Who are we?
Univerra, S.A. de C.V. (hereinafter “VitaPay”, “we”, or “the Company”) is a non-financial institution entity that, through electronic, digital, and similar platforms operated by itself or third parties and managed by the Company, regularly and professionally provides virtual asset custody services. The foregoing services are used to facilitate and process virtual assets under clients’ names, and are accompanied by technical support services required for the custody, storage, and transfer of virtual assets.
The foregoing business includes relevant transactions conducted outside of Mexico for Mexican citizens, in accordance with applicable laws and regulations. For the purposes of the Company’s scope of business, virtual assets refers to units of value recorded in electronic form that are used as a medium of exchange for lawful transactions among the public and can only be transferred electronically; fiat currencies, foreign currencies, and any other assets denominated in fiat or foreign currencies are not considered virtual assets.
The Company may enter into all lawful legal instruments and agreements and engage in all types of ancillary and related businesses necessary or convenient to achieve the Company’s business objectives; provided, however, that such businesses must be lawful and must not fall within the exclusive scope of businesses reserved for financial institutions or other licensed entities, unless the Company has obtained the corresponding business license in advance.
VitaPay acts as the data controller for the purposes of this Privacy Statement, meaning we determine the purposes and means of processing your personal data. In some cases, we may also act as a data processor for other entities authorized to process your personal data.
In summary, we process your personal data to provide and deliver virtual asset custody products and services to you through various channels, improve such products and services, and ensure compliance with legal and regulatory obligations. The following sections explain this in detail.
Why do you need to read this Privacy Statement?
When we refer to “personal data,” we mean any information relating to an identified or identifiable natural person (such as you). Data from which your identity cannot be identified is not personal data and is not covered by this Privacy Statement.
This Privacy Statement explains how we collect, store, use, disclose, transmit, protect, and generally process your personal data, and what personal data we process when you interact with us for any reason.
Therefore, this Privacy Statement explains what rights you have regarding your personal data. Let us begin:
Some personal data is necessary for us or third parties to provide products and services or to comply with legal and regulatory obligations. If you do not provide such required data, we may not be able to open an account for you or provide certain products and services, nor allow others to do so. Other data is optional, and not providing it will not affect your use of the core services.
We may collect your personal data in the following circumstances:
- When you access any of our mobile applications.
- When you access any of our websites, including our official platform at vita-pay.com.
- When you use any of the products and services available on our applications or websites.
We may also collect your personal data from third parties, as described in more detail below (see Personal Data Collected).
For certain products, services, and interactions, other privacy statements may apply in addition to this Privacy Statement. Such statements may provide more specific information and will always prevail in the event of a conflict with this general Privacy Statement.
To the extent that you have a relationship with us, this Privacy Statement applies in conjunction with any terms and conditions and other contractual documents that we may enter into with you. If you do not accept these documents, you should immediately cease any interaction and terminate your relationship with us (if applicable).
If you have any questions about how we process personal data, you may contact our Data Protection Officer at any time (see contact information in Appendix I).
What personal data do we collect about you and from what sources?
We collect several categories and types of personal data through the following three methods:
3.1 Data you provide
May include:
| Data Category | Data Types |
|---|---|
| Account Data | First name, last name, alias or nickname, residential address, email, phone number, access credentials, account number, profile photo, and settings and preferences, etc. |
| Demographic Data | Date of birth, nationality, location, tax residence, gender, and marital status, etc. |
| Identity Verification Data | Government-issued identification documents (passport, driver’s license, or national ID card) and any data contained therein, other identification numbers/photos/videos, other biometric samples, proof of address, and signature, etc. / Please note: Biometric samples are considered sensitive data. |
| Financial Data | Virtual asset wallet addresses, etc. |
| Compliance Data | Self-declaration of Politically Exposed Person (PEP) or public figure status. |
| Economic Data | Employment or business activities, source of funds, source of wealth, income, expenses, and tax filings, etc. |
| User Content Data | Names, last names, aliases or nicknames, residential addresses, government-issued identification documents and any data contained therein of legal representatives and ultimate beneficial owners of legal entities; communication records with customer support; information from uploaded files; feedback, complaints, or inquiries, etc. |
3.2 Data generated when you use our products and services
May include:
| Data Category | Data Types |
|---|---|
| Financial Data | Details and timestamps of virtual asset transfers and withdrawals, transaction counterparties, and balances, etc. |
