Privacy Policy

Last Updated: 1.09.2026

1. Introduction

RIEGEL DEL SUR, S.A.S. DE C.V. ("Company", "we", "us", "our"), a simplified joint-stock company with variable capital (Sociedad por Acciones Simplificada de Capital Variable) duly organized under the laws of the Republic of El Salvador, registered with the Commercial Registry under No. 198, Book 4957 of the Companies Registry, with Business Registration No. 2026135109, and Tax ID (NIT) 9311-020271-101-9, is committed to protecting the privacy of individuals who use our platform available at https://puento.tech/ (the "Platform").

This Privacy Policy explains how we collect, use, disclose, and safeguard your Personal Data when you access or use our Platform. It complies with applicable data protection legislation, including the Law on Personal Data Protection (Ley de Proteccion de Datos Personales, Legislative Decree No. 144) and its implementing regulations, as well as other applicable laws of the Republic of El Salvador.

By using the Platform, you consent to the collection and processing of your Personal Data as described in this Privacy Policy.

2. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject").

"Processing" means any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, or erasure.

"Data Controller" means the entity that determines the purposes and means of Processing Personal Data - in this case, RIEGEL DEL SUR, S.A.S. DE C.V.

"Data Processor" means a natural or legal person that Processes Personal Data on behalf of the Data Controller.

"ACE" means the State Cybersecurity Agency (Agencia de Ciberseguridad), El Salvador's data protection supervisory authority.

"Sensitive Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health information, sexual orientation, genetic data, or biometric data used for identification.

3. Personal Data We Collect

We may collect the following categories of Personal Data from you:

3.1 Information You Provide Directly

Registration Data: full name, email address, phone number, date of birth, residential address, country of residence.

Identity Verification Data (KYC): government-issued identification documents (passport, national ID, or driver's license), selfie/photograph for identity verification, proof of address (utility bill or bank statement). This data is collected through our KYC provider, Sumsub.

Financial Records: cryptocurrency wallet addresses, transaction history, deposit and withdrawal records, exchange/swaps history, and other financial information related to your use of the Platform.

Correspondence: any communications you send to us, including inquiries, support requests, and complaints.

3.2 Information Collected Automatically

Device Information: IP address, browser type and version, operating system, device type, unique device identifiers.

Usage Data: pages visited, time spent on the Platform, click patterns, features used, transaction frequency and volume.

Analytics Data: aggregated usage statistics, session recordings, user behavior metrics collected through analytics tools integrated into the Platform.

Crash Logs: technical logs generated when the Platform encounters errors, including device state, time of crash, and actions leading up to the crash.

SDK Data: information collected by third-party software development kits (SDKs) integrated into the Platform, which may include device identifiers, IP addresses, and usage statistics for functionality and analytics purposes.

3.3 Information from Third Parties

From Sumsub (KYC Provider): identity verification results, including document authenticity confirmation, liveness check results, and screening outcomes against sanctions and PEP lists.

From blockchain analytics providers: risk scores and analyses of cryptocurrency wallet addresses involved in transactions.

4. Purposes of Processing

We Process your Personal Data for the following purposes:

To create and maintain your account on the Platform.

To verify your identity in compliance with our AML/CFT obligations under the Law Against Money Laundering and Asset Laundering (LCLDA) and the Special Law for the Prevention of ML/TF/FPWMD (Decree No. 426 of 2025).

To process cryptocurrency swaps and other transactions you initiate.

To detect, prevent, and investigate fraud, money laundering, terrorist financing, and other illegal activities.

To communicate with you regarding your account, transactions, and support requests.

To improve and optimize the Platform through analytics and crash log analysis.

To comply with legal and regulatory obligations applicable to us under Salvadoran law.

To enforce our Terms of Use and other applicable policies.

5. Legal Basis for Processing

Under the Personal Data Protection Law of El Salvador, we process Personal Data on the following legal bases:

Your explicit, informed consent - collected at registration and at the time of data collection, which you may withdraw at any time (subject to legal retention requirements). Pre-checked boxes are not used; consent must be given by an affirmative action.

Performance of a contract - processing necessary to provide the services you request under our Terms of Use.

Compliance with legal obligations - processing required to comply with AML/CFT laws, sanctions regimes, and other applicable regulations.

Legitimate interests - processing for fraud prevention, Platform security, and business improvement, balanced against your rights and interests.

6. Data Retention and Deletion

6.1 Data Deleted Immediately After Purpose Fulfillment

Selfie photographs and biometric data used for liveness verification - deleted immediately after the verification result is obtained.

Temporary session data and cached identifiers - cleared upon logout or session expiry.

Raw video streams and images captured during the KYC process - not retained beyond the verification session except for audit-compliant records as required by law.

6.2 Data Retained for Legal and Operational Purposes

We retain certain data for the periods required by applicable law or as necessary for our business operations:

KYC/AML records (including identification documents, verification results, and screening outcomes): retained for at least fifteen (15) years after the closure of your account or the end of the business relationship, as required by Article 12 of the LCLDA.

Transaction records: retained for at least five (5) years after the transaction date, as required by applicable AML/CFT regulations.

Account and registration data: retained for the duration of your account and for a reasonable period thereafter to comply with legal obligations.

Communications and support records: retained for three (3) years after the resolution of the matter.

Crash logs and technical error data: retained for up to ninety (90) days for debugging and platform improvement purposes.

