onboarding, customer due diligence and transaction information held in SumSub and ClickUp; it does not receive information from Jotform and cannot create, amend, approve or delete records in those systems.
4. How and Why We Use Your Information
We use personal information only for purposes connected with the relationship or another lawful business or regulatory need. In particular, we use it to:
- establish, assess, maintain and administer the customer relationship and determine the services or channels available to you;
- provide, operate and support requested services, accounts, wallets, payments, conversions, transactions and related customer communications;
- perform verification, compliance, financial-crime prevention, sanctions, fraud, risk, security, recordkeeping, investigation and regulatory activities, including automated or AI-assisted analysis used to organize, summarize and assess onboarding and customer-risk information; and
- operate, protect, audit and administer GOAT Finance, including customer support, complaints, finance, legal matters, service-provider management and reasonable improvement of systems and controls.
Under the current model, automated or AI-assisted tools support our compliance teams and do not make the final onboarding, risk or service-acceptance decision on their own; material decisions are reviewed and determined by authorized personnel who can accept, correct, override or escalate an AI-generated result. Our AI provider processes your information only on our documented instructions and is contractually prohibited from using it to train, retrain, fine-tune or improve any general-purpose or shared model or any product made available to other customers, from selling it or using it for advertising or profiling for unrelated purposes, and from using it in marketing or demonstration materials. Where the underlying model or interface offers settings that prevent provider training or reduce content retention, the most protective setting reasonably available is enabled. The legal basis for a particular use depends on the law that applies to that processing. It may include taking steps at your request or performing a contract, complying with a legal or regulatory obligation, pursuing legitimate business or Group interests that are not overridden by applicable privacy rights, obtaining consent or authorization where required, or another basis permitted by applicable law. Where consent is legally required, we will request it separately and explain the relevant choice. Withdrawing consent does not affect processing already carried out lawfully and does not prevent processing that must continue under another lawful basis or legal obligation.
5. How We Share and Transfer Your Information
We share personal information only where there is a lawful and relevant purpose and only to the extent reasonably necessary. This may include sharing within GOAT Finance under the responsibility model described in Section 2; with approved service and infrastructure providers or customer-facing partners that support onboarding, technology, verification, compliance, accounts, wallets, payments or operations; with financial institutions, liquidity, settlement or other transaction counterparties needed to carry out a requested service; with professional advisers, auditors and insurers; or with regulators, courts, governmental authorities and other recipients where disclosure is required or permitted by law. The providers operating the onboarding and compliance systems identified in Section 3, together with approved AI and analytics providers, may process personal information on our behalf for those purposes.
For U.S. financial privacy purposes, the information disclosed may include the same general categories described in Section 3, but only as appropriate to the recipient and purpose. Under the current model, GOAT Finance does not sell personal information or disclose nonpublic personal information to nonaffiliated third parties for their own unrelated marketing. Nonaffiliated disclosures are limited to providing or administering requested services, processing transactions, preventing fraud or financial crime, complying with law or another permitted purpose. If these practices materially change and applicable law requires an opt-out, consent or revised notice, we will provide it before the new practice is used where required.
Because GOAT Finance operates internationally, personal information may be stored, accessed or otherwise processed outside the country where it was collected. Under the current architecture, GOAT-controlled Platform infrastructure used for operational customer data is hosted within the European Economic Area: the BaaS primary hosting and access environment made available to customers (a customer-facing instance of the Platform) is hosted in Stockholm, Sweden, and the GOAT Finance Platform is hosted in Frankfurt, Germany. The public website layer is hosted in Oregon, United States, and is not used for operational customer data. Information may also be made available to the Applicable Service Entity in its jurisdiction, including GOAT Finance LTD in Canada or GOAT Finance SAGL in Switzerland. The infrastructure locations described above relate to GOAT-controlled environments. Onboarding and compliance information is also processed through the systems identified in Section 3 and by approved AI or analytics providers; their hosting, remote-access and subprocessor locations may differ and are subject to the applicable transfer safeguards. Under the current model, production information made available to our AI provider is stored within the European Economic Area unless we approve another location in writing, and the provider must give prior notice before appointing a new material subprocessor or materially changing a processing location. Because the AI provider is established in the United States, remote access from the United States is covered by the 2021 EU Standard Contractual Clauses (Module Two, controller to processor), adapted as required for transfers governed by Swiss law, or by another lawful transfer mechanism where applicable. We use contractual, organizational and technical safeguards required by applicable law, including adequacy decisions and recognized standard contractual clauses where required. Additional jurisdiction-specific transfer information is provided in Section 9.
6. How We Protect and Retain Your Information
GOAT Finance uses risk-based administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, loss or destruction. Safeguards include appropriate access controls, security monitoring, confidentiality requirements, service-provider oversight and incident-management processes. No system can be guaranteed to be completely secure, but our controls are maintained and adjusted according to the sensitivity of the information, the services involved and applicable legal requirements.
We retain personal information only for as long as reasonably necessary for the purpose for which it is processed and for any longer period required or permitted by law, regulation, financial-crime rules, recordkeeping obligations, investigations, legal holds, complaints or disputes. Different GOAT Finance entities may therefore have different retention requirements for the records attributable to them. When information is no longer required, it is deleted, anonymized or otherwise disposed of in accordance with applicable requirements and operational controls. Information retained after a customer relationship ends remains subject to the confidentiality and sharing principles described in this Notice. Our AI provider is required to minimize the information it retains, may keep security, access and operational logs for no more than twelve months unless a longer period is legally required, must return or securely delete the information in its active systems within thirty days of the end of the services, and must delete or overwrite backup copies through its normal backup cycle within ninety days.
7. Your Privacy Rights
Depending on the law that applies to you and the relevant processing, you may have rights to request access to personal information, correct inaccurate information, request deletion, restrict or object to certain processing, receive certain information in a portable form, withdraw consent where processing is based on consent, appeal certain privacy decisions, or complain to a competent privacy or data-protection authority. Some rights are subject to statutory exceptions, identity-verification requirements and records that GOAT Finance must retain or process for legal, regulatory, fraud-prevention, security or other permitted purposes.
You do not need to identify which GOAT Finance entity holds a particular record before making a request. Balansas may act as the common intake point and will route the request to the entity responsible for the relevant processing. We may ask for information reasonably necessary to verify identity or authority before responding. Where a specific law imposes a response period or additional procedure, the responsible entity will apply that requirement.
8. Contact, Complaints and Changes to This Notice
For privacy questions, requests or complaints, contact:
| Privacy Contact | GOAT Finance Global Compliance |
|---|---|
| [email protected] | |
| Balansas LLC | 127 N Higgins Ave Ste 307d #3094, Missoula, Montana 59802, United States |
| Website | https://goatfinance.io |
Section 9 provides additional controller and privacy contact information for certain jurisdictions. Where required, a service-specific notice may provide another local representative or complaint route. You may also have the right to complain directly to the competent privacy or data-protection authority in your jurisdiction.
We may update this Notice to reflect changes in law, GOAT Finance's structure, services, systems, providers or processing practices. The current version will be published on https://goatfinance.io and will state its effective date. Where applicable law requires additional notice, consent or another action for a material change, we will provide it before the change takes effect for the relevant processing.
9. Additional Information for Certain Jurisdictions
9.1 United States — Financial Privacy
Where Balansas LLC or GOAT Finance LLC establishes a personal, family or household customer relationship, U.S. federal financial privacy rules apply to the relevant nonpublic personal information. Those entities collect the categories described in Section 3 from you, your transactions, GOAT Finance affiliates, verification and service providers, and other permitted sources. They may disclose those categories to GOAT Finance affiliates and to nonaffiliated service providers, financial institutions, transaction counterparties, advisers or authorities only for the purposes described in Sections 4 and 5 or as otherwise permitted by law. The same general disclosure practices apply after the customer relationship ends. Under the current model, GOAT Finance does not sell nonpublic personal information or disclose it to nonaffiliated third parties for their own unrelated marketing, and no Regulation P opt-out is currently triggered. If a future practice creates an opt-out, consent or revised-notice right, the required choice will be provided before that practice is used.
9.2 Canada
When GOAT Finance LTD is responsible for a Canadian service or relationship, it is the organization accountable for that processing. GOAT Finance LTD is located at 1019-7070E Farrell Road SE, Calgary, Alberta, Canada, T2H 0T2. Its Privacy Officer may be contacted at [email protected]. GOAT-controlled Platform infrastructure used in connection with Canadian relationships is hosted in Sweden and Germany. Onboarding and compliance service providers, including the systems identified in Section 3 and, where engaged for the relevant service, approved AI or analytics providers, may also process Canadian personal information outside Canada under contractual and other safeguards. Current information about the countries in which those providers process or access personal information may be requested from the Privacy Officer. Those jurisdictions may have laws that permit public authorities to access information in accordance with local law. GOAT Finance LTD remains accountable for personal information under its control and uses contractual and other safeguards appropriate to the processing. Where Canadian law requires consent to collect, use or disclose personal information, that consent will be requested separately from acknowledgement of this Notice. Refusing or withdrawing consent may limit our ability to complete onboarding or provide a service where the processing is necessary and no statutory exception applies.