| Compliance Data | Records related to anti-money laundering (AML), counter-terrorism financing (CTF), anti-fraud (AF), Politically Exposed Person (PEP) or sanctions status checks; and risk ratings, etc. |
| Usage Data | Access logs, pages viewed, features used, error reports, and session duration, etc. |
| Communication Data | In-app/web messages, customer service phone calls or emails, and communication preferences, etc. |
| Device and Cookie Data | IP address, MAC address, browser type, operating system, device identifiers, mobile network, geolocation, logs, cookies, and similar technologies, etc. |
3.3 Data from other sources
May include:
| Data Category | Data Types |
|---|---|
| Financial Data | Confirmation information for details and timestamps of virtual asset transfers, withdrawals, transaction counterparties, and balances. |
| Compliance Data | Identity verification, anti-money laundering (AML), counter-terrorism financing (CTF), anti-fraud (AF), Politically Exposed Person (PEP), and sanctions status checks, etc. |
| Official Authority Data | Criminal/tax/civil/commercial/labor/other investigations or legal proceedings related to you as notified by official authorities, etc. |
| Business Partners and Affiliates | Information from referral programs, joint promotions, and co-branded products and services, etc. |
| Other Users | Data provided by other users (e.g., if they send you virtual assets, or report you). |
When we collect your personal data from third parties, we require that they have obtained authorization to transmit data to you and that their collection methods are lawful.
We may collect your personal data by querying risk and background information agencies on a large scale; anti-money laundering (AML), counter-terrorism financing (CTF), anti-fraud (AF), Politically Exposed Person (PEP) and sanctions status lists; credit and custody institutions; remittance or fund transmission institutions; associations of financial institutions and other payment network participants; credit reference agencies; administrative and judicial bodies; markets or third-party channels where we provide products and services; entities with which we have business alliances; and other third parties that you have authorized or that are otherwise authorized to transmit personal data to you.
What are the lawful bases we rely on to process your personal data?
We process your personal data only when we have a lawful basis to do so. Typically, we process your personal data in the following circumstances:
Contract performance
We need some of your personal data to provide and deliver our products and services to you. For example, to verify your identity, open your account, and process your requests. Without this personal data, we cannot provide products and services and fulfill our agreement with you.
Legal and regulatory obligations
In several cases, we have statutory obligations to collect, store, use, disclose, and transmit your personal data. For example, under AML, CTF, AF, tax, and financial reporting laws and regulations, we must analyze certain information about users and their transactions and allow agents of the authorities and the financial system to conduct such analysis. This may be aimed at preventing or preventing crime and tax collection purposes.
Significant public interest
In some cases, we may process your personal data due to the need to comply with our understanding of legal or regulatory obligations, or even to protect the integrity of the virtual asset system and the financial system or other significant values. For example, cooperating with authorities to combat crime.
Legitimate interests
In some cases, we may process your personal data because we have legitimate business reasons, provided that your rights are not overridden. When we rely on legitimate interests, we conduct a balancing test to ensure your rights are protected. For example, improving platform security or our products and services.
Consent
In several cases, we rely on your explicit consent, such as accepting this Privacy Statement or other privacy statements. For example, when you consent to receive marketing communications, optionally use the content in our applications and websites, or consent to others providing their products and services to you through our channels. You may withdraw your consent at any time.
The exact legal basis for processing may vary depending on your location, the products or services you use, and the applicable legal and regulatory requirements. Sometimes, we may provide additional privacy notices at the time of data collection to inform you of the specific lawful basis we rely on.
For what purposes may we process your personal data?
We process your personal data for the following purposes:
5.1 Verifying your identity, authenticating your access, and authorizing you to use products and services
We process your account data, demographic data, identity verification data, financial data, economic data, compliance data, and device data, etc.
For example, this helps us verify whether you are being impersonated, whether you can access specific applications or websites and use our specific products and services, depending on, for example, your location or nationality, or whether you are an individual user, merchant, or institutional user.
Legal basis: Contract performance; legal and regulatory obligations; and/or consent.
5.2 Processing virtual asset transactions on our platform
We process your account data, financial data, compliance data, and device data, etc.
For example, this helps us execute virtual asset transfers and withdrawals.
Legal basis: Contract performance; legal and regulatory obligations; and/or consent.
5.3 Providing technical support services for virtual asset custody, storage, and transfer
We process your account data, financial data, compliance data, and device data, etc.
