1 Who We Are
Geneva Sovereign Trust (trading as GSTBank) is the data controller responsible for your personal information. We operate the banking platform at genevasovereigntrust.com.
2 Data We Collect
We collect the following categories of personal data when you use GSTBank services:
- Identity data: First name, last name, date of birth, nationality, government-issued ID number (e.g. NIN, Aadhaar, SSN depending on your country)
- Contact data: Email address, phone number, residential address
- Financial data: Account number, account balance, transaction history, IBAN details
- KYC documents: Photographs of identity documents (front and back), selfie / face verification images
- Technical data: IP address, browser type, device identifiers, login timestamps
- Usage data: Pages visited, features used, session duration
- Communication data: Messages sent via our contact form or live chat
3 How We Use Your Data
We use your personal data for the following purposes:
- Opening and managing your banking account
- Processing payments, transfers, and transactions
- Verifying your identity in compliance with AML / KYC regulations
- Detecting and preventing fraud, money laundering, and unauthorised access
- Providing customer support and responding to enquiries
- Sending account notifications, security alerts, and transaction receipts
- Improving our platform and services
- Complying with legal obligations
4 Legal Basis for Processing
We process your data under the following legal bases:
- Contract performance: Processing necessary to provide our banking services to you
- Legal obligation: AML compliance, KYC verification, regulatory reporting
- Legitimate interests: Fraud prevention, security monitoring, service improvement
- Consent: Marketing communications (where you have opted in)
5 Data Sharing & Third Parties
We do not sell your personal data. We may share data with:
- Regulatory authorities: Financial regulators and law enforcement where legally required
- Payment processors: To facilitate transfers and transactions
- Identity verification providers: To complete KYC checks
- Cloud infrastructure providers: For secure data hosting (subject to data processing agreements)
- Professional advisors: Legal, accounting, and compliance consultants under confidentiality obligations
All third-party processors are contractually bound to protect your data and process it only on our instructions.
6 Data Retention
We retain your personal data for as long as necessary to provide our services and comply with legal obligations:
- Account data: For the duration of your account plus 7 years after closure (regulatory requirement)
- Transaction records: 10 years (AML compliance)
- KYC documents: 5 years after account closure
- Contact form messages: 2 years
- Technical/log data: 90 days
7 Your Rights
Under GDPR and applicable data protection law, you have the following rights:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data (subject to legal retention obligations)
- Right to restriction: Limit how we process your data in certain circumstances
- Right to data portability: Receive your data in a machine-readable format
- Right to object: Object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent, you may withdraw at any time
To exercise any of these rights, contact us at support@genevasovereigntrust.com. We will respond within 30 days.
8 Cookies & Tracking
We use the following types of cookies and tracking technologies:
- Essential cookies: Required for secure login sessions and platform functionality
- Analytics cookies: Help us understand how users interact with our platform (anonymised)
- Live chat cookies: Used by HubSpot to provide chat support functionality
You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.
9 Security
We implement bank-grade technical and organisational security measures including:
- AES-256 encryption for data at rest
- TLS 1.3 encryption for all data in transit (HTTPS)
- Multi-factor authentication for account access
- Transaction PIN protection for all financial operations
- Regular security audits and penetration testing
- Access controls limiting data to authorised staff only
10 Contact & Complaints
For privacy-related enquiries or to exercise your rights, contact our Data Protection team: