SWIIT DATA PRIVACY POLICY

Sweet Intelligence Inc. and Affiliates

Last Updated: 5 August 2026

1. Introduction

Welcome to Swiit. This Data Privacy Policy (“Policy”) explains how the Sweet Intelligence group of companies (“Swiit,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the Swiit mobile application, web platform, and related services (collectively, the “Services”). This Policy applies to both Swiit App (Individual Account) and Swiit Business (Business Account) users.

This Policy also serves as our Notice at Collection under the California Consumer Privacy Act (CCPA/CPRA), informing you of the categories of personal information we collect and the purposes for which they are used.

This Policy covers data processing across all Swiit service channels, including accounts and services provided through our regulated financial institution partners and licensed service providers (each, a “Service Partner”). Service Partners as used in this Policy correspond to “Service Providers” as defined in the Swiit Terms. A complete list of our current Service Partners, their roles, and links to their privacy policies is provided in the Service Partner Privacy Schedule at the end of this Policy.

By using the Services, you acknowledge that you have read and understood this Policy. We may update this Policy from time to time as described in Section 12.

This Policy is separate from, but supplementary to, the Swiit Terms. In the Swiit Terms, “Swiit” refers to Sweet Intelligence Inc. specifically; in this Policy, “Swiit” refers to the group of affiliated entities described in Section 2. For information about how we share your data in the context of financial services, please also review Section 3 (Consumer Financial Privacy Notice) of the Swiit Terms.

2. Who We Are

Swiit is a financial technology service offered through a group of affiliated legal entities:

Sweet Intelligence Inc. (USA) – “SII” is our U.S. entity incorporated in Colorado. SII is a FinCEN-registered Money Services Business (MSB) and the primary data controller for U.S. customer data. SII operates the Swiit platform in partnership with regulated financial institutions and licensed service providers.

Sweet Intelligence Pte. Ltd. (Singapore) – “SIPTE” operates our mobile application and technology platform. SIPTE processes personal data as a service provider to SII for application development, platform operations, and technical support.

Sweet Intelligence Limited (Hong Kong) – “SIL” is based in Hong Kong and provides anti-money laundering screening and compliance support services. SIL processes personal data as a service provider to SII for compliance-related functions.

For purposes of this Policy, “Swiit” refers collectively to SII, SIPTE, and SIL. SII is the data controller for personal data collected through the Swiit platform for its own purposes. Where a Service Partner provides services to you, that Service Partner may act as a separate, independent data controller for the personal data it processes to provide those services. In particular, for customers resident in the EU who use BVNK-powered services, System Pay Services (Malta) Limited acts as the data controller under the GDPR for the personal data it processes to provide the e-money account; SII collects that data through the Swiit platform and shares it with System Pay Services (Malta) Limited for that purpose (see the Service Partner Privacy Schedule).

Swiit delivers its Services through regulated financial institution partners and licensed service providers (collectively, “Service Partners”). Each Service Partner is identified in the Service Partner Privacy Schedule, along with its role, data-controller status, and a link to its own privacy policy. Where a Service Partner acts as an independent data controller, that partner’s own privacy policy governs its independent processing of your personal data.

3. Categories of Personal Data Collected

We collect various categories of personal data to provide and improve our Services, comply with legal requirements, and protect our users.

3.1 Individual Account Data

Identity Data: Full name, date of birth, nationality, and government-issued identification documents (e.g., passport, driver’s license, national ID card).

Selfie and Biometric Data: A photograph or live selfie for identity verification. We use third-party identity verification providers (such as Zoloz and Sumsub) to perform facial-recognition matching between your selfie and your ID document. This data is used solely for KYC identity verification and is not used for any other purpose. Biometric templates generated during verification are deleted within thirty (30) days of successful verification. The underlying selfie image is retained for the duration of your Account relationship and deleted within three (3) years of Account closure or last interaction, whichever is first, unless longer retention is required by BSA/AML record-keeping obligations. We do not sell, lease, or trade biometric data. By submitting your selfie during onboarding, you consent to this collection and use of your biometric information.