For example, this helps us provide the technical infrastructure and support services required for virtual asset custody, storage, and transfer, including wallet management, key management, and transaction monitoring.
Legal basis: Contract performance; legal and regulatory obligations; and/or consent.
5.4 Protecting our business and ensuring compliance with laws, regulations, and official authority orders
We process your account data, demographic data, identity verification data, financial data, economic data, user content data, compliance data, usage data, communication data, device and cookie data, official authority data, business partner and affiliate data, and other user data, etc.
For example, this helps us manage the financial and operational risks we face and maintain platform integrity. This includes:
- Preventing, detecting, and mitigating risks (e.g., safeguarding the security of custodial assets and preventing the risk of unauthorized use or illegal access to custody accounts).
- Working to protect users, assets, and the platform from cybercrime and crime in general.
- Handling disputes, chargebacks, reversals, denials, and similar matters.
Legal basis: Legal and regulatory obligations; significant public interest; and legitimate interests.
5.5 Submitting mandatory reports, responding to investigations or litigation, and cooperating with official authorities
We process your account data, demographic data, identity verification data, financial data, economic data, user content data, compliance data, usage data, communication data, device data, official authority data, business partner and affiliate data, and other user data, etc.
For example, this helps us respond to or voluntarily cooperate with investigations or legal proceedings by official authorities in the jurisdictions where we operate, or where there is a connection or derivative interaction with our products and services. This includes:
- Preventing, detecting, and reporting suspicious activities or transactions within custody accounts.
- Preventing, detecting, and reporting fraud (e.g., cross-referencing account data with third-party databases and updating such databases).
- Preventing, detecting, and reporting situations where custody accounts become associated with persons on sanctions lists.
- Responding to or participating in criminal, civil, commercial, labor, or other administrative or judicial investigations or proceedings.
Legal basis: Legal and regulatory obligations, significant public interest, legitimate interests, and/or consent.
5.6 Managing our relationship with you
We process your account data, demographic data, identity verification data, financial data, economic data, user content data, compliance data, usage data, communication data, device and cookie data, official authority data, business partner and affiliate data, and other user data, etc.
For example, when you register on our applications or websites, subscribe to updates/blogs/other information, or contact us directly, we use your personal data to:
- Inform you about products and services, our platform, and any related aspects, including changes thereto.
- Notify you of disruptions, scheduled/unscheduled maintenance, or security alerts.
- Provide user support, issue resolution, and transaction reminders.
- Solicit or receive feedback to improve our products, services, and platform.
Legal basis: Contract performance; legal and regulatory obligations, legitimate interests, and/or consent.
5.7 Collecting outstanding debts you may owe us
We process your account data, etc.
For example, we may process your personal data to send you notifications or contact you to collect outstanding debts you may owe us.
Legal basis: Contract performance, legitimate interests, and/or consent.
5.8 Marketing our products and services, providing rewards or other benefits, or inviting you to participate in our events
We process your account data, demographic data, financial data, usage data, communication data, device and cookie data, and business partner and affiliate data, etc.
For example, we may process your personal data to personalize and send you marketing communications. If you do not wish to be contacted for this purpose, you may opt out at any time.
Legal basis: Consent.
5.9 Conducting research and building on research findings
We process your account data, demographic data, financial data, user content data, usage data, communication data, and device and cookie data, etc.
For example, we may process your personal data to:
- Research market trends and user needs and concerns.
- Develop, improve, and innovate products and services (e.g., new custody-related features).
- Improve user experience through personalization.
- Provide aggregated reports and insights to merchants or institutional partners.
Legal basis: Legitimate interests and/or consent.
Do we make automated decisions about you?
Yes. Depending on the product or service, we may use our own decision-making models or third-party decision-making models to conduct automated decision-making processes, including profiling. When such decisions produce legal effects or otherwise significantly affect you, we will:
- Explain the logic involved in the decision-making process in an easily understandable manner, and describe its importance and potential consequences for you.
- Provide you with the right to request human intervention, express your views, and contest the decision.
We use automated systems to conduct risk screening of you and your custody account activities at the time of your registration and throughout your use of the custody services, and may make decisions to accept, reject, suspend, or ban custody accounts. Its purpose is to efficiently and effectively prevent and detect crime. You may refer again to Section 5 for a deeper understanding of this purpose. You have the right to request human intervention, express your views, and contest the decision.
