PRIVACY NOTICE
MONETTY — Monetty Fintech Ltda.
Document drafted in accordance with Law No. 13.709/2018 (General Personal Data Protection Law – LGPD), Law No. 12.965/2014 (Marco Civil da Internet) and Law No. 8.078/1990 (Consumer Defense Code).
PART 1 — PLAIN-LANGUAGE SUMMARY
"What We Do With Your Information"
This summary was created so that you can understand, quickly and without legalese, how Monetty collects, uses, stores, and protects your personal information when you use the Monetty website and the international transfer, receipt of funds from abroad, currency conversion (foreign exchange), and cross-border payment services made available through it. This summary does not replace the complete Privacy Notice presented in Part 2 of this document, which is the text that prevails legally in the event of doubt or conflict of interpretation.
If you have any questions about how we process your data, contact us through the channels below:
- General contact e-mail: hello@monetty.com
- Support e-mail: support@monetty.com
- Privacy e-mail: privacy@monetty.com
- Telephone: +55 (24) 99851-2163
- Website: https://monetty.com/
1. Who is responsible for the processing?
Monetty Fintech Ltda., enrolled with the CNPJ under No. 57.609.035/0001-40, is the Controller of your personal data, that is, it is the party that makes the decisions about how and for what purpose your data are used. To enable part of the operations (such as processing of international transfers, foreign exchange, payments, and identity verification), Monetty uses partners — called Operators — that process data exclusively under our instructions and for the authorized purposes.
2. How do we secure your data?
We adopt technical and administrative measures compatible with Monetty's size, currently classified as a small-scale processing agent, following the guidance of the ANPD Guidance Guide for Small-Scale Processing Agents, with use of encryption in transit (HTTPS/TLS), secure storage, permission-based access control, user authentication, one-time passcode (OTP) confirmation, event logging (logs), backups, anti-fraud monitoring, and manual review of atypical operations.
3. Which data do you need to provide?
The data vary according to the type of user:
- Individual User (end customer): full name, e-mail, telephone, date of birth, nationality, residential address, identification document (RG, CNH, or passport), CPF, selfie for identity verification, proof of address, bank details, information on the beneficiaries of the transfers, and data of the transactions carried out (amounts, currencies, countries of origin and destination).
- Legal Entity User (client company): corporate name, trade name, CNPJ, business address, constitutive documents, data of legal representatives, partners, and ultimate beneficial owners (UBOs), identification documents of the representatives, bank details, and other documents required in the KYB process.
- Website visitor: browsing data, cookies, IP address, device identifiers, and access logs.
4. For what purposes do we use your data?
We use your data to create and manage your account, verify your identity (KYC/KYB), prevent fraud, process transfers and payments, issue receipts, provide customer service and support, ensure the security of the website, comply with legal and regulatory obligations, send communications related to the services, and continuously improve your experience. The specific purposes and legal bases for each data item are detailed in the table in Clause 6 of this Notice.
5. With whom do we share your data?
We share only the strictly necessary data with our operator partners — authorized payment institutions, identity-verification providers (KYC/KYB), cloud-hosting services, and fraud-prevention tools — to enable the requested financial operations, always with an applicable legal basis, and also when required by court order or determination of a competent authority.
6. Will your access logs be collected?
Yes. We collect and store, in confidence, the IP address, date, and time of access to the website, for a minimum period of 6 (six) months, as required by article 15 of Law No. 12.965/2014 (Marco Civil da Internet).
7. Will data be collected indirectly?
Yes, through cookies and similar technologies used on our website, including necessary and advertising cookies, as well as technical data about your device and use of the website. To learn more, see our Cookie Policy, available on our website.
8. Will communications records be stored?
Yes. The history of conversations carried out through the official customer-service channels (e-mail and WhatsApp) is stored for customer service, follow-up of requests, fraud prevention, continuous improvement of support, and as evidence of the interactions carried out, with access restricted to authorized persons.
9. What are your rights?
You have the right to: (i) confirmation that we process your data; (ii) access to the data; (iii) correction of incomplete or outdated data; (iv) anonymization, blocking, or deletion of unnecessary data; (v) portability to another provider; (vi) deletion of data processed on the basis of consent; (vii) information about with whom we share your data; (viii) information about the possibility of not providing consent and its consequences; and (ix) revocation of consent at any time.
