Skip to content
Legal
Home / Legal / Global Privacy Policy
Contents
  1. 1 Who We Are
  2. 2 How This Policy Works
  3. 3 Goat Finance's Privacy Governance Model
  4. 4 Phase-Based Privacy Model
  5. 5 Controller Allocation
  6. 6 Handoff Between Controllers
  7. 7 Jurisdiction-Aware Website and Onboarding Controls
  8. 8 Personal Data We May Collect
  9. 9 Sources of Personal Data
  10. 10 Why We Process Personal Data
  11. 11 Legal Bases and Lawful Grounds
  12. 12 Special Category Data, Sensitive Data and Criminal-Offence Related Data
  13. 13 How We Share Personal Data Within Goat Finance
  14. 14 How We Share Personal Data With Third Parties
  15. 15 Partner-Supported Services
  16. 16 International Transfers
  17. 17 Retention
  18. 18 Security
  19. 19 Artificial Intelligence, Automated Processing, Profiling and Risk Assessment
  20. 20 Your Privacy Rights
  21. 21 U.S. Privacy Framework
  22. 22 Cookies and Similar Technologies
  23. 23 Children
  24. 24 Notice Delivery and Evidence
  25. 25 Updates to This Global Privacy Policy
  26. 26 Contact
  27. S1 Layered Privacy Notice Framework
  28. S2 Phase-Based Privacy Model and Controller Handoff
  29. S3 Controller and Entity Routing Overview
  30. S4 Shared Resources, Intragroup Access and International Transfers
  31. S5 Jurisdiction-Aware Website and Reverse-Solicitation Controls
  32. S6 Legal and Jurisdictional Privacy Framework

02 / Global Legal Layer

Global Privacy Policy

Version
1.2
Effective
August 03, 2026
Last updated
August 03, 2026
Primary site
goatfinance.io

Important Notice

Goat Finance operates as a multilateral organization through separate legal entities, shared policies, shared systems, shared operational resources, shared compliance functions and global governance standards.

Goat Finance is not a single legal entity. The Goat Finance entity responsible for your personal data may depend on the onboarding phase, product, service, contracting entity, jurisdiction, partner framework, service route and the specific purpose for which the data is processed.

This Global Privacy Policy explains, at a general level, how Goat Finance collects, uses, verifies, shares, transfers, stores, protects and otherwise processes personal data across its multilateral organization.

This Global Privacy Policy must be read together with:

  1. the applicable Phase 1 Privacy Notice;

  2. the applicable entity Privacy Notice;

  3. any product-specific privacy notice or service-specific privacy disclosure;

  4. any partner-related privacy or data-sharing disclosure;

  5. any privacy information presented during onboarding, product activation, transaction processing or customer communications.

This Global Privacy Policy is the general privacy framework. It does not replace the specific privacy notices or disclosures that may apply to a particular onboarding phase, Goat Finance entity, product, service, jurisdiction or partner-supported route.

1. Who We Are

For the purposes of this Global Privacy Policy, “Goat Finance”, “we”, “us” or “our” means the Goat Finance multilateral organization and, where applicable, the specific Goat Finance legal entity responsible for the relevant processing activity.

The current principal operating entities are:

  1. Goat Finance SAGL, Switzerland;

  2. Goat Finance LLC, United States; and

  3. Goat Finance LTD, Canada.

Additional Goat Finance entities may be added to the organization from time to time.

The relevant controller will be identified in the applicable privacy notice, onboarding flow, entity terms, product terms, handoff notice, customer profile, transaction confirmation or other communication provided to you.

2. How This Policy Works

This Global Privacy Policy provides the general privacy framework for Goat Finance.

It explains:

  1. how Goat Finance is organized from a privacy perspective;

  2. how Phase 1 and Phase 2 onboarding work;

  3. how data controllers are allocated;

  4. how personal data is handed over from one controller to another;

  5. what categories of personal data Goat Finance may process;

  6. why Goat Finance may process personal data;

  7. how Goat Finance may share personal data internally;

  8. how Goat Finance may share personal data with providers, partners and authorities;

  9. how Goat Finance uses shared resources while preserving entity-level responsibility;

  10. how international transfers may occur;

  11. how long personal data may be retained;

  12. what privacy rights may apply;

  13. how Goat Finance manages jurisdiction-aware website and onboarding controls;

  14. how to contact Goat Finance about privacy matters;

  15. how Goat Finance may use artificial intelligence systems, machine-learning tools, automated agents and other AI-assisted technologies;

  16. how personal data may be accessed or processed by artificial intelligence developers, AI system providers, model providers and related technology providers;

  17. how Goat Finance manages human oversight, automated processing, AI-generated outputs, risk assessments and material decisions supported by AI systems;

  18. what rights and safeguards may apply where artificial intelligence or automated processing affects you.

3. Goat Finance's Privacy Governance Model

Goat Finance applies a layered privacy governance model.

At a high level:

  1. Global Privacy Policy explains the organization-wide privacy framework.

  2. Phase 1 Privacy Notices explain the pre-onboarding, eligibility and routing process.

  3. Entity Privacy Notices explain how a specific Goat Finance entity processes personal data when it becomes responsible for Phase 2 onboarding, service provision or customer relationship management.

  4. Product-specific privacy notices or service-specific disclosures explain how personal data is used or shared for a specific product, service, partner-supported feature or transaction route.

  5. Partner disclosures explain partner-specific processing or data-sharing requirements where applicable.

Goat Finance maintains internal controls designed to support appropriate controller allocation, need-to-know access, privacy notice delivery, data sharing, international transfer assessment, retention, recordkeeping and controller handoff between onboarding phases.

Goat Finance also maintains governance controls designed to support the responsible development, acquisition, configuration and use of artificial intelligence systems and AI-assisted processing. Depending on the system, intended purpose and applicable law, these controls may include system classification, impact assessments, vendor due diligence, data-use restrictions, testing, validation, human oversight, access controls, monitoring, incident management, change control, recordkeeping and measures to support the development of appropriate AI literacy among personnel and other persons operating or using AI systems on behalf of Goat Finance.

4. Phase-Based Privacy Model

Goat Finance uses a phase-based onboarding and privacy model.

4.1 Phase 1 — Pre-Onboarding, Eligibility, Screening and Routing

Phase 1 is the global pre-onboarding, initial screening, eligibility assessment, KYC initiation and routing phase.

Unless otherwise stated in the applicable Phase 1 Privacy Notice, Goat Finance SAGL acts as the controller for Phase 1 processing.

During Phase 1, Goat Finance may process personal data to:

  1. receive your initial request;

  2. identify you or your business;

  3. understand the product or service you are requesting;

  4. perform initial sanctions, jurisdiction, industry, occupation and risk screening;

  5. assess whether you fall within Goat Finance's risk appetite and eligibility criteria;

  6. determine whether any Goat Finance entity may provide the requested product or service;

  7. determine the relevant contracting entity, service route or partner-supported route;

  8. determine whether additional documents, enhanced due diligence or partner review may be required;

  9. prepare the handoff to the relevant Phase 2 controller;

  10. use AI-assisted tools to extract, organize, compare, summarize or analyze information, identify inconsistencies or risk indicators, support preliminary due diligence and assist authorized personnel with eligibility and routing assessments.

AI-assisted processing during Phase 1 may generate summaries, preliminary classifications, alerts, inconsistencies, risk indicators, suggested follow-up questions or other derived information. Such outputs may form part of the Phase 1 record but remain subject to validation, applicable controls and human review where required.

Completion of Phase 1 does not create a customer relationship, account, right to transact or entitlement to any Goat Finance product or service.

4.2 Phase 2 — Product-Specific Onboarding and Service Delivery

Phase 2 begins when you are routed to the relevant Goat Finance entity for product-specific onboarding, service activation, transaction review, customer relationship management or partner-supported processing.

The Phase 2 controller will generally be the Goat Finance entity that contracts with you, provides the relevant service, arranges the relevant product route or determines the purposes and essential means of the relevant processing.

The applicable Phase 2 controller will be communicated to you before service activation, transaction execution, account opening or partner-supported product activation.

Phase 2 processing may include:

  1. product-specific KYC/KYB;

  2. customer due diligence;

  3. enhanced due diligence;

  4. source of funds and source of wealth review;

  5. sanctions, PEP and adverse media screening;

  6. fraud prevention;

  7. transaction monitoring;

  8. wallet and blockchain analytics screening;

  9. payment, banking or settlement review;

  10. partner onboarding or partner approval;

  11. account, product or service activation;

  12. customer support;

  13. complaints handling;

  14. recordkeeping;

  15. audit;

  16. legal, regulatory, tax, compliance and reporting obligations;

  17. AI-assisted document extraction, information verification, case summarization and compliance analysis;

  18. AI-assisted customer due diligence, enhanced due diligence, risk identification, alert prioritization and preparation of compliance recommendations or requests for information;

  19. human review, validation, monitoring and governance of AI-generated outputs used in connection with material compliance or service decisions.

