Legal — 01
Terms & Conditions
SAF SV, S.A.S. de C.V. · Version 2.0 — B2B / B2B2C · 06/05/2026
These Terms & Conditions establish the base contractual framework under which SAF SV, S.A.S. de C.V. (“saf.”) provides digital-asset services to previously approved Corporate Clients under an institutional B2B / B2B2C model.
This document summarizes the operational sections (definitions, nature of the service, obligations, compliance, technical custody, fees, continuity, data, complaints, suspension, risks, liability and modifications) applicable to the relationship between saf. and its Corporate Clients.
Definitions
- saf.
- SAF SV, S.A.S. de C.V., a Salvadoran company applying for registration as a Digital-Asset Service Provider (PSAD) and operator of the infrastructure described in these Terms.
- Corporate Client / B2B partner
- Legal entity approved by saf. via KYB that contracts services, integrates saf. infrastructure and maintains the direct relationship with its end users.
- End user
- Natural or legal person served by the Corporate Client. Their primary KYC is the responsibility of the Corporate Client, without prejudice to saf.'s right to request information, review files, block operations or suspend services.
- Services
- Digital-asset services, technical infrastructure, conversion, transfer, temporary technical custody, order reception/transmission, reconciliation, reporting and related settlement, as per contract, annex and approved matrix.
- Digital asset
- Digital representation of value or right whose transmission, custody, administration or conversion is performed through distributed-ledger or analogous technology, within the approved flow.
- Ultimate Beneficial Owner (UBO)
- Natural person who ultimately owns or controls, directly or indirectly, the Corporate Client, including anyone with 25% or more of capital, voting rights, economic rights or effective control.
- Account, wallet or subaccount
- Technical, logical, operational or accounting structure used to identify balances, instructions, assets, records or transactions of a Corporate Client and, where applicable, an end user or operation.
- Technical custody
- Receipt, safekeeping, technical administration, signing, operational control or temporary availability of digital assets or access/control means within authorized flows.
- Order / instruction
- Request, message, API call, file, record or authorized instruction from the Corporate Client to initiate, modify, query, cancel, settle or close an operation.
- Transaction
- Movement, conversion, transfer, settlement, receipt or transmission of order associated with a Corporate Client, end user, beneficiary, wallet, account, amount, asset, currency, date and status.
- Controlled reliance
- Mechanism whereby saf. uses information, verifications or evidence generated by a Corporate Client regarding its end users, always under documented, verifiable, auditable and revocable conditions. It does not transfer or eliminate saf.'s regulatory responsibility.
- Minimum data
- Information required to attribute, monitor, execute, reconcile, report and reconstruct an operation, including client, end user, originator, beneficiary, account, wallet, amount, asset, currency, hash, purpose and supporting documentation.
- Incident
- Event that affects or may affect availability, integrity, confidentiality, assets, credentials, wallets, data, settlement, reconciliation, compliance, records or end users.
- Complaint
- Request, grievance, dispute, adjustment, reported error, reversal request or objection filed by a Corporate Client or, through it, by an end user.
- Travel Rule
- Obligation to obtain, retain and, where applicable, transmit originator and beneficiary information in digital-asset transfers, per applicable regulations, international standards and saf.'s internal policies.
- External provider
- Bank, rail, liquidity provider, infrastructure, wallet, custody, monitoring, verification, cloud, messaging or technology participating in an authorized flow.
Nature of the services and exclusions
saf. provides services only to approved Corporate Clients, within the scope defined in contract, annexes, SOPs, technical matrices and compliance approvals. The service is initiated at the Corporate Client's instruction and may include receipt of digital assets, temporary technical custody, conversion, transfer, order reception and transmission, reconciliation, reporting and related fiat settlement.
The list of enabled assets, networks, corridors, currencies, banks, rails, limits, jurisdictions, providers and modalities is defined by contract and internal approval. No asset, corridor or feature shall be deemed approved solely because it is described as a technical possibility in commercial or product documentation.
- No retail wallet
- saf. does not offer, in this version, an open retail wallet or a direct account for mass consumers.
- No proprietary issuance
- The scope does not include the issuance of proprietary digital assets, tokens, stablecoins or other instruments by saf.
- No investment or advice
- saf. does not provide financial advice, investment recommendations, portfolio management or yield promises.