10. What is the content of the Notice?
The complete Privacy Notice, presented in Part 2, contains the following clauses:
- Date of Availability
- Glossary of Technical Terms
- Processing Agents
- Information Security
- Data Collection
- Processing of Personal Data
- Account Closure and Data Deletion
- Data Subject Rights
- Changes to the Privacy Notice
- Privacy Communication Channel
- Contact on General Matters
PART 2 — FORMAL PRIVACY NOTICE
1. DATE OF AVAILABILITY
1.1. This Privacy Notice was made available and enters into force as of 12/09/2026.
2. GLOSSARY OF TECHNICAL TERMS
2.1. For a better understanding of this Notice, the definitions of the main technical terms used follow:
- Controller: legal entity to which the decisions regarding the processing of personal data compete.
- Cookies: small text files stored on the User's device for recognition and improvement of the browsing experience.
- Encryption: data-encoding technique that prevents unauthorized access to the information.
- Personal data: information related to an identified or identifiable natural person.
- Sensitive personal data: data about racial or ethnic origin, religious conviction, political opinion, membership in a trade union, data concerning health or sexual life, genetic or biometric data.
- Data Protection Officer (DPO): person appointed to act as a communication channel among the Controller, the data subjects, and the ANPD.
- IP (Internet Protocol): numeric code that identifies a device connected to a network.
- Operator: legal entity that carries out the processing of personal data on behalf of the Controller.
- Data processing: every operation carried out with personal data, such as collection, storage, use, sharing, and deletion.
- User(s): natural or legal person that uses the Monetty website, in the modalities described in subclause 2.2.
2.2. The following are considered Users of the Monetty website:
2.2.1. Individual User: individual who uses the website to send, receive, or convert financial resources.
2.2.2. Legal Entity User: company that contracts Monetty's services to make international payments to suppliers and service providers.
2.2.3. Visitor: person who accesses the website without registering or carrying out a financial operation.
3. PROCESSING AGENTS
3.1. Monetty Fintech Ltda. acts as Controller of the personal data collected from its Users, being responsible for defining the purposes and means of processing such data, with the objective of enabling the provision of international transfer services, receipt of funds from abroad, currency conversion (foreign exchange), cross-border payments, beneficiary management, issuance of receipts, identity verification (KYC/KYB), and monitoring of transactions through a digital account.
3.1.1. Monetty acts as a technological platform and interface with the User, with the regulated financial services being executed by partner institutions duly authorized by the competent bodies, as detailed in the Terms of Use.
3.2. For the execution of certain stages of the service, Monetty uses partners that act as Operators, processing personal data exclusively in accordance with Monetty's instructions and for the purposes indicated below:
3.2.1. Nvio Brasil Bitso Instituição de Pagamento Ltda. (CNPJ No. 35.136.120/0001-03): processing of the international transfers, payments, and receipts carried out in Brazil.
3.2.2. Asaas Gestão Financeira Instituição de Pagamento S.A. (integration in progress): provision of payment accounts, Pix, boleto payments, and other financial services, when those services are launched.
3.2.3. Identity-verification service providers (KYC/KYB), cloud hosting, and fraud prevention: processing restricted to the data strictly necessary for the performance of those activities.
3.3. The Operators indicated above undertake to process the shared personal data exclusively for the purposes described in this clause, adopting security, technical, and administrative measures capable of protecting the personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication, or dissemination, their use for different purposes being prohibited, under penalty of civil, criminal, and administrative liability before the National Data Protection Authority (ANPD).
3.4. International Transfer of Data. The servers used by Monetty are located in the United States of America, for which reason certain personal data of the User are transferred outside the national territory. The transfer observes, in any event, compliance with the LGPD, with Resolução CD/ANPD nº 19/2024, and with the Standard Contractual Clauses approved by the ANPD, guaranteeing a level of protection of personal data compatible with that provided for in Brazilian legislation.
4. INFORMATION SECURITY
4.1. Monetty, currently classified as a small-scale processing agent, adopts the security measures recommended by the ANPD Guidance Guide for Small-Scale Processing Agents. If Monetty ceases to fall within that category, it will apply international information-security standards, formal risk analysis, and its own Information Security Policy (PSI).
4.1.1. The measures adopted include controls for prevention, detection, response, and recovery from security incidents, with a focus on preserving the confidentiality, integrity, and availability (CIA triad) of the personal data processed.
4.1.2. Among the measures adopted are encryption of data in transit (HTTPS/TLS), secure storage of the information, permission-based access control, authentication of Users, confirmation by one-time passcode (OTP), anti-fraud monitoring, event logging (logs), performance of backups, and observance of internal information-security policies.
