Legal
Privacy Policy
How SK Fuerte Capital collects, uses, stores and shares your personal data in connection with our website, our client portal and the digital asset services we provide as a DASP registered with the Comisión Nacional de Activos Digitales (CNAD) of El Salvador.
Last updated: 2026
SK FUERTE CAPITAL, S.A. de C.V.
PRIVACY POLICY
Website: https://www.skfuertecapital.sv
NIT: 0623-270526-118-0 · NRC: 386759-8
San Salvador, El Salvador — 2026
Welcome to the Privacy Policy of SK FUERTE CAPITAL, S.A. de C.V. ("SK Fuerte Capital", "the Company", "we") (this "Policy").
The privacy and security of your personal data are of the utmost importance to SK Fuerte Capital. We recognize the need to protect the confidential information you share with us. For this reason, we have created this Privacy Policy to explain how we collect, use, store and share your personal data in connection with our website, our client portal and the digital asset services we provide as a Digital Asset Service Provider (DASP) registered with the Comisión Nacional de Activos Digitales (CNAD) of El Salvador.
This Policy is based on the principles of lawfulness, transparency, purpose limitation, proportionality, security and accountability. We are committed to ensuring that your personal data is processed with the greatest care and in accordance with the Ley de Protección de Datos Personales of the Republic of El Salvador (the "Data Protection Law"), the Ley de Emisión de Activos Digitales ("LEAD"), the Reglamento de Proveedores de Servicios de Activos Digitales ("RPSAD"), the Salvadoran anti-money laundering framework and other applicable legislation.
This document should be read together with our Terms and Conditions of Use, which contain an overview of our platform, and our Cookie Notice.
Important: SK Fuerte Capital provides its services exclusively to corporate, institutional and high-net-worth clients. We do not offer services to retail consumers. References to "you" in this Policy include legal representatives, beneficial owners, authorized signatories and other individuals connected to a corporate or institutional client, as well as high-net-worth individual clients.
1. Definitions
For the purposes of this document, the following definitions apply:
User: any natural person who accesses or interacts with the website, client portal or services offered by SK Fuerte Capital, including legal representatives, directors, beneficial owners and authorized persons acting on behalf of a corporate or institutional client, and high-net-worth individual clients. The User must have legal capacity to accept this Privacy Policy and the Company's other documents.
Account: the manner in which a client is represented when accessing the functionalities of the SK Fuerte Capital client portal and services, corresponding to a set of data that identifies the client (such as registration and KYC/KYB data) and other data relevant to the relationship between SK Fuerte Capital and the client.
Cookies: small files or data packets sent by SK Fuerte Capital to the User's device to identify the device and collect information that helps SK Fuerte Capital improve its services, as described in our Cookie Notice.
Personal Data: information relating to an identified or identifiable natural person, such as name, address, e-mail, telephone number, identification number, tax identification, IP address or blockchain wallet address where linked to an identified person.
Data Protection Officer (DPO): the person designated by SK Fuerte Capital to act as a communication channel between the Company, data subjects and the competent supervisory authority.
Database: a structured set of personal data located in one or more places, in electronic or physical form.
Consent: the free, informed and unequivocal manifestation by which the User accepts the processing of their personal data for a specific purpose, where consent is the applicable legal basis.
2. Information we collect
Personal data is collected when it is voluntarily entered or submitted by the User on the website, client portal and services offered by SK Fuerte Capital, such as during onboarding, account creation, browsing, interaction with content and use of services.
We may also collect personal data that is submitted in an automated manner, without any action by the User — for example, through cookies and similar technologies (see our Cookie Notice) or through service providers authorized to share personal data with SK Fuerte Capital (such as identity verification and screening providers).
SK Fuerte Capital processes Users' personal data as necessary to comply with its legal and regulatory obligations, to perform its contracts, to operate its business and to provide the services that clients use.
