1Introduction
About us. DoctorSwap ("we", "us" or "our") operates an automated, non-custodial Digital Asset swap service in a risk-aware manner: a user requests a quote, sends the input asset to a generated deposit address, our systems screen the deposit before anything is paid out, a third-party exchange or Liquidity Provider performs the conversion, and the output asset is sent to the user’s destination address. The Services are operated by 3-102-959244 Sociedad de Responsabilidad Limitada (S.R.L.), a company registered in the Republic of Costa Rica under corporate ID 3-102-959244, with registered office at Provincia 01 San José, Cantón 01 San José, Mata Redonda, Sabana Norte, Avenida Las Américas, Edificio Torres del Parque, Número Trescientos Tres. This entity is the data controller for the processing described in this Notice.
This Privacy Notice explains how 3-102-959244 Sociedad de Responsabilidad Limitada (S.R.L.) ("DoctorSwap", "we", "us" or "our"), a company organised under the laws of the Republic of Costa Rica, collects, uses, discloses and otherwise processes personal information in connection with Drswap.io and our related products, APIs, widgets and automated tools (collectively, the "Services"). DoctorSwap is a non-custodial technology tool that lets users swap Digital Assets, with the conversion performed by third-party Liquidity Providers. Our data practices are deliberately minimised: we collect only what is necessary to deliver the Services, apply our risk and sanctions controls, and meet our legal obligations.
By accessing or using the Services you confirm that you have read and understood this Privacy Notice. Reading this Notice is not, by itself, your consent to all processing described here: most of our processing relies on legal bases other than consent (Section 4), and where we do rely on consent (for example, certain analytics cookies) we ask for it separately and you may withdraw it. We may update this Notice at any time; the current version and its "Last updated" date are always published at Drswap.io.
1.1Our role (controller / processor)
For most personal information we handle to operate the Services — transaction data, screening results, verification data, communications and security logs — 3-102-959244 Sociedad de Responsabilidad Limitada (S.R.L.) acts as the controller (it determines the purposes and means of processing). Our vendors — hosting, transaction-screening, sanctions-screening, identity-verification and analytics providers, including AMLBot, the third-party provider of our transaction-screening (KYT) and identity-verification (KYC) services — act as our processors and handle data on our documented instructions. Liquidity Providers act as independent controllers (or, for Travel-Rule information where applicable, as separate obliged entities) for the data they receive to execute a conversion and for their own compliance; their processing is governed by their own privacy notices. Where we and another party jointly determine purposes and means for a specific processing activity, we act as joint controllers and allocate responsibilities in the relevant agreement.
2How Data Flows Through a Transaction
Our processing follows the Transaction lifecycle, so that it is clear what is collected at each step:
- Before deposit (quote). When you request a Quote, we process the assets and amounts selected, your Receiving Address, and technical data (IP address, device/session signals) used to serve the Quote and apply geo-blocking and eligibility checks.
- After deposit (screening gate). When you deposit, we process the deposit (Sending) address, the transaction hash, amount and asset, and run KYT and sanctions screening on the deposit and destination addresses and associated flows, generating a risk score and category flags.
- During conversion (LP routing). To execute the swap, we transmit the minimum data necessary to the selected Liquidity Provider — typically the assets, amounts and the relevant addresses, and, where a transfer/Travel Rule applies, limited originator/beneficiary information.
- Payout, return or hold. We process the payout (Receiving) address and payout hash, or the return details, or — where a Compliance Review or legal override applies — the hold, verification and reporting data.
3Information We Collect
We collect the categories below. Because wallet addresses, IP addresses and KYT metadata can, alone or combined with other data, be linked to an individual, we treat them as personal information and protect them accordingly — even where we do not set out to identify you.
| Category | What it includes | Source |
|---|---|---|
| CategoryTransaction data | What it includesQuote ID; input/output assets and amounts; quoted and executed rate and fees; deposit (Sending) address; destination (Receiving) address; deposit and payout transaction hashes; confirmations; timestamps; LP routing/order data; return details. | SourceYou; the Services; public Blockchains; Liquidity Providers |
| CategoryRisk & sanctions screening data | What it includesKYT metadata: composite risk score (0–100), exposure category flags, list-match details, hop/exposure data, and the disposition. Automated screening is a control gate: a Medium/High score or a possible sanctions match holds the payout for review; adverse results can lead to hold, return, block or a report. A human reviewer decides adverse outcomes (Section 6). | SourceAMLBot (our third-party transaction-screening provider); our systems |
| CategoryVerification (KYC) data | What it includesWhere a tier or trigger applies: name, date of birth, nationality, residence country; government-issued ID document and liveness/selfie check; source-of-funds / source-of-wealth evidence; PEP/adverse-media results. | SourceYou; AMLBot (our third-party identity-verification provider); official registers |
| CategoryCommunications | What it includesYour name, contact details, social handle and message contents when you contact support via [email protected] or the on-site form. Access is restricted to support/compliance staff on a need-to-know basis. | SourceYou |
| CategoryTechnical & usage data | What it includesIP address; device/session identifiers; operating system and browser; URLs accessed; date/time and duration; general (non-precise) location; VPN/proxy/Tor signals used for eligibility; and cookies/analytics per Section 3.1. | SourceAutomatically collected |
| CategoryThird-party data | What it includesData from Liquidity Providers, screening/analytics providers and public sources (including public Blockchains), which we may combine with data we hold to operate our controls. | SourceLiquidity Providers; AMLBot (transaction screening / blockchain analytics); public sources |
3.1Cookies, analytics and device data
We use strictly necessary cookies required to operate the Services and to apply our security and geo-blocking controls; these cannot be switched off. We also use analytics cookies, provided by our third-party analytics provider, to understand how the Services are used and to improve them. Analytics cookies are set only with your consent, which we request via a cookie banner on your first visit; you can withdraw or change your choices at any time through the cookie settings. Server and security logs (including IP addresses and access events) are kept for the periods in Section 8.
