← Back to home

Legal — 01

Terms & Conditions

SAF SV, S.A.S. de C.V. · Version 2.0 — B2B / B2B2C · 06/05/2026

These Terms & Conditions establish the base contractual framework under which SAF SV, S.A.S. de C.V. (“saf.”) provides digital-asset services to previously approved Corporate Clients under an institutional B2B / B2B2C model.

This document summarizes the operational sections (definitions, nature of the service, obligations, compliance, technical custody, fees, continuity, data, complaints, suspension, risks, liability and modifications) applicable to the relationship between saf. and its Corporate Clients.

01

Definitions

saf.
SAF SV, S.A.S. de C.V., a Salvadoran company applying for registration as a Digital-Asset Service Provider (PSAD) and operator of the infrastructure described in these Terms.
Corporate Client / B2B partner
Legal entity approved by saf. via KYB that contracts services, integrates saf. infrastructure and maintains the direct relationship with its end users.
End user
Natural or legal person served by the Corporate Client. Their primary KYC is the responsibility of the Corporate Client, without prejudice to saf.'s right to request information, review files, block operations or suspend services.
Services
Digital-asset services, technical infrastructure, conversion, transfer, temporary technical custody, order reception/transmission, reconciliation, reporting and related settlement, as per contract, annex and approved matrix.
Digital asset
Digital representation of value or right whose transmission, custody, administration or conversion is performed through distributed-ledger or analogous technology, within the approved flow.
Ultimate Beneficial Owner (UBO)
Natural person who ultimately owns or controls, directly or indirectly, the Corporate Client, including anyone with 25% or more of capital, voting rights, economic rights or effective control.
Account, wallet or subaccount
Technical, logical, operational or accounting structure used to identify balances, instructions, assets, records or transactions of a Corporate Client and, where applicable, an end user or operation.
Technical custody
Receipt, safekeeping, technical administration, signing, operational control or temporary availability of digital assets or access/control means within authorized flows.
Order / instruction
Request, message, API call, file, record or authorized instruction from the Corporate Client to initiate, modify, query, cancel, settle or close an operation.
Transaction
Movement, conversion, transfer, settlement, receipt or transmission of order associated with a Corporate Client, end user, beneficiary, wallet, account, amount, asset, currency, date and status.
Controlled reliance
Mechanism whereby saf. uses information, verifications or evidence generated by a Corporate Client regarding its end users, always under documented, verifiable, auditable and revocable conditions. It does not transfer or eliminate saf.'s regulatory responsibility.
Minimum data
Information required to attribute, monitor, execute, reconcile, report and reconstruct an operation, including client, end user, originator, beneficiary, account, wallet, amount, asset, currency, hash, purpose and supporting documentation.
Incident
Event that affects or may affect availability, integrity, confidentiality, assets, credentials, wallets, data, settlement, reconciliation, compliance, records or end users.
Complaint
Request, grievance, dispute, adjustment, reported error, reversal request or objection filed by a Corporate Client or, through it, by an end user.
Travel Rule
Obligation to obtain, retain and, where applicable, transmit originator and beneficiary information in digital-asset transfers, per applicable regulations, international standards and saf.'s internal policies.
External provider
Bank, rail, liquidity provider, infrastructure, wallet, custody, monitoring, verification, cloud, messaging or technology participating in an authorized flow.
02

Nature of the services and exclusions

saf. provides services only to approved Corporate Clients, within the scope defined in contract, annexes, SOPs, technical matrices and compliance approvals. The service is initiated at the Corporate Client's instruction and may include receipt of digital assets, temporary technical custody, conversion, transfer, order reception and transmission, reconciliation, reporting and related fiat settlement.

The list of enabled assets, networks, corridors, currencies, banks, rails, limits, jurisdictions, providers and modalities is defined by contract and internal approval. No asset, corridor or feature shall be deemed approved solely because it is described as a technical possibility in commercial or product documentation.

