ViaExpress

Information & Regulation

Privacy Policy

Last updated: 20 August 2026

1. Introduction

At BR Corporation SA, which operates the Via Express brand ("Via Express", "we", "us", "our"), your privacy is a priority. We are an international money transfer provider based in Switzerland, and we handle personal data with care, transparency and in line with the law.

This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have. It applies to our website, our mobile application, our WhatsApp channel, our call centre and our physical agencies.

We process personal data in accordance with the Swiss Federal Act on Data Protection (revFADP / nFADP) and, where applicable, the European Union General Data Protection Regulation (GDPR). As a money transfer operator, we are also subject to the Swiss Anti-Money Laundering Act (AMLA) and to the rules of PolyReg, our self-regulatory organisation.

2. Who is responsible for your data (data controller)

The controller responsible for processing your personal data is:

BR Corporation SA (operating as Via Express) Rue de Chantepoulet 8, 1201 Genève, Switzerland Commercial register (Registre du commerce de Genève): CH-660.2.546.013-1 Email: info@viaexpress.ch Phone: 0840 40 20 10

For any question or request relating to data protection, please use the contact details above. We handle data protection matters through this contact.

3. Scope of this policy

This policy covers personal data processed when you:

  • use our website or mobile application;
  • contact us or send a transfer through WhatsApp, our call centre, or in one of our agencies;
  • register as a customer and use our money transfer services;
  • are named as a beneficiary of a transfer;
  • apply for a job with us; or
  • interact with us in any other way (reviews, promotions, support).

Where we link to third-party websites or services, their own privacy policies apply. We are not responsible for the content or practices of third-party sites.

4. Personal data we collect

Depending on how you interact with us, we may process the following categories of personal data.

Identification and verification data (KYC): full name, date of birth, nationality, gender, address, photograph, and details from an official identity document (passport, ID card, residence permit), and any other information required to meet our legal identification obligations.

Contact data: telephone number, email address, postal address, and preferred language.

Transaction data: amount sent, currency, exchange rate applied, fees, payment method, date and time, destination country, transfer reference or code, and status of the transfer.

Beneficiary data: name, contact details, bank account or collection details of the person you send money to. If you provide us with a third party's data, you confirm that you are entitled to share it.

Payment data: the payment method used and related details necessary to process your payment (for card payments, payment details are processed by our payment providers).

Communications: the content of your messages and calls with us through WhatsApp, the call centre, email, chat and in agencies, including records kept for quality, security and compliance purposes.

Technical and usage data: IP address, device and browser information, cookies and similar technologies, app usage data, and website analytics. See section 8.

Compliance and risk data: information used to comply with anti-money-laundering, sanctions, fraud-prevention and counter-terrorism-financing obligations, including results of screening against official watchlists and sanctions lists.

Recruitment data: if you apply for a role, the data in your CV, cover letter and application.

We do not intentionally collect special categories of data (such as data on health, religion or political opinions), except where such data appears in an identity document and is strictly necessary for identification.

5. How we collect your data

We collect personal data:

  • directly from you, when you register, place a transfer, contact us, apply for a job, or use our channels;
  • automatically, through cookies and analytics tools on our website and app (see section 8);
  • from third parties, such as identity-verification providers, sanctions and watchlist databases, our payment providers, our payout partner Swiss Money Corp, and public sources, where necessary to verify your identity, prevent fraud, and meet our legal obligations.

6. Why we use your data and our legal bases

To provide our services (performance of a contract). To register you, process and execute your transfers, communicate with you about them, and provide customer support.

To comply with legal obligations. To meet our identification, verification, record-keeping, monitoring and reporting duties under the Swiss Anti-Money Laundering Act, sanctions rules, tax rules, and the requirements of PolyReg and the competent authorities. This includes verifying your identity, monitoring transactions, and reporting suspicious activity where the law requires it.

To protect our legitimate interests. To prevent, detect and investigate fraud and abuse, ensure the security of our systems, manage risk, improve our services, and defend or exercise legal claims. We balance these interests against your rights.

With your consent. For non-essential cookies, for marketing communications where consent is required, and for any processing that specifically relies on consent. You can withdraw consent at any time.

Where processing is necessary to comply with a legal obligation or to perform your transfer, providing the data is mandatory. If you do not provide it, we may be unable to offer the service.

7. Anti-money-laundering and identity verification

As a regulated money transfer operator affiliated with PolyReg, we are legally required to identify our customers, verify their identity, understand the purpose of transactions, monitor activity, and keep records. We may screen customers and beneficiaries against official sanctions and watchlists.

We may delay, refuse, freeze or report a transaction where required to comply with these obligations, and we are not always permitted to explain the reason. Personal data processed for these purposes cannot be deleted on request before the end of the legally required retention period (see section 11).