When local laws and regulations require your consent to make automated decisions, accepting this Privacy Statement constitutes your consent, but we may separately seek your consent again.
How do we process your personal data for marketing purposes?
If you register for our products and services through any channel, or register for products and services provided by others within our channels, and to the extent permitted by national laws and regulations, we and third parties may process your personal data to send you information about us or such third parties and their respective products, services, offers, and promotions via email, push notifications, in-app messages, SMS, phone calls, or mail.
We also process your personal data to personalize marketing communications to make them more relevant and useful to you. This may include analyzing how you use our products and services and your overall engagement with us. You may object to profiling for direct marketing purposes at any time.
When local laws and regulations require your consent to send marketing communications, accepting this Privacy Statement constitutes your consent, but we may separately seek your consent again.
You can always control your marketing preferences. You may:
- Adjust your preferences (if available) in the application or website settings.
- Click the unsubscribe link in any marketing email we send you.
- Directly inform us that you do not wish to be contacted for marketing communications again.
If you opt out of profiling for marketing, you will no longer receive personalized or direct marketing communications. However, you may still receive other direct communications unrelated to marketing purposes, as well as general marketing information about our products and services on our own or third-party applications or websites.
We do not sell your personal data.
What rights do you have?
You have several rights regarding how we process your personal data. The following explains the meaning of each right and how it applies:
| Your Rights | Description |
|---|---|
| Right to Information | You have the right to know who is processing, how they are processing, why they are processing, and what personal data of yours has been processed. This Privacy Statement explains how and why we collect, store, use, disclose, transmit, protect, and generally process your personal data, and what personal data we process when you interact with us for any reason. This includes the right to know the source of personal data and who is processing it when it is not obtained directly from you. |
| Right to Object to Direct Marketing | You have the right to request that we stop processing certain personal data we hold about you for direct marketing purposes, including profiling related to direct marketing. If you opt out of profiling for direct marketing, you will no longer receive personalized or direct marketing communications. However, you may still receive other direct communications unrelated to marketing purposes. |
| Right to Object to Processing Based on Legitimate Interests | When we process personal data we hold about you based on legitimate interests and you disagree, you have the right to object. If we have compelling legitimate grounds to continue processing, we may refuse the request. In certain cases, this may mean we are unable to continue providing or delivering products or services to you. |
| Right of Access | You have the right to request a copy of the personal data we hold about you. We will not be able to grant you access to personal data of other persons you are not authorized to represent, personal data related to ongoing monitoring/investigations or legal proceedings (such as monitoring alerts, suspicions, potential or suspected criminal activities), legal opinions, or other data that is not your personal data (and therefore constitutes proprietary data). Before accessing your records, we may need to verify your identity. |
| Right to Rectification | You have the right to correct (if applicable) yourself or request that we correct incomplete or inaccurate personal data we hold about you. If you request changes to the amount or date of a settled transaction, or request changes to internal assessments or conclusions, we will not be able to modify your records; we can only correct factual data. Before updating your records, we may need to verify your identity and the accuracy of the new information you provide. |
| Right to Erasure (“Right to be Forgotten”) | In the following circumstances, you have the right to request that we delete certain personal data we hold about you: we have no lawful basis to process such data and you have withdrawn consent or objected to our processing; we have unlawfully used your data; or laws and regulations require us to delete it. Under laws and regulations, we must retain certain personal data about you to fulfill legal and regulatory obligations (such as AML, CTF, and AF-related obligations), and we may further retain certain personal data about you under other lawful bases, such as for the establishment or defense of legal claims. If we are unable to delete your data, we will always inform you. |
| Right to Restrict Processing | In the following circumstances, you have the right to request that we temporarily stop processing personal data we hold about you: you wish us to verify its accuracy (during the corresponding verification period); our processing has no clear legal basis but you do not request deletion (for an indefinite period, until the reason ceases to exist); we no longer need it but you wish us to retain it for legal claims (for an indefinite period, until the reason ceases to exist); or you have objected to processing and we need to verify our basis. To fulfill our contract with you or pursuant to laws and regulations, significant public interest, or legitimate interests, we may still be required or permitted to process certain personal data about you. If we are unable to restrict the processing of your data, we will always inform you. |
| Right to Data Portability | You have the right to request that we transmit personal data we hold about you to you or another company in a structured, commonly used, and machine-readable format, where technically feasible and lawful. Under laws and regulations, we may refuse to transmit certain personal data about you. If we are unable to transmit your data, we will always inform you. |
| Right to Human Review of Automated Decisions | If we make automated decisions that produce legal effects or otherwise significantly affect you, you have the right to request human review, provide supplementary information, and challenge the outcome. Before reviewing any part of your records, we may need to verify your identity and confirm whether a review is practically possible. |
| Right to Withdraw Consent | If we process personal data we hold about you based on your consent, you have the right to withdraw consent at any time (e.g., by operating in the application or website settings (if available), or by contacting our DPO). Withdrawal does not affect the lawfulness of processing based on consent prior to the withdrawal. |
| Right to Lodge a Complaint with the Supervisory Authority | If you believe your rights have been infringed, you also have the right to lodge a complaint with the supervisory authority (see the supervisory authority in Appendix I) and seek applicable remedies. If a third party exercises rights on your behalf, we need to verify their identity and confirm the legal qualification evidencing such agency. |
How do you exercise your rights?