4How We Use Information and Legal Bases
We use personal information to: (i) provide, operate and maintain the Services and execute Transactions; (ii) apply KYT, sanctions and risk screening and verification, and prevent fraud and abuse; (iii) provide support and resolve disputes; (iv) maintain the security and integrity of the Services; (v) comply with applicable law (including AML/CFT record-keeping and reporting) and respond to valid legal process; and (vi) communicate with you.
We do not sell your personal information, and we do not use it for behavioural advertising or for building marketing profiles. We do not use verification or transaction data for unrelated profiling. Aggregated or anonymised data may be used to improve and secure the Services.
Legal bases (where data-protection laws such as the EU/UK GDPR apply to a user accessing the Services): performance of our contract with you (executing your Transaction and support); compliance with a legal obligation (AML/CFT screening, verification, record-keeping and reporting under Law No. 7786 (consolidated as Law No. 8204) and applicable sanctions law, and under Article 15 quáter as added by Legislative Decree No. 10961 once it enters into force on or about 19 September 2026); our legitimate interests (security, fraud prevention, safe operation of the Services), balanced against your rights; and consent (for non-essential cookies/analytics), which you may withdraw. Costa Rican data-protection law (Law No. 8968 and its regulations) applies to our processing in Costa Rica.
5How We Disclose Information
We disclose personal information only as set out below, to the minimum extent necessary, and we maintain and reconcile a processor/vendor and Affiliate map to keep this accurate:
| Recipient | What is shared and when | Safeguard |
|---|---|---|
| RecipientLiquidity Providers | What is shared and whenAt the conversion step: assets, amounts and relevant addresses, and — where a transfer/Travel Rule applies — limited originator/beneficiary information. | SafeguardContract; data minimisation; independent-controller notice |
| RecipientScreening / analytics provider: AMLBot (transaction screening and blockchain analytics) | What is shared and whenAt the screening gate: addresses and transaction data needed to screen exposure and sanctions. | SafeguardProcessor agreement; purpose limitation |
| RecipientIdentity-verification vendor: AMLBot | What is shared and whenWhen verification is triggered: identity/SoF documents and data you submit. | SafeguardProcessor agreement; encryption |
| RecipientHosting / infrastructure (our cloud hosting provider) | What is shared and whenData processed to host and secure the Services. | SafeguardProcessor agreement; encryption; access controls |
| RecipientTravel-Rule providers (if/when applicable) | What is shared and whenFor qualifying transfers: originator/beneficiary information required by the rule. | SafeguardProcessor/independent-controller terms; minimisation |
| RecipientLaw enforcement / authorities (incl. UIF/ICD) | What is shared and whenWhere required by law or valid legal process; limited to what is legally required. | SafeguardValidated internally (Section 5.1); no tipping-off |
| RecipientAffiliates | What is shared and whenOnly Affiliates that assist in providing, supporting or securing the Services, for that role only. | SafeguardCommon control; same protections; role limitation |
| RecipientCorporate transactions | What is shared and whenIn a merger, acquisition, financing or sale of assets, information may transfer as an asset. | SafeguardConfidentiality; successor bound by this Notice |
5.1Validating and logging disclosures
Law-enforcement and authority requests are validated by our compliance function against the requesting authority and legal basis before any disclosure; disclosures are approved by the Compliance Officer (or Deputy), limited to what is legally required, and logged (who requested, what was disclosed, the legal basis and date). Access to sensitive files (verification and any suspicious-activity records) is restricted and access-logged.
6Automated Screening and Decisions
We apply automated transaction screening as a control gate on every deposit. Screening itself does not make a final adverse decision about you: where a score or flag warrants it, the Transaction is held and a human reviewer in our compliance function decides the outcome (proceed, request verification, return, block or report). Where a decision producing a legal or similarly significant effect would be based solely on automated processing and data-protection law gives you the right to human involvement, you may contact us (Section 13) to request review, subject to the limits of what we can disclose for sanctions and anti-tipping-off reasons.