2.1 Information Provided During Onboarding and Use of the Services
We collect the content, communications and other information provided when you or your organization register with SK Fuerte Capital, including:
- identification data of the individual and of the legal entity: full name, corporate name, identity document or passport number, tax identification (NIT or equivalent), date of birth, nationality, address, e-mail address and telephone number;
- Know-Your-Client / Know-Your-Business (KYC/KYB) data: identity documents, proof of address, corporate documents, ownership and control structure, identification of beneficial owners, source of funds and source of wealth documentation, and a photograph or selfie used for liveness verification;
- enhanced due diligence data required for high-net-worth individual clients and higher-risk relationships, in accordance with our AML/CFT/CPF Program;
- financial and transactional data: fiat account details, blockchain wallet addresses, transaction instructions, order and conversion history, custody balances, and destination addresses registered in the withdrawal whitelist;
- communications with our support and complaints channels.
2.2 Device Information
We collect information from and about the computers, phones and other web-connected devices you use when accessing our platform, and we may combine this information across the different devices you use. This information includes:
- Device attributes: operating system, hardware and software versions, browser type, and application identifiers;
- Network and connections: internet service provider, language, time zone and IP address;
- Security signals: data used for authentication, session integrity and fraud prevention, such as login events and two-factor authentication events.
2.3 Blockchain and Screening Data
Given the nature of digital asset services, we also process:
- public blockchain data associated with the wallet addresses involved in your transactions;
- the results of transaction screening (KYT) and sanctions, PEP and adverse-media screening performed by our compliance providers; and
- originator and beneficiary information collected, safeguarded and transmitted in compliance with the FATF Travel Rule (IVMS101 standard) for applicable digital asset transfers.
3. Legal bases for processing
We process personal data on the following legal bases, as applicable:
- compliance with legal and regulatory obligations, including the LEAD, the RPSAD, CNAD regulations, the Ley Contra el Lavado de Dinero y de Activos, UIF instructions and the FATF Travel Rule — this is the primary basis for KYC/KYB, screening, monitoring, record keeping and regulatory reporting;
- performance of a contract, for account administration, execution of orders, custody, transfers and on/off-ramp services;
- legitimate interest, for fraud prevention, platform security, service improvement and defense of the Company's rights, always balanced against your rights and expectations; and
- consent, for non-essential cookies and optional communications, which you may withdraw at any time with effect for the future.
4. Use of information
Always prioritizing your privacy, SK Fuerte Capital ensures that all data and information relating to you is treated with due confidentiality and used only for the purposes described here, principally:
Account access and authentication: personal data collected when creating your account is used to identify and authenticate you in our services, using multi-factor authentication and the access controls described in our Information Security and Cybersecurity Policy.
Regulatory compliance and financial crime prevention: we use your personal data to comply with our obligations as a CNAD-regulated DASP, including KYC/KYB verification, PEP and sanctions screening, real-time transaction monitoring (KYT), Travel Rule data exchange, suspicious activity reporting to the Unidad de Investigación Financiera (UIF), and record keeping for supervisory purposes.
Processing of operations: we use your personal data to process, execute, settle and report on the status of your operations — deposits, withdrawals, conversions, order execution, custody movements and transfers — including through the tamper-evident audit trail maintained by our platform.
Fraud prevention and security: we use your personal data to assess risk, prevent fraud, detect unauthorized access, enforce withdrawal controls (including the destination address whitelist) and protect client assets.
Customer service and complaints: if you contact our customer service or complaints channels, we use your personal data to process your requests in accordance with our Customer Complaints Handling Policy.
Service improvement: we use aggregated and, where possible, de-identified data to understand how our platform is used and to improve our technology and services.
Institutional communications: we may use your contact details to send service notices, regulatory communications and, with your consent where required, institutional newsletters and industry insights relevant to corporate and institutional clients. SK Fuerte Capital does not conduct retail marketing, behavioral advertising profiles for consumers, or cold outreach.
Where we intend to use personal data for a purpose not described in this Policy and not within your legitimate expectations, we will do so only with your prior authorization or another valid legal basis.
