1Purpose
This Compliance Policy describes, at a high level and for transparency to our users and partners, how DoctorSwap (“we”, “us” or “our”) operates its automated, non-custodial Digital Asset swap service in a risk-aware manner. In practice, a user requests a quote, sends the input asset to a generated deposit address, our systems screen the deposit before anything is paid out, a third-party exchange or liquidity provider performs the conversion, and the output asset is sent to the user’s destination address. There are no user accounts or stored balances; each swap is a one-off Transaction. This Policy explains the compliance controls that sit around that flow.
2Our Role
DoctorSwap is a non-custodial technology provider. The Services are delivered through an automated software tool (a “bot”) that lets users exchange one Digital Asset for another by routing assets to a network of established third-party exchanges and liquidity providers that perform the conversion on their own platforms. The company behind DoctorSwap is a technology company registered in the Republic of Costa Rica. The regulated conversion of Digital Assets — and the customer-level compliance that conversion entails — is carried out by those licensed/registered providers, not by us. We are transparent that we operate the technology and screening layer around each swap: we generate deposit addresses, screen deposits and destination addresses, route Transactions, and can hold, decline or return a Transaction on a risk or legal basis. In the ordinary course we:
- do not take custody of user Digital Assets, and do not pool, hold, lend or control user funds;
- do not operate as a bank, custodian, exchange, money transmitter or money-services business, and do not ourselves perform the regulated conversion of Digital Assets; and
- do not carry out the regulated exchange activity itself — the conversion, and any customer onboarding it entails, occurs at the level of the exchanges to which the Services connect.
This description of our role is aligned with our Terms of Service and with our internal assessment of the Costa Rican regulatory perimeter, which we keep under review with qualified counsel as the law develops (see Section 9).
3Transaction Screening
Every inbound Digital Asset deposit is subject to automated transaction screening (“Know-Your-Transaction” / KYT) using our third-party transaction-screening (blockchain-analytics) provider, to assess the source and risk of funds before a swap is completed. Both the deposit (source) address and the destination (payout) address are screened, and no payout is released until screening has completed and a clear result has been reached.
We apply a dynamic, risk-based approach to customer due diligence. The Services are available to individuals (natural persons) only. For low-value, lower-risk swaps the service can be used without identity verification. Where our risk controls or applicable law require it — for example on higher-value activity, or where screening or other indicators raise the risk — we may request identity verification and, in higher-risk cases, source-of-funds information, as a condition of processing a Transaction. We do not publish the exact thresholds or indicators that trigger these steps.
4Sanctions and Prohibited Activity
We apply sanctions screening of relevant addresses and counterparties against the lists of the U.S. Office of Foreign Assets Control (OFAC), including its Specially Designated Nationals (SDN) List, the United Nations, the European Union and the United Kingdom (OFSI), and other applicable authorities. We will not knowingly facilitate Transactions involving sanctioned persons, entities, wallets or jurisdictions, or Transactions connected to stolen or hacked funds, child sexual abuse material, terrorist financing, ransomware or darknet-market activity.
Where screening identifies or reasonably suggests any of the above, we may delay, refuse, return, withhold or stop the Transaction, request verification, and restrict the relevant address — in each case in accordance with applicable law and consistent with our Terms of Service. Taking custody of, or freezing, an asset is not part of our ordinary business model, and we do not freeze assets as a discretionary business choice. However, where applicable sanctions law or a valid legal order requires it, we will comply — which may include not completing the Transaction and not returning the asset, and instead acting in accordance with applicable law and lawful direction. The mechanics of any hold or return follow our Terms of Service and our internal handling procedure.
5Liquidity Providers
We connect only to established, reputable exchanges and liquidity providers that maintain their own licensing or registration and their own compliance programmes; the regulated conversion of Digital Assets, and the related customer-level compliance, are performed by these providers. We do not, however, rely on a provider’s licence alone. We apply documented, risk-based due diligence to each provider before integrating it — including verification of its licence/registration, ownership and beneficial owners, and sanctions and adverse-media screening — and we monitor providers on an ongoing basis.
We suspend or disconnect a provider, and route through alternatives, where it becomes sanctioned, loses or has suspended its licence/registration, suffers a serious AML or compliance failure, enforcement action, insolvency, or a major security incident, or where credible adverse media indicates such a problem. Our internal Liquidity / Exchange Partner Policy sets out these onboarding checks, monitoring and suspension triggers in detail.
6Data Minimisation and Security
We collect only the data necessary to operate the Services and apply our screening controls, and we handle it in accordance with our Privacy Notice, which is the authoritative description of what we collect (including during screening and any verification) and how long we keep it. We retain data for as long as necessary for those purposes and to meet our legal obligations. Certain records — in particular anti-money-laundering, screening and verification records — must be kept for minimum periods set by law (no less than five years where required), and we retain those for the required period before deletion or anonymisation, even where other data is deleted sooner. Data is encrypted and held on secured infrastructure with access controls; our detailed security controls are maintained internally.
7Law-Enforcement Cooperation
We cooperate with law enforcement and competent authorities in response to valid, lawful requests. Requests are validated internally before any data is shared — we confirm the legal basis, authority and scope of a request and disclose only what is legally required. Where applicable law requires, we report relevant activity to the competent authorities, including Costa Rica’s financial intelligence unit (the Unidad de Inteligencia Financiera within the Instituto Costarricense sobre Drogas), in line with our internal suspicious-activity procedure and staff escalation process. We observe the no-tipping-off principle and safeguard user privacy to the extent permitted by law.
8Prohibited Users and Jurisdictions
We do not provide the Services to sanctioned persons or entities, to persons in prohibited or sanctioned jurisdictions, or to United States persons, nor to anyone using the Services in connection with unlawful activity. “United States persons” is applied consistently to US citizens and residents, entities organised in the United States, and access from United States IP addresses; a reliable US nexus is treated as a basis to decline. The prohibited and restricted jurisdictions we enforce are aligned with the restricted-jurisdictions list in our Terms of Service and our internal compliance procedures.
We restrict access from the United States and other prohibited locations using IP-based geo-blocking together with detection of VPN, proxy, Tor and other anonymising or evasion methods, and we act on repeat circumvention attempts; users also represent that they are not US persons and are not located in a prohibited jurisdiction. Accessing the Services from a prohibited location, or circumventing these controls, is prohibited, and we may block access without notice.
9Review and Updates
This Policy is reviewed at least annually, and additionally whenever there is a material change in our business, our partner network, or applicable law — including developments in the Costa Rican regulatory framework for virtual asset service providers. The current version and its date are published on this page.
10Contact
Compliance enquiries may be directed to [email protected]