7Blockchain Transparency
Transactions are recorded on public Blockchains. Information written to a Blockchain (such as addresses, amounts and timestamps) is public, may be visible to anyone, and — because of the immutable nature of Blockchains — generally cannot be altered or deleted by us. You should be aware that wallet addresses and transaction patterns can be linked to your identity by us or by third parties through blockchain-analytics techniques (including the clustering and attribution used in our KYT screening). Please consider this before transacting.
8Data Retention
We retain personal information for the period required by applicable law and otherwise only for as long as necessary for the purposes above. For AML/CFT records, the minimum retention is five (5) years, consistent with Law No. 7786. After the applicable period, data is deleted or irreversibly anonymised. Information recorded on a public Blockchain cannot be deleted by us.
| Data category | Retention | Basis |
|---|---|---|
| Data categoryTransaction & screening records (addresses, hashes, amounts, KYT results, dispositions) | Retention5 years from the Transaction date | BasisAML/CFT record-keeping (Law 7786 / Art. 15 quáter; FATF R.11) |
| Data categoryVerification (CDD/EDD) files | Retention5 years from the last Transaction of the linked cluster | BasisAML/CFT record-keeping |
| Data categorySuspicious-activity (ROS/SAR) files | Retention5 years from filing/decision (longer if required) | BasisLaw 7786 / UIF direction; confidentiality (Art. 25) |
| Data categorySupport communications | Retention24 months, or longer where linked to a dispute or case | BasisLegitimate interest; legal claims |
| Data categoryTechnical / security & access logs | Retention2 years (5 years where linked to a case) | BasisSecurity; extended where case-linked |
| Data categoryCookies / analytics data | RetentionPer Section 3.1 and your consent choices; analytics cookies expire no later than 13 months after being set | BasisConsent / strictly necessary |
8.1Erasure and the AML override
Where a retention period ends, or where a valid erasure request applies and no overriding obligation exists, we delete or irreversibly anonymise the personal information in our internal systems, so that any on-chain identifiers we hold (such as wallet addresses) can no longer be linked by us to an identified or identifiable person. Where you ask us to erase data that we are legally required to keep — in particular AML/CFT records subject to the five-year minimum, or data under a legal hold, investigation or sanctions obligation — we cannot delete it until that obligation ends; we will tell you when this is the case. We cannot alter or remove data already written to a public Blockchain.
9Data Security
- Hosting. The Services and data are hosted with our cloud hosting provider on secured infrastructure.
- Encryption. Data is encrypted in transit (TLS 1.2+/TLS 1.3) and at rest (AES-256 or equivalent).
- Access controls. Role-based, least-privilege access; sensitive files (verification, suspicious-activity records) restricted to compliance roles; access reviewed at least quarterly.
- Logging. Privileged actions and access to sensitive records are logged to an immutable, tamper-evident audit trail.
- Vendor security. Processors are assessed for security and bound by contract; data minimisation is applied to what each receives.
- Incident handling. We maintain an incident-response process and will notify affected individuals and competent authorities where required by applicable law within the applicable timeframes.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10Your Rights
Depending on your jurisdiction (including under Costa Rican Law No. 8968 and, where applicable, the EU/UK GDPR), you may have rights to access, correct, delete, port, or object to or restrict certain processing of your personal information, and to withdraw consent where processing is based on consent. To exercise a right, contact [email protected]. We verify your identity and, for wallet-linked data, may ask you to demonstrate control of the relevant address before we act, so that we do not disclose data to the wrong person. We respond within 30 days (extendable where permitted, with notice). We may refuse or limit a request where the data is subject to a legal retention or hold, where disclosure would breach the no-tipping-off rule or an ongoing investigation, where it would adversely affect others’ rights, or where the request is manifestly unfounded or excessive; we will explain the basis for any refusal to the extent we are legally permitted.
11Children
The Services are not directed to, and we do not knowingly collect personal information from, anyone under the age of 18. We enforce this age restriction through the eligibility representation in the Terms of Service and, where identity verification is triggered, through the date-of-birth and ID checks performed by our verification vendor; we do not otherwise age-verify every user at access. If we learn that we hold personal information of a person under 18, we delete it promptly.
12International Transfers and Third-Party Links
We and our processors may process personal information in countries other than where you reside, including Costa Rica and the jurisdictions where our hosting, screening, verification and analytics vendors and Liquidity Providers operate. Where transfers are subject to data-protection laws that restrict cross-border transfers (such as the EU/UK GDPR), we rely on an appropriate safeguard — for example an adequacy decision or Standard Contractual Clauses — and apply data minimisation. The current list of processor jurisdictions and safeguards is available on request at [email protected]. The Services may link to third-party sites and Liquidity Providers whose privacy practices we do not control; please review their notices.
13Contact and Complaints
- Privacy requests and questions: [email protected] (privacy-specific address, monitored by the Compliance Officer / privacy owner).
- Escalation: if you are not satisfied with our response, you may escalate to 3-102-959244 Sociedad de Responsabilidad Limitada (S.R.L.)’s Compliance Officer at [email protected] and, where applicable, lodge a complaint with the competent data-protection authority in your jurisdiction (in Costa Rica, the Agencia de Protección de Datos de los Habitantes — PRODHAB).