Legal / Data Protection

Paymesh Privacy Policy

Brazil (LGPD) - Card-Funded Stablecoin Ramp Programme with Avenia

Paymesh LTDA ("Paymesh", "we", "us" or "our") is committed to protecting personal data and processing it transparently, securely and in accordance with applicable data protection law, including Brazil's Lei Geral de Proteção de Dados Pessoais – LGPD (Law No. 13,709/2018).

This Privacy Policy explains how Paymesh handles personal data when you visit or use pay-mesh.com, dev.pay-mesh.com, docs.pay-mesh.com, support.pay-mesh.com, any other website, application, page, API or customer interface operated by Paymesh, and the related services we make available (collectively, the "Services").

For eligible card-funded stablecoin transactions, Paymesh operates the customer-facing technology, compliance-integration and transaction-orchestration layer. In Brazil, Avenia acts as the Brazilian ramp provider and the regulated virtual-asset service provider responsible for the regulated virtual-asset intermediation and custody functions. Paymesh may also work with other regional ramp partners for services made available outside Brazil.

This Privacy Policy does not replace any privacy notice separately provided by Avenia, a regional ramp partner, a card issuer, an acquirer, a card network or another independent controller involved in a transaction.

If you have questions about this Policy or wish to exercise your privacy rights, contact privacy@pay-mesh.com.

1. Who is responsible for your personal data?

1.1 Paymesh LTDA

For the Paymesh account, customer interface, website, customer support, platform security, fraud prevention, product administration, transaction orchestration, service analytics, communications and Paymesh's own legal and compliance obligations, the principal Paymesh entity responsible for the processing described in this Policy is:

PAYMESH LTDA

CNPJ: 50.522.210/0001-18

Av. Presidente Juscelino Kubitschek n° 1545, 6° Floor, Vila Nova Conceição, São Paulo/SP, Brazil

Email: privacy@pay-mesh.com

For these purposes, Paymesh generally acts as a controller ("controlador") under the LGPD because it determines the relevant purposes and means of processing.

1.2 Processing performed for Avenia

In connection with the Brazilian cardholder stablecoin wallet-loading programme, Paymesh may collect, verify, transmit, organize or otherwise process certain customer and transaction data within policies, criteria and parameters established or approved by Avenia.

To the extent Paymesh processes personal data solely on documented instructions from Avenia for Avenia's regulated virtual-asset services, Paymesh may act as an operator ("operador") for that specific processing activity. The precise controller/operator allocation depends on the purpose of the processing, the applicable contractual arrangements and the factual operation of the service.

1.3 Avenia

Avenia separately determines the purposes and means of processing required to provide and supervise its regulated virtual-asset services, including customer eligibility for those services, regulated transaction approval, virtual-asset execution, custody, wallet controls, blockchain monitoring, suspicious-activity analysis and regulatory reporting. For those purposes, Avenia acts as a separate controller of the relevant personal data.

Paymesh does not make Avenia's final regulatory decisions, does not control the customer's private keys or custodial assets, and does not independently execute the regulated virtual-asset transfer.

1.4 Other regional ramp and payment partners

Outside Brazil, another regional ramp provider or regulated service provider may be responsible for the conversion, custody, settlement or other regulated part of a transaction. Such entities may act as independent controllers for processing they determine is necessary for their own legal, regulatory, payment or service obligations.

Card networks, acquirers, processors, issuers, financial institutions and other payment participants may also act as independent controllers where they determine the purposes and means of their own processing.

2. Data Protection Officer / Encarregado

Paymesh maintains a privacy contact channel at privacy@pay-mesh.com.

The Encarregado acts as a communication channel between Paymesh, data subjects and the Brazilian data protection authority, the Agência Nacional de Proteção de Dados (ANPD), in accordance with applicable law.

3. Scope and service availability

This Privacy Policy applies to personal data processed through the Services regardless of whether a particular Paymesh product is available in your country.

Service availability is determined separately under the applicable Terms and Conditions, sanctions controls, card-network rules, partner requirements and local law. If you are in a jurisdiction where a Service is unavailable, we may still process limited personal data, such as IP address, device information, location indicators or verification information, where necessary to determine eligibility, prevent fraud, protect the platform or comply with law.