AI systems may support Phase 2 processes, but material decisions concerning onboarding approval, rejection, customer risk classification, enhanced due diligence, transaction restrictions, suspension, offboarding, suspicious activity escalation or regulatory reporting remain subject to the authority, review and determination of appropriately authorized personnel, except where a different form of automated decision-making is expressly permitted by applicable law and disclosed to the affected person.

5. Controller Allocation

The controller of your personal data depends on the processing phase, entity, product, service, route and purpose.

At a general level:

Processing Activity / Route General Controller
Phase 1 global pre-onboarding, eligibility, screening and routingGoat Finance SAGL
Phase 2 routed to Goat Finance SAGLGoat Finance SAGL
Phase 2 routed to Goat Finance LLCGoat Finance LLC
Phase 2 routed to Goat Finance LtdGoat Finance LTD
Multi-product or dual-entity scenarioController determined per product and per entity
Partner-supported serviceRelevant Goat Finance entity and partner role as described in the applicable product notice, disclosure or partner documentation

A Goat Finance entity, technology provider, AI developer or AI system provider is not automatically a controller merely because it belongs to the Goat Finance organization, employs a person involved in the process, pays for a tool, hosts a system, develops or configures an AI solution, provides technical support or has technical access to personal data.

Controller, joint-controller and processor roles are determined according to the actual purposes and essential means of the relevant processing, the instructions governing the processing, the contractual arrangements and applicable law. Where two or more entities jointly determine the purposes and essential means of a specific processing activity, those entities may act as joint controllers.

Where this applies, the essence of the joint-controller arrangement will be made available in the applicable privacy notice or disclosure.

6. Handoff Between Controllers

Where a case moves from Phase 1 to Phase 2, Goat Finance may transfer or make available relevant personal data from the Phase 1 controller to the Phase 2 controller.

This handoff may include:

  1. identity and contact information;

  2. onboarding form responses;

  3. jurisdictional information;

  4. product or service request information;

  5. KYC/KYB information already collected;

  6. screening results;

  7. risk classification;

  8. documents uploaded during Phase 1;

  9. eligibility assessment results;

  10. routing decision;

  11. notes necessary to continue onboarding;

  12. records of notices, terms or disclosures shown during Phase 1;

  13. AI-generated or AI-assisted summaries of onboarding information;

  14. identified inconsistencies, alerts, preliminary classifications or risk indicators;

  15. records showing whether AI-generated information was validated, corrected or reviewed by authorized personnel.

AI-generated or AI-assisted information included in a controller handoff must be treated according to its nature and reliability. Preliminary inferences, alerts and recommendations must not be represented as verified facts unless they have been appropriately validated.

Before or during Phase 2, the relevant Phase 2 controller will provide or make available the applicable entity Privacy Notice and, where relevant, product-specific privacy or partner data-sharing disclosures.

The Phase 2 controller may request additional personal data, documents or confirmations beyond those collected during Phase 1.

7. Jurisdiction-Aware Website and Onboarding Controls

Goat Finance may process limited technical, location, declared-jurisdiction and website-interaction data to implement jurisdiction-aware website, onboarding and product-information controls.

This may include:

  1. IP address;

  2. approximate location derived from IP address;

  3. browser language or locale;

  4. country selected or declared by you;

  5. country of residence;

  6. country of incorporation;

  7. product-interest selection;

  8. product pages viewed;

  9. legal notices, warnings or pop-ups shown to you;

  10. timestamps and version records;

  11. device and user agent information;

  12. whether you acknowledged a jurisdictional notice;

  13. onboarding route and eligibility outcome.

Goat Finance may use this information to:

  1. avoid displaying product information that may not be appropriate for your jurisdiction;

  2. comply with financial promotion, reverse solicitation, marketing, licensing, regulatory perimeter and product-availability controls;

  3. determine whether you should be directed to a general information page, an eligibility assessment, a specific Goat Finance entity, a restricted flow or a blocked flow;

  4. keep evidence of the notices, product information and legal documents shown to you;

  5. support legal, compliance, audit and risk management controls.

This processing is designed to support Goat Finance's compliance framework and does not, by itself, determine whether you are eligible for any product or service.

8. Personal Data We May Collect

Depending on your interaction with Goat Finance, we may collect the following categories of personal data.

8.1 Identity and Contact Data

This may include:

  1. full name;

  2. date of birth;

  3. place of birth;

  4. nationality;

  5. country of residence;

  6. residential address;

  7. email address;

  8. telephone number;

  9. identity document details;

  10. tax identification information;

  11. government identification numbers;

  12. signature;

  13. selfie, liveness check or biometric verification data where required by the onboarding process.

8.2 Business and KYB Data

For legal entities, this may include:

  1. company name;

  2. registration number;

  3. registered office;

  4. principal place of business;

  5. company formation documents;

  6. constitutional documents;

  7. ownership structure;

  8. shareholder information;

  9. beneficial ownership information;

  10. directors, officers, signatories and authorized representatives;

  11. business model;

  12. industry and occupation information;

  13. licenses and registrations;

  14. tax status;

  15. financial statements;

  16. invoices, contracts or business evidence.

8.3 Financial, Wallet and Transaction Data

This may include:

  1. bank account details;

  2. payment account details;

  3. wallet addresses;

  4. blockchain transaction data;

  5. source of funds;

  6. source of wealth;

  7. income, revenue or asset information;

  8. expected transaction volume;

  9. transaction history;

  10. payment references;

  11. settlement information;

  12. transaction purpose;

  13. counterparty information;

  14. invoices, contracts or supporting documents.

8.4 Compliance, Risk and Screening Data

This may include:

  1. sanctions screening results;

  2. politically exposed person screening results;

  3. adverse media screening results;

  4. fraud risk indicators;

  5. transaction monitoring alerts;

  6. blockchain analytics results;

  7. wallet risk scores;

  8. jurisdictional risk assessment;

  9. industry or occupation risk assessment;

  10. internal risk rating;

  11. enhanced due diligence information;

  12. compliance notes;

  13. regulatory, partner or law enforcement correspondence, where applicable.

8.5 Technical, Device, Website and Usage Data

This may include:

  1. IP address;

  2. device identifiers;

  3. browser type;

  4. operating system;

  5. login data;

  6. cookies and similar technologies;

  7. user agent;

  8. session data;

  9. platform activity;

  10. website page views;

  11. product page interactions;

  12. security logs;

  13. access logs;

  14. communication metadata.

8.6 Communications and Relationship Data

This may include:

  1. emails;

  2. support requests;

  3. chat messages;

  4. platform messages;

  5. forms submitted by you;

  6. call notes;

  7. meeting notes;

  8. transaction instructions;

  9. complaints;

  10. customer support records;

  11. records of terms accepted;

  12. records of privacy notices, disclosures or warnings shown or acknowledged.

8.7 AI-Generated, Derived and Inferred Data

Where Goat Finance uses artificial intelligence or AI-assisted processing, we may generate, receive or maintain information derived from other personal data. This may include:

  1. extracted or structured information obtained from documents, forms, communications or records;

  2. summaries of customer, beneficial-owner, transaction or business information;

  3. identified inconsistencies, missing information or document-verification issues;

  4. preliminary customer, transaction, wallet, jurisdiction, industry or product risk indicators;

  5. alerts, prioritization results or suggested review categories;

  6. proposed risk classifications or enhanced due diligence indicators;

  7. suggested requests for information or supporting documentation;

  8. associations or comparisons between information contained in different records;

  9. AI-generated compliance analyses, recommendations, explanations or draft memoranda;

  10. confidence indicators or other information concerning the reliability of an AI-generated result;

  11. prompts, system instructions, outputs, interaction records and technical logs;

  12. records of human review, correction, validation, rejection or approval of AI-generated outputs;

  13. information concerning the AI system, model or version involved in the processing.

AI-generated or inferred information may constitute personal data even where it was not provided directly by you.