8. Cookies and similar technologies

Cookies are small files placed on your device that help the website work, remember your choices, and, with your consent, measure and improve performance. We also use similar technologies such as pixels, tags and local storage.

We use: strictly necessary cookies (required for the site to function, no consent needed); preference cookies (remember choices such as your language); analytics and performance cookies (only with your consent, to understand and improve how the site is used); and, where applicable, marketing cookies (only with your consent). Some of these tools are provided by Google (for example, Google Tag Manager and related analytics), which may process data on our behalf, including outside Switzerland or the European Economic Area, subject to the safeguards described in section 10.

When you first visit our site, a consent banner lets you accept or refuse non-essential cookies. By default, non-essential cookies remain off until you consent. You can view the cookies in use, with their purpose and duration, and change your choices at any time through the cookie preferences on our site or through your browser settings. Blocking strictly necessary cookies may affect how the site works.

9. Who we share your data with

We share personal data only where necessary, with:

  • Swiss Money Corp, our payout partner, and its paying agents and networks, to deliver funds to the beneficiary at the destination;
  • banking correspondents and financial institutions involved in executing your transfer;
  • payment providers that process your payment;
  • service providers who work on our behalf under contract (IT, hosting, analytics, communications, customer support, identity verification, security), bound by confidentiality and data protection obligations;
  • regulators and authorities, including PolyReg, the Money Laundering Reporting Office Switzerland (MROS), tax authorities, courts and law-enforcement bodies, where required by law;
  • professional advisers (auditors, lawyers) where necessary;
  • a successor or acquirer, in the event of a merger, acquisition or reorganisation, subject to appropriate safeguards.

We do not sell your personal data and we do not share it with third parties for their own marketing.

10. International data transfers

By the nature of an international money transfer, some of your data (and the beneficiary's data) is transferred to the destination country, which may be outside Switzerland and the European Economic Area, to enable payout. Some technical data may also be processed by service providers located abroad.

Where we transfer data to a country that does not offer an adequate level of protection, we rely on appropriate safeguards (such as Standard Contractual Clauses and the Swiss addendum), or on legal exceptions, including that the transfer is necessary for the performance of your transfer contract or for the establishment or defence of legal claims. You can request more information about these safeguards using the contact details below.

11. How long we keep your data

We keep personal data only as long as necessary for the purposes described, and in any case for the periods required by law.

  • Identification (KYC) and transaction records: retained for at least 10 years after the end of the business relationship or the transaction, as required by the Swiss Anti-Money Laundering Act.
  • Communications and support records: for the period necessary to handle your request and to meet legal and evidentiary needs.
  • Website and analytics data: for the limited periods described in section 8 and shown in our cookie preferences.
  • Recruitment data: kept for the duration of the recruitment process and, with your consent, for a limited period afterwards.

When data is no longer needed and no legal retention period applies, we delete or anonymise it.

12. How we protect your data

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include access controls, staff confidentiality and training, secure infrastructure, and ongoing compliance procedures. Our front-office teams undergo a selection process and continuous compliance training.

13. Your rights

Subject to the conditions and limits of applicable law, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict or object to certain processing;
  • data portability, to receive certain data in a structured, common format;
  • withdraw consent at any time, where processing is based on consent (for example, cookies or marketing).

Please note that some rights are limited by our legal obligations. In particular, we cannot delete identification and transaction data before the end of the legal retention period, and we may be unable to disclose certain information related to anti-money-laundering monitoring.

To exercise your rights, contact us at info@viaexpress.ch. We may need to verify your identity before responding. We aim to respond within the timeframe required by law.

If you believe your data is not handled correctly, you can lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch. If you are in the European Union, you may also contact your local data protection authority.

14. Automated processing and profiling

To prevent fraud and comply with anti-money-laundering rules, we use automated tools to screen and monitor transactions (for example, against sanctions lists and risk indicators). These tools may flag a transaction for human review. We do not take decisions that produce legal effects on you based solely on automated processing without appropriate safeguards and, where required, human involvement.

15. Minors

Our services are intended for individuals aged 18 or older. We do not knowingly collect data from minors. If you believe a minor has provided us with data, please contact us so we can address it.

16. Marketing communications

Where permitted, we may send you information about our services. Where consent is required, we ask for it, and you can unsubscribe or withdraw consent at any time, at no cost, using the link in the message or by contacting us.

17. Changes to this policy

We may update this Privacy Policy to reflect changes in our practices or in the law. The date at the top shows the latest version. We encourage you to review this page periodically. Where changes are significant, we will take reasonable steps to inform you.

18. Contact

For any question about this policy or the processing of your personal data:

BR Corporation SA (Via Express) Rue de Chantepoulet 8, 1201 Genève, Switzerland Email: info@viaexpress.ch Phone: 0840 40 20 10