To exercise any of the rights described in the preceding section, you may contact us (see contact information in Appendix I).
For security reasons, we cannot process your request unless we are satisfied as to your identity. Depending on the available channels, we may require you to provide identification again or authenticate by logging in. If you have authorized a third party, or a third party has other rights to act on your behalf, we may also require proof of their authorization or authority.
When you exercise a right, we will respond within 10 business days of receiving your request. In certain cases, if your request is complex or you have submitted multiple requests, this period may be extended by up to 5 business days. If we need more time, we will always notify you.
We do not charge a fee for exercising your rights. In certain countries/regions, the law allows us to charge a reasonable fee or refuse to process requests that are manifestly unfounded or excessive, where not prohibited.
If you are not satisfied with how we have handled your request, you have the right to file a complaint with the supervisory authority (see the supervisory authority in Appendix I) and seek applicable remedies.
Do we transfer your personal data to others?
Yes. We will transfer your personal data to third parties in the course of multiple purposes carried out jointly with or through such third parties (see Processing Purposes). Typically, we transfer your personal data to:
- Common infrastructure and common service providers: In most cases, we allocate all personal data to common infrastructure and common service providers worldwide to process your personal data under conditions of scalability, availability, integrity, and confidentiality, thereby integrating and improving our products and services and enhancing your experience. These may be cloud service providers in multiple countries/regions, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS) providers, or other IT hosting service providers.
- Financial institutions and other payment network participants: We transfer some of your personal data to financial institutions and other payment network participants worldwide to process virtual asset transfers and withdrawal transactions; or to enable us to provide products and services to you through various channels, or to enable them to provide their products and services within our channels.
- Blockchain network nodes: We query blockchain network nodes for on-chain public asset status information corresponding to custody accounts, to display custodial asset balances. We do not initiate or broadcast user transactions, nor do we transmit user transaction instructions.
- Markets or third-party channels where we provide products and services: We transfer some of your personal data to markets or third-party channels where we provide products and services, to provide indirect user support, or to allow you to view your products and services with us on your preferred channels.
- Identity verification and screening service providers: We transfer some of your personal data to identity verification and screening service providers worldwide to verify your identity; check records related to AML, CTF, AF, PEP status, and sanctions status; or verify risk ratings.
- Other technology and other service providers: We transfer some of your personal data to other technology and other service providers worldwide to conduct analysis; or provide security or customer support services on our behalf.
- Official authorities, including law enforcement agencies, regulatory authorities, or other administrative and judicial bodies: When required by applicable laws, regulations, or orders from such authorities, we transfer some of your personal data to official authorities (including law enforcement agencies, regulatory authorities, or other administrative and judicial bodies) worldwide to fulfill financial, tax, or other periodic reporting obligations; cooperate in preventing, detecting, and prosecuting crime through reporting and performing other relevant obligations; or when we deem it necessary to voluntarily cooperate with such activities in the significant public interest.
- Risk and background information agencies and associations of financial institutions and other payment network participants (if applicable): We transfer limited personal data to risk and background information agencies and associations of financial institutions and other payment network participants to coordinate efforts aimed at preventing, detecting, and prosecuting crime in the significant public interest.
- Third-party providers referred to you (if applicable): When you choose to participate in jointly hosted or co-branded events, products, and services, we transfer limited personal data to third-party providers worldwide.
- Marketing business partners (if applicable): When you choose to participate in promotions or events conducted jointly with them, we transfer limited personal data to marketing business partners worldwide.