9. Sources of Personal Data

We may collect personal data from:

  1. you directly;

  2. your authorized representative;

  3. your employer or company;

  4. beneficial owners, directors, officers, controllers, shareholders or business representatives;

  5. onboarding forms;

  6. KYC/KYB providers;

  7. identity verification providers;

  8. sanctions screening providers;

  9. politically exposed person and adverse media providers;

  10. blockchain analytics providers;

  11. fraud prevention providers;

  12. payment providers;

  13. banking partners;

  14. liquidity providers;

  15. settlement providers;

  16. partner-supported service providers;

  17. public registries;

  18. company registries;

  19. public websites and databases;

  20. government, regulatory, court or law enforcement sources;

  21. business partners, introducers or referral sources;

  22. internal Goat Finance systems, records and shared operational resources;

  23. artificial intelligence systems, automated tools and machine-learning systems used by or on behalf of Goat Finance;

  24. AI developers, AI system providers, model providers, model-hosting providers and other providers involved in developing, configuring, testing, maintaining or supporting AI-assisted systems;

  25. information, patterns, associations, classifications or inferences generated from personal data already held by Goat Finance or lawfully obtained from another source.

10. Why We Process Personal Data

Goat Finance may process personal data for the purposes described below.

10.1 Onboarding, Eligibility and Routing

We may process personal data to:

  1. receive your application or request;

  2. verify your identity or business;

  3. assess eligibility;

  4. determine whether Goat Finance can support the requested product or service;

  5. determine the applicable contracting entity;

  6. determine the applicable controller;

  7. determine the applicable partner route;

  8. assess jurisdictional, product, customer, industry, occupation and risk eligibility;

  9. conduct Phase 1 to Phase 2 handoff;

  10. provide the appropriate terms, privacy notices and disclosures.

10.2 Compliance, KYC, KYB, AML/CFT and Sanctions

We may process personal data to:

  1. comply with anti-money laundering requirements;

  2. comply with counter-terrorist financing requirements;

  3. comply with sanctions, asset-freezing and restricted-party controls;

  4. verify identity and beneficial ownership;

  5. understand source of funds and source of wealth;

  6. conduct PEP and adverse media screening;

  7. monitor transactions;

  8. investigate alerts;

  9. detect suspicious activity;

  10. respond to regulator, bank, partner, court or law enforcement requests;

  11. maintain compliance records.

10.3 Product and Service Provision

We may process personal data to:

  1. provide requested and approved products or services;

  2. process transaction instructions;

  3. execute or settle approved transactions;

  4. support payment or settlement flows;

  5. support partner-enabled service routes;

  6. provide platform or portal access;

  7. communicate with you;

  8. provide customer support;

  9. manage disputes, complaints or investigations;

  10. manage service status.

10.4 Risk, Fraud and Security

We may process personal data to:

  1. detect fraud;

  2. prevent unauthorized access;

  3. protect accounts and systems;

  4. investigate suspicious activity;

  5. monitor wallets and counterparties;

  6. identify transaction anomalies;

  7. prevent misuse of Goat Finance services;

  8. protect Goat Finance, customers, partners and the financial system;

  9. maintain cybersecurity and operational resilience.

10.5 Website, Jurisdiction and Reverse-Solicitation Controls

We may process personal data to:

  1. identify your approximate location or declared jurisdiction;

  2. apply jurisdiction-aware content controls;

  3. avoid showing product content where it may not be appropriate;

  4. manage financial promotion, reverse solicitation, licensing and product-availability controls;

  5. record which notices, warnings, pop-ups, terms or disclosures were shown to you;

  6. support legal, compliance, audit and risk evidence.

10.6 Legal, Regulatory, Audit and Governance

We may process personal data to:

  1. comply with applicable laws and regulations;

  2. comply with court orders, regulator requests or law enforcement requests;

  3. maintain records;

  4. conduct audits;

  5. manage internal governance;

  6. comply with contractual obligations;

  7. manage legal claims;

  8. enforce terms, policies and controls;

  9. implement global governance, routing, access, transfer and privacy control frameworks.

10.7 Communications and Relationship Management

We may process personal data to:

  1. respond to inquiries;

  2. send service notices;

  3. send legal, privacy or policy updates;

  4. provide transaction confirmations;

  5. manage customer relationships;

  6. conduct customer support;

  7. handle complaints.

10.8 Marketing

Where permitted by applicable law, we may process limited personal data to send marketing, product updates, educational materials or commercial communications.

Where consent is required, we will request consent separately.

You may opt out of marketing communications where required or permitted by applicable law.

Goat Finance may restrict or suppress marketing or product communications in certain jurisdictions to support compliance with applicable financial promotion, reverse solicitation, licensing or product-availability controls.

10.9 Artificial Intelligence and AI-Assisted Processing

We may use artificial intelligence systems, machine-learning tools, generative AI, automated agents or similar technologies to support authorized business, compliance, risk-management, security and operational purposes. These purposes may include:

  1. extracting and structuring information from identification documents, corporate documents, financial documents, communications and supporting records;

  2. comparing information across forms, documents, systems and data sources;

  3. identifying missing, inconsistent, incomplete or potentially inaccurate information;

  4. summarizing onboarding, customer due diligence and enhanced due diligence files;

  5. assisting with identity, business, ownership and document-verification processes;

  6. supporting sanctions, PEP, adverse-media, fraud and compliance reviews;

  7. identifying customer, jurisdictional, industry, occupation, transaction, counterparty or wallet risk indicators;

  8. prioritizing cases, alerts, transactions or reviews;

  9. suggesting additional due diligence, enhanced due diligence or supporting documentation;

  10. generating draft requests for information;

  11. preparing draft risk analyses, compliance memoranda, case summaries or recommendations for review by authorized personnel;

  12. supporting customer-risk classification and periodic review;

  13. identifying unusual activity, inconsistencies or patterns requiring further investigation;

  14. supporting transaction monitoring, fraud prevention and security controls;

  15. assisting with routing, product eligibility and partner-supported review;

  16. supporting audit, quality assurance, testing and control validation;

  17. monitoring the performance, accuracy, security and reliability of AI-assisted processes;

  18. maintaining evidence, logs and records required for governance, audit, legal, regulatory and compliance purposes.

The use of AI does not change the underlying purpose or legal basis applicable to the processing of personal data.

11. Legal Bases and Lawful Grounds

The legal basis or lawful ground for processing depends on the jurisdiction, processing activity and applicable law.

Where EU GDPR or UK GDPR applies, we may rely on one or more of the following legal bases:

  1. performance of a contract;

  2. steps taken before entering into a contract;

  3. compliance with legal obligations;

  4. legitimate interests;

  5. consent, where required;

  6. substantial public interest or other applicable grounds for sensitive data, where relevant;

  7. establishment, exercise or defense of legal claims.

Where Swiss data protection law applies, we process personal data in accordance with applicable Swiss privacy principles, including transparency, proportionality, purpose limitation, security, accuracy and lawful disclosure requirements.

Where U.S. privacy laws apply, we process personal information for the purposes disclosed in this Global Privacy Policy, the applicable entity Privacy Notice, any U.S. privacy notice or module, and any product-specific notice or service-specific disclosure.

Where Canadian privacy laws apply, we process personal information for the purposes disclosed in this Global Privacy Policy, the applicable entity Privacy Notice, any Canadian privacy notice or module, and any product-specific notice or service-specific disclosure.

Where we rely on consent for optional processing, consent will be requested separately and may be withdrawn according to the process described in the applicable notice.

We do not rely on blanket mandatory consent where processing is necessary for onboarding, eligibility, compliance screening, AML/CFT controls, sanctions screening, service provision, transaction monitoring, fraud prevention, legal obligations, legitimate operational purposes, jurisdiction-aware website controls or risk management.

The use of an AI system, automated tool or AI-assisted process does not, by itself, constitute a separate legal basis for processing. The applicable legal basis is determined by the underlying purpose for which personal data is processed.

Where an AI system processes personal data for onboarding, KYC/KYB, customer due diligence, enhanced due diligence, sanctions, AML/CFT, fraud prevention, security, transaction monitoring, risk management or legal compliance, Goat Finance relies on the legal basis or lawful ground applicable to the relevant underlying activity.

Where applicable law regulates decisions based solely or materially on automated processing, Goat Finance will identify and apply the additional legal basis, transparency, assessment and safeguard requirements applicable to that processing.

12. Special Category Data, Sensitive Data and Criminal-Offence Related Data

Goat Finance does not intentionally seek to collect sensitive or special category data unless it is necessary, permitted or required for identity verification, onboarding, KYC/KYB, AML/CFT, sanctions screening, fraud prevention, regulatory compliance, legal claims, security or product-specific requirements.

Depending on the jurisdiction, this may include:

  1. biometric data used for identity verification, selfie checks or liveness checks;

  2. politically exposed person information;

  3. adverse media information;

  4. criminal-offence related information or allegations;

  5. sanctions-related information;

  6. sensitive personal information under applicable U.S. privacy laws.