Contact Data: Residential address, email address, phone number, and mailing address.

Address and KYC Documents: Proof-of-address documents such as utility bills, bank statements, or government correspondence.

Financial and Transaction Data: Transaction history, account balances, transfer details (including sender/receiver information, amounts, and dates), payment methods, and related financial records.

Usage and Metadata: Logs of your actions within the app (e.g., features accessed, pages viewed, time spent), app version, and interaction patterns.

Device and Technical Information: Device type, operating system, browser type, unique device identifiers, IP address, network information, and language settings.

Geolocation Data: Approximate location derived from your IP address, and precise location data from your mobile device if you grant location permissions (used for fraud detection and KYC geofencing purposes). You can disable location permissions through your device settings.

Cookies and Analytics Data: Information collected through cookies, pixels, and similar technologies on our website and app, including browsing behavior, referral sources, and session data.

Device Fingerprint and Fraud-Prevention Signals: Technical device characteristics, behavioral patterns, and other signals collected by our fraud-prevention systems to detect and prevent unauthorized access and fraudulent transactions.

Preferences and Behavioral Data: Your settings, preferences, notification choices, and any customization within the app.

Communications Data: Records of your communications with us, including customer support inquiries, emails, chat messages, and feedback.

Third-Party Compliance Data: Information obtained from external sources for compliance, fraud prevention, and screening purposes, including sanctions screening results, adverse media data, politically exposed person (PEP) checks, and consumer reports from consumer reporting agencies.

Inferences: Conclusions we draw from the information listed above, such as risk scores, fraud probability assessments, and account eligibility determinations.

Service Channel–Specific Data: Depending on which service channel(s) you activate, we may collect additional data specific to that channel, such as channel-specific account identifiers, transaction histories, card numbers (tokenized), merchant details, authorization and fraud-check results, dispute and chargeback records, currency conversion records, and disbursement data. The specific data categories collected for each Service Partner are detailed in the Service Partner Privacy Schedule.

3.2 Additional Business Account Data

Business Entity Data: Company name, registration number, jurisdiction of incorporation, business type, operating address, website, and description of business activities.

Beneficial Ownership Data: Names, dates of birth, nationalities, government IDs, ownership percentages, and control information for all beneficial owners (individuals who directly or indirectly own 25% or more of the entity or exercise significant control).

Authorized Representative Data: Name, title, contact information, government ID, and documentation evidencing authorization to act on behalf of the entity.

Business Financial Data: Business bank statements, financial projections, revenue information, and other financial documentation provided during KYB verification.

PEP and Sanctions Screening (Entity-Level): Screening results for the entity, its beneficial owners, and authorized representatives against sanctions lists, PEP databases, and adverse media sources.

3.3 How We Collect Data

We collect most personal data directly from you through our app’s onboarding process, forms, document uploads, and your use of the Services. We also collect data from third-party sources, including identity verification providers, sanctions screening databases, consumer reporting agencies, public records, and your use of Service Partner services. Some data is collected automatically through your use of the app and website.

We will indicate to you when data is required versus optional. Certain data is required to open and maintain your Account under applicable law. Failure to provide required data may prevent us from offering you the Services.

4. Purposes of Processing Personal Data

We collect and process personal data for the following purposes:

Providing and Maintaining Services: To set up your Account, authenticate your identity, process transactions, maintain your account records, and deliver the core Swiit Services.

Business Account Services: To perform KYB verification, verify beneficial ownership, manage authorized users, and conduct ongoing business monitoring for Business Accounts.

Communication and Customer Support: To respond to your inquiries, provide customer support, send account-related notifications, and deliver important updates.

Identity Verification and Fraud Prevention: To verify your identity (and, for Business Accounts, the entity’s identity and beneficial ownership), detect and prevent fraud, and comply with KYC/KYB requirements. This includes the use of biometric identity verification as described in Section 3.1.