- No derivatives
- No derivatives on digital assets are offered unless specifically authorized, contracted and documented.
- No anonymous operations
- Anonymous accounts, fictitious names, untraceable users, unapproved assets/corridors or insufficient information are not permitted.
- No unidentifiable users
- The Corporate Client may not process operations from end users who have not been identified, verified or assessed in accordance with its KYC/KYT obligations and saf.'s information requirements.
Acceptance, applicability and relationship with end users
These Terms apply to the Corporate Client, its authorized representatives, directors, employees, contractors, technical users, integrations and any person using saf.'s credentials, channels or services on its behalf. Acceptance may be effected via contract, annex, order, onboarding, API use, production activation or any legally valid mechanism defined by Legal.
The end user maintains their primary commercial and contractual relationship with the Corporate Client, who must ensure that its terms, notices, authorizations, consents, privacy policies, KYC, complaints and communications allow information sharing with saf. and enable saf. to execute, monitor, suspend, report and retain records under these Terms.
Eligibility, onboarding and enablement
saf. will not enable access to a Corporate Client until individualized review and analysis are complete. Commercial approval does not replace compliance, legal, technical and operational approval.
- Complete KYB
- Legal existence, representatives, UBOs, licenses, activity, jurisdictions, AML/KYC/KYT program, sanctions, PEP, adverse media, cybersecurity and cooperation capacity.
- Contract and annexes
- Master agreement, operational annexes, service terms, responsibility matrix, confidentiality, data, audit, suspension, incidents and termination.
- Technical matrix
- Services, assets, networks, wallets, accounts, countries, corridors, limits, APIs, permissions, states, minimum data, SLAs and owners.
- Testing & integration
- Test environment, secure credentials, UAT, data validation, reconciliation, monitoring, logs and rollback procedures where applicable.
- Production approval
- Formal record of approval by Compliance, Legal, Technology, Operations and Senior Management when risk requires.
Corporate Client obligations
The Corporate Client is responsible for operating within the approved scope, maintaining complete information and cooperating with saf. in a timely manner. These obligations are incorporated in contract, annexes and applicable SOPs.
- Maintain the primary relationship with its end users and ensure that its terms, notices, consents and policies allow information sharing with saf. and enable the applicable compliance controls.
- Maintain existence, authorizations, licenses, records and controls adequate for its activities, markets, end users and products.
- Execute KYC, CDD, EDD, sanctions, PEP, adverse-media, transaction monitoring, Travel Rule and its own reporting where applicable.
- Obtain the legal bases, authorizations, consents or notices needed to share with saf. data of end users, beneficiaries, originators, counterparties, accounts, wallets and operations.
- Provide complete minimum data before, during or after an operation, per the approved flow and per authority, bank, provider or internal-control requirements.
- Respond to requests for information, files, supporting materials, narrative, investigation, complaints or audit within the applicable contractual or regulatory term.
- Not present the services as authorized for assets, corridors, countries, limits, users or products not approved by saf.
- Not use the infrastructure for illicit activity, fraud, sanctions evasion, market abuse, anonymous accounts, fictitious names, unauthorized nesting or activity outside the contract.
- Notify saf. immediately of anomalous or suspicious activity, security incidents, data breaches, credential loss, settlement errors or material changes.
- Maintain sufficient records to reconstruct operations and enable audit or inspection by CNAD, UIF, allied banks or competent authorities.
- Keep KYB information up to date and notify material changes in ownership, control, beneficiaries, licenses, jurisdictions, products, providers or regulatory status.
- Deliver critical information triggered by alert or authority request immediately or within 24 hours.
- Allow saf. to conduct reviews, sampling, remote or on-site audits and Travel Rule validations when risk, regulation, contract or an authority so requires.
- When an operation involves digital assets, provide the information necessary to comply with Travel Rule, monitoring, audit and record-keeping; insufficient information may prevent execution, settlement or closing.
Rights and responsibilities of saf.
saf. retains the responsibility to operate its infrastructure with reasonable controls for compliance, security, traceability, asset protection, incidents, continuity, record-keeping and response to authorities. Acceptance of reliance does not limit these rights.
- Information and review
- Request data, documents, KYC files, transactional support, source/destination of funds, purpose, beneficiaries, wallets, accounts and monitoring records.
- Monitoring and controls
- Validate instructions against approved scope, limits, assets, corridors, sanctions, PEP, KYT, unusual patterns and risk signals.