Where EU GDPR or UK GDPR applies, Goat Finance processes special category data or criminal-offence related data only where an applicable legal basis and condition permit such processing.

Where Swiss law applies, Goat Finance processes sensitive personal data only where permitted and subject to appropriate safeguards.

Where U.S. or Canadian privacy laws apply, Goat Finance does not use sensitive personal information to infer characteristics unless stated in a specific notice and permitted by applicable law.

Where artificial intelligence or AI-assisted processing is used, Goat Finance does not treat an AI-generated inference, allegation, association or classification concerning sensitive data, criminal conduct, sanctions exposure, political exposure or adverse media as a verified fact without appropriate review and validation.

Unless separately disclosed, legally permitted and necessary for a defined purpose, Goat Finance does not use AI systems to infer sensitive personal characteristics that are unrelated to the relevant onboarding, compliance, security or risk-management purpose.

Goat Finance does not use AI systems for emotion recognition or biometric categorization in relation to customers or prospective customers unless such processing is specifically assessed, legally permitted, necessary for a documented purpose and disclosed as required by applicable law.

Where special category or sensitive data is processed for testing, bias detection or correction, Goat Finance will apply the legal conditions and safeguards required by applicable law. These may include strict necessity, data minimization, pseudonymization, access controls, confidentiality, security measures, reuse restrictions, limited retention and documented deletion.

13. How We Share Personal Data Within Goat Finance

Goat Finance operates through separate entities, shared systems, shared personnel, shared compliance functions, shared technology and shared operational resources.

Goat Finance may share personal data within its multilateral organization where necessary for:

  1. onboarding;

  2. eligibility assessment;

  3. routing;

  4. Phase 1 to Phase 2 handoff;

  5. customer due diligence;

  6. enhanced due diligence;

  7. sanctions screening;

  8. transaction monitoring;

  9. fraud prevention;

  10. customer support;

  11. technology operations;

  12. security;

  13. payment or settlement support;

  14. CRM;

  15. audit;

  16. reporting;

  17. legal and regulatory compliance;

  18. governance;

  19. service administration;

  20. recordkeeping;

  21. internal controls;

  22. AI-assisted document processing and case analysis;

  23. validation, monitoring and human review of AI-generated outputs;

  24. AI governance, system testing, model-risk management and incident investigation.

Personal data is not made available to all Goat Finance entities by default.

Access is granted on a need-to-know basis, taking into account:

  1. the relevant product or service;

  2. the relevant Goat Finance entity;

  3. the relevant processing phase;

  4. the role of the person requesting access;

  5. the purpose of access;

  6. case assignment;

  7. applicable law;

  8. transfer requirements;

  9. security controls;

  10. the applicable access matrix or equivalent internal control.

The use of shared resources does not automatically change controller status.

Access to AI systems or AI-generated records does not permit unrestricted access to the underlying customer information. Access remains subject to the relevant entity, product, processing phase, role, case assignment, purpose, need-to-know requirement and access-control framework.

14. How We Share Personal Data With Third Parties

We may share personal data with third parties where necessary or permitted for the purposes described in this Global Privacy Policy, the applicable entity Privacy Notice, product-specific privacy notice, partner disclosure or service-specific data-sharing section.

Third parties may include:

  1. KYC/KYB providers;

  2. identity verification providers;

  3. sanctions screening providers;

  4. PEP and adverse media providers;

  5. blockchain analytics providers;

  6. fraud prevention providers;

  7. banks;

  8. payment providers;

  9. settlement providers;

  10. e-money institutions;

  11. liquidity providers;

  12. exchanges or execution providers;

  13. custodians or custody-connected providers, where applicable;

  14. technology providers;

  15. cloud providers;

  16. CRM providers;

  17. communication providers;

  18. customer support tools;

  19. professional advisers;

  20. auditors;

  21. insurers;

  22. regulators;

  23. law enforcement authorities;

  24. courts;

  25. tax authorities;

  26. government authorities;

  27. business partners, introducers or referral sources;

  28. commercial partner, where the commercial partner-supported route applies;

  29. other partners or service providers required to provide, review, approve, monitor or support the relevant product or service;

  30. artificial intelligence developers;

  31. AI system providers and AI platform providers;

  32. general-purpose AI model providers and model-hosting providers;

  33. providers supporting the development, configuration, testing, validation, monitoring, maintenance or security of AI-assisted systems;

  34. providers of data-extraction, document-analysis, workflow-automation, case-management or decision-support technology.

We may also share personal data where necessary to:

  1. comply with legal obligations;

  2. respond to lawful requests;

  3. enforce our terms;

  4. protect Goat Finance's rights;

  5. investigate fraud or misconduct;

  6. prevent financial crime;

  7. protect customers, partners and the public;

  8. support audits, examinations or regulatory reviews;

  9. complete a corporate transaction, restructuring, merger, acquisition, sale, financing or transfer of business assets, where legally permitted.

Product-specific privacy notices or service-specific data-sharing disclosures will describe partner-specific sharing where required or appropriate.

An AI developer, AI system provider or model provider may act as a processor, subprocessor, independent controller, joint controller or technology provider, depending on the processing activity, contractual framework and applicable law.

Where an AI provider processes personal data on behalf of Goat Finance, Goat Finance seeks to implement appropriate contractual and operational restrictions concerning:

  1. documented processing instructions;

  2. purpose limitation;

  3. confidentiality;

  4. security;

  5. authorized personnel;

  6. subprocessor approval and oversight;

  7. international transfers;

  8. incident reporting;

  9. audit and compliance information;

  10. retention, return and deletion of personal data;

  11. restrictions on combining Goat Finance data with data belonging to other customers or third parties;

  12. restrictions on unauthorized reuse of personal data.

Unless separately disclosed and permitted by applicable law, Goat Finance does not authorize AI developers, AI system providers, model providers or their subprocessors to use identifiable Goat Finance customer data to train, retrain or improve general-purpose models or products made available to other customers.

Human access by an AI provider to customer data is limited to authorized circumstances such as development, configuration, testing, troubleshooting, maintenance, security, incident response or other documented support purposes.

Where reasonably possible and appropriate for the relevant development or testing purpose, Goat Finance may use synthetic, anonymized, pseudonymized or otherwise minimized information instead of directly identifiable customer data.

15. Partner-Supported Services

Some Goat Finance services may be supported by banking, payment, settlement, liquidity, infrastructure, compliance, KYC/KYB, blockchain analytics, technology or other partners.

Where a partner-supported service applies, Goat Finance may share personal data with the relevant partner and its service providers where necessary to:

  1. review eligibility;

  2. conduct onboarding;

  3. verify identity or business information;

  4. conduct due diligence;

  5. conduct sanctions, fraud, AML/CFT or risk review;

  6. open, support or administer the relevant product or service;

  7. process payments, settlements or transactions;

  8. monitor transactions;

  9. manage partner risk;

  10. respond to partner, regulator, court or law enforcement requests;

  11. suspend, restrict or terminate the service.

Partner-supported services may involve partners acting as processors, independent controllers, joint controllers or regulated providers, depending on the facts and the applicable partner framework.

The applicable product-specific privacy notice, partner disclosure or service-specific data-sharing section will provide additional information where relevant.

A technology provider or AI developer supporting Goat Finance's internal onboarding, compliance, due diligence or operational processes is not treated as a provider of financial services to the customer solely because it develops, hosts or supports the relevant technology.

The privacy and data-protection role of an AI developer or technology provider will be determined separately from the regulatory or commercial role of a banking, payment, settlement or financial-infrastructure partner.

Where an AI system is integrated into a partner-supported service, the relevant product-specific notice, partner disclosure or service-specific privacy section may provide additional information concerning the entities involved, their roles, the purposes of AI-assisted processing and the applicable data-sharing arrangements.

16. International Transfers

Goat Finance operates internationally. Your personal data may be processed in, accessed from or transferred to countries other than the country where you are located.

International transfers may occur because:

  1. Goat Finance entities are located in different countries;

  2. shared personnel or global roles may support operations from different locations;

  3. vendors and service providers may operate internationally;

  4. cloud, CRM, communication, KYC/KYB, blockchain analytics, payment, banking, partner and compliance systems may involve cross-border access;

  5. applicable partners or providers may be located outside your jurisdiction;

  6. AI systems or underlying models may be hosted or operated in another country;

  7. an AI developer, model provider, support team or subprocessor may access personal data remotely from another jurisdiction;

  8. prompts, outputs, logs, backups, security records or technical telemetry may be processed or stored in more than one country;

  9. an AI system may rely on cloud, hosting, infrastructure, security or model providers located in different jurisdictions;

  10. development, testing, troubleshooting, maintenance or incident response may require authorized cross-border access.

