This Payment Processing Service, provided by AAX Limited enabled by Facilitapay for the purchase and sale of Digital Assets for Brazilian and Mexican users on AAX Platform through locally acceptable means of payment, so that they can invest in these digital assets with the experience of a local investment.

This Payment Processing Privacy Policy sets out:

A. the information we collect about you (“user” or “you” or “your”) when you use the Payment Processing Service by Facilitapay at www.aax.com;

B. how we use and share, process to enable the Payment Transactions and

C. how you may access and control the information.

This Payment Processing Privacy Policy should be read in conjunction with our Payment Processing Terms of Use (Link) and also AAX Privacy Policy (https://www.aax.com/en-US/legal-privacy/terms-of-use/). For further information on how we store and secure your Personal Data, please refer to the AAX Privacy Policy.

“AAX Platform” collectively refers to our website at www.aax.com, our application(s), our application programming interfaces (“APIs”), our notifications and any information or content appearing therein.

“Data Controller” means natural person or legal entity, governed by public or private law, in charge of making decisions about the processing of personal data and in this context refers to AAX;

“Data Operator” means natural person or legal entity, governed by public or private law, which processes personal data in the name of the controller and in this context refers to Facilta;

“Payment Transaction” means transaction initiated by you for purchase and sale of Digital Assets using this Payment Processing Service;

1. What information we collect about you

1.1. When you register for an account on the AAX Platform, we collect the following types of information about you in accordance with our Privacy Policy:

(a) account and profile information and documents that you provide when you register for an account or sign up for our products or services, for example name, username, similar identifier, other personal description, occupation, date of birth, address, email address, phone number, identification number, identification documents such as passport or national identity cards or driving license, proof of address documents, income and wealth information (collectively known as “Account Data”);

(b) information you provide through support channels, for example when you report a problem to us or interact with our support team, including any contact information, documentation, or screenshots (collectively known as “Support Data”);

(c) communication, marketing, and other preferences that you provide us when you participate in a survey or a questionnaire that we send you (collectively known as “Preference Data”);

(d) details of any transactions, purchases, or orders that you've made with us (collectively known as “Transaction Data”);

(e) payment information, for example bank account information or payment details (collectively known as “Financial Data”);

(f) information about your device or connection, for example your internet protocol (IP) address, log-in data, browser type and version, time-zone setting, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our products or services and information we collect through cookies and other data collection technologies (please read our Cookies Policy for details) (collectively known as “Technical Data”); and

(g) Information about your use of or visit to our Platform, for example your clickstream to, through, and from our Platform, products you viewed, used, or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), or methods to browse away from the page (collectively known as “Usage Data”).

The data set out in paragraph 1.1(a) to (g) are collectively known as “Personal Information” or “Personal Data” and it refers to any aforesaid data, information, or combination of data and information that is provided by you to us, or through your use of our products or services, that relates to an identifiable individual.

1.2. We do not collect sensitive data or special category data about you. This includes details about your race, ethnic origin, politics, religion, trade union membership, genetics, biometrics, health, or sexual orientation.

2. Legal Basis for Collection and sharing of Personal Data for Payment Processing Service

2.1. We collect your Personal Information when you provide it to us or when you register for an account at AAX Platform.

2.2. Consent is the Legal Basis for sharing your Personal Data with AAX and Facilita for the Payment Processing Service. We will rely on your consent to use and share (i) Account Data for processing of your Payment Transactions using the Payment Processing Service; and (ii) Financial Data and Transaction Data for instructions in relation to the Payment Transactions. You may withdraw your consent at any time by contacting us using the information at the end of this Privacy Policy or by following an unsubscribe link in any marketing communication you receive from us. However if you withdraw consent you will not be able to use the Payment Processing Service.

3. How we use and share information for Payment Processing Service

3.1. AAX is the Data Controller when handling your Personal Data including your financial data. We make certain that we take the appropriate measures to ensure compliance with applicable data protection laws and regulations.

3.2. Facilita is the Data Operator when handling your Personal Data.

3.3. To provide you with the Payment Processing Service, AAX requires your consent to disclose your Account Data to Facilita for the following purpose:

3.3.1. Your name and identification documents for KYC verification prior to the Payment Transaction;

3.3.2. Source of funds/wealth (if requested) for source of funds verification and Enhanced Due Diligence;

3.3.3. Name, address and account number or IBAN to the banks involved or the operators of payment and communication for debit instructions to your card, bank or payment account.

3.4. The data will only be shared with Facilita and only for the purpose of the Payment Transactions and for no other purpose.

3.5. Facilita may share your Personal Data and Transaction Data with government and law enforcement officials to comply with applicable laws or regulations, for example when we respond to claims, legal processes, law enforcement, or national security requests.

3.6. All payments or receipts to and from abroad that Facilita transacts contain information on the beneficiaries of the transactions and origin of the funds, with an exchange record between Facilita and the international company, in compliance with BACEN Circulars 3,691/2013 and 3,813/2016. All banks that settle Facilita's operations have copies of these transactions and are responsible for informing BACEN about such transactions when required by the regulatory body.

4. Your Rights

4.1. You have the right to:

(a) be informed of what we do with your Personal Information;

(b) request a copy of Personal Information we hold about you;

(c) require us to correct any inaccuracy or error in any Personal Information we hold about you;

(d) request erasure of your personal information (note, however, that we may not always be able to comply with your request of erasure for record keeping purposes, to complete transactions, or to comply with our legal obligations);

(e) object to or restrict the processing by us of your personal information (including for marketing purposes);

(f) request to receive some of your personal information in a structured, commonly used, and machine readable format, and request that we transfer such information to another party; and

(g) withdraw your consent at any time where we are relying on consent to process your personal information (although this will not affect the lawfulness of any processing carried out before you withdraw your consent).

4.2. As a security measure, we may need specific information from you to help us confirm your identity when processing your privacy requests or when you exercise your rights.

4.3. Any request under paragraph 4.1 will normally be addressed free of charge. However, we may charge a reasonable administration fee if your request is clearly unfounded, repetitive, or excessive.

4.4. We will respond to all legitimate requests approximately within 15 days. Occasionally, it may take us longer than 15 days if your request is particularly complex or if you have made a number of requests

5. Changes to this policy

6. We reserve the right to amend this Privacy Policy from time to time by posting the updated Privacy Policy on our Platform. By continuing to use our Platform after the changes come into effect, you agree to be bound by the revised policy.

a. Contact us

You may contact us at: cs@aax.com if you have any concerns about this policy and your personal information or if you would like to file a data request.

Did this answer your question?