Analytics data (aggregated and anonymized): retained for business intelligence purposes; where data can no longer be anonymized, it is deleted or de-identified after twenty-four (24) months.

SDK-related logs: retained in accordance with the retention policies of the respective SDK providers, typically not exceeding twelve (12) months.

7. Data Sharing and Disclosure

We may share your Personal Data with the following categories of recipients:

7.1 Service Providers and Processors

KYC/identity verification provider - receives your identity documents and biometric data for verification purposes.

Blockchain analytics providers - receive transactional data to perform risk assessments on cryptocurrency addresses.

Cloud hosting and infrastructure providers - store encrypted backend data, including databases and crash logs.

Analytics service providers - receive aggregated, anonymized usage data.

SDK providers - receive device and usage data as described in Section 3.2.

7.2 Legal and Regulatory Disclosures

To the Financial Investigation Unit (Unidad de Investigacion Financiera - UIF) of the Attorney General's Office of El Salvador, in compliance with suspicious transaction reporting obligations.

To the National Commission for Digital Assets (Comision Nacional de Activos Digitales - CNAD) or the Central Reserve Bank (BCR) as applicable.

To law enforcement agencies, courts, or government authorities when required by applicable law, court order, or legal process.

To comply with international sanctions regimes, including UN Security Council resolutions and OFAC sanctions.

7.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or substantially all of our assets, your Personal Data may be transferred to the successor entity, subject to this Privacy Policy.

7.4 No Sale of Personal Data

We do not sell, rent, or trade your Personal Data to third parties for their marketing purposes.

8. International Data Transfers

Your Personal Data may be transferred to and processed in countries outside the Republic of El Salvador, including where our service providers are located. When we transfer Personal Data internationally, we ensure appropriate safeguards are in place in accordance with the Personal Data Protection Law, including:

Ensuring the recipient country provides an adequate level of data protection equivalent to or greater than that provided in El Salvador.

Entering into data transfer agreements that incorporate standard data protection clauses.

Obtaining your explicit consent to the international transfer after informing you of the possible risks.

9. Data Security

We implement appropriate technical and organizational measures to protect your Personal Data against unauthorized access, alteration, disclosure, or destruction, in compliance with the security requirements of the Personal Data Protection Law of El Salvador. These measures include:

Encryption of data in transit (TLS 1.2+ protocols) and at rest (AES-256).

Access controls and authentication mechanisms restricting access to Personal Data on a need-to-know basis.

Regular security audits and vulnerability assessments.

Incident response procedures for data breaches, including notification to ACE within 72 hours of becoming aware of a breach, and notification to affected data subjects as required by law.

Data Protection Impact Assessments (DPIA) for high-risk processing activities.

Employee training on data protection and confidentiality obligations.

10. Your Data Protection Rights

Under the Personal Data Protection Law of El Salvador (ARCO-POL rights), you have the following rights regarding your Personal Data:

Right of Access (ARCO): You have the right to obtain confirmation of whether we are processing your Personal Data and, if so, to request access to such data and information about the processing.

Right of Rectification: You have the right to request the correction of inaccurate or incomplete Personal Data.

Right of Cancellation/Deletion: You have the right to request the deletion of your Personal Data when it is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.

Right of Opposition: You have the right to object to the processing of your Personal Data for legitimate reasons related to your particular situation.

Right to Data Portability: You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Erasure (Right to be Forgotten): You have the right to request the deletion of your Personal Data under certain circumstances.

Right to Withdraw Consent: You have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

Right to Lodge a Complaint: You have the right to lodge a complaint with ACE (Agencia de Ciberseguridad) if you believe that your data protection rights have been violated.

To exercise any of these rights, please contact us as specified in Section 15. We will respond to your request within the timeframes established by applicable law.

11. Cookies and Tracking Technologies

Our Platform may use cookies, web beacons, and similar tracking technologies to enhance user experience, analyze usage patterns, and provide functionality. We use:

Essential cookies - necessary for the operation of the Platform.

Analytics cookies - to collect information about how users interact with the Platform, enabling us to improve its performance.

Session cookies - temporary cookies that are deleted when you close your browser.

You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Platform. Where required by law, we obtain your prior consent before placing non-essential cookies.

12. Third-Party Services and SDKs

Our Platform integrates third-party services and SDKs that may collect certain information automatically. These include:

Sumsub SDK - for identity verification and KYC processes. Sumsub's privacy practices are governed by their own privacy policy.

Analytics SDKs - for tracking usage patterns and Platform performance.

Blockchain analytics SDKs - for screening cryptocurrency wallet addresses against risk indicators.

We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

13. Children's Privacy

Our Platform is not intended for individuals under the age of eighteen (18). We do not knowingly collect Personal Data from minors. If we become aware that a minor has provided us with Personal Data, we will take steps to delete such information.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. Material changes will be notified to you through the Platform or by email at least fifteen (15) days before they become effective. Your continued use of the Platform after the effective date constitutes your acceptance of the updated Privacy Policy.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your Personal Data, please contact us:

Company
RIEGEL DEL SUR, S.A.S. DE C.V.
Sole Administrator
Rainer Friederich Jackle
Address
Avenida El Espino, Colonia San Benito, Centro Comercial Estacion del Casco, Third Level, STOFFICENTER, Office 10, San Salvador, El Salvador
Email
complience@puento.tech
Data Protection Contact
complience@puento.tech
Supervisory Authority
Agencia de Ciberseguridad (ACE) - Republic of El Salvador