- Rejection or suspension
- Reject, pause, block, hold, preventively freeze or suspend APIs, wallets, accounts, users, transactions or relationships when risk or a requirement exists.
- Reporting and cooperation
- Prepare or file reports, respond to CNAD, UIF, allied banks, auditors or competent authorities and preserve evidence.
- Update of conditions
- Modify technical requirements, minimum data, controls, limits, assets, providers, documentation or processes when risk, law, contract or service changes.
- Termination
- Terminate services or the relationship when risk is unacceptable, there is material breach, operational impossibility, an authority requirement or lack of cooperation.
Instructions, authorization and transaction processing
saf. will process only instructions received through authorized channels and attributable to an enabled Corporate Client. The Corporate Client is responsible for the accuracy, authorization, sufficiency and timeliness of the instructions transmitted.
- Reception
- The instruction must come from an authorized channel, credential, technical user or representative and contain a unique reference and minimum data.
- Validation
- saf. verifies permissions, KYB status, reliance, limits, corridor, asset, data, monitoring, sanctions and operational availability.
- Execution
- The operation may be executed, rejected, paused or require additional information based on risk status, availability, contract, provider and applicable law.
- Finality and reversals
- Operations on digital-asset networks may be irreversible or dependent on third parties. Reversals, adjustments or re-execution follow contract, SOP and operational/legal analysis.
- Errors
- Errors in data, wallets, accounts, beneficiaries, amounts or instructions must be reported immediately. saf. does not guarantee recovery if the operation is already irreversible or processed by a third party.
- Reconciliation
- saf. keeps records of status, hash, reference, settlement, reconciliation, differences and closure for reconstruction and audit.
Assets, wallets, technical custody and balance protection
When the approved flow includes digital assets, saf. may receive, hold, technically administer, transfer or convert such assets within wallets, accounts, subaccounts or segregated structures. Segregation may be implemented through wallets, subaccounts, internal identifiers, technical tags, accounting records, logs, data matrices and reconciliations.
Technical custody runs on saf.'s custody core, which integrates specialized provider wallet infrastructure under a self-custody scheme, with exclusive administration of the root cryptographic material by saf., segregation per Corporate Client and subaccounts per end user, and dual-signature controls for sensitive actions. No clause shall be construed as an absolute guarantee against loss, theft, damage, volatility, network failure, hacking, force majeure or third-party conduct.
- Segregation
- Identification of assets, wallets, subaccounts, records, instructions and balances per Corporate Client and, where applicable, end user or operation.
- Reconciliation
- Reconciliation of digital-asset and fiat movements, internal states, provider, bank, hash, reference and settlement.
- Access
- Limited, revocable permissions with activity logging, separation of duties and enhanced approval for sensitive actions.
- Monitoring
- Review of patterns, alerts, limits, counterparties, sanctions, PEP, adverse media, wallets, reversals, errors and incidents.
- Incidents
- Detection, containment, evidence preservation, recovery, reconciliation, communication, remediation and closure.
AML/CFT/CPF compliance, sanctions and reporting
Use of the services is subject to controls for the prevention of money laundering, terrorist financing, financing of the proliferation of weapons of mass destruction, sanctions, PEP, adverse-media, Travel Rule, transaction monitoring and applicable regulatory reporting.
- saf. may request information about originator, beneficiary, end user, counterparty, wallet, account, hash, amount, currency, asset, date, time, purpose, source of funds, destination and supporting documentation.
- saf. may reject, suspend, pause, hold or preventively freeze operations when there are alerts, insufficient information, unusual activity, an authority request or unacceptable risk.
- saf. and the Corporate Client must avoid any communication that could constitute tipping-off when there is analysis, reporting or investigation of a suspicious operation.
- The Corporate Client shall cooperate with saf. to prepare analysis, narrative, evidence, support and response before CNAD, UIF, allied banks, providers or competent authorities.
- STR, goAML, SIRAF, Travel Rule and periodic or special regulatory reports will apply under current regulation.
- When information is incomplete, inconsistent, unverifiable or insufficient for Travel Rule, monitoring, reporting or operational reconstruction, saf. may reject, pause or suspend the operation.
- The Corporate Client shall refrain from communicating to the end user, beneficiary, counterparty or third party any information that may reveal analysis, escalation, report, investigation or authority request, except with saf.'s express authorization or legal requirement.