Where required by applicable law, Goat Finance will use appropriate safeguards for international transfers.

These may include:

  1. adequacy decisions;

  2. standard contractual clauses;

  3. UK international transfer mechanisms;

  4. Swiss-recognized transfer safeguards;

  5. contractual safeguards;

  6. technical and organizational measures;

  7. access restrictions;

  8. minimization;

  9. encryption;

  10. pseudonymization;

  11. transfer assessments;

  12. other lawful mechanisms.

Where a specific transfer route applies to your product, onboarding route, partner-supported service or contracting entity, additional information may be provided in the applicable entity Privacy Notice, product-specific privacy notice or service-specific disclosure.

When assessing an AI-related transfer, Goat Finance may consider not only the location of the contracting provider, but also the location of the underlying model, hosting environment, subprocessors, support personnel, backups, logs, technical telemetry and remote-access arrangements.

17. Retention

Goat Finance retains personal data for as long as necessary for the purposes described in this Global Privacy Policy, the applicable privacy notice or as required or permitted by law, regulation, contractual obligation, audit requirement, dispute resolution, AML/CFT recordkeeping, tax, accounting, security, partner requirement or compliance obligation.

Retention periods may vary depending on:

  1. the type of personal data;

  2. the product or service;

  3. the relevant Goat Finance entity;

  4. the relevant jurisdiction;

  5. whether you become a customer;

  6. whether your application is rejected, declined or incomplete;

  7. AML/CFT and sanctions obligations;

  8. legal limitation periods;

  9. regulatory expectations;

  10. partner requirements;

  11. audit and governance requirements;

  12. whether there is an ongoing dispute, investigation, review, legal hold or regulatory inquiry;

  13. whether the information forms part of an AI prompt, output, inference, recommendation or system log;

  14. whether the information is necessary to reconstruct or explain a compliance review or material decision;

  15. whether the record is required for AI governance, system testing, validation, monitoring, audit or incident investigation;

  16. the AI system, model, version and intended purpose involved;

  17. whether the information was used for development, testing or production.

Unless a shorter or longer period applies under applicable law or a specific retention notice, onboarding, customer due diligence and transaction records may generally be retained for up to 10 years after the end of the relationship or the relevant decision, subject to applicable legal requirements and documented exceptions.

Where your application does not proceed to Phase 2, the relevant Phase 1 controller may retain your data in accordance with the applicable retention period for rejected, incomplete or declined applications.

AI-related records may include prompts, system instructions, source information, generated outputs, risk indicators, recommendations, model or system versions, validation records, human-review records, final decisions, corrections, testing records, security records and incident records.

AI development and testing data will be retained only for as long as reasonably necessary for the documented development, validation, legal, security, audit or compliance purpose, subject to applicable retention requirements.

Where an applicable AI law requires Goat Finance to retain automatically generated logs for a minimum period, Goat Finance will retain logs under its control for at least that period. Where the same records are also subject to longer AML/CFT, sanctions, financial-services, litigation, audit or regulatory recordkeeping requirements, the longer applicable period may apply.

18. Security

Goat Finance uses technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure or destruction.

These measures may include:

  1. access controls;

  2. role-based permissions;

  3. system-level restrictions;

  4. need-to-know access;

  5. authentication controls;

  6. logging and monitoring;

  7. encryption where appropriate;

  8. segregation of data where appropriate;

  9. vendor due diligence;

  10. internal governance controls;

  11. incident escalation procedures;

  12. audit and review controls;

  13. transfer controls;

  14. data minimization controls;

  15. secure document handling procedures;

  16. segregation between development, testing and production environments;

  17. logical separation between Goat Finance data and data belonging to other customers of a provider;

  18. encryption of AI-related data in transit and at rest, where appropriate;

  19. controls designed to reduce prompt injection, unauthorized tool use, malicious instructions and data-exfiltration risks;

  20. restrictions on the systems, connectors, repositories, databases and external tools accessible to an AI agent;

  21. security and privacy review of AI developers, system providers, model providers and subprocessors;

  22. contractual restrictions on unauthorized model training, reuse or combination of Goat Finance data;

  23. logging of access, system activity and material AI-assisted processing;

  24. use of synthetic, anonymized, pseudonymized or minimized information for development and testing where reasonably possible;

  25. validation and review of AI-generated outputs;

  26. procedures for identifying, escalating, investigating and mitigating AI-related errors, risks and incidents;

  27. procedures for suspending or restricting an AI system where it presents an unacceptable legal, privacy, security, compliance or operational risk;

  28. secure return, deletion, migration and exit procedures when an AI provider or system is replaced or terminated.

Goat Finance takes measures designed to support the development of AI literacy among personnel and other persons operating or using AI systems on its behalf. Such measures may take into account the person's role, technical knowledge, experience, education, training, the context in which the system is used and the persons who may be affected by its use.

Personnel responsible for human oversight should have appropriate competence, training, authority and support to understand the relevant system's intended purpose, capabilities and limitations; identify errors or unexpected outputs; avoid overreliance on automated results; and disregard, override, suspend or escalate an AI-generated result where appropriate.

No system or method of transmission is completely secure. Goat Finance cannot guarantee absolute security, but it takes reasonable steps designed to protect personal data according to the nature of the data and the processing activity.

19. Artificial Intelligence, Automated Processing, Profiling and Risk Assessment

19.1 Scope

Goat Finance may use artificial intelligence systems, machine-learning tools, generative AI, automated agents, automated workflows and other automated or semi-automated technologies.

For the purposes of this Global Privacy Policy, “AI-Assisted Processing” means the use of such technologies to extract, structure, compare, analyze, classify, summarize, prioritize, generate, verify or otherwise process information in support of Goat Finance activities.

Where applicable, Goat Finance's development, acquisition, deployment and use of AI systems is subject to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence, as amended by Regulation (EU) 2026/1744 and as may be further amended, supplemented or replaced from time to time, referred to in this Policy as the “EU AI Act”, together with other applicable laws governing artificial intelligence, automated decision-making, data protection, financial services, consumer protection, security and regulatory compliance.

19.2 Activities Supported by AI

Goat Finance may use AI-Assisted Processing to support:

  1. onboarding;

  2. identity and document verification;

  3. KYC and KYB;

  4. customer due diligence;

  5. enhanced due diligence;

  6. source of funds and source of wealth review;

  7. beneficial ownership analysis;

  8. sanctions, PEP and adverse-media review;

  9. fraud prevention;

  10. transaction monitoring;

  11. blockchain and wallet analytics;

  12. customer and transaction risk assessment;

  13. eligibility and routing;

  14. case prioritization;

  15. identification of missing or inconsistent information;

  16. preparation of requests for information;

  17. preparation of case summaries, risk analyses and draft compliance recommendations;

  18. customer support and communications;

  19. security monitoring;

  20. audit, quality assurance, testing and governance.

19.3 Information Generated by AI Systems

AI systems may generate or assist in generating:

  1. extracted information;

  2. document summaries;

  3. inconsistencies;

  4. alerts;

  5. risk indicators;

  6. preliminary classifications;

  7. case priorities;

  8. suggested follow-up questions;

  9. recommended documentation;

  10. draft analyses;

  11. draft memoranda;

  12. draft communications;

  13. explanations or rationales;

  14. technical or confidence indicators.

AI-generated outputs may be incomplete, inaccurate, outdated, misleading or affected by limitations in the information, system, model or configuration used. An AI-generated output is not treated as a verified fact solely because it was generated by an AI system.

19.4 Human Oversight and Material Decisions

AI-generated outputs are intended to support, and not improperly replace, the professional judgment, legal responsibilities and decision-making authority of the relevant Goat Finance personnel.

Material decisions concerning:

  1. approval or rejection of onboarding;

  2. final customer risk classification;

  3. enhanced due diligence requirements;

  4. material requests for additional information;

  5. transaction restriction, rejection or suspension;

  6. customer suspension or offboarding;

  7. suspicious activity escalation;

  8. regulatory reporting;

  9. other decisions producing legal or similarly significant effects;

are subject to meaningful review and determination by appropriately authorized personnel, except where a different form of automated decision-making is expressly permitted by applicable law, supported by a valid legal basis and accompanied by the required safeguards and disclosures.