9.3 Switzerland
When GOAT Finance SAGL is responsible for a Swiss service or relationship, the controller is GOAT Finance SAGL, Via Serafino Balestra 3, 6900 Lugano, Switzerland. Privacy questions may be sent to [email protected]. GOAT-controlled Platform infrastructure is hosted in Sweden, where the BaaS primary hosting and access environment is located, and in Germany, where the GOAT Finance Platform is hosted. Onboarding and compliance information is also processed through the systems identified in Section 3 and by approved AI or analytics providers, which may involve additional destination countries. GOAT Finance SAGL is the contracting GOAT Finance entity for the AI-assisted compliance analysis provided by Recomply, Inc. and is the controller for that processing; another GOAT Finance entity may be added as a controller for that service only by written notice under the applicable data-processing addendum. Where information is disclosed to a country that is not recognized as providing adequate protection under Swiss law, GOAT Finance uses an applicable recognized safeguard, including recognized standard contractual clauses and supplementary measures where required.
9.4 European Union / European Economic Area
For EU/EEA applicants, Balansas LLC is the controller for the common onboarding, eligibility and routing stage. If the application is approved and routed for EU/EEA service, the onboarding file is handed to GOAT Finance LTD in Canada, which becomes the controller for the ongoing customer and service relationship. EU/EEA customers are serviced outside the customer-facing GOAT Finance Platform and do not receive a Platform account, dashboard or customer wallet as part of that route.
For processing subject to the GDPR, the principal legal bases are: Article 6(1)(b) for steps requested before entering into a relationship and processing necessary to provide the requested service; Article 6(1)(f) for legitimate interests such as fraud prevention, security, risk management, legal-risk management, routing, recordkeeping and evidence of a customer-initiated request, where those interests are not overridden by your rights; Article 6(1)(c) where a Union or Member State legal obligation applies; and Article 6(1)(a) where we specifically ask for consent.
Certain information is required to assess your application, perform legally or operationally required checks or provide the requested service. If you do not provide information identified as required, we may be unable to complete onboarding or provide the service. We may use automated or AI-assisted profiling to organize, summarize and analyze onboarding and risk information and to support compliance review. Under the current model, these tools support human review and do not make the final onboarding, risk or service-acceptance decision without human involvement. We do not use solely automated decision-making that produces legal or similarly significant effects in onboarding unless we separately inform you and implement the safeguards required by Article 22 GDPR.
GOAT-controlled Platform infrastructure used for EU/EEA personal information is hosted within the European Economic Area — in Stockholm, Sweden for the BaaS environment and in Frankfurt, Germany for the GOAT Finance Platform — and the onboarding file may be handed to GOAT Finance LTD in Canada for the ongoing service relationship. Hosting in Sweden and Germany does not involve a transfer outside the EEA. Canada is recognized by the European Commission as providing adequate protection for organizations covered by the applicable adequacy decision, and transfers to GOAT Finance LTD may rely on that decision. Onboarding and compliance providers, including the systems identified in Section 3 and approved AI or analytics providers, may also process EU/EEA personal information outside the EEA. Current information about the providers involved, the countries in which they host or may remotely access personal information, and the transfer mechanism applicable to each may be requested through the contact in Section 8. Where they do, GOAT Finance relies on an applicable adequacy mechanism or the 2021 EU Standard Contractual Clauses and supplementary measures where required. Where an EEA controller or exporter makes personal data available to Balansas in the United States, including through the public website layer hosted in Oregon, and no applicable adequacy mechanism covers the recipient, GOAT Finance uses the 2021 EU Standard Contractual Clauses and supplementary measures where required. You may request information about the applicable transfer safeguard through the contact in Section 8.
Under the GDPR, subject to the applicable statutory conditions and exceptions, you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the legal basis. You also have the right to lodge a complaint with the supervisory authority in the EU/EEA country of your habitual residence, place of work or the place of the alleged infringement.
EU Representative (Article 27): GOAT Finance UAB, Jogailos g. 4, LT-01116 Vilnius, Lithuania; [email protected]. GOAT Finance UAB is appointed in writing as the representative in the Union for Balansas LLC, GOAT Finance LTD and GOAT Finance SAGL in respect of processing subject to the GDPR. You may contact the representative on all matters relating to that processing, in addition to or instead of the relevant controller.
Data Protection Officer: [email protected]. The Data Protection Officer may be contacted about any matter relating to the processing of your personal information or the exercise of your rights under the GDPR.