Additionally, as part of a sale of some or all of our business and assets or any business restructuring or reorganization, we may transfer your personal data to any third party.
Other relevant aspects
We do not sell your personal data and only transfer it in accordance with this Privacy Statement, applicable laws and regulations, and appropriate safeguards.
When we transfer personal data outside of Mexico and any other country/region where we operate, we take measures to ensure your personal data is protected (as needed). Such transfers are typically conducted under the following conditions:
- Appropriate safeguards recognized by applicable data protection laws; or
- Standard Contractual Clauses (SCC) or equivalent data transfer mechanisms recognized by relevant authorities; or
- Adequacy decisions by relevant data protection authorities (where applicable).
In exceptional and limited cases, when the above safeguards are not available, we may rely on exceptions specified in applicable data protection laws. These include, but are not limited to:
- Transfers necessary for reasons of significant public interest;
- Transfers necessary for the establishment, exercise, or defense of legal claims; or
- Transfers based on your explicit consent (including your consent through this Privacy Statement or other privacy statements).
By accepting this Privacy Statement, you are deemed to have further consent to transfers outside of Mexico when strictly necessary and no other safeguards are available. Before giving this consent, please note that the level of data protection in certain countries/regions may not be fully equivalent to the level guaranteed within Mexico, and your rights may not always be enforceable in the same manner.
Nevertheless, we take strict internal measures to minimize these risks and ensure that any such transfers are secure and proportionate to their intended purpose.
In particular, as a virtual asset service provider and distributed ledger technology service provider, we may be required by law or regulation to transfer certain personal data outside of Mexico to official authorities (including law enforcement agencies, regulatory authorities, or other administrative and judicial bodies) as well as financial institutions and other payment network participants. Such disclosures are strictly limited to compliance with financial, tax, or other periodic reporting obligations; cooperation in preventing, detecting, and prosecuting crime through reporting and performing other relevant obligations; or when we deem it necessary to voluntarily cooperate with such activities in the significant public interest.
When we transfer your personal data, such third parties will act as processors or controllers. Third parties acting as processors will process your personal data following our instructions, and third parties acting as controllers may also independently determine the purposes and means of processing your personal data.
How do we protect your personal data?
We recognize the importance of protecting your personal data. Any personal data we process is treated with care and security.
We adopt various organizational and technical measures to:
- Maintain the confidentiality, availability, and integrity of your personal data;
- Ensure that your personal data is not misused; or
- Ensure that your personal data is not improperly disclosed.
Measures we take include:
- Detailed information security and personal data processing policies and procedures that all employees must comply with.
- Regular training for employees on information security and personal data processing.
- Access management controls to ensure that only authorized personnel can access personal data on a “need-to-know” basis.
- Encryption (including AES-256 encryption for data at rest and TLS/HTTPS encryption for data in transit), password protection, pseudonymization, or other controls for protected systems.
- User virtual asset storage employs a cold and hot wallet separation mechanism.
- Sensitive operations require multi-factor authentication.
- Secure communication protocols.
- Review and security assessment of third-party service providers or partners before sharing data.
- All third-party service providers or partners must enter into written agreements containing personal data protection obligations consistent with applicable data protection laws.
- Regular security audits, vulnerability scanning, and penetration testing.
- Real-time intrusion detection and automated security response mechanisms.
Please note: While we take reasonable measures to ensure the security of your personal data, no method of processing is 100% secure. You also have a responsibility to ensure the security of your account and credentials by protecting your passwords, PINs, one-time verification codes, security questions, email, and devices. Remember: we will never ask you for this information by phone, email, social media, or SMS.
How long do we retain your personal data?
We retain your personal data only for as long as necessary to achieve the purposes for which it was collected, and in compliance with legal and regulatory requirements.
In particular, as a regulated virtual asset service provider, we are required to retain certain personal data for specific periods in accordance with financial, tax, or other periodic reporting obligations, as well as crime-related obligations (crime prevention, detection, and prosecution). For example, under Mexico’s anti-money laundering law (the Federal Law for the Prevention and Identification of Operations with Illicit Proceeds), we are required to retain certain identification and transaction records for at least 10 years. Such retention periods vary by jurisdiction.
We may also extend the retention of your personal data in the following circumstances:
- There is ongoing or potential litigation; or
- Laws, regulations, or competent authorities require us to do so.