Human oversight may include:

  1. reviewing source documents and underlying information;

  2. evaluating whether an AI-generated result is relevant, reliable and proportionate;

  3. considering contrary or additional information;

  4. correcting inaccurate inputs or outputs;

  5. disregarding or overriding an AI-generated recommendation;

  6. requesting additional due diligence;

  7. escalating the case;

  8. suspending use of the system or output;

  9. documenting the final decision and its basis.

Goat Finance seeks to reduce automation bias and does not require authorized personnel to accept an AI-generated recommendation merely because it was generated by an automated system.

19.5 Solely Automated Decisions

Unless otherwise stated in a specific notice and permitted by applicable law, Goat Finance does not make decisions based solely on automated processing where the decision produces legal effects or similarly significantly affects a natural person.

Where such processing is used, Goat Finance will provide the information, legal basis and safeguards required by applicable law. Depending on the circumstances, these safeguards may include the ability to request human intervention, provide additional information, express a point of view, correct inaccurate information, challenge the result or obtain an explanation.

19.6 Transparency and Direct Interaction

Where an AI system is intended to interact directly with a natural person, Goat Finance or the relevant provider will inform the person that they are interacting with an AI system where required by applicable law, unless this is obvious in the circumstances.

Where an AI system materially assists a decision concerning a natural person and applicable law requires notice of that use, Goat Finance will provide the relevant information through this Global Privacy Policy, an entity Privacy Notice, an AI-specific notice, an onboarding disclosure, a product-specific disclosure, the relevant interface or another appropriate communication.

The information may explain:

  1. that AI or automated processing is involved;

  2. the general purpose for which it is used;

  3. whether the system provides assistance or makes an automated determination;

  4. the role of human oversight;

  5. the types of data and outputs involved;

  6. the possible consequences of the processing;

  7. the rights or review mechanisms that may apply.

19.7 Accuracy, Reliability and Fairness

Goat Finance applies controls designed to support the appropriate accuracy, reliability and fairness of AI-Assisted Processing.

These controls may include:

  1. evaluating the relevance and quality of input data;

  2. validating extracted or generated information against source records;

  3. testing for material errors, false positives and false negatives;

  4. monitoring model or system performance;

  5. monitoring for unexpected changes or performance drift;

  6. testing for unjustified discriminatory effects;

  7. evaluating the reliability and source quality of adverse-media information;

  8. distinguishing allegations, inferences and indicators from verified facts;

  9. documenting corrections and human overrides;

  10. reviewing material changes to the system, model, data, configuration or intended purpose.

19.8 Providers and Data Use

AI-Assisted Processing may involve AI developers, system providers, model providers, cloud providers, hosting providers and other subprocessors.

Where those providers process personal data on behalf of Goat Finance, their processing is subject to the relevant contractual, security, confidentiality, access, purpose, retention, deletion and transfer requirements.

Unless separately disclosed and permitted by applicable law, Goat Finance does not authorize identifiable customer data to be used to train or improve general-purpose AI models or products made available to unrelated customers.

19.9 Monitoring, Records and Incidents

Goat Finance may maintain records concerning:

  1. the AI system and model used;

  2. the system or model version;

  3. the intended purpose;

  4. source information;

  5. prompts or system instructions;

  6. outputs;

  7. risk indicators or recommendations;

  8. human-review activity;

  9. corrections and overrides;

  10. final decisions;

  11. errors, incidents and remedial actions.

Where Goat Finance has reason to believe that an AI system or its use presents a material legal, privacy, security, compliance, fundamental-rights or operational risk, Goat Finance may suspend, restrict, modify or terminate the relevant use and may notify the provider, partner or competent authority where required.

19.10 AI System Classification and Assessments

Goat Finance may assess AI systems according to their intended purpose, functionality, affected persons, data involved, degree of autonomy, role in decision-making and potential impact.

Where required by applicable law or appropriate to the risk, Goat Finance may conduct:

  1. an AI system classification assessment;

  2. a data protection impact assessment;

  3. a fundamental-rights impact assessment;

  4. a security or cybersecurity assessment;

  5. a vendor and subprocessor assessment;

  6. a model, accuracy, bias or performance assessment;

  7. a transfer assessment;

  8. an operational, legal, compliance or risk assessment.

The classification or legal treatment of an AI system may change if its intended purpose, functionality, data, model, configuration, level of autonomy or role in decision-making changes.

20. Your Privacy Rights

Depending on your jurisdiction and applicable law, you may have rights in relation to your personal data.

These may include:

  1. the right to access personal data;

  2. the right to receive information about processing;

  3. the right to correct inaccurate personal data;

  4. the right to request deletion;

  5. the right to restrict processing;

  6. the right to object to processing;

  7. the right to data portability;

  8. the right to withdraw consent where processing is based on consent;

  9. the right to lodge a complaint with a supervisory authority;

  10. the right to appeal or challenge certain decisions, where applicable;

  11. the right to opt out of certain uses, where applicable under U.S. state privacy law;

  12. the right not to be discriminated against for exercising applicable privacy rights;

  13. the right to be informed about applicable AI-assisted or automated processing;

  14. the right to request human intervention or review where provided by applicable law;

  15. the right to provide additional information or express your point of view in relation to certain automated decisions;

  16. the right to challenge or contest certain decisions supported by automated processing;

  17. the right to receive a clear and meaningful explanation of the role of an AI system and the main elements of certain decisions, where required by applicable law.

Where you believe that an AI-assisted decision was based on inaccurate, incomplete or misleading information, you may contact Goat Finance and request that the relevant information be reviewed or corrected, subject to applicable law and the limitations described below.

A request for explanation does not necessarily entitle a person to receive source code, model weights, complete prompts, proprietary algorithms, confidential compliance rules, security-sensitive information, legally protected information or trade secrets.

Information or explanations may also be limited where disclosure would conflict with AML/CFT requirements, sanctions requirements, fraud prevention, suspicious activity reporting, tipping-off restrictions, law-enforcement confidentiality, regulatory instructions, the rights of third parties, system security or other lawful restrictions.

These rights may be subject to limitations, including where processing is required or permitted for AML/CFT, sanctions, fraud prevention, regulatory compliance, legal claims, recordkeeping, security, tax, audit, partner requirements, transaction monitoring or other lawful purposes.

To exercise your rights, contact:

[email protected]

We may need to verify your identity before responding to your request.

The applicable entity Privacy Notice may provide additional entity-specific or jurisdiction-specific rights information and contact details.

21. U.S. Privacy Framework

Where U.S. privacy laws apply, Goat Finance may process personal information for the purposes disclosed in this Global Privacy Policy, the applicable entity Privacy Notice, any product-specific privacy notice and any notice at collection.

Depending on the applicable U.S. state law, personal information may include:

  1. identifiers;

  2. contact information;

  3. government identification information;

  4. financial information;

  5. commercial information;

  6. internet or network activity information;

  7. approximate geolocation information;

  8. professional or employment information;

  9. business representative information;

  10. sensitive personal information where required for compliance, identity verification, sanctions screening, security, legal obligations or service provision;

  11. inferences used for risk, fraud or eligibility assessment;

  12. communications and support information.

Goat Finance does not sell personal information for money.

Unless a specific notice states otherwise, Goat Finance does not share personal information for cross-context behavioral advertising as those terms may be defined under applicable U.S. state privacy laws.

Where applicable, U.S. residents may have rights to know, access, delete, correct, obtain a portable copy, opt out, limit certain uses of sensitive personal information, appeal a privacy rights decision and not be discriminated against for exercising applicable privacy rights.

Additional U.S.-specific disclosures may be provided in the applicable entity Privacy Notice or notice at collection.

22. Cookies and Similar Technologies

Goat Finance may use cookies, pixels, tags, analytics tools and similar technologies on its website, platform and communications.

These technologies may be used for:

  1. website functionality;

  2. security;

  3. authentication;

  4. analytics;

  5. user experience;

  6. fraud prevention;

  7. preference management;

  8. compliance;

  9. jurisdiction-aware content controls;

  10. product-availability controls;

  11. marketing, where permitted.

Further information is available in the Goat Finance Cookie Policy

23. Children

Goat Finance services are not intended for children.

Goat Finance does not knowingly provide financial services to minors.

If you believe that a child has provided personal data to Goat Finance, please contact:

[email protected]

24. Notice Delivery and Evidence

Goat Finance may record evidence that privacy notices, product notices, service disclosures, partner disclosures, pop-ups or jurisdictional warnings were made available to you.