Providing Financial Services through Service Partners: To share relevant personal data with our Service Partners as necessary to operate your account, process transactions, facilitate currency conversions, issue and service cards, and perform related financial services that you activate. Data shared with each Service Partner is limited to what is necessary to provide the specific service. See the Service Partner Privacy Schedule for details on each partner’s role and the data categories shared.

Automated Decision-Making: Your account-opening application is subject to automated identity verification and sanctions screening tools, supplemented by human review of flagged cases. These automated processes may result in the denial of your application or the restriction of your Account. If your application is declined or your Account is restricted based on automated processing, you may request human review by contacting zoe@swiit.ai.

Improving and Developing Services: To analyze usage patterns, conduct research, and develop new features and improvements.

Marketing and Personalization: With your permission, to send promotional communications and personalize your experience. You can opt out of marketing communications at any time.

Legal Compliance and Risk Management: To comply with applicable laws and regulations (including BSA/AML, OFAC sanctions, tax reporting, and consumer protection requirements), manage legal risks, and respond to legal process.

Other Purposes: If we intend to use your personal data for a purpose materially different from those described above, we will notify you and, where required by law, obtain your consent.

We process personal data based on various legal grounds depending on the context: performance of our contract with you, compliance with legal obligations, our legitimate business interests, and (where applicable) your consent.

5. Disclosure of Personal Data to Third Parties

We treat your personal data with care and confidentiality. We do not sell your personal information. We do not share personal information for cross-context behavioral advertising. We share personal data with the following categories of recipients only as described below:

Service Partners: We share personal data with the regulated financial institutions and licensed service providers that power each Swiit service channel. These Service Partners receive personal, identity, financial, and transaction data necessary to operate your account, process transactions, issue and service cards, monitor for fraud, and comply with applicable regulations. Each Service Partner is either an independent data controller for the data it receives, or acts as a data processor on our behalf, as specified in the Service Partner Privacy Schedule. Data shared with each partner is limited to what is necessary to provide the specific service you have activated. Where a Service Partner acts as an independent data controller, that partner’s own privacy policy governs its processing of your personal data; links to each partner’s privacy policy are provided in the Schedule.

Consumer Reporting Agencies: SII may obtain consumer reports or specialty consumer reports from third-party consumer reporting agencies in connection with your account application and ongoing account monitoring. If adverse action is taken based in whole or in part on information in a consumer report, we will provide you with the notices required by the Fair Credit Reporting Act (15 U.S.C. §1681m), including the name and contact information of the consumer reporting agency that provided the report.

Affiliate and Subsidiary Companies: We may share personal data among SII, SIPTE, and SIL for the purposes described in this Policy.

Third-Party Vendors: We engage third-party companies to perform functions on our behalf, including cloud infrastructure providers, identity verification services (Zoloz, Sumsub), compliance screening partners, analytics tools, and communications providers. These service providers process data only on our instructions and are contractually required to maintain confidentiality and security.

Third-Party Integrations: If you choose to link external accounts or integrate third-party services with your Swiit Account, we will share the data necessary to facilitate that integration, with your consent.

Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal data may be transferred. We will notify you of any such transfer.

Legal and Regulatory Disclosures: We may disclose personal data when required or permitted by law, including in response to subpoenas, court orders, or government requests; to comply with regulatory reporting obligations; to protect our rights, safety, or property; or to prevent or investigate fraud. We will seek to minimize disclosure to only what is specifically requested and will challenge overly broad requests where appropriate.

Travel Rule Disclosures: For wire transfers of $3,000 or more, we are required under BSA regulations (31 CFR §1010.410) to transmit identifying information about the sender and recipient to intermediary and beneficiary financial institutions.

In all cases, we share only the minimum necessary information to fulfill the purpose.