5. Sharing of information
SK Fuerte Capital does not sell personal data. We share personal data only as described below and, in each case, subject to contractual, technical and organizational safeguards:
Service providers and technology partners: we work with specialized providers that enable us to operate our regulated business, including custody and settlement infrastructure (Fireblocks), identity verification and screening providers (Sumsub / Didit), blockchain analytics (KYT) providers, Travel Rule messaging (Notabene), regulated banking and payment service partners for fiat on/off-ramp, institutional liquidity providers, e-mail delivery and cloud infrastructure providers. We impose strict restrictions on how these providers may use and disclose the data, and each provider is subject to the due diligence and contractual requirements of our vendor management framework.
Travel Rule counterparties: for digital asset transfers at or above the applicable threshold, originator and beneficiary information is exchanged with counterparty Virtual Asset Service Providers in compliance with the FATF Travel Rule and UIF requirements.
Regulators and authorities: we share information with CNAD, the UIF and other competent public authorities where required by the applicable law, by regulation or by a lawful order, including for supervisory inspections, regulatory reporting and suspicious activity reports. Every administrative export of client data from our platform is itself logged and auditable.
Law enforcement and legal proceedings: we may share your information with judicial or law-enforcement authorities, within or outside your country of residence, when required by applicable law, court decision or lawful request, or as necessary to respond to legal proceedings or defend the Company's rights.
Corporate transactions: in the event of a merger, acquisition or corporate reorganization, personal data may be transferred to the successor entity, which will remain bound by this Policy or an equivalent standard of protection.
With your authorization: in any other case, we will share your data only with your express authorization.
Under Article 36 of the LEAD and applicable CNAD regulations, SK Fuerte Capital safeguards the identity of its clients and discloses client information to authorities only through the applicable legal process.
6. International data transfers
SK Fuerte Capital may transfer personal data to other countries as part of the activities related to the services provided — for example, to our identity verification, custody, analytics and Travel Rule providers, or to counterparty VASPs located abroad.
When sharing information with partners located in other countries, we ensure that the partner's data protection and information security standards are compatible with this Privacy Policy and with the requirements of the Salvadoran Data Protection Law, through contractual safeguards and provider due diligence, so that your data remains protected in accordance with these terms.
Some jurisdictions have data protection laws that differ from those of your country of residence. Where an international transfer is necessary for the purposes described in this Policy, SK Fuerte Capital will implement appropriate measures to ensure that your information remains protected as required by the applicable data protection legislation.
7. Protection of information
SK Fuerte Capital dedicates its best efforts to respect and protect your personal information against loss, theft or any form of misuse, as well as against unauthorized access, disclosure, alteration and destruction.
Our platform was designed on a "compliance-by-construction" and security-by-design basis, described in detail in our Information Technology Plan and Information Security and Cybersecurity Policy. Key measures include:
- encryption of data in transit (TLS 1.2+/1.3) and protection of high-sensitivity secrets at rest (AES-256-GCM);
- client data isolation enforced at the database engine level through Row-Level Security, so that one client's data cannot be accessed in the context of another client;
- role-based access control, least-privilege profiles, multi-factor authentication, and immediate revocation of access upon role change or termination;
- a tamper-evident, hash-chained audit trail of all administrative and transactional actions, including any administrative access to client data;
- centralized redaction that prevents credentials, tokens and personal data from reaching logs or error telemetry;
- independent penetration tests before launch and annually thereafter; and
- encrypted backups with periodic restore testing.
We also limit access to your personal information to employees and contractors of SK Fuerte Capital who need it to fulfil their responsibilities, and we require them to treat it confidentially and in accordance with this Privacy Policy.
It is nevertheless important to note that no system or internet transmission can be guaranteed to be completely secure. If you suspect any unauthorized activity relating to your information or your account, please contact us immediately through a secure channel so that we can take appropriate measures.
8. Data retention
SK Fuerte Capital stores your information for the period necessary for the purposes established in the Terms and Conditions of Use and in this Privacy Policy, respecting the retention periods determined by the applicable law.