This may include:

  1. document name;

  2. document version;

  3. date and time;

  4. user ID;

  5. customer ID;

  6. IP address;

  7. user agent;

  8. country detected;

  9. country declared;

  10. onboarding route;

  11. product route;

  12. notice text shown;

  13. acknowledgement records;

  14. session information;

  15. communication channel;

  16. whether an AI or automated-processing notice was shown;

  17. the version and content of the relevant AI notice or disclosure;

  18. whether the person was informed that they were interacting with an AI system;

  19. the AI system, model or system version involved, where appropriate;

  20. the general purpose and role of the AI system;

  21. the relevant AI-generated output, indicator or recommendation;

  22. the identity or role of the authorized person who reviewed the output;

  23. records of correction, override, escalation or final determination.

Goat Finance may use this information to demonstrate compliance with applicable privacy, artificial intelligence, financial-services, consumer-protection, audit, governance, risk-management and recordkeeping requirements.

25. Updates to This Global Privacy Policy

Goat Finance may update this Global Privacy Policy from time to time.

Updates may be made to reflect:

  1. changes in law;

  2. regulatory requirements;

  3. new products or services;

  4. changes in Goat Finance's structure;

  5. new entities;

  6. changes in partners or vendors;

  7. changes in systems;

  8. operational changes;

  9. security or compliance requirements;

  10. updates to onboarding, routing or privacy governance controls;

  11. the introduction or material modification of an AI system;

  12. a change in the intended purpose, functionality or level of autonomy of an AI system;

  13. a change in the role of AI in onboarding, due diligence, risk assessment or decision-making;

  14. the appointment or replacement of an AI developer, AI system provider, model provider or material subprocessor;

  15. changes in applicable artificial intelligence, automated decision-making or data-protection requirements.

The updated version will be published on https://goatfinance.io and will indicate the effective date.

Where required by law, Goat Finance will provide additional notice of material changes.

26. Contact

For privacy questions, requests or complaints, contact:

Goat Finance Privacy Contact
Email: [email protected]

Where applicable, the relevant entity Privacy Notice may identify additional entity-specific, jurisdiction-specific, representative, supervisory authority or complaint contact details.

Schedule 1

Layered Privacy Notice Framework

1. Purpose of this Schedule

This Schedule explains how Goat Finance uses layered privacy notices to avoid unnecessary duplication while providing the information required for each phase, entity, product, service, jurisdiction and partner-supported route.

2. Global Privacy Policy

The Global Privacy Policy explains the organization-wide privacy framework, including:

  1. multilateral structure;

  2. Phase 1 and Phase 2 model;

  3. controller allocation;

  4. controller handoff;

  5. shared resources;

  6. intragroup access;

  7. general categories of personal data;

  8. general purposes of processing;

  9. general sharing;

  10. international transfers;

  11. retention;

  12. rights;

  13. security;

  14. artificial intelligence and AI-Assisted Processing;

  15. automated decision-making, profiling and human oversight;

  16. AI developers, model providers and related data sharing;

  17. AI-generated information, records and applicable rights;

  18. jurisdiction-aware website controls.

3. Phase 1 Privacy Notices

Phase 1 Privacy Notices explain the processing that occurs during pre-onboarding, eligibility, screening and routing.

There may be separate Phase 1 Privacy Notices for:

  1. EU/EEA individuals;

  2. United Kingdom individuals;

  3. Rest of World individuals.

4. Entity Privacy Notices

Entity Privacy Notices explain how a specific Goat Finance entity processes personal data when it becomes responsible for Phase 2 onboarding, service provision, transaction review, compliance monitoring or customer relationship management.

Entity Privacy Notices may include:

  1. Goat Finance SAGL Privacy Notice;

  2. Goat Finance LLC Privacy Notice;

  3. Goat Finance LTD Privacy Notice;

  4. notices for any additional Goat Finance entity added in the future.

5. Product-Specific Privacy Notices and Service-Specific Disclosures

Product-specific privacy notices or service-specific privacy sections explain how personal data is processed or shared for a specific product, service, partner-supported feature or transaction route.

These may be provided as:

  1. a standalone product-specific privacy notice;

  2. a service-specific privacy and partner data-sharing section inside Product Terms;

  3. a product disclosure;

  4. a partner-related privacy disclosure;

  5. an onboarding notice.

6. AI and Automated Processing Notices

Where appropriate or required, Goat Finance may provide additional information concerning artificial intelligence, automated processing or profiling.

This information may be provided through:

  1. an AI-specific privacy notice;

  2. an entity Privacy Notice;

  3. a product-specific privacy notice;

  4. an onboarding disclosure;

  5. a partner-related disclosure;

  6. a platform or interface notice;

  7. a customer communication;

  8. a notice displayed at the time of interaction with an AI system.

An AI or automated-processing notice may explain:

  1. the relevant AI system or category of system;

  2. the purpose of the processing;

  3. the role of the system in the relevant process or decision;

  4. the types of data and outputs involved;

  5. whether human review applies;

  6. the relevant provider or recipient categories;

  7. the possible consequences of the processing;

  8. the applicable rights, safeguards and contact channels.

7. No Unnecessary Duplication

Goat Finance may avoid repeating the same information in every privacy notice.

Where a specific notice incorporates this Global Privacy Policy by reference, the specific notice will focus on what is specific to the relevant phase, entity, product, jurisdiction or partner route.

Schedule 2

Phase-Based Privacy Model and Controller Handoff

1. Phase 1

Phase 1 is the global pre-onboarding, eligibility, initial screening, KYC initiation and routing phase.

Unless otherwise stated in the applicable Phase 1 Privacy Notice, Goat Finance SAGL acts as the controller for Phase 1 processing.

Phase 1 may involve:

  1. intake forms;

  2. identity and contact collection;

  3. preliminary profile assessment;

  4. initial KYC steps;

  5. sanctions screening;

  6. prohibited jurisdiction screening;

  7. prohibited activity screening;

  8. preliminary risk assessment;

  9. product eligibility assessment;

  10. partner route assessment;

  11. routing to the relevant Phase 2 entity;

  12. AI-assisted document and information processing;

  13. AI-assisted identification of inconsistencies, missing information and preliminary risk indicators;

  14. human validation and review of material AI-generated outputs.

Phase 1 does not create a customer relationship.

2. Phase 2

Phase 2 is the product-specific onboarding, service activation and customer relationship phase.

The Phase 2 controller is the Goat Finance entity responsible for the relevant product, service or customer relationship.

Phase 2 may involve:

  1. additional KYC or KYB;

  2. customer due diligence;

  3. enhanced due diligence;

  4. source of funds and source of wealth review;

  5. product-specific data collection;

  6. partner-specific data collection;

  7. service activation;

  8. transaction monitoring;

  9. ongoing compliance;

  10. customer support;

  11. complaints handling;

  12. recordkeeping;

  13. AI-assisted customer due diligence and enhanced due diligence;

  14. AI-assisted document analysis, case summarization and risk identification;

  15. AI-assisted preparation of requests for information, analyses or recommendations;

  16. human review and determination of material compliance decisions.

3. Handoff From Phase 1 to Phase 2

The handoff from Phase 1 to Phase 2 occurs when Goat Finance determines the relevant service entity and product route.

Before or during Phase 2, the customer should be shown or sent:

  1. the identity of the Phase 2 controller;

  2. the applicable entity Privacy Notice;

  3. the applicable product-specific privacy notice or service-specific privacy disclosure;

  4. the applicable terms and conditions;

  5. the applicable product disclosure;

  6. any partner-related disclosure, where applicable;

  7. any relevant AI-generated summary, alert, inconsistency or preliminary risk indicator;

  8. records of human validation or correction of material AI-generated information.

4. Multi-Product Scenarios

If the same customer requests or uses more than one product, different Goat Finance entities may be responsible for different products.

In that case, controller allocation will be determined per product and per entity.

Approval for one product does not imply approval for another product.

Schedule 3

Controller and Entity Routing Overview

1. Purpose

This Schedule provides a high-level overview of how Goat Finance allocates controller responsibility.

It does not replace the applicable privacy notice provided during onboarding or service activation.

2. General Controller Routing Table

Processing Activity / Route General Controller
Phase 1 pre-onboarding, eligibility, screening and routingGoat Finance SAGL
Phase 2 routed to Goat Finance SAGLGoat Finance SAGL
Phase 2 routed to Goat Finance LLCGoat Finance LLC
Phase 2 routed to Goat Finance LTDGoat Finance LTD
Partner-supported servicesRelevant Goat Finance entity and partner role as described in the applicable product notice, disclosure or partner documentation
Partner-enabled financial infrastructureRelevant Goat Finance entity and partner route, as described in signed documentation and applicable privacy notice or disclosure
Multi-product / dual-entity scenarioController determined per product and per entity

3. No Default Whole-Group Controller

Goat Finance does not treat all group entities as controllers merely because they belong to the Goat Finance organization.

