Insurance, Retention, and Escalation Schedule
Version 2026-08-24 · Effective August 24, 2026
Issued by Ohana Capital AG
Effective date
August 24, 2026

Issued by
Ohana Capital AG
1. Purpose
This schedule records the insurance position of Ohana Capital AG, the target clocks for complaints escalation, and the record-retention periods applied across platform systems. It supports the Complaints Policy and the Privacy Policy.
2. Insurance position
| Coverage type | Current status |
|---|---|
| Customer deposit guarantee | Not claimed |
| Investor compensation scheme | Not claimed |
| Professional indemnity / cyber / crime policies | To be confirmed with brokers and listed here once bound |
| Custody / client-asset insurance | Not applicable while no client assets are held |
Customer-facing insurance wording is published only when a binder or policy schedule is on file. When policies are obtained, this schedule records: insurer, policy number, period, limits, deductibles, insured entity, and material exclusions.
3. Complaints escalation path
Operational path (aligned with the Complaints Policy):
- Intake — in-platform support, published support email (including office / CRM inbound mail where configured), or help-center channels.
- First-line support — acknowledge, gather facts, attempt resolution.
- Escalation to operations / compliance — disputes about identity decisions, ledger corrections, suspected fraud, or regulatory issues.
- Senior management / counsel — material loss allegations, legal threats, media risk, or authority requests.
- External body — where a live regulated product and local scheme apply; details are added per jurisdiction at launch.
Target internal clocks (operational goals, not guarantees):
| Stage | Target |
|---|---|
| Acknowledgement | Within 2 business days |
| Substantive update | Within 10 business days |
| Outcome letter | Within 30 calendar days where practicable; complex cases may take longer with notice |
4. Retention schedule
Retention runs from account closure or record creation, whichever rule applies, subject to longer legal holds.
| Record class | Systems of record | Retention period |
|---|---|---|
| Account profile & auth events | Supabase Auth / profiles | Account life + 5–10 years (per local requirement) |
| KYC documents & review decisions | documents bucket + document_uploads + audit logs |
Account life + minimum AML period (often 5–10 years, set per jurisdiction) |
| Legal acceptances | legal_acceptances / versions |
Account life + 10 years |
| Orders, positions, ledger events | Trading / ledger tables | Account life + 5–10 years |
| Support / CRM email threads | Resend + CRM inbox tables | 3–7 years |
| Complaints files | Support + compliance archive | 5–10 years |
| Analytics events (consented) | PostHog | Per analytics retention config / consent withdrawal |
| Cookie consent records | Consent API / storage | 2–5 years |
| Server / access logs | Hosting providers | 30–365 days unless security investigation |
Retention periods are aligned to jurisdiction-specific mandatory periods as each market is approved for live client-money operations.
5. Legal holds
When litigation, authority request, or investigation is reasonably anticipated, relevant records are preserved beyond normal deletion schedules until released by counsel or compliance.
6. Related documents
Questions about this document?
Contact Ohana Capital AG and include the document title and version in your message.
Contact support