Legal

    Privacy Policy

    How Mesa de Pagos collects, uses, stores, protects and shares personal data across its platform and payment services.

    Last updated: May 12, 2026

    1.Purpose of this Policy

    Mesa de Pagos Bolivia S.R.L. ("Mesa de Pagos" or "MDP") recognises that protecting personal data is essential to its business, and commits to processing it under the principles of legality, lawfulness, purpose limitation, proportionality, quality, confidentiality, security, accountability and good faith — in observance of the Political Constitution of the Plurinational State of Bolivia, applicable regulation and international best practice on data protection.

    This Privacy Policy describes how MDP collects, uses, stores, protects, shares and retains the personal data of its clients, prospective clients, legal representatives, ultimate beneficial owners and other users of the Platform. It forms an integral part of the Terms & Conditions of use, available at /terms.

    Accessing, registering with and using the Platform implies knowledge and acceptance of this Policy, without prejudice to those processing activities that require express consent under applicable law.

    2.Data Controller

    Mesa de Pagos is the controller of the personal data obtained while providing its technology and operational services relating to international payments, OTC transactions with virtual assets, Pay-in and Pay-out services, and the other services offered through its Platform.

    Mesa de Pagos determines the purposes and means of processing in accordance with applicable legislation, its regulatory obligations and its internal compliance, information security and risk management policies.

    3.Personal data we collect

    Depending on the nature of the services used, Mesa de Pagos may collect and process the following categories of information:

    Identification data
    Full name, identity document, nationality, date of birth, address, email address, phone number and signature.
    Corporate information
    Where the Client is a legal entity: details of legal representatives, shareholders, ultimate beneficial owners and ownership structure.
    Financial and tax information
    Bank accounts, tax information, economic activity and source of funds.
    Compliance documentation
    Documents required for KYC/KYB, anti-money laundering, counter-terrorist financing and regulatory compliance processes.
    Biometric information
    Used exclusively for identity verification processes, where applicable.
    Technical information
    Derived from use of the Platform: IP addresses, device identifiers, access logs, browsing information and audit trails.
    Transaction information
    Payments, transfers, conversions, OTC operations and other transactions executed through the Platform.

    Mesa de Pagos will only collect the data reasonably necessary to fulfil the purposes described in this Policy.

    5.Purposes of processing

    Personal data may be used to:

    • Register and administer user accounts.
    • Verify the identity of the Client and its ultimate beneficial owners.
    • Execute payment, collection and conversion operations and the other services offered.
    • Comply with legal and regulatory obligations, including AML, CTF and counter-proliferation financing requirements.
    • Detect, prevent and investigate fraud, unusual operations and security threats.
    • Handle enquiries, requests, complaints and client support.
    • Maintain accounting, financial and regulatory records.
    • Respond to requirements from competent authorities.
    • Improve the security, stability and performance of the Platform.
    • Carry out internal and external audits.
    • Send institutional information, regulatory updates or commercial communications where the Client has given consent.

    Mesa de Pagos does not sell or trade personal data.

    6.Sharing information

    Mesa de Pagos may share personal information only where necessary to properly deliver its services or to comply with legal obligations. Depending on the case, data may be shared with:

    • Financial institutions.
    • Correspondent banks.
    • Payment service providers.
    • Virtual asset service providers (VASPs).
    • Technology infrastructure and cloud service providers.
    • Identity verification providers.
    • Specialist providers of fraud prevention, transaction monitoring and regulatory compliance.
    • External auditors.
    • Administrative, judicial or regulatory authorities with legal competence.

    Every third party that accesses personal information must be bound by contractual confidentiality and data protection obligations equivalent to those applied by Mesa de Pagos.

    7.International data transfers

    Given the international nature of the services offered, some personal data may be processed or stored outside the Plurinational State of Bolivia by technology providers, financial institutions, payment processors, infrastructure platforms, identity verification providers or other strategic partners located in different jurisdictions.

    Mesa de Pagos will adopt reasonable contractual, organisational and technical measures to ensure that such transfers maintain an adequate level of protection for personal data, in line with international best practice and applicable regulation.

    8.Data retention

    Personal data will be retained for as long as necessary to fulfil the purposes described in this Policy and the applicable legal, regulatory, tax, accounting and financial crime prevention obligations.

    As a general rule, information may be retained for up to ten (10) years after the contractual relationship ends, unless current legislation or a competent authority requires a longer period.

    Once those periods have elapsed, data will be securely deleted, anonymised or blocked when its retention is no longer legally necessary.

    9.Information security

    Mesa de Pagos implements technical, organisational and administrative measures designed to preserve the confidentiality, integrity, availability and authenticity of personal data.

    • Strong authentication mechanisms.
    • Role-based access controls.
    • Encryption of communications through secure protocols.
    • Auditable logs and continuous monitoring.
    • Segregation of technology environments.
    • Periodic backups and internal information security policies.

    These measures are reviewed and updated periodically in line with technological developments, identified risks and regulatory change.

    10.Security incident management

    Mesa de Pagos maintains internal procedures to identify, contain, investigate and mitigate incidents that may affect the confidentiality, integrity or availability of personal data.

    Where an incident represents a material risk to data subjects, Mesa de Pagos will adopt the corresponding corrective measures and make the notifications required under applicable regulation.

    11.Automated decisions and monitoring

    To prevent fraud, comply with regulatory obligations and protect the security of the Platform, Mesa de Pagos may use technology tools that incorporate automated processes for transaction assessment, transaction monitoring, identity verification, detection of unusual behaviour and risk analysis.

    Final decisions that produce material effects for the Client may be reviewed by authorised personnel where circumstances so require.

    12.Cookies and similar technologies

    The Platform may use cookies, session technologies and similar tools to enable the site to work properly, authenticate users, keep sessions active, improve the browsing experience, produce statistical analysis and strengthen information security.

    Users may configure their browser to reject certain cookies; doing so may affect the operation of some Platform features.

    13.Your rights as a data subject

    Data subjects may request:

    • Access to their personal data.
    • Rectification of inaccurate or incomplete information.
    • Updating of their data.
    • Deletion, where legally applicable.
    • Objection to processing in the cases permitted by law.
    • Withdrawal of consent for commercial purposes.

    Mesa de Pagos may request sufficient information to verify the identity of the applicant before responding to any request relating to personal data. Requests can be sent to info@mesadepagos.com.

    Deletion will not proceed where there is a legal obligation to retain the information, or where it is necessary to defend rights or comply with regulatory obligations.

    14.Minors

    The services offered by Mesa de Pagos are directed exclusively at persons with the legal capacity to contract and, in the case of legal entities, at their duly authorised representatives.

    Mesa de Pagos does not knowingly collect personal information from minors.

    15.Updates to this Policy

    Mesa de Pagos may amend this Policy where necessary due to regulatory, technological or operational changes, or as its services evolve.

    Amendments will be published on the Platform and take effect from publication, unless a different date is stated. Continued use of the services after such amendments constitutes acceptance of the version in force.

    16.Contact

    To exercise your rights or raise any question about the processing of personal data, write to info@mesadepagos.com or use the official contact channels published at contact.

    Mesa de Pagos will address requests within reasonable timeframes and in accordance with applicable regulation, keeping records of the actions taken as part of its compliance and data protection framework.

    This page is maintained by Mesa de Pagos. The Spanish version is the authoritative legal text; translations are provided for convenience.