We do not use citizenship alone as a privacy-law basis for refusing to recognize a person's rights in personal data already held by Paymesh.

4. Personal data we collect

The data we collect depends on the Services you use, your jurisdiction, the transaction type and the level of verification required.

4.1 Information you provide directly

We may collect:

  • Account and contact data: full name, email address, telephone number, residential address, date of birth, account credentials and customer identifiers.
  • Identity and verification data: CPF or other tax or national identifier where required, passport, national identity card or other government-issued identification, document images, document numbers, nationality, country of residence, selfie, liveness check and other identity-verification information.
  • Sensitive personal data: biometric data used for identity verification, authentication and fraud prevention. Biometric data is treated as sensitive personal data under the LGPD.
  • Financial and payment data: payment-card details and payment metadata necessary for the transaction, which may include tokenized card information, BIN, last four digits, issuer information, 3DS/authentication information, authorization results, chargeback or dispute information and transaction references. Full payment-card data is handled only through approved payment and PCI-compliant channels where applicable.
  • Source-of-funds and enhanced due-diligence data: information or documents concerning source of funds, source of wealth, occupation, employment, business activity or transaction purpose where required by risk or compliance controls.
  • Transaction and order data: asset type, order amount, fiat amount, quoted price, fees disclosed by the responsible provider, timestamps, order status, payment authorization data, transaction identifiers and the custodial wallet identifier or destination wallet information applicable to the approved ramp flow.
  • Support and communications data: messages, emails, support requests, complaint information, call or chat records where recorded, survey responses and other information you provide when communicating with us.
  • Business relationship data: where you interact with Paymesh in a business capacity, your employer, role, business contact details, corporate information and information relating to the business relationship.

4.2 Information collected automatically

When you use the Services, we may collect:

  • IP address and approximate location derived from IP or device data;
  • device identifiers, device fingerprint and device-risk indicators;
  • browser type and version, operating system, language and time-zone information;
  • authentication activity, login records and account-security events;
  • cookie, session and website interaction data;
  • page views, clickstream and service usage information;
  • fraud, abuse, bot, proxy, VPN and account-takeover indicators; and
  • technical logs required to operate, secure, troubleshoot and audit the Services.

Precise GPS location is collected only where the relevant feature requires it and where permitted by law and device permissions.

4.3 Information from third parties

We may receive personal data from:

  • Avenia, including transaction status, custodial wallet references, regulated approval status, blockchain or wallet-risk results and other information necessary to coordinate the Brazilian ramp transaction;
  • other regional ramp partners supporting transactions outside Brazil;
  • identity, KYC and biometric providers, including Persona;
  • fraud and transaction-risk providers, including nSure.ai;
  • card networks, including Visa, acquirers, processors, issuers and other payment participants;
  • financial institutions and payment service providers;
  • sanctions, PEP, adverse-media, fraud-prevention and public-record databases;
  • blockchain analytics or wallet-screening providers where relevant to a supported service;
  • corporate or business counterparties; and
  • public sources where permitted by law.

We do not treat a positive result from an automated provider as conclusive where other information creates a material identity, fraud or compliance concern.

5. How the Brazil ramp data flow works

For an eligible card-funded stablecoin transaction in Brazil, personal data may be processed through the following operational sequence:

  1. You create or access a Paymesh account and provide the required identification and transaction information.
  2. Paymesh and its approved providers perform identity, biometric, authentication, fraud and risk checks.
  3. Paymesh routes the card transaction through the applicable acquiring, processing and card-network infrastructure.
  4. Paymesh transmits the information required by Avenia to assess and process the regulated virtual-asset service.
  5. Avenia retains ultimate authority over the regulated customer and transaction decision and, if approved, executes or ensures execution of the stablecoin credit to the customer's custodial wallet.
  6. Paymesh correlates the card, order and Avenia transaction records for customer support, fraud prevention, reconciliation, audit and service administration.

Paymesh's messages to Avenia concerning a wallet credit or stablecoin credit are technological or operational messages. Paymesh does not use those messages to exercise independent custody or control over the customer's virtual assets.