As a regulated DASP, we are legally required to retain transactional records, KYC/KYB documentation, compliance screening results, Travel Rule records and audit trail records for a minimum of five (5) years — or longer where CNAD or UIF rules so require — including after the closure of your account. Audit records are retained on an append-only basis.
If you request the deletion of your account, personal information that is not subject to mandatory retention will be deleted in accordance with the applicable legislation. We may also retain information where there is a pending matter related to your account, such as an ongoing complaint or dispute, or where retention is necessary for our legitimate interests, such as fraud prevention and the security of our clients.
9. Your rights as a data subject
You always have the option not to disclose your data to SK Fuerte Capital; however, certain data is legally required for onboarding and for the use of our services, and we will be unable to establish or maintain a client relationship without it.
In accordance with the Salvadoran Data Protection Law, you have the following rights:
Right of access: to request and receive confirmation of, and a copy of, the personal data we hold about you.
Right of rectification: to request the correction of your personal data at any time if you identify incorrect, incomplete or outdated information. To make a correction effective, we may need to verify the validity of the data you provide.
Right of erasure: to request the deletion of personal data we hold about you. Data will be deleted when you so request or when it is no longer necessary for the provision of our services, except where there is another reason for its retention, such as the mandatory regulatory retention obligations described in Section 8 or the protection of SK Fuerte Capital's rights.
Right to object: to object to the processing of your personal data for specific purposes. In some situations we may demonstrate legitimate or legally mandated grounds to continue processing that override the objection — in particular, processing required by AML/CFT and CNAD regulations cannot be discontinued while the client relationship or the legal retention period subsists.
Right to restriction (blocking): to request the suspension of processing in certain situations, for example while the accuracy of the data is verified.
Right to portability: to receive your personal data in a structured, interoperable format, or to have it transmitted to a third party you designate, where technically feasible.
Right to withdraw consent: where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of prior processing. If you withdraw consent, we may be unable to provide certain services.
Right to review automated decisions: to request human review of decisions made solely on the basis of automated processing of your personal data that affect your interests. Note that certain automated controls — such as sanctions screening blocks and KYT risk blocks — are legally mandated and are subject to compliance review rather than removal.
In some cases we may need to request specific information to confirm your identity before acting on a request, as a security measure to prevent disclosure of personal data to unauthorized persons. We aim to respond to all legitimate requests within five (5) business days; complex requests may take longer, in which case we will keep you informed of progress.
To exercise any of these rights, contact our Data Protection Officer through the channel indicated in Section 11. If you consider that your rights have not been adequately addressed, you may also file a complaint with the competent Salvadoran supervisory authority.
10. Your responsibilities
You are solely responsible for keeping your access credentials in a safe place, and sharing them with third parties is prohibited. Administrative users of corporate accounts are responsible for maintaining the accuracy of the list of authorized persons. You agree to notify SK Fuerte Capital immediately, through a secure channel, of any unauthorized use of your account or any unauthorized access to it.
11. Questions and contact — Data Protection Officer
Our Data Protection Officer (DPO) is available to clarify any questions on this subject. If you have any request or concern regarding the privacy of your data, please contact the DPO by e-mail:
[dpo@skfuertecapital.sv — to be confirmed as the official DPO address]
General inquiries and complaints may also be directed to: info@skfuertecapital.sv
12. Updates to this Privacy Policy
SK Fuerte Capital reserves the right to amend this Policy as necessary to provide you with greater security and transparency and to reflect changes in our services or in the applicable legislation. For this reason, it is important to review this Policy periodically. The date of the last update is indicated at the beginning of the document. Where relevant changes are made that require new authorizations from you, we will publish an updated Privacy Policy and, where applicable, request your renewed consent.
13. Governing law and jurisdiction
This document is governed by, and must be interpreted in accordance with, the laws of the Republic of El Salvador. The courts of the city of San Salvador, Republic of El Salvador, are hereby elected as competent to resolve any disputes arising from this document, with express waiver of any other forum, however privileged it may be, without prejudice to the mandatory competence of CNAD, the UIF or other Salvadoran authorities within their respective spheres.