4.2. Access logs (IP address, date, and time) are kept in confidence, in a controlled environment of restricted access, for a minimum period of 6 (six) months, pursuant to article 15 of Law No. 12.965/2014 (Marco Civil da Internet) and article 7º, item II, of the LGPD.
4.3. Monetty undertakes to maintain the stability and security of the website, while remaining exempt, however, from liability for any invasions, unauthorized access, or attacks carried out by third parties that use unlawful means to violate the security mechanisms adopted, undertaking, in those cases, to adopt the diligence necessary to identify the party responsible and mitigate the damages.
5. DATA COLLECTION
5.1. The collection of personal data occurs according to the User profile:
5.1.1. Individual User: full name, e-mail, telephone, date of birth, nationality, residential address, identification document (RG, CNH, or passport), CPF or equivalent tax document, selfie for identity verification, proof of address, bank details, information on the beneficiaries of the transfers, data of the transactions carried out, and other information necessary to fulfill the regulatory KYC and anti-money-laundering obligations.
5.1.2. Legal Entity User: corporate name, trade name (when applicable), CNPJ or equivalent registration, business address, constitutive documents of the company, data of legal representatives, partners, and ultimate beneficial owners (UBOs), identification documents of the representatives, bank details, and other documents required in the KYB process.
5.1.3. Visitor: browsing data, cookies, IP address, device identifiers, operating system, browser type, and access logs.
5.2. Monetty stores the history of conversations carried out through the official customer-service channels (e-mail and WhatsApp), for customer service, follow-up of requests, problem resolution, fraud prevention, continuous improvement of service, and as evidence of the interactions that took place between Monetty and the User, access to such records being restricted to authorized persons.
5.3. Certain data are collected automatically, through cookies and similar technologies, including IP address, device identifiers, operating system, browser type, access logs, website-usage information, and diagnostic data, used for security, fraud prevention, monitoring of website stability, performance analysis, compliance with legal obligations, and improvement of the browsing experience, as detailed in the Cookie Policy of Monetty, available on its website.
5.4. Monetty does not carry out continuous monitoring of Users' location. Occasionally, approximate location data may be used, obtained from the IP address or provided by the device upon the User's authorization, exclusively to reinforce security, prevent fraud, comply with regulatory obligations, and improve the experience of use.
6. PROCESSING OF PERSONAL DATA
6.1. By accepting this Privacy Notice, the User declares that they are aware of and agree with the processing of their personal data under the terms and for the purposes described in the table below:
| Type of Personal Data | Legal Basis | Purpose |
|---|---|---|
| First name/Last name | Art. 7º, V, LGPD — performance of a contract | Identification of the User for provision of the contracted service and fulfillment of contractual obligations. |
| CPF/RG | Art. 7º, II, LGPD — compliance with a legal or regulatory obligation | Identity verification (KYC) and compliance with anti-money-laundering rules (PLD/FT). |
| E-mail/Telephone | (a) Art. 7º, V, LGPD — performance of a contract (b) Art. 7º, IX, LGPD — legitimate interest |
(a) Communication about the provision of the service, support, and User assistance. (b) Sending of communications and offers of Monetty products and services. |
| Identification documents, selfie (biometric verification), and proof of address | Art. 7º, II, LGPD — compliance with a legal or regulatory obligation | Identity verification (KYC/KYB) and fraud prevention, in accordance with regulatory requirements applicable to the payments sector. |
| Bank details and transaction information (amounts, currencies, countries of origin and destination) | Art. 7º, V, LGPD — performance of a contract | Processing of the currency-conversion, sending, and receipt of funds operations requested by the User. |
| Data of the beneficiaries of the transfers | Art. 7º, V, LGPD — performance of a contract | Execution of the international transfer orders requested by the User, management of the beneficiary list, and issuance of the respective receipts. |
| Corporate data, data of legal representatives and of ultimate beneficial owners — UBOs (Legal Entity User) | Art. 7º, V, LGPD — performance of a contract | Contractual formalization, fulfillment of the KYB process, and execution of international payment services for companies. |
| Conversation history | Art. 7º, IX, LGPD — legitimate interest | Continuous improvement of customer service and production of evidence of the interactions carried out between Monetty and the User. |
| Access logs (IP, source logical port, date and time) | Art. 7º, II, LGPD — compliance with a legal obligation | Fulfillment of the access-log retention obligation provided for in art. 15 of Law No. 12.965/2014, for a minimum period of 6 (six) months. |
| Technical data of the device and of website use (device identifiers, operating system, browser, and diagnostic data) | Art. 7º, IX, LGPD — legitimate interest | Information security, fraud prevention, monitoring of website stability, and performance analysis. |
| Approximate location data | Art. 7º, II, LGPD — compliance with a legal or regulatory obligation | Reinforcement of the security of the operations, fraud prevention, and fulfillment of regulatory obligations applicable to the payments sector. |
| Cookies and browsing data | Art. 7º, I, LGPD — consent | Personalization of the browsing experience and analysis of website performance, in accordance with the Cookie Policy. |
7. ACCOUNT CLOSURE AND DATA DELETION
7.1. Monetty may cancel the User's account in the event of inappropriate conduct, violation of the Terms of Use, indications of fraud, or failure to comply with the applicable regulatory rules.