No retail wallet
saf. does not offer, in this version, an open retail wallet or a direct account for mass consumers.
No proprietary issuance
The scope does not include the issuance of proprietary digital assets, tokens, stablecoins or other instruments by saf.
No investment or advice
saf. does not provide financial advice, investment recommendations, portfolio management or yield promises.
No derivatives
No derivatives on digital assets are offered unless specifically authorized, contracted and documented.
No anonymous operations
Anonymous accounts, fictitious names, untraceable users, unapproved assets/corridors or insufficient information are not permitted.
No unidentifiable users
The Corporate Client may not process operations from end users who have not been identified, verified or assessed in accordance with its KYC/KYT obligations and saf.'s information requirements.
03

Acceptance, applicability and relationship with end users

These Terms apply to the Corporate Client, its authorized representatives, directors, employees, contractors, technical users, integrations and any person using saf.'s credentials, channels or services on its behalf. Acceptance may be effected via contract, annex, order, onboarding, API use, production activation or any legally valid mechanism defined by Legal.

The end user maintains their primary commercial and contractual relationship with the Corporate Client, who must ensure that its terms, notices, authorizations, consents, privacy policies, KYC, complaints and communications allow information sharing with saf. and enable saf. to execute, monitor, suspend, report and retain records under these Terms.

04

Eligibility, onboarding and enablement

saf. will not enable access to a Corporate Client until individualized review and analysis are complete. Commercial approval does not replace compliance, legal, technical and operational approval.

Complete KYB
Legal existence, representatives, UBOs, licenses, activity, jurisdictions, AML/KYC/KYT program, sanctions, PEP, adverse media, cybersecurity and cooperation capacity.
Contract and annexes
Master agreement, operational annexes, service terms, responsibility matrix, confidentiality, data, audit, suspension, incidents and termination.
Technical matrix
Services, assets, networks, wallets, accounts, countries, corridors, limits, APIs, permissions, states, minimum data, SLAs and owners.
Testing & integration
Test environment, secure credentials, UAT, data validation, reconciliation, monitoring, logs and rollback procedures where applicable.
Production approval
Formal record of approval by Compliance, Legal, Technology, Operations and Senior Management when risk requires.
05

Corporate Client obligations

The Corporate Client is responsible for operating within the approved scope, maintaining complete information and cooperating with saf. in a timely manner. These obligations are incorporated in contract, annexes and applicable SOPs.

  • Maintain the primary relationship with its end users and ensure that its terms, notices, consents and policies allow information sharing with saf. and enable the applicable compliance controls.
  • Maintain existence, authorizations, licenses, records and controls adequate for its activities, markets, end users and products.
  • Execute KYC, CDD, EDD, sanctions, PEP, adverse-media, transaction monitoring, Travel Rule and its own reporting where applicable.
  • Obtain the legal bases, authorizations, consents or notices needed to share with saf. data of end users, beneficiaries, originators, counterparties, accounts, wallets and operations.
  • Provide complete minimum data before, during or after an operation, per the approved flow and per authority, bank, provider or internal-control requirements.
  • Respond to requests for information, files, supporting materials, narrative, investigation, complaints or audit within the applicable contractual or regulatory term.
  • Not present the services as authorized for assets, corridors, countries, limits, users or products not approved by saf.
  • Not use the infrastructure for illicit activity, fraud, sanctions evasion, market abuse, anonymous accounts, fictitious names, unauthorized nesting or activity outside the contract.
  • Notify saf. immediately of anomalous or suspicious activity, security incidents, data breaches, credential loss, settlement errors or material changes.
  • Maintain sufficient records to reconstruct operations and enable audit or inspection by CNAD, UIF, allied banks or competent authorities.
  • Keep KYB information up to date and notify material changes in ownership, control, beneficiaries, licenses, jurisdictions, products, providers or regulatory status.
  • Deliver critical information triggered by alert or authority request immediately or within 24 hours.
  • Allow saf. to conduct reviews, sampling, remote or on-site audits and Travel Rule validations when risk, regulation, contract or an authority so requires.
  • When an operation involves digital assets, provide the information necessary to comply with Travel Rule, monitoring, audit and record-keeping; insufficient information may prevent execution, settlement or closing.
06

Rights and responsibilities of saf.

saf. retains the responsibility to operate its infrastructure with reasonable controls for compliance, security, traceability, asset protection, incidents, continuity, record-keeping and response to authorities. Acceptance of reliance does not limit these rights.