6. Data Subject Rights and Choices

You have certain rights and choices regarding your personal data. Swiit is committed to honoring your rights under applicable law.

6.1 General Rights (All Users)

Right to Access: You may request a copy of the personal data we hold about you.

Right to Correction: You may request correction of inaccurate or incomplete personal data.

Right to Deletion: You may request deletion of your personal data, subject to legal retention requirements (e.g., BSA/AML).

Right to Withdraw Consent: Where processing is based on your consent, you may withdraw consent at any time.

Right to Data Portability: You may request a copy of your personal data in a structured, commonly used, machine-readable format.

Right to Object: You may object to processing based on legitimate interests or direct marketing.

Right to Human Review of Automated Decisions: If a decision affecting your Account was made through automated processing, you may request human review by contacting zoe@swiit.ai.

No Discrimination: We will not discriminate against you for exercising your privacy rights.

6.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the CCPA/CPRA:

Right to Know: You may request disclosure of the categories and specific pieces of personal information collected, sources of collection, business purposes, and categories of third parties with whom we share your information.

Right to Delete: You may request deletion, subject to legal exceptions.

Right to Correct: You may request correction of inaccurate personal information.

Right to Opt-Out of Sale/Sharing: Swiit does not sell your personal information. We do not share personal information for cross-context behavioral advertising.

Right to Limit Use of Sensitive Personal Information: You may request that we limit the use of sensitive personal information to purposes necessary to provide the Services.

Authorized Agents: You may designate an authorized agent (with written permission and verified identity) to make requests on your behalf.

Retention Disclosure: We retain each category of personal information for the periods described in Section 8.2 of this Policy.

Swiit does not share personal information with third parties for their direct marketing purposes (Cal. Civ. Code §1798.83). To submit a CCPA/CPRA request, contact us at zoe@swiit.ai. We will verify your identity and respond within 45 days.

6.3 Colorado Residents (CPA)

If you are a Colorado resident, you have rights under the Colorado Privacy Act (CPA):

Rights: Access, correct, delete, and data portability as described in Section 6.1.

Right to Opt Out: You may opt out of targeted advertising, sale of personal data (Swiit does not sell data), and profiling in furtherance of decisions that produce legal or similarly significant effects.

Universal Opt-Out Mechanism: Swiit recognizes and honors Global Privacy Control (GPC) signals and other universal opt-out mechanisms as required by Colorado law.

Appeal Process: If we deny your request, you may appeal within sixty (60) days by contacting zoe@swiit.ai with the subject line “CPA Appeal.” We will respond to your appeal within forty-five (45) days. If we deny your appeal, we will provide instructions for contacting the Colorado Attorney General.

6.4 Other U.S. State Privacy Laws

If you reside in a state with a comprehensive privacy law, you may have additional rights. This includes residents of Virginia (VCDPA), Connecticut (CTDPA), Texas (TDPSA), Oregon (OCPA), Utah (UCPA), Tennessee (TIPA), Montana (MCDPA), New Jersey (NJDPA), Delaware (DPDPA), Iowa (ICDPA), New Hampshire (NHPA), and other states that have enacted privacy legislation. These laws generally provide rights of access, correction, deletion, data portability, and opt-out of targeted advertising and profiling. Contact us at zoe@swiit.ai to exercise any applicable rights.

6.5 EU/EEA and UK Residents (GDPR)

If you are located in the European Economic Area or the United Kingdom, you have rights under the GDPR or UK GDPR, including rights of access, rectification, erasure, restriction, portability, objection, and the right not to be subject to automated decision-making with legal effects. You also have the right to lodge a complaint with your local data protection authority. Contact us at zoe@swiit.ai.

6.6 Singapore Residents (PDPA)

If you are located in Singapore, you have rights under the Personal Data Protection Act (PDPA), including rights of access, correction, and withdrawal of consent. Contact us at zoe@swiit.ai.

