Privacy Policy

PACTSETTLE
Last updated: July 30, 2026

Introduction

PactSettle (“PactSettle“, “we“, “us“, or “our“) respects your privacy and is committed to protecting personal data. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you visit our website at https://www.pactsettle.io (the “Website“) or use our digital asset conversion and settlement services (the “Services“).

This Privacy Policy is prepared in accordance with Law No. 81 of March 26, 2019 on the Protection of Personal Data of the Republic of Panama (the “Data Protection Law“), as regulated by Executive Decree No. 285 of May 28, 2021, and any other applicable Panamanian legislation.

Because PactSettle serves business clients, most of the personal data we process relates to individuals connected with our clients — directors, officers, authorized users, signatories, and ultimate beneficial owners — rather than to consumers. This Privacy Policy should be read together with our Terms and Conditions.

The party responsible for the processing of personal data (the “Data Controller“) is the operator of the PactSettle brand, an entity indirectly owned by Ramp Capital S.A., a company incorporated under the laws of the Republic of Panama.

This Privacy Policy applies to the personal data of:

  • Website visitors and individuals who submit enquiries or complete contact or onboarding forms;

  • Client representatives, including directors, officers, authorized users, signatories, compliance contacts, and technical contacts of our business clients;

  • Ultimate beneficial owners and controllers of our business clients, whose details we are required to identify and verify; and

  • Other individuals whose data appears in transaction or settlement instructions, such as named beneficiaries of a payout.

Controller and processor roles. In respect of onboarding, due diligence, compliance, and our own provision of the Services, we act as a Data Controller. Where you transmit to us personal data relating to your own customers or counterparties solely so that we can execute your instructions, we act as a processor on your behalf in respect of that data, and you remain responsible for having a lawful basis for the transfer and for providing any notices required under applicable law.

This Privacy Policy does not apply to the practices of third parties we do not own or control, including third-party websites, blockchain networks, wallet providers, or decentralized protocols.

We collect and process the following categories of personal data:

a) Client and representative identity data. Names, job titles, roles, business e-mail addresses, business telephone numbers, dates of birth, nationality, and country of residence of directors, officers, authorized users, signatories, and other representatives of our clients.

b) Beneficial ownership and control data. Identity details, ownership percentages, and control arrangements relating to ultimate beneficial owners, together with corporate structure information and supporting documentation.

c) Due diligence and screening data. Government-issued identification documents and images, proof of address, corporate registry extracts, licensing documentation, source-of-funds and source-of-wealth information, and the results of sanctions, politically exposed person (“PEP”), adverse media, and other screening checks carried out by us or by third-party providers. Where any check involves biometric identifiers derived from facial images, we process such data only where the individual has given explicit consent or where processing is required to comply with a legal obligation.

d) Transaction and settlement data. Details of Settlement Transactions, including asset types, amounts, quoted and executed rates, fees, timestamps, status, blockchain transaction hashes, wallet addresses, and bank account, IBAN, SWIFT/BIC, beneficiary name, and payment reference details submitted in settlement instructions.

e) Account, technical, and API data. User account identifiers, authentication and multi-factor authentication data, API keys and key metadata, audit logs of actions taken in the dashboard or via the API, IP addresses used for access, and device and session information.

f) Communications data. The content of e-mails, support tickets, chat messages, and other correspondence with us, including attachments, and records of our responses. Where a call is recorded, we will inform you and, where required, obtain consent.

g) Website usage data. IP address, approximate location derived from IP address, browser type and version, device identifiers, operating system, referring pages, session identifiers, pages viewed, and interaction data, collected through cookies and similar technologies (see Section 11).

Except as described in Section 4(c), we do not intentionally collect sensitive personal data, and we ask that you do not submit such data to us unless we specifically request it.

We collect personal data:

  • directly from you or your organization, during onboarding, through forms, documentation, settlement instructions, dashboard and API activity, and correspondence;

  • automatically, when the Website, dashboard, or APIs are accessed, through cookies, server logs, and audit logging; and

  • from third parties and public sources, including identity-verification and screening providers, corporate registries, blockchain analytics providers, payment processors and banking partners, credit and business-information providers, sanctions and PEP lists, adverse media sources, and public blockchain records.

We process personal data for the following purposes and on the following bases recognized under the Data Protection Law:

  • To onboard and administer client relationships, including assessing applications, configuring accounts, managing users, and performing the contract — based on the performance of a contract (or steps taken prior to entering into one) and our legitimate interests in managing our business relationships.

  • To provide the Services, including quoting, executing, and settling transactions, producing reconciliation and reporting data, and providing dashboard and API access — based on the performance of a contract.

  • To conduct due diligence and prevent financial crime, including identity verification, beneficial ownership identification, sanctions, PEP and adverse media screening, source-of-funds assessment, fraud prevention, and transaction monitoring — based on compliance with a legal obligation and our legitimate interests in preventing fraud and unlawful use of the Services, and, in respect of any biometric processing, on explicit consent.

  • To comply with legal and regulatory obligations, including anti-money-laundering, counter-terrorism-financing, sanctions, tax, accounting, audit, and record-keeping requirements, and to respond to lawful requests from competent authorities, courts, and banking partners — based on compliance with a legal obligation.

  • To provide support and manage communications — based on the performance of a contract and our legitimate interests.

  • To operate, secure, maintain, and improve the Website, dashboard, and APIs, including security monitoring, incident investigation, capacity planning, fault diagnosis, and usage analysis — based on our legitimate interests.

  • To manage risk and credit exposure, including counterparty risk assessment and limit setting — based on our legitimate interests.

  • To establish, exercise, or defend legal claims, and to manage complaints, disputes, and regulatory enquiries — based on our legitimate interests and compliance with a legal obligation.

  • To send service notifications and, where permitted, business marketing communications about our products and features — based on our legitimate interests in business-to-business communications or, where required, on consent, which may be withdrawn at any time.

Where processing is based on consent, that consent may be withdrawn at any time without affecting the lawfulness of processing carried out beforehand. Where processing is necessary to provide the Services or to comply with a legal obligation, we may be unable to continue providing the Services if the relevant data is not provided.

We do not sell personal data. We may share personal data with:

  • Service providers and processors who perform services on our behalf — including cloud hosting and infrastructure, identity verification and KYC/KYB providers, sanctions, PEP and adverse media screening providers, blockchain analytics providers, payment processors, acquiring and correspondent banks, custodial and liquidity partners where necessary to execute and settle your transactions, e-mail and messaging providers, customer-support and ticketing platforms, accounting and reconciliation tools, and security and fraud-prevention providers — in each case under contractual obligations to protect the data and process it only on our instructions;

  • Affiliates within our group, including Ramp Capital S.A. and its subsidiaries, for compliance, risk management, internal administration, audit, and shared operational functions;

  • Professional advisors, such as legal, accounting, audit, and tax advisors, and insurers, where necessary;

  • Competent authorities, regulators, law enforcement, tax authorities, or courts, where required to comply with a legal obligation, respond to a lawful request, prevent or detect crime, or protect our rights or the rights of others; and

  • Successors in the event of a merger, acquisition, reorganization, financing, or sale of assets, subject to appropriate confidentiality safeguards.

Any third party with whom we share personal data is required to maintain confidentiality and to apply security measures consistent with the Data Protection Law.

Please note: blockchain transactions are recorded on public, immutable ledgers. Wallet addresses, amounts, and transaction hashes associated with Settlement Transactions are publicly visible and outside our control. We cannot alter or delete information recorded on a public blockchain.

We collect personal data:

  • directly from you or your organization, during onboarding, through forms, documentation, settlement instructions, dashboard and API activity, and correspondence;

  • automatically, when the Website, dashboard, or APIs are accessed, through cookies, server logs, and audit logging; and

  • from third parties and public sources, including identity-verification and screening providers, corporate registries, blockchain analytics providers, payment processors and banking partners, credit and business-information providers, sanctions and PEP lists, adverse media sources, and public blockchain records.

Our infrastructure, service providers, banking partners, and group affiliates operate in multiple jurisdictions, including outside the Republic of Panama. Where personal data is transferred internationally, we take reasonable steps to ensure the transfer is carried out in accordance with the Data Protection Law and that an adequate level of protection is maintained, including through contractual safeguards with the recipient requiring confidentiality, purpose limitation, onward-transfer restrictions, and appropriate technical and organizational security measures.

You may request further information about the safeguards applied to international transfers by contacting us at support@pactsettle.io.

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, regulatory, audit, and reporting requirements, and to establish, exercise, or defend legal claims.

In particular:

  • Onboarding, due diligence, beneficial ownership, and transaction records are retained for the period required by applicable anti-money-laundering and record-keeping legislation, which is generally not less than five (5) years from the date of the transaction or the end of the client relationship, whichever is later.

  • Accounting and tax records are retained for the periods required under applicable Panamanian and other relevant legislation.

  • Audit logs and security records are retained for periods appropriate to security monitoring, incident investigation, and dispute resolution.

  • Support and communications records are retained for the period necessary to address the matter and for a reasonable period thereafter.

  • Declined applications are retained for a limited period sufficient to record the decision and its basis.

Where personal data is no longer required and no legal obligation requires its retention, we will securely delete or irreversibly anonymize it.

In accordance with the Data Protection Law, individuals whose personal data we process have the right to:

  • Access the personal data we hold about them and obtain information about how it is processed;

  • Rectify inaccurate, incomplete, or outdated personal data;

  • Delete (cancel) personal data where it is no longer necessary for the purposes for which it was collected or where the processing does not comply with the law;

  • Object or oppose the processing of personal data in the circumstances permitted by law;

  • Restrict processing, or request portability of the data, where applicable; and

  • Withdraw consent at any time where processing is based on consent.

These rights are not absolute. We may decline a request in whole or in part where we are required or entitled by law to retain the data — for example, where anti-money-laundering legislation requires us to keep due diligence and transaction records for a minimum period, or where disclosure would prejudice the prevention or detection of crime or breach a legal prohibition on tipping off.

Where we act as a processor on behalf of a client, requests relating to that client’s own customers should be directed to the client as controller; we will assist the client in responding as required.

To exercise any of these rights, please contact us at support@pactsettle.io. We may need to verify identity before acting on a request. We will respond within the timeframes established by the Data Protection Law and its regulations.

If an individual believes their rights have not been adequately addressed, they may lodge a complaint with the National Authority for Transparency and Access to Information (ANTAI) of the Republic of Panama, the supervisory authority for personal data protection.

The Website and dashboard use cookies and similar technologies to enable core functionality (such as maintaining your authenticated session and security state), remember preferences, and analyze traffic and usage.

We use:

  • Strictly necessary cookies, required for the Website and dashboard to function and for security and authentication purposes;

  • Preference cookies, which remember settings such as language and display options; and

  • Analytics cookies, which help us understand usage so that we can improve the Services.

You can control or disable cookies through your browser settings; however, disabling strictly necessary cookies will prevent the dashboard from functioning. Where required by law, we will request consent before placing non-essential cookies.

Certain checks we apply — including sanctions and PEP screening, fraud scoring, risk scoring, and transaction monitoring — may involve automated processing that can result in an application being declined, a transaction being delayed, declined, or flagged for manual review, or an account being suspended. Where such a decision significantly affects an individual, they may request human review by contacting us at support@pactsettle.io, subject to any legal restriction that prevents us from disclosing the reason for a decision.

We implement reasonable technical, organizational, and administrative measures designed to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls and least-privilege permissioning, multi-factor authentication for administrative access, API key management and rotation, network segmentation, audit logging and monitoring, personnel confidentiality obligations, vendor due diligence, and periodic review of our security practices.

No method of transmission or storage is completely secure, and while we strive to protect personal data, we cannot guarantee absolute security. In the event of a data-security breach affecting personal data, we will act in accordance with the notification requirements of the Data Protection Law and will inform affected clients without undue delay where required.

The Website and Services are directed exclusively to businesses and to individuals aged eighteen (18) or over acting in a business capacity. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected such data, please contact us at support@pactsettle.io so that we may delete it.

The Website may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The revised version will be posted on the Website with an updated “Last updated” date and will take effect upon posting. Where a change is material, we will use reasonable efforts to notify affected clients. We encourage you to review this Privacy Policy periodically.

For any questions, requests, or complaints regarding this Privacy Policy or the processing of personal data, please contact:

PactSettle — Data Protection Contact E-mail: support@pactsettle.io

Pactsettle is a product of PactSwap Labs Ltd. Platform services are operated by Ramp Capital SA, Panama.