Information and review
Request data, documents, KYC files, transactional support, source/destination of funds, purpose, beneficiaries, wallets, accounts and monitoring records.
Monitoring and controls
Validate instructions against approved scope, limits, assets, corridors, sanctions, PEP, KYT, unusual patterns and risk signals.
Rejection or suspension
Reject, pause, block, hold, preventively freeze or suspend APIs, wallets, accounts, users, transactions or relationships when risk or a requirement exists.
Reporting and cooperation
Prepare or file reports, respond to CNAD, UIF, allied banks, auditors or competent authorities and preserve evidence.
Update of conditions
Modify technical requirements, minimum data, controls, limits, assets, providers, documentation or processes when risk, law, contract or service changes.
Termination
Terminate services or the relationship when risk is unacceptable, there is material breach, operational impossibility, an authority requirement or lack of cooperation.
07

Instructions, authorization and transaction processing

saf. will process only instructions received through authorized channels and attributable to an enabled Corporate Client. The Corporate Client is responsible for the accuracy, authorization, sufficiency and timeliness of the instructions transmitted.

Reception
The instruction must come from an authorized channel, credential, technical user or representative and contain a unique reference and minimum data.
Validation
saf. verifies permissions, KYB status, reliance, limits, corridor, asset, data, monitoring, sanctions and operational availability.
Execution
The operation may be executed, rejected, paused or require additional information based on risk status, availability, contract, provider and applicable law.
Finality and reversals
Operations on digital-asset networks may be irreversible or dependent on third parties. Reversals, adjustments or re-execution follow contract, SOP and operational/legal analysis.
Errors
Errors in data, wallets, accounts, beneficiaries, amounts or instructions must be reported immediately. saf. does not guarantee recovery if the operation is already irreversible or processed by a third party.
Reconciliation
saf. keeps records of status, hash, reference, settlement, reconciliation, differences and closure for reconstruction and audit.
08

Assets, wallets, technical custody and balance protection

When the approved flow includes digital assets, saf. may receive, hold, technically administer, transfer or convert such assets within wallets, accounts, subaccounts or segregated structures. Segregation may be implemented through wallets, subaccounts, internal identifiers, technical tags, accounting records, logs, data matrices and reconciliations.

Technical custody runs on saf.'s custody core, which integrates specialized provider wallet infrastructure under a self-custody scheme, with exclusive administration of the root cryptographic material by saf., segregation per Corporate Client and subaccounts per end user, and dual-signature controls for sensitive actions. No clause shall be construed as an absolute guarantee against loss, theft, damage, volatility, network failure, hacking, force majeure or third-party conduct.

Segregation
Identification of assets, wallets, subaccounts, records, instructions and balances per Corporate Client and, where applicable, end user or operation.
Reconciliation
Reconciliation of digital-asset and fiat movements, internal states, provider, bank, hash, reference and settlement.
Access
Limited, revocable permissions with activity logging, separation of duties and enhanced approval for sensitive actions.
Monitoring
Review of patterns, alerts, limits, counterparties, sanctions, PEP, adverse media, wallets, reversals, errors and incidents.
Incidents
Detection, containment, evidence preservation, recovery, reconciliation, communication, remediation and closure.
09

AML/CFT/CPF compliance, sanctions and reporting

Use of the services is subject to controls for the prevention of money laundering, terrorist financing, financing of the proliferation of weapons of mass destruction, sanctions, PEP, adverse-media, Travel Rule, transaction monitoring and applicable regulatory reporting.

  • saf. may request information about originator, beneficiary, end user, counterparty, wallet, account, hash, amount, currency, asset, date, time, purpose, source of funds, destination and supporting documentation.
  • saf. may reject, suspend, pause, hold or preventively freeze operations when there are alerts, insufficient information, unusual activity, an authority request or unacceptable risk.
  • saf. and the Corporate Client must avoid any communication that could constitute tipping-off when there is analysis, reporting or investigation of a suspicious operation.
  • The Corporate Client shall cooperate with saf. to prepare analysis, narrative, evidence, support and response before CNAD, UIF, allied banks, providers or competent authorities.
  • STR, goAML, SIRAF, Travel Rule and periodic or special regulatory reports will apply under current regulation.
  • When information is incomplete, inconsistent, unverifiable or insufficient for Travel Rule, monitoring, reporting or operational reconstruction, saf. may reject, pause or suspend the operation.
  • The Corporate Client shall refrain from communicating to the end user, beneficiary, counterparty or third party any information that may reveal analysis, escalation, report, investigation or authority request, except with saf.'s express authorization or legal requirement.
10

Fees, pricing, taxes and settlement

Fees, commissions, spreads, network charges, provider costs, conversion charges, settlement charges, platform charges or any other applicable charge are set out in the contract, order, annex, commercial schedule or operational confirmation. saf. will not communicate hidden charges or charges not provided in the framework applicable to the Corporate Client, who is responsible for communicating to its end users, where applicable, the charges, costs, taxes, exchange rates, settlement times and applicable risks.