Fees, pricing, taxes and settlement
Fees, commissions, spreads, network charges, provider costs, conversion charges, settlement charges, platform charges or any other applicable charge are set out in the contract, order, annex, commercial schedule or operational confirmation. saf. will not communicate hidden charges or charges not provided in the framework applicable to the Corporate Client, who is responsible for communicating to its end users, where applicable, the charges, costs, taxes, exchange rates, settlement times and applicable risks.
Responsibility for taxes, withholdings, filings, tax obligations, receipts, accounting treatment and communication to the end user will be defined in the contract between saf. and the Corporate Client and reviewed by competent tax or legal advisors.
Fiat settlement depends on banks, rails, hours, cut-offs, availability, compliance, limits, data, providers and rules of the approved corridor. saf. does not guarantee specific times, exchange rate, continuous availability or settlement on a specific date unless expressly agreed in the contract.
Availability, continuity, providers and operational changes
The services may depend on external providers, blockchain networks, banks, payment rails, liquidity providers, cloud infrastructure, verification and monitoring tools, wallet/custody, messaging, telecommunications and the Corporate Client's systems. saf. manages such dependencies through due diligence, contracts, monitoring, continuity and contingency plans proportional to risk.
- Unavailability
- saf. may pause operations, apply contingency, communicate with the Corporate Client, prioritize critical flows and log the event.
- Change of provider
- Requires risk, security, compliance, continuity, contract, data, confidentiality assessment and internal approval.
- Network or bank failure
- The operation may be delayed, rejected, kept pending, require retry or escalation per SOP.
- Maintenance
- saf. may schedule maintenance and communicate impacts to the Corporate Client via contractual channels.
- Continuity
- saf. maintains backup, recovery, DRP and periodic testing per its internal policies (compliance@saf.money).
Data, privacy, confidentiality and record retention
saf. processes corporate, personal, transactional, technical and compliance data to the extent necessary for KYB/KYC and KYT, service execution, monitoring, risk prevention, reporting, audit, reconciliation, complaint handling, incidents, legal defense, authority requirements and record retention.
The Corporate Client must ensure it has the legal bases, consents, privacy notices, contractual authorizations or equivalent mechanisms to transfer to saf. information about end users, beneficiaries, counterparties, representatives, wallets, accounts and operations.
Compliance and transaction records will be retained for a period of no less than 15 years from the end of the relationship or operation, or for the longer term required by applicable regulation, an investigation, an authority request or a contractual obligation. Other corporate, tax, employment, accounting or commercial records will be retained per the applicable term.
Transfer of information to Allied Bank, financial rails and regulated third parties
The Corporate Client acknowledges and accepts that, for enablement, operation, execution, settlement, reconciliation, monitoring, traceability, risk prevention, complaint handling, audit, regulatory compliance, AML/CFT/CPF compliance, sanctions, Travel Rule and requirements from authorities, correspondent banks, financial rails, liquidity providers or participating financial entities, saf. may share with its principal Allied Bank, correspondent banks, payment rails, regulated financial entities, critical providers or regulated third parties participating in the authorized flow the corporate, personal, transactional, technical and compliance information that is necessary, reasonable or required for such purposes.
Shared information may include, without limitation: the Corporate Client's KYB information; identification of legal representatives, attorneys-in-fact, directors, authorized signatories and UBOs; due-diligence opinions or evidence; end-user, sub-client, originator, beneficiary, counterparty or recipient KYC/KYB/KYT information; supporting documentation; source of funds or wealth where applicable; operation purpose; accounts, wallets, subaccounts, addresses, internal identifiers, payment references, hashes, amounts, currencies, digital assets, dates, times, origin or destination country, operation status, screening results, sanctions/PEP/adverse-media matches, alerts and transactional analysis.
The Corporate Client must ensure its end users and sub-clients are informed, before using the Services, that their data may be processed and transferred to saf., the Allied Bank and third parties participating in the flow for the purposes indicated above.
When information is transferred to an Allied Bank or regulated third party acting as an independent controller, it will be responsible under the applicable regulation. When acting as processor, sub-processor or provider of saf., it must be subject to contractual obligations of confidentiality, security, limited use, retention and data protection no less strict than those applicable to saf.
