Legal and compliance
Compliance and Legal Notice
The control framework governing identity verification, financial-crime prevention, customer protection, regulated services, operational resilience, and accountable oversight.
Northline publishes legal entity, regulatory, complaint, customer-funds, privacy, and risk information so customers can verify the service and understand the applicable product terms.
01
Legal entity and regulatory status
The operating entity is NORTH ATLANTIC FINANCIAL GROUP AG, incorporated in Switzerland under registration number CHE312749508, with registered office at Bleichistrasse 8 Zug 6300. Current status: Northline is subject to Swiss financial-market regulation by the Swiss Financial Market Supervisory Authority FINMA. Authorised activities, licensing category, customer eligibility, and jurisdictional scope are limited to the permissions recorded in FINMA's official register and the applicable customer agreements.. Regulator: Swiss Financial Market Supervisory Authority (FINMA). Licence or registration: CHE312749508. Official register
02
Regulated-service perimeter
Each service is operated within its documented legal classification, licensing perimeter, territorial scope, responsible entity, provider contract, safeguarding or custody model, customer disclosures, complaints route, privacy impact, financial-crime controls, operational readiness, and authorized-management approval. Customer agreements and official regulatory registers define the binding scope.
03
Governance and accountability
Business owners are responsible for operating controls and customer outcomes. Independent compliance and risk functions define policy, monitor adherence, challenge decisions, and escalate breaches. Internal audit or independent review tests governance and control effectiveness. Material issues are assigned owners, deadlines, remediation evidence, and senior-management oversight.
04
Risk-based compliance programme
The programme is proportionate to customer, geography, product, delivery channel, transaction, provider, and technology risk. Documented enterprise and product risk assessments inform policies, customer-risk scoring, enhanced due diligence, monitoring, training, assurance, and resource allocation.
05
Customer due diligence
Applicants are verified for identity, age, residence, contact details, tax information, account purpose, expected activity, source of funds, and other risk-relevant information. Verification uses reliable evidence and may require enhanced due diligence for higher-risk profiles, products, jurisdictions, politically exposed persons, unusual wealth, adverse information, or unexplained activity.
06
Sanctions, PEP, and adverse-information screening
Customers, beneficial owners, representatives, counterparties, and transactions may be screened against applicable sanctions, politically exposed person, enforcement, disqualification, and adverse-information data. Potential matches require trained review and documented disposition. Assets or transactions are frozen, rejected, blocked, or reported where law requires.
07
Source of funds and source of wealth
Evidence may include payslips, tax returns, bank statements, contracts, company accounts, sale documents, inheritance records, investment statements, property records, or other reliable material. Information must be consistent with the customer profile and transaction activity. Unsatisfactory evidence may result in delay, restriction, rejection, reporting, or closure.
08
Transaction and behavioural monitoring
Payment, card, balance, lending, device, login, support, and account activity may be monitored for fraud, laundering, terrorist financing, sanctions evasion, account takeover, exploitation, mule activity, velocity, structuring, unusual counterparties, or inconsistency with expected use. Alerts require timely, evidenced investigation and quality assurance.
09
Payments, cards, and transfer controls
Payment and card services require disclosed regulated providers, scheme compliance, transaction screening, limits, reconciliation, settlement controls, error handling, chargeback processes, customer authentication, fraud allocation, and complaints procedures. Account identifiers are issued only under an authorized operating model with clear ownership and customer-funds treatment.
10
Customer funds and protection
Configured treatment: Customer funds are handled according to Swiss regulatory requirements and the applicable Northline customer agreement. Where required, funds are held through FINMA-authorised banking, payment, custody, or safeguarding arrangements. Dashboard balances are operational ledger records and the exact customer-funds treatment is defined by the applicable product agreement.. Legal documents state whether funds are deposits, safeguarded payment funds, electronic money, custody assets, client money, or another category; identify the account structure and responsible provider; explain insolvency treatment; and accurately describe any deposit-guarantee or compensation scheme.
11
Lending and customer outcomes
Credit applications require verified identity, residence, income, expenditure, debts, household circumstances, purpose, and supporting evidence. Decisions follow applicable creditworthiness, affordability, fair-lending, disclosure, pricing, cancellation, arrears, forbearance, vulnerability, and recordkeeping requirements. Approval requires the applicable legally executed credit agreement or funding arrangement.
12
Digital-asset and market-information services
Digital-asset and market-information features are governed by product eligibility, customer verification, jurisdictional permissions, custody or wallet controls, sanctions screening, travel-rule obligations where applicable, formal product disclosures, official register details, and customer agreement terms.
13
Information security and operational resilience
Production operation uses least privilege, encryption, secrets management, hardened infrastructure, secure development, dependency scanning, vulnerability remediation, monitored logs, backups, recovery testing, capacity planning, change control, incident playbooks, provider escalation, customer communication, and legally required regulatory reporting.
14
Complaints and redress
Complaints may be submitted to complaints@northline.finance. They are recorded, acknowledged, investigated impartially, root-caused, and answered within applicable deadlines. Eligible unresolved complaints may be escalated to replace-with-ombudsman-or-alternative-dispute-resolution-body. Complaint trends inform product, conduct, training, and control improvements.
15
Authoritative disclosures and contact
Product agreements, fee schedules, privacy notices, provider terms, credit agreements, safeguarding disclosures, and jurisdiction-specific notices prevail where more specific. Compliance and legal inquiries may be sent to legal@northline.finance. Public authorization statements must match the exact scope shown in the official regulatory register.