Responsibility for taxes, withholdings, filings, tax obligations, receipts, accounting treatment and communication to the end user will be defined in the contract between saf. and the Corporate Client and reviewed by competent tax or legal advisors.

Fiat settlement depends on banks, rails, hours, cut-offs, availability, compliance, limits, data, providers and rules of the approved corridor. saf. does not guarantee specific times, exchange rate, continuous availability or settlement on a specific date unless expressly agreed in the contract.

11

Availability, continuity, providers and operational changes

The services may depend on external providers, blockchain networks, banks, payment rails, liquidity providers, cloud infrastructure, verification and monitoring tools, wallet/custody, messaging, telecommunications and the Corporate Client's systems. saf. manages such dependencies through due diligence, contracts, monitoring, continuity and contingency plans proportional to risk.

Unavailability
saf. may pause operations, apply contingency, communicate with the Corporate Client, prioritize critical flows and log the event.
Change of provider
Requires risk, security, compliance, continuity, contract, data, confidentiality assessment and internal approval.
Network or bank failure
The operation may be delayed, rejected, kept pending, require retry or escalation per SOP.
Maintenance
saf. may schedule maintenance and communicate impacts to the Corporate Client via contractual channels.
Continuity
saf. maintains backup, recovery, DRP and periodic testing per its internal policies (compliance@saf.money).
12

Data, privacy, confidentiality and record retention

saf. processes corporate, personal, transactional, technical and compliance data to the extent necessary for KYB/KYC and KYT, service execution, monitoring, risk prevention, reporting, audit, reconciliation, complaint handling, incidents, legal defense, authority requirements and record retention.

The Corporate Client must ensure it has the legal bases, consents, privacy notices, contractual authorizations or equivalent mechanisms to transfer to saf. information about end users, beneficiaries, counterparties, representatives, wallets, accounts and operations.

Compliance and transaction records will be retained for a period of no less than 15 years from the end of the relationship or operation, or for the longer term required by applicable regulation, an investigation, an authority request or a contractual obligation. Other corporate, tax, employment, accounting or commercial records will be retained per the applicable term.

13

Transfer of information to Allied Bank, financial rails and regulated third parties

The Corporate Client acknowledges and accepts that, for enablement, operation, execution, settlement, reconciliation, monitoring, traceability, risk prevention, complaint handling, audit, regulatory compliance, AML/CFT/CPF compliance, sanctions, Travel Rule and requirements from authorities, correspondent banks, financial rails, liquidity providers or participating financial entities, saf. may share with its principal Allied Bank, correspondent banks, payment rails, regulated financial entities, critical providers or regulated third parties participating in the authorized flow the corporate, personal, transactional, technical and compliance information that is necessary, reasonable or required for such purposes.

Shared information may include, without limitation: the Corporate Client's KYB information; identification of legal representatives, attorneys-in-fact, directors, authorized signatories and UBOs; due-diligence opinions or evidence; end-user, sub-client, originator, beneficiary, counterparty or recipient KYC/KYB/KYT information; supporting documentation; source of funds or wealth where applicable; operation purpose; accounts, wallets, subaccounts, addresses, internal identifiers, payment references, hashes, amounts, currencies, digital assets, dates, times, origin or destination country, operation status, screening results, sanctions/PEP/adverse-media matches, alerts and transactional analysis.

The Corporate Client must ensure its end users and sub-clients are informed, before using the Services, that their data may be processed and transferred to saf., the Allied Bank and third parties participating in the flow for the purposes indicated above.

When information is transferred to an Allied Bank or regulated third party acting as an independent controller, it will be responsible under the applicable regulation. When acting as processor, sub-processor or provider of saf., it must be subject to contractual obligations of confidentiality, security, limited use, retention and data protection no less strict than those applicable to saf.