Complaints, errors, support and communications
Corporate-Client complaints are handled through the agreed institutional channels. When a complaint comes from an end user, the primary channel is the Corporate Client, unless law, contract or an authority requires direct intervention by saf. Every complaint must include operation reference, date, amount, asset, currency, end user where applicable, account, wallet, hash or identifier, description of the problem, supporting documentation and contact person.
- Corporate Client
- Contractual channels, institutional email, ticketing, API, operational contact or approved emergency channel.
- End user
- Preferably through the Corporate Client; saf. may request information, support the investigation or intervene if the applicable framework requires.
- Authorities
- Compliance Officer, Legal, CISO or authorized representative will handle requests, reports, incidents or regulatory communications.
- No tipping-off
- No analysis, reports or investigations that could alert a party to a suspicious operation or ongoing investigation will be disclosed.
- Compensation
- Any reversal, adjustment, re-execution, credit or compensation requires review by Operations, Compliance, Legal and Senior Management as applicable.
Until a specific regulatory channel exists, formal communications will be handled via approved contractual channels and under coordination of Legal and the Compliance Officer.
Suspension, blocking, rejection and termination
saf. may reject, pause, suspend, block, limit, hold, preventively freeze or terminate services, operations, APIs, wallets, accounts, subaccounts, credentials, technical users, assets, corridors or the entire relationship when risk or breach exists. When the measure derives from AML/CFT/CPF risk, sanctions, an authority request or suspicion, saf. may limit the information communicated to the Corporate Client to comply with confidentiality and no-tipping-off obligations.
- Compliance
- Sanctions, unmitigated PEP, adverse media, STR, incomplete Travel Rule, insufficient KYC/KYB/KYT, no tipping-off, UIF/CNAD request or AML/CFT/CPF risk.
- Information
- False, incomplete, inconsistent, expired or unverifiable data; refusal to deliver files, supporting materials, originator/beneficiary or evidence.
- Contract
- Use outside scope, unapproved asset/corridor, unauthorized nesting, breach of limits, SLA, SOP, annexes or technical matrix.
- Security
- Compromised credentials, unauthorized access, fraud, phishing, incident, data leak, tampering, malware or failure of critical controls.
- Operation
- Material error, failed reconciliation, impossible settlement, provider/bank unavailability, force majeure, regulatory change or unfeasible instruction.
- Authority
- Judicial, administrative, regulatory order, seizure, freeze, block, information request or instruction from a competent authority.
Suspension or termination will not affect rights, obligations, debts, reports, investigations, record retention, confidentiality, cooperation, indemnities, reconciliations or responsibilities arising before its effective date. Return, transfer or settlement of assets or balances will be performed per contract, law, network availability, risk control, authority orders and applicable wind-down plan.
Digital-asset risks
The Corporate Client acknowledges that digital assets, blockchain networks, stablecoins, Bitcoin, wallets, settlement rails and related providers may be exposed to technological, operational, regulatory, liquidity, volatility, availability, irreversible-settlement, cybersecurity, sanctions, forks, network congestion, provider failure and force-majeure risks.
saf. does not guarantee appreciation of value, price stability, permanent liquidity, immediate settlement, reversibility of operations, continuous network availability or the absence of regulatory changes. Each Corporate Client must communicate the applicable risks of the flow it offers to its end users.
Liability, indemnity and dispute resolution
Definitive clauses on liability, exclusions, limitations, indemnity, indirect damages, force majeure, third-party liability, liability to end users, liability for incorrect data and loss allocation will be defined in the master agreement and validated by Legal before signing or publication.
As an operational principle, the Corporate Client shall hold saf. harmless against claims arising from false or incomplete information, insufficient KYC, lack of end-user authorization, use outside scope, breach of law, fraud, erroneous instructions, lack of consent, breach of data protection, sanctions violations or misleading communication to the end user, to the extent permitted by law and contract.
Modifications, notices and order of precedence
saf. may update these Terms when law, the PSAD application or registration, the service scope, technology, providers, banks, assets, corridors, risks, controls, contracts, authority requirements or internal policies change. Updates will be notified to the Corporate Client via the applicable contractual channel and kept under version control.
In the event of conflict between these Terms and a signed master agreement, the signed contract prevails to the extent permitted by law and provided it does not reduce saf.'s regulatory obligations, compliance powers, or information, suspension, reporting, retention or cooperation rights without legal and compliance approval.