A Goat Finance entity is treated as controller only where it determines the purposes and essential means of the relevant processing activity.

Access to personal data is not granted to all Goat Finance entities by default.

4. Joint Controllership

Joint controllership may apply only where two or more entities jointly determine the purposes and essential means of the same processing activity.

Where joint controllership applies, the essence of the relevant arrangement will be made available in the applicable notice or disclosure.

Schedule 4

Shared Resources, Intragroup Access and International Transfers

1. Purpose

This Schedule explains how Goat Finance uses shared resources while preserving entity responsibility, local legal obligations and need-to-know access.

2. Shared Resources

Goat Finance may use shared resources across the multilateral organization, including:

  1. shared personnel;

  2. shared compliance functions;

  3. shared technology;

  4. shared onboarding systems;

  5. shared KYC/KYB tools;

  6. shared CRM tools;

  7. shared communication tools;

  8. shared document repositories;

  9. shared customer support;

  10. shared transaction monitoring tools;

  11. shared blockchain analytics tools;

  12. shared audit and governance resources;

  13. shared artificial intelligence systems and automated agents;

  14. shared AI development, testing and monitoring environments;

  15. shared AI governance, validation and human-oversight resources;

  16. shared model-hosting, document-analysis and workflow-automation tools.

The shared use of an AI system does not automatically make every Goat Finance entity a controller of all personal data processed through that system. Controller, joint-controller, processor and access responsibilities remain determined according to the relevant entity, phase, product, purpose, instructions and actual decision-making authority.

3. Need-to-Know Access

Access to personal data is granted only where relevant and proportionate.

Factors considered may include:

  1. role;

  2. product;

  3. entity;

  4. phase;

  5. case assignment;

  6. compliance purpose;

  7. operational need;

  8. legal requirement;

  9. partner requirement;

  10. security requirement.

Default access by all Goat Finance entities or all personnel is not permitted.

4. Intragroup Disclosures

Personal data may be shared between Goat Finance entities where necessary for:

  1. Phase 1 intake and routing;

  2. Phase 2 onboarding;

  3. product-specific service delivery;

  4. compliance review;

  5. transaction monitoring;

  6. fraud prevention;

  7. customer support;

  8. legal or regulatory compliance;

  9. internal governance;

  10. audit;

  11. reporting;

  12. security.

5. International Transfers

Where personal data is transferred or accessed across borders, Goat Finance applies a route-based transfer governance model.

Where required, transfers are subject to:

  1. transfer route assessment;

  2. transfer mechanism identification;

  3. contractual safeguards;

  4. supplementary technical and organizational measures;

  5. access restrictions;

  6. ongoing review.

6. Providers and Partners

Where third-party providers or partners process personal data, Goat Finance seeks to ensure that appropriate contractual, technical, organizational and legal controls are in place, where required.

Partner-specific processing will be described in the relevant product notice, product disclosure or service-specific privacy section.

7. Artificial Intelligence Providers and Systems

Where artificial intelligence systems are used as shared resources, Goat Finance applies a route-based governance model designed to identify:

  1. the relevant Goat Finance controller;

  2. the intended purpose of the AI system;

  3. the AI developer, system provider, model provider and material subprocessors;

  4. the systems and data sources accessible to the AI system;

  5. the jurisdictions in which data may be hosted, processed or accessed;

  6. the applicable contractual and transfer safeguards;

  7. the applicable access, retention, security and deletion controls;

  8. the persons responsible for human oversight;

  9. the records required to support audit, monitoring and accountability.

The use of shared AI resources does not permit unrestricted reuse of personal data or unrestricted access by Member Companies, providers or personnel.

Schedule 5

Jurisdiction-Aware Website and Reverse-Solicitation Controls

1. Purpose

This Schedule explains why Goat Finance may process limited technical, location, declared-jurisdiction and website-interaction data to support jurisdiction-aware website controls, product-availability controls, financial promotion controls and reverse-solicitation controls.

2. Data Used for These Controls

Goat Finance may process:

  1. IP address;

  2. approximate location derived from IP address;

  3. browser language or locale;

  4. country selected or declared by you;

  5. country of residence;

  6. country of incorporation;

  7. product-interest selection;

  8. product pages viewed;

  9. legal warnings, notices or pop-ups shown;

  10. acknowledgement records;

  11. timestamps;

  12. user agent;

  13. onboarding route;

  14. product route;

  15. eligibility outcome.

3. Purposes

Goat Finance may use this data to:

  1. avoid displaying product information where it may not be appropriate;

  2. apply safe-mode or restricted-mode website content;

  3. route users to general information instead of product-specific content;

  4. provide jurisdictional notices;

  5. support financial promotion and reverse-solicitation controls;

  6. evidence what content, notices and disclosures were shown to a specific user;

  7. support compliance, legal, audit and risk management.

4. Limitations

These controls are not a guarantee of eligibility.

A user's location, country selection, IP address or acknowledgement of a notice does not by itself create a right to any product or service.

Product availability is determined through onboarding, eligibility assessment, contracting entity allocation, partner approval and applicable law.

Schedule 6

Legal and Jurisdictional Privacy Framework

1. Purpose

This Schedule provides a high-level explanation of the legal privacy frameworks that Goat Finance may consider.

Specific entity Privacy Notices or product-specific notices may provide additional details.

2. EU/EEA and UK Privacy Framework

Where EU GDPR or UK GDPR applies, Goat Finance will provide privacy information intended to explain, as applicable:

  1. controller identity;

  2. purposes of processing;

  3. legal bases;

  4. categories of personal data;

  5. recipients or categories of recipients;

  6. international transfers;

  7. retention;

  8. rights;

  9. complaint channels;

  10. automated decision-making or profiling information where required;

  11. whether data provision is required and the consequences of not providing it, where relevant.

3. Swiss Privacy Framework

Where Swiss data protection law applies, Goat Finance will process personal data in accordance with Swiss privacy principles, including:

  1. transparency;

  2. fairness;

  3. proportionality;

  4. purpose limitation;

  5. accuracy;

  6. security;

  7. data subject rights;

  8. lawful disclosure;

  9. appropriate safeguards for international transfers.

The applicable entity Privacy Notice may identify the relevant controller, contact details, purposes, recipients or recipient categories, international disclosures and other information required under Swiss law.

4. U.S. Privacy Framework

Where U.S. privacy laws apply, Goat Finance may provide additional information through an entity Privacy Notice, U.S. privacy notice or notice at collection.

This may include:

  1. categories of personal information collected;

  2. sources of personal information;

  3. purposes of processing;

  4. categories of recipients;

  5. sensitive personal information;

  6. sale, sharing or targeted advertising disclosures;

  7. retention information;

  8. consumer rights;

  9. methods for submitting requests;

  10. authorized agent process, where applicable;

  11. non-discrimination language.

4. Canadian Privacy Framework

Where Canadian privacy laws apply, Goat Finance may provide additional information through an entity Privacy Notice, Canadian privacy notice or notice at collection.

This may include:

  1. categories of personal information collected;

  2. sources of personal information;

  3. purposes of processing;

  4. categories of recipients;

  5. sensitive personal information;

  6. sale, sharing or targeted advertising disclosures;

  7. retention information;

  8. consumer rights;

  9. methods for submitting requests;

  10. authorized agent process, where applicable;

  11. non-discrimination language.

Regulated Entities

  • GOAT Finance SAGL · Switzerland CHE-291.938.013 · FINMA · PolyReg SRO · 2024
  • GOAT Finance LLC · United States FinCEN · MSB #31000303269462 · 2024
  • GOAT Finance Ltd. · Canada FINTRAC · MSB #C10001600 · 2025

Legal Hub

  • Hub Index
  • Global Terms
  • Privacy Policy
  • Acceptable Use
  • Risk Disclosure
  • Cookie Policy

Goat Finance operates as a multilateral organization through separate legal entities. The Goat Finance entity responsible for your personal data depends on the onboarding phase, product, contracting entity, jurisdiction, partner framework and service route applicable to you. Please read this Global Privacy Policy together with the specific Phase 1 Privacy Notice, entity Privacy Notice and product-specific privacy disclosure presented to you during onboarding or service activation.

Goat Finance operates as a multilateral organization through separate legal entities. Product availability depends on jurisdiction, eligibility assessment, compliance approval, contracting entity, partner requirements and applicable law.

© 2026 GOAT Finance GroupAll rights reserved General inquiries[email protected]