7.2. The User may close their account and request cancellation of the services at any time, directly through the website or through Monetty's official customer-service channels, without a penalty charge. Financial operations already initiated or completed may not be cancelled and remain subject to the fees previously informed. Before closing the account, the User must regularize any outstanding matters and withdraw the available balance, subject to the applicable legal and regulatory requirements.
7.3. The User's personal data will be deleted when the purpose of the processing has ended, or upon express request sent to the e-mail privacy@monetty.com. The request will be reviewed and fulfilled under the terms of the LGPD, except in the cases in which retention of the data is required by law or by a regulatory rule, necessary to fulfill tax obligations, to prevent fraud, or to regularly exercise rights in judicial, administrative, or arbitral proceedings, as well as access logs, which will be retained under the terms of Law No. 12.965/2014 and article 7º, item II, of the LGPD.
8. DATA SUBJECT RIGHTS
8.1. Under the terms of article 18 of the LGPD, the User, as a personal-data subject, may request from Monetty, as Controller:
8.1.1. Confirmation of the existence of processing of their personal data.
8.1.2. Access to their personal data.
8.1.3. Correction of incomplete, inaccurate, or outdated data.
8.1.4. Anonymization, blocking, or deletion of unnecessary, excessive, or data processed in nonconformity with the LGPD.
8.1.5. Portability of the data to another service or product provider, upon express request.
8.1.6. Deletion of the personal data processed on the basis of consent, except in the retention hypotheses provided for by law.
8.1.7. Information about the public and private entities with which Monetty shared data.
8.1.8. Information about the possibility of not providing consent and about the consequences of refusal.
8.1.9. Revocation of consent, at any time, upon express manifestation by the User.
9. CHANGES TO THE PRIVACY NOTICE
9.1. Monetty may unilaterally amend this Privacy Notice at any time, and the amendments enter into force as of their publication on the website. The User's continued use of the website after publication of the amendments constitutes tacit acceptance of the new conditions.
9.2. When the amendment depends on the User's specific consent, under the terms of the LGPD, the User will be presented with the option to freely and in an informed manner accept or refuse the new conditions.
9.3. If the User does not agree with the amendments made, they may request the closure of their account and the termination of the contractual relationship, without prejudice to the fulfillment of the obligations assumed prior to termination.
10. PRIVACY COMMUNICATION CHANNEL
10.1. Monetty, by reason of its classification as a small-scale processing agent, is exempt from the formal appointment of a Data Protection Officer (DPO), under the terms of Resolução CD/ANPD nº 2/2022.
10.2. Even so, Monetty makes available a specific channel to handle matters related to privacy and the protection of personal data, through the e-mail privacy@monetty.com.
10.2.1. If Monetty comes to formally appoint a Data Protection Officer (DPO), their contact information will be disclosed on the company's website and in this Privacy Notice.
10.3. The Terms of Use of the Monetty website form an inseparable part of this Privacy Notice, and both documents must be interpreted jointly and in a complementary manner.
11. CONTACT ON GENERAL MATTERS
11.1. For general communications not related to privacy and data protection, the User may contact Monetty through the e-mail hello@monetty.com, the support channel support@monetty.com and/or the telephone +55 (24) 99851-2163.
MONETTY FINTECH LTDA.
CNPJ: 57.609.035/0001-40
Address: Rua Jorge Batista Sampaio, nº 44, Bairro Alegria, CEP 27.524-110, Resende/RJ
Date of availability of this Notice: 12/09/2026