6. Why we use personal data and our legal bases

Under the LGPD, Paymesh processes personal data only where a valid legal basis applies. Depending on the activity, we may rely on one or more of the following:

6.1 Performance of a contract or pre-contractual steps

We process data where necessary to create and administer your account, provide the Paymesh interface, process your request, coordinate an eligible transaction, provide support, issue confirmations and perform other steps you request in connection with the Services.

6.2 Compliance with legal or regulatory obligations

We process data where necessary to comply with obligations applicable to Paymesh, or to support required controls within the regulated service framework applicable to Avenia or another partner, including identity verification, sanctions controls, recordkeeping, fraud prevention, dispute handling and lawful requests from competent authorities.

6.3 Legitimate interests

Where permitted by law and after considering necessity and the rights of affected individuals, we may process personal data for legitimate interests including:

  • securing the Services and customer accounts;
  • preventing fraud, abuse, account takeover and payment disputes;
  • maintaining audit trails and operational resilience;
  • improving service performance and reliability;
  • investigating errors and complaints;
  • defending legal claims and protecting Paymesh, customers and partners; and
  • limited business analytics and product improvement.

Where we rely on legitimate interests, we apply data-minimization, access-control and proportionality measures appropriate to the risk.

6.4 Fraud prevention and security involving biometric data

Where permitted under the LGPD, biometric data may be processed where indispensable to prevent fraud and protect the security of the data subject in electronic identification and authentication processes, subject to the rights and safeguards provided by law.

6.5 Exercise of rights

We may process personal data where necessary for the regular exercise of rights in judicial, administrative, arbitration, dispute, chargeback or other legal proceedings.

6.6 Consent

We rely on consent where required by law, including for certain optional marketing, cookies or other processing that is not necessary for the core Service. Where processing is based on consent, you may withdraw it as described below.

7. KYC, AML, sanctions, fraud and transaction monitoring

Paymesh performs or integrates customer-facing identification, KYC, biometric verification, eligibility, authentication, fraud-prevention and transaction-monitoring controls as part of its operating role.

In the Brazilian ramp programme, these controls operate within the policies, criteria and parameters established or approved by Avenia for the regulated virtual-asset service. Avenia retains the ultimate regulatory authority over customer eligibility for its service, final regulated transaction decisions, suspicious-activity analysis, legally required restrictions and regulatory reporting.

Paymesh may place a technological or fraud hold on an account or transaction where its own security or fraud controls are triggered, where required information is incomplete, or where Avenia or another authorized participant instructs Paymesh to restrict the workflow.

8. Automated processing and review

Paymesh and its service providers use automated tools to assist with identity verification, biometric matching, fraud detection, sanctions and PEP screening, device-risk assessment, transaction monitoring, authentication and account-security decisions.

Automated tools may result in a transaction being paused, rejected or referred for manual review. In the Brazilian regulated ramp flow, Avenia retains the ability to establish, approve, modify or override the regulatory criteria applicable to its virtual-asset service.

Where the LGPD gives you the right to request review of a decision made solely on the basis of automated processing that affects your interests, you may submit a request to privacy@pay-mesh.com. Subject to applicable law and protection of commercial and industrial secrets, we will provide information about the criteria and procedures used for the relevant automated processing.

9. How we share personal data

We disclose personal data only where there is a legitimate and lawful purpose. Depending on the Service, recipients may include:

  • Avenia, for the Brazilian regulated ramp, virtual-asset intermediation, custody, wallet, blockchain-control and regulatory functions;
  • other regional ramp partners, where a different regulated provider supports a transaction outside Brazil;
  • Persona, for identity, document and biometric verification and related compliance controls;
  • nSure.ai, for transaction-level fraud and risk monitoring;
  • Visa and other card networks, acquirers, processors, issuers and payment institutions, for authorization, authentication, clearing, settlement, fraud, dispute management and compliance with applicable card-network requirements;
  • cloud-hosting, cybersecurity, communications, customer-support, analytics and technical service providers;
  • professional advisors, auditors, insurers and consultants subject to appropriate confidentiality duties;
  • law-enforcement agencies, regulators, courts, tax authorities and other competent authorities where disclosure is legally required or permitted;
  • parties involved in a merger, acquisition, financing, restructuring or sale of all or part of Paymesh's business, subject to appropriate confidentiality and data-protection safeguards; and
  • other persons where you have specifically authorized disclosure or where disclosure is otherwise lawful.