6.7 How to Exercise Your Rights

You can exercise most rights by contacting us at zoe@swiit.ai or through the Swiit app’s privacy settings. We will verify your identity before processing requests. We aim to respond within the timeframe required by applicable law (generally 30–45 days).

7. International Transfers of Personal Data

Swiit operates globally, and your personal data may be transferred to and processed in the United States and other countries where our affiliates and service providers operate. We apply consistent privacy and security safeguards regardless of where data is processed.

If you are located outside the United States, please be aware that data protection laws in the United States may differ from those in your jurisdiction. By using our Services, you consent to the transfer of your personal data to the United States and other countries as described in this Policy.

Where required by applicable law (such as the GDPR), we implement appropriate safeguards for cross-border transfers, including Standard Contractual Clauses or other lawful transfer mechanisms. For transfers from Singapore, we comply with the PDPA’s requirements for overseas transfers.

8. Data Security and Retention

8.1 Security Measures

Swiit employs a comprehensive information security program, including:

Encryption: All communications are encrypted using modern TLS protocols. Sensitive data at rest is encrypted using industry-standard algorithms.

Access Controls: Strict access control mechanisms limit access to authorized personnel with a legitimate business need.

Network and Application Security: Firewalls, intrusion detection, regular vulnerability scans, and penetration tests.

Monitoring and Incident Response: Continuous monitoring with a detailed incident response plan including prompt notification to affected users and regulators as required by applicable law (including all 50 U.S. states, GDPR 72-hour notification, and Singapore PDPA breach notification requirements).

While we strive to protect your personal data, no method of transmission or storage is 100% secure.

8.2 Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, and protect our legitimate interests. Specific retention periods include:

Active Accounts: Personal data is retained for the duration of your Account relationship and for a reasonable period thereafter.

AML/KYC/KYB Records: Customer identification, beneficial ownership, and transaction records are retained for a minimum of five (5) years after Account closure, as required by BSA regulations (31 CFR §1020.220(a)(3)).

Transaction Records: Financial transaction records are retained for at least five (5) years after the transaction or Account closure (31 CFR §1010.306(a)(2)).

Wire Transfer Records (≥$3,000): Records of funds transfers of $3,000 or more are retained for five (5) years (Travel Rule, 31 CFR §1010.410).

SAR Supporting Documentation: Documentation supporting suspicious activity reports is retained for five (5) years from filing (31 CFR §1020.320(d)).

Biometric Data: Biometric templates are deleted within thirty (30) days of successful verification. Underlying selfie images are retained for the duration of the Account relationship and deleted within three (3) years of Account closure or last interaction, whichever is first, unless BSA record-keeping requires longer retention.

Communications Records: Customer support correspondence is retained for two to three years for quality assurance and dispute resolution.

Beneficial Ownership Data: Retained for at least five (5) years after Account closure, consistent with FinCEN CDD Rule requirements.

Card Transaction Records: Card transaction records, dispute records, and chargeback data are retained for a minimum of five (5) years after the transaction or card account closure, consistent with card network rules and BSA record-keeping requirements.

Analytics Data: Aggregated or anonymized data may be retained indefinitely for statistical and research purposes.

When data is no longer needed, we securely delete or anonymize it in accordance with our data retention policies and applicable law.

9. Children’s Privacy

Our Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18, nor do we knowingly collect personal information from children under 13 as defined by the Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected personal data from a child under 18, we will take steps to delete that data promptly. If you believe a child has provided us with personal data, please contact us at zoe@swiit.ai.

10. Governing Law

This Privacy Policy is governed by the laws of the State of Colorado, without regard to conflict-of-law principles, to the extent not preempted by federal law.

If you are located in a jurisdiction with mandatory data protection laws (such as the GDPR in the EU, the PDPA in Singapore, or state privacy laws in the U.S.), those laws apply to the extent they provide you with additional rights that cannot be waived.

Disputes arising under this Policy are subject to the Dispute Resolution and Arbitration provisions in the Swiit Terms (Section 7).

