Privacy Policy
Pacha Exchange is a business platform. This policy explains what we collect about you and the people at your organization, why we hold it, who we share it with, how long we keep it, and how you get it back or have it erased.
Last updated: August 28, 2026
1. Who controls your data
Pacha Exchange, Inc. is a company incorporated in Delaware, United States, with its place of business at 3114 Leland Street, Chevy Chase, Maryland 20815, United States. It is the controller of the personal data described here. Write to administration@pachaexchange.com, or to that address, for anything in this policy — including requests to see, correct, export or delete your data.
We are established in the United States and serve users in Peru, the European Union and elsewhere, so we comply with United States federal and state privacy law, with Peru's data protection law, and, where it applies, with the GDPR. Our operations in Peru are run by our Peruvian subsidiary, part of the same group and our establishment there. Users in Peru may send any request in this policy to that company or to us; either route reaches the same team.
Where your organization uploads data about its own staff, customers or suppliers into the platform, your organization is the controller of that data and we act as its processor, under the terms of your service agreement with us.
2. What we collect
| Category | Examples |
|---|---|
| Account and identity | Name, work email, phone, job role, password hash, language, profile photo, login history and the devices or IP addresses you sign in from |
| Organization and legal | Company name, tax identifier, registered and operating addresses, legal documents you upload, team membership and permissions |
| Commercial | Listings, orders, negotiations, shipments, inventory, agronomy records, connections and contacts, and the messages and notes attached to them |
| Financial | Prices, payment terms, invoices, settlements, payment evidence, and bank account details you add for payouts (stored encrypted) |
| Files you upload | Invoices, packing lists, liquidations, receipts, photos and any other document or spreadsheet you or your counterparties submit |
| Technical and usage | Pages visited, features used, timestamps, browser and device data, error logs, and AI token usage counted for billing |
We do not ask for special-category data (health, biometrics, political or religious views) and you should not upload it. We do not knowingly collect data from anyone under 18; the platform is for business use only.
3. Where it comes from
- From you directly, when you register, fill in a form or upload a file.
- From your organization, when an administrator invites you or edits your permissions.
- From your counterparties, when another company on the platform records an order, a document or a contact that names you.
- From service providers, such as carriers and tracking services that return shipment status, and payment providers that confirm a transaction.
4. Why we use it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Running your account and delivering the features of your plan | Performance of our contract with you or your organization |
| Processing your documents with AI agents so the platform can extract, reconcile and route the data they contain | Performance of contract; legitimate interest in automating manual data entry |
| Billing, invoicing, collections and usage metering | Performance of contract; legal obligation under tax law |
| Security, fraud prevention, abuse detection and audit logging | Legitimate interest in keeping the platform and its users safe |
| Service emails: verification codes, invitations, payment reminders, incident notices | Performance of contract |
| Product analytics and improvement | Consent, given through our cookie banner |
| Responding to lawful requests and defending legal claims | Legal obligation; legitimate interest |
Where we rely on consent, you may withdraw it at any time without affecting anything we did before you withdrew it.
5. How we use artificial intelligence
Parts of the platform are built on large language models. When you upload a document, ask an agent a question, or use extraction, reconciliation, ERP export, the settlement reader or the company analyst, the content you submit is sent to our AI provider, Anthropic, and processed on servers in the United States.
- That content can include personal data and commercial data contained in your files, and the prompts you type.
- Anthropic processes it on our instructions as a subprocessor and does not use content submitted through its commercial API to train its models.
- AI output is a suggestion, not a decision. Extractions, reconciliation matches and settlement readings are surfaced for a person at your organization to review, edit or reject.
- We do not make decisions about you that produce legal or similarly significant effects using automated processing alone.
- AI is imperfect. Check its output before you rely on it for a payment, a contract or a filing.
Where the platform tells you that you are talking to an agent, you are interacting with an AI system rather than a person.
7. International transfers
The platform runs on infrastructure in the United States, so data you enter in Peru or Europe is transferred there and processed by us and by the providers listed above. When personal data leaves the European Economic Area, the United Kingdom or Peru, we rely on Standard Contractual Clauses or an equivalent transfer mechanism, together with encryption in transit and at rest. Ask us and we will describe the safeguards that apply to a specific transfer.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | For as long as the account is active, then up to 24 months |
| Commercial and financial records, invoices and settlements | For the period required by applicable tax and commercial law — generally seven years in the United States, and five years after the relevant tax period for records tied to Peru |
| Documents you upload | Until you delete them or the parent record is deleted; a background sweep removes orphaned and abandoned uploads |
| Security and audit logs | Up to 12 months |
| Analytics data | Up to 14 months, or until you withdraw consent |
| Backups | Rolling, overwritten within 90 days |
When a retention period ends we delete the data or irreversibly anonymize it. Records we must keep for tax or legal reasons are retained even after an account closes, and are not used for anything else.
9. Your rights
Depending on where you live, you have some or all of the following rights. We honour all of them for every user, wherever you are.
- Access — get a copy of the personal data we hold about you and know who we shared it with.
- Rectification — correct anything inaccurate or incomplete.
- Erasure — have your data deleted, except records we must keep by law.
- Portability — receive your data in a structured, machine-readable format, or have it sent to another provider.
- Objection and restriction — object to processing based on legitimate interest, or ask us to pause it while a dispute is resolved.
- Opt out — of any sale of personal data, targeted advertising, or profiling with a legal or similarly significant effect. We do none of these, so there is nothing to opt out of, but the right stands if that ever changes.
- Withdraw consent — turn off analytics cookies at any time from our Cookie Policy.
- Non-discrimination — we will not degrade your service because you exercised a right.
To exercise any of these, write to administration@pachaexchange.com from the address on your account, or ask us to verify you another way. We answer within 45 calendar days and will tell you if we need one extension. An authorized agent may act for you if you confirm the authorization. Using these rights is free.
If we refuse a request, we will tell you why and how to appeal. To appeal, reply to our decision at administration@pachaexchange.com with the word "appeal". We will decide within 60 days, explain our reasoning in writing, and give you a way to complain to your state attorney general if you are still unsatisfied.
If data was uploaded about you by an organization that uses Pacha, we will forward your request to that organization, since it decides what happens to its records.
10. Security
- Traffic is encrypted with TLS and stored data is encrypted at rest.
- Bank account details are encrypted with AES-256-GCM under a key held in a managed secret store, separate from the database.
- Documents you upload live in a private bucket and are reachable only through short-lived signed links issued to authorized users.
- Access is role- and permission-based, sessions can be revoked, and logins from unrecognized sources are challenged with a one-time code.
- Photos published on public listing pages are served from a public content network. Do not put confidential material in a listing image.
No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority within the deadlines the law sets — 72 hours under the GDPR, 60 days under Delaware law, and the period required by Peruvian law.
12. Changes and complaints
We update this policy when our practices change. Material changes are announced in the app or by email before they take effect, and the date at the top always shows the current version.
Talk to us first at administration@pachaexchange.com. You can also complain to the Delaware Department of Justice, to your own state attorney general in the United States, to the Autoridad Nacional de Protección de Datos Personales in Peru, or to your national data protection authority in the European Union or the United Kingdom.