Paymesh does not sell personal data in the ordinary course of business and does not permit service providers acting solely on our behalf to use personal data for their own unrelated marketing purposes.

10. Avenia and other independent controllers

Avenia and other regional ramp or payment partners may process personal data for their own legal and regulatory purposes. Their processing may include identity verification, sanctions screening, transaction approval, custody, wallet monitoring, blockchain analytics, suspicious-activity analysis, regulatory reporting, payment processing, dispute management and recordkeeping.

Where another entity acts as an independent controller, its processing is governed by its own privacy notice and legal obligations. Paymesh may assist you in identifying or contacting the relevant provider, but Paymesh cannot delete, amend or override data independently controlled by another entity unless Paymesh is authorized to do so.

11. International transfers of personal data

Paymesh is based in Brazil but uses service providers and infrastructure that may process personal data in other countries. Personal data may therefore be transferred from Brazil to jurisdictions in which Paymesh affiliates, cloud providers, identity-verification providers, fraud providers, ramp partners, payment participants or other service providers operate.

International transfers are permitted only where a valid mechanism under the LGPD and applicable ANPD rules is available. Depending on the transfer, this may include:

  • a country or international organization recognized by the ANPD as providing an adequate level of protection;
  • the ANPD's standard contractual clauses;
  • specific contractual clauses approved by the ANPD;
  • binding corporate rules/global corporate standards approved under applicable rules; or
  • another transfer mechanism expressly permitted by Article 33 of the LGPD.

Where contractual transfer mechanisms are used, Paymesh requires appropriate data-protection, security, confidentiality and onward-transfer safeguards.

You may contact privacy@pay-mesh.com to request additional information about the international-transfer mechanisms applicable to your personal data, subject to appropriate protection of confidential information.

12. Security of personal data

Paymesh maintains technical and organizational safeguards designed to protect personal data against unauthorized access, destruction, loss, alteration, communication or unlawful processing.

Controls may include, as appropriate:

  • role-based and least-privilege access controls;
  • authentication and privileged-access controls;
  • encryption in transit and at rest where appropriate;
  • secure API and integration controls;
  • logging, monitoring and audit trails;
  • fraud and account-takeover detection;
  • segregation of environments and security responsibilities;
  • vulnerability management and incident response;
  • vendor due diligence and contractual security requirements;
  • backup, continuity and recovery arrangements; and
  • staff confidentiality and security training.

Payment-card data is handled through approved payment infrastructure and PCI-compliant environments where applicable to the relevant system or provider.

No system is completely secure. If you believe your account or personal data has been compromised, contact us promptly at privacy@pay-mesh.com or through Paymesh support.

13. Security incidents

Where Paymesh is the controller of affected personal data, we assess personal-data security incidents and notify the ANPD and affected data subjects where required by the LGPD and applicable ANPD rules.

Where Paymesh is acting as an operator for Avenia or another controller, Paymesh will notify and support the relevant controller in accordance with applicable law and contractual incident-response requirements so that the controller can make any required regulatory or data-subject notifications.

Paymesh maintains records of reportable and non-reportable security incidents for the periods required by applicable law and internal governance requirements.

14. Retention and deletion

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for any additional period required or permitted by law.

Retention periods may depend on:

  • account and contractual requirements;
  • KYC, AML, sanctions, fraud and financial-crime controls;
  • card-network, payment, dispute and chargeback requirements;
  • tax, accounting and regulatory recordkeeping;
  • legal claims, investigations and litigation holds;
  • security, audit and incident records; and
  • requirements imposed on Avenia or another regulated service provider where Paymesh is required to preserve supporting records.

After the applicable retention period ends, personal data is deleted, securely destroyed or anonymized, unless continued retention is permitted or required under Article 16 of the LGPD or another applicable law.

Closing your Paymesh account does not necessarily result in immediate deletion of all records where continued retention is legally required or necessary to establish, exercise or defend legal rights.

15. Children's data

The consumer Services covered by this Policy are intended for persons aged 18 or older, or the higher age of majority applicable in their jurisdiction.