11. Contact Us

If you have questions, concerns, or requests regarding this Policy or our data practices:

By Email: zoe@swiit.ai (include “Privacy Inquiry” in the subject line)

By Mail: Attn: Compliance Officer – Sweet Intelligence Inc., 1312 17th St, Unit Num-2955, Denver, CO 80202

U.S. consumers may also file a complaint with the CFPB at https://www.consumerfinance.gov/complaint or with their state attorney general or banking regulator.

We will respond to inquiries promptly – generally within a few business days for simple queries, and within the timeframes required by applicable law for formal rights requests.

12. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by email, in-app notification, or by prominently posting a notice on our website at least thirty (30) days before the changes take effect. Your continued use of the Services after the effective date constitutes your acceptance of the revised Policy.

The “Last Updated” date at the top of this Policy indicates when it was last revised.

By using the Services, you agree to this Policy. Thank you for entrusting Swiit with your personal data.

Service Partner Privacy Schedule

The following Service Partners currently provide services through the Swiit platform. This Schedule is updated when Service Partners change; an update that does not change the Service Partners handling your personal data does not, by itself, constitute a material change to this Policy requiring the 30-day advance notice described in Section 12. However, if a Schedule update results in a new or replacement Service Partner processing your personal data, that change is treated as a material change as to you and handled in accordance with Section 12.

1. Zenus Bank (Banking Partner)

Legal Entity: Zenus Bank International, Inc. Role: Issuer of Swiit Accounts through the Zenus Bank channel; BIN sponsor for card services. Data-Controller Status: Independent data controller for banking data it receives and processes. Data Categories Shared: Identity data, contact data, financial and transaction data, compliance-related data. Privacy Policy: Zenus Bank’s own privacy practices apply to data it independently controls; presented at account opening.

2. BVNK (Fiat Payment Partner)

Legal Entity: The applicable BVNK entity depends on your country of residence—System Pay Services, Inc. d/b/a BVNK (United States) for customers resident outside the European Union (EU), or System Pay Services (Malta) Limited (Malta; MFSA-authorised Electronic Money Institution, company registration number C66961) for customers resident in the EU. Role: Operator of your BVNK-powered fiat payment or e-money account. Data-Controller Status: The applicable BVNK entity is an independent data controller for personal data it processes in connection with operating your BVNK-powered account; for EU customers, System Pay Services (Malta) Limited acts as the data controller under the GDPR. Data Categories Shared: Identity data, contact data, financial data, BVNK account identifiers, transaction history, currency conversion records. Privacy Policy: https://www.bvnk.com/privacy-policy (a group-wide policy covering both BVNK entities; incorporated by reference into the Swiit Terms).

3. Connect Financial (Card Program Partner)

Legal Entity: Connect Fintech Services, LLC (d/b/a Connect Financial). Role: Card program manager; processes card issuance, transaction processing, fraud monitoring, and dispute resolution together with applicable card networks. Data-Controller Status: Independent data controller for card-related data it receives. Data Categories Shared: Identity data, financial data, card transaction data (tokenized card number, merchant details, transaction amounts, dates and times of transactions, authorization data, fraud check results, dispute and chargeback data, card status information), device and fraud-prevention signals. Privacy Policy: Privacy practices described in the Swiit Cardholder Agreement.

4. Infinitus Pay (Payment Account Technology Partner)

Legal Entity: InfinitusPay Inc. Role: Technology platform facilitating payment account and disbursement services through its Financial Services Partner banks. Infinitus Pay is not a bank and does not itself hold customer deposits. Data-Controller Status: Data processor on behalf of SII for data processed in connection with Swiit services; its Financial Services Partner banks may independently control data as required by banking regulations. Data Categories Shared: Identity data, contact information, financial data, transaction data (account identifiers, transaction history, disbursement records, payment amounts, dates and times of transactions), compliance-related data. Privacy Policy: Governed by this Policy.