We have detailed data retention and deletion policies and procedures to ensure compliance with these requirements. After account deletion, we will delete or anonymize your information in accordance with legal requirements, subject to the aforementioned retention obligations.
How does blockchain technology affect you?
Our platform allows you to interact with blockchain technology. A blockchain is a distributed ledger consisting of digitally recorded data in the form of a chain of data packages called “blocks.” These blocks are linked in chronological order, meaning that once data is recorded, it is extremely difficult to alter. Additionally, since the ledger may be distributed across the globe (across multiple “nodes” or participants), this means that no single entity makes decisions or otherwise manages the system, nor does it have a centralized location.
Therefore, records on a blockchain cannot be altered or deleted by design, which is referred to as “immutability.” This affects the ability of you, us, and third parties to exercise rights over any data on a blockchain that may be linked to you (see Your Rights).
In most cases, (i) the final decision to transact on any blockchain using your virtual asset wallet address, and (ii) to share the public key associated with your virtual asset wallet address with anyone (including us), is yours.
This platform only provides asset custody and safekeeping and will not initiate, sign, or broadcast any blockchain transactions on your behalf; all on-chain transfer operations are completed by users in external systems.
Data on a blockchain is generally open to the public, and you may be associated with such data. If you wish to ensure that your privacy rights are not affected in any way, you should not transact on a blockchain, as certain rights may not be fully exercisable by you, us, or third parties.
How will we notify you of changes to this Privacy Statement?
If we change the way we use your personal data, we will update this Privacy Statement.
Where appropriate, we will also subsequently notify you directly, for example:
- Sending an email;
- Displaying an in-app notification; or
- Posting the update on our website.
We encourage you to review this Privacy Statement regularly to stay informed about how we protect your data.
Changes to the contact information and supervisory authorities in Appendix I or other formal changes may take effect without notice.
App Permissions and Third-Party SDKs
16.1 App Permissions
To provide complete services, our application may require the following device permissions. All permissions require your explicit authorization before use:
| Permission | Purpose |
|---|---|
| Camera | Used for capturing ID document photos and performing liveness detection for identity verification. Permission is only requested after you click the capture button. |
| Photo Album/Storage | Used for uploading ID document photos. We only access the images you actively select and do not read your entire photo album. |
| Notifications | Used to send you transaction status updates, security alerts, and important announcements. You may disable this at any time in your device settings. |
| Network Access | A fundamental requirement for the application to function properly, used for data transmission and server communication. |
| Wi-Fi Connection Information | Used to detect network connection status, ensuring account operations are performed under stable network conditions. |
| Device Information | Collects device identifiers and system information for anti-fraud and risk assessment purposes. |
| Advertising Identifier (AD_ID) | Used for advertising attribution analysis and personalized ad delivery. You may reset or restrict this feature in your device settings. |
16.2 Third-Party SDKs
Our application integrates the following third-party SDKs to support specific functionality:
| SDK Name | Purpose |
|---|---|
| Firebase (Google) | Firebase Cloud Messaging for push notifications; Firebase Crashlytics for crash log collection and application stability monitoring. |
| AppsFlyer | Used for advertising attribution analysis and marketing effectiveness measurement. |
| Google Analytics | Used for user behavior data analysis and product experience optimization. |
| Liveness Detection SDK | Used for facial recognition and liveness detection in KYC identity verification. |
| Facebook SDK | Used for monitoring advertising campaign effectiveness. |
| Google Play In-App Updates | Used for silent update detection and application version management. |
All of the above third-party SDKs are subject to strict contractual obligations and may only process relevant information when necessary for the provision of services, and may not use such information for other purposes. All data transmissions employ encrypted transmission protocols.
Appendix I — Company Information
| Item | Details |
|---|---|
| Company | Univerra, S.A. de C.V. |
| Country | Mexico |
| Data Protection Officer (DPO) | [Data Protection Officer Name] / Email: privacy@vitapay.com |
| Mailing Address | [Company Address], Mexico City, Mexico |
| Contact Information | Email: privacy@vitapay.com / Website: https://vita-pay.com |
| Supervisory Authority | Name: Secretaria Anticorrupcion y Buen Gobierno / Website: gob.mx/buengobierno |
Version Control
| Version | Date | Author | Key Changes |
|---|---|---|---|
| 1 | August 2026 | VitaPay Legal & Compliance Department | Created |
© 2026 Univerra, S.A. de C.V. All rights reserved.