We do not knowingly permit minors to use the applicable consumer ramp Services. If we learn that a minor has provided personal data in connection with an ineligible account, we will restrict the account and address the data in accordance with applicable law, including any retention obligation that prevents immediate deletion.

16. Marketing, cookies and analytics

Paymesh may send marketing communications where permitted by law. Where consent is required, we will obtain it before sending the relevant marketing communication.

You may opt out of marketing at any time using the unsubscribe mechanism in the communication, your available account settings, or by contacting privacy@pay-mesh.com. Opting out of marketing does not prevent us from sending security, compliance, account, transaction or other service communications that are necessary to operate the Services.

We may use cookies and similar technologies for essential functionality, authentication, security, fraud prevention, analytics and, where permitted, marketing. Non-essential cookies are subject to the consent and preference controls required by applicable law. Additional details may be provided in our Cookie Policy or cookie-management interface.

17. Your rights under the LGPD

Subject to the conditions and exceptions in applicable law, a data subject in Brazil may request:

  • confirmation that Paymesh processes their personal data;
  • access to personal data held by Paymesh;
  • correction of incomplete, inaccurate or outdated data;
  • anonymization, blocking or deletion of unnecessary or excessive data or data processed in violation of the LGPD;
  • portability of data to another service or product provider, where applicable and subject to ANPD regulation and protection of commercial and industrial secrets;
  • deletion of personal data processed on the basis of consent, subject to lawful retention exceptions;
  • information about public and private entities with which Paymesh has shared personal data;
  • information about the possibility of refusing consent and the consequences of doing so where consent is requested;
  • withdrawal of consent where consent is the legal basis;
  • opposition to processing based on a legal basis other than consent where the requirements of the LGPD are not being observed;
  • review of decisions made solely through automated processing that affect the data subject's interests, where applicable;
  • information concerning the criteria and procedures used for relevant automated decisions, subject to protection of commercial and industrial secrets; and
  • petition to the ANPD or competent consumer-protection bodies in accordance with applicable law.

To exercise a right, contact privacy@pay-mesh.com. We may request information reasonably necessary to verify your identity and protect your account before acting on a request.

Requests are handled free of charge where required by law. We may refuse or limit a request where the law permits or requires us to retain or continue processing particular information, in which case we will explain the applicable basis where required.

If the requested data is controlled by Avenia, a regional ramp provider, a card issuer or another independent controller, we may direct or forward the request to the appropriate entity where permitted.

18. Rights outside Brazil

If another privacy law applies to you because of your location or the way Paymesh offers Services in your jurisdiction, you may have additional rights beyond those described above.

This may include rights available under the EU General Data Protection Regulation, UK GDPR, Swiss data-protection law or other applicable privacy legislation. Paymesh will honor such rights where the relevant law applies to the processing.

You may use privacy@pay-mesh.com as the initial contact channel for privacy requests regardless of jurisdiction.

19. Data of job applicants and business contacts

If you apply to work with Paymesh, we may process your name, contact information, CV/resume, professional history, qualifications, interview information, references, eligibility-to-work information and other data reasonably necessary to evaluate and administer the application.

If you interact with Paymesh on behalf of a merchant, supplier, investor, professional adviser, service provider or other organization, we may process your professional contact details, role, communications and relationship information for business administration, due diligence, contract management, compliance and security.

These processing activities are subject to the same security, retention, international-transfer and data-subject-rights principles described in this Policy, as applicable.

20. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, regulation, regulatory guidance, our technology, our providers, our product structure or our processing activities.

The "Effective Date" above indicates when this version takes effect. Where a change materially affects the way we use personal data or where applicable law requires direct notice, we will provide appropriate notice through the Site, account interface, email or another suitable channel.

21. Contact and complaints

For privacy questions, requests or complaints, contact:

Paymesh LTDA

CNPJ: 50.522.210/0001-18

Av. Presidente Juscelino Kubitschek n° 1545, 6° Floor, Vila Nova Conceição, São Paulo/SP, Brazil

Contact: privacy@pay-mesh.com

If you believe your rights under the LGPD have not been respected, you may also have the right to petition the ANPD after first contacting the relevant controller through its official privacy channel, and may have rights before applicable consumer-protection authorities.