14

Complaints, errors, support and communications

Corporate-Client complaints are handled through the agreed institutional channels. When a complaint comes from an end user, the primary channel is the Corporate Client, unless law, contract or an authority requires direct intervention by saf. Every complaint must include operation reference, date, amount, asset, currency, end user where applicable, account, wallet, hash or identifier, description of the problem, supporting documentation and contact person.

Corporate Client
Contractual channels, institutional email, ticketing, API, operational contact or approved emergency channel.
End user
Preferably through the Corporate Client; saf. may request information, support the investigation or intervene if the applicable framework requires.
Authorities
Compliance Officer, Legal, CISO or authorized representative will handle requests, reports, incidents or regulatory communications.
No tipping-off
No analysis, reports or investigations that could alert a party to a suspicious operation or ongoing investigation will be disclosed.
Compensation
Any reversal, adjustment, re-execution, credit or compensation requires review by Operations, Compliance, Legal and Senior Management as applicable.

Until a specific regulatory channel exists, formal communications will be handled via approved contractual channels and under coordination of Legal and the Compliance Officer.

15

Suspension, blocking, rejection and termination

saf. may reject, pause, suspend, block, limit, hold, preventively freeze or terminate services, operations, APIs, wallets, accounts, subaccounts, credentials, technical users, assets, corridors or the entire relationship when risk or breach exists. When the measure derives from AML/CFT/CPF risk, sanctions, an authority request or suspicion, saf. may limit the information communicated to the Corporate Client to comply with confidentiality and no-tipping-off obligations.

Compliance
Sanctions, unmitigated PEP, adverse media, STR, incomplete Travel Rule, insufficient KYC/KYB/KYT, no tipping-off, UIF/CNAD request or AML/CFT/CPF risk.
Information
False, incomplete, inconsistent, expired or unverifiable data; refusal to deliver files, supporting materials, originator/beneficiary or evidence.
Contract
Use outside scope, unapproved asset/corridor, unauthorized nesting, breach of limits, SLA, SOP, annexes or technical matrix.
Security
Compromised credentials, unauthorized access, fraud, phishing, incident, data leak, tampering, malware or failure of critical controls.
Operation
Material error, failed reconciliation, impossible settlement, provider/bank unavailability, force majeure, regulatory change or unfeasible instruction.
Authority
Judicial, administrative, regulatory order, seizure, freeze, block, information request or instruction from a competent authority.

Suspension or termination will not affect rights, obligations, debts, reports, investigations, record retention, confidentiality, cooperation, indemnities, reconciliations or responsibilities arising before its effective date. Return, transfer or settlement of assets or balances will be performed per contract, law, network availability, risk control, authority orders and applicable wind-down plan.

16

Digital-asset risks

The Corporate Client acknowledges that digital assets, blockchain networks, stablecoins, Bitcoin, wallets, settlement rails and related providers may be exposed to technological, operational, regulatory, liquidity, volatility, availability, irreversible-settlement, cybersecurity, sanctions, forks, network congestion, provider failure and force-majeure risks.

saf. does not guarantee appreciation of value, price stability, permanent liquidity, immediate settlement, reversibility of operations, continuous network availability or the absence of regulatory changes. Each Corporate Client must communicate the applicable risks of the flow it offers to its end users.

17

Liability, indemnity and dispute resolution

Definitive clauses on liability, exclusions, limitations, indemnity, indirect damages, force majeure, third-party liability, liability to end users, liability for incorrect data and loss allocation will be defined in the master agreement and validated by Legal before signing or publication.

As an operational principle, the Corporate Client shall hold saf. harmless against claims arising from false or incomplete information, insufficient KYC, lack of end-user authorization, use outside scope, breach of law, fraud, erroneous instructions, lack of consent, breach of data protection, sanctions violations or misleading communication to the end user, to the extent permitted by law and contract.

18

Modifications, notices and order of precedence

saf. may update these Terms when law, the PSAD application or registration, the service scope, technology, providers, banks, assets, corridors, risks, controls, contracts, authority requirements or internal policies change. Updates will be notified to the Corporate Client via the applicable contractual channel and kept under version control.

In the event of conflict between these Terms and a signed master agreement, the signed contract prevails to the extent permitted by law and provided it does not reduce saf.'s regulatory obligations, compliance powers, or information, suspension, reporting, retention or cooperation rights without legal and compliance approval.