Skip to main content
← Crosswire

Privacy Policy

Last updated: 12 August 2026

1. Who we are / controller

Crosswire is operated by Wernberg & Partners AB (org. no. 556978-1734), Sveavägen 159, 113 46 Stockholm, Sweden, which is the data controller for the processing described in this Privacy Policy.

For privacy questions, or to exercise your rights, contact compliance@crosswirepay.com.

2. What we collect

  • Information you submit - name, work email, company, website, vertical, volume, regions, and anything you type into free-text fields when you use our consult, pricing or enquiry tools.
  • AI and solution data - the descriptions, requirements and questions you enter into Crosswire AI or other AI-assisted interfaces, together with the proposed provider combinations, coverage indications and indicative commercial terms generated in response.
  • Onboarding data - information collected when you proceed with a provider introduction, including contact and company details, corporate documentation, ownership and control information, and the status of onboarding steps. The Crosswire Onboarding privacy notice, provided to you at the start of that process, sets out the detailed information layer for onboarding.
  • Offer and interaction data - the offers, counter-offers, target prices and responses exchanged through Crosswire, and records of your interactions with our pages, proposals and communications.
  • Technical data - IP address, device and browser information, pages viewed, and first-party analytics events.
  • Marketing source data - UTM parameters and referrer.

Please do not include sensitive information (such as data revealing health, political opinions, religious beliefs, trade union membership, biometric or genetic data, or criminal offence data) in free-text fields or AI prompts. We do not require it and it is not needed to use our services.

3. AI-assisted services

Parts of Crosswire use AI to interpret what you describe, classify your requirements, and generate proposed provider combinations, coverage indications and indicative commercial terms. Text you enter into these interfaces is processed by us and by our AI service provider acting on our behalf as a processor under contract.

Recommendations, proposed provider combinations, coverage indications and commercial terms generated through Crosswire's technology or AI interfaces are indicative and do not constitute approval or a commitment by any third-party provider.

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing. AI outputs are proposals that are reviewed by our team, and every regulated decision on approval, onboarding and continued service is taken by the applicable licensed provider.

4. Why we use your information / legal bases

  • To respond to your enquiry and provide our service - including designing proposed provider combinations, coordinating introductions and supporting onboarding. Legal basis: performance of a contract, or steps taken at your request prior to a contract.
  • To operate, secure and improve the site and our services - including first-party analytics, fraud and abuse prevention, and quality review of AI outputs. Legal basis: our legitimate interests in running and improving a reliable service.
  • To coordinate with third-party providers - sharing the details needed for a provider to assess and contact you. Legal basis: steps taken at your request prior to a contract, and our legitimate interests in operating an introduction service.
  • To send you marketing and relevant information - where you have agreed. Legal basis: consent, which you may withdraw at any time.
  • To meet legal and regulatory obligations - including record-keeping, accounting and responding to lawful requests. Legal basis: compliance with a legal obligation.

5. When we share information

We share information with third-party providers (such as banking, payment, acquiring and infrastructure providers) where you have asked us to explore, request pricing for, or proceed with a solution involving them. What we share is limited to what the provider needs to assess your requirements, respond commercially, and, where you proceed, begin onboarding. Each provider acts as an independent controller for its own assessment, due diligence and onboarding, and processes your information under its own privacy notice.

We share information with service providers who process it on our behalf under contract, including hosting and infrastructure, database and CRM, email delivery, and the AI service provider used for AI-assisted features. These providers may only process your information on our documented instructions.

We may also share information with professional advisers, or where required to comply with law, enforce our terms, or protect the rights, safety and property of Crosswire, our clients or others. We do not sell your personal data. See our partner disclosure for how we are compensated.

6. International transfers

Some of our providers and service providers are located outside the European Economic Area. Where we transfer personal data outside the EEA, we rely on an adequacy decision where one applies, or otherwise on the European Commission's Standard Contractual Clauses together with any additional safeguards required in the circumstances.

You may request a copy of the Standard Contractual Clauses or details of the safeguards in place by contacting compliance@crosswirepay.com.

7. Retention

  • Enquiry, CRM and AI data - Enquiry, CRM and AI data is kept for up to 24 months after our last meaningful contact with you, then deleted or anonymised. A live engagement or a legal obligation can extend that, and nothing else does.
  • Onboarding data - Onboarding records are kept for the duration of the introduction and for as long as it has to be evidenced, subject to any longer period required by law.
  • Analytics and technical data - Analytics data is kept in identifiable form for up to 13 months, then aggregated or deleted.

8. Your rights

Subject to law, you may access, correct, delete, port, restrict or object to processing of your data, and withdraw consent at any time without affecting processing carried out before withdrawal. To exercise these, contact compliance@crosswirepay.com. You may also complain to your data protection authority (in the EU, your national DPA; in Sweden, Integritetsskyddsmyndigheten (IMY)).

9. Security

We use appropriate technical and organisational measures to protect your data, including encryption in transit, access controls and least-privilege access to our systems. No method of transmission or storage is 100% secure.

10. Cookies

We use a small number of first-party cookies and local storage. A strictly necessary cookie stores your cookie choice, and a first-party session and attribution cookie is set only after you accept analytics, so that we can measure traffic and see which campaign or referrer brought you here. Analytics events are sent to our own endpoint on this domain and are not shared with a third-party analytics platform. We do not run advertising or third-party tracking pixels. Web fonts are loaded from Google Fonts, which does not set cookies but does receive your IP address as part of that request. Full details are in our Cookie Policy.

11. Required information

Some information is necessary for us to act. If you do not provide the contact and business details requested in our enquiry, pricing or onboarding forms, we may be unable to respond to your enquiry, produce indicative pricing, introduce you to a provider, or support onboarding. Providing free-text detail and marketing consent is optional, and declining does not affect your ability to contact us.

12. Changes

We may update this policy from time to time. The "last updated" date at the top of this page will change, and material changes will be highlighted on this page.