X4T Card Privacy Policy

Version 1.0 — effective 10.09.2026

This X4T Card Privacy Policy (“Policy”) explains how personal data is collected, used, stored, shared, transferred, retained and otherwise processed in connection with the X4T Card programme.

Please read this Policy carefully. By applying for, activating, holding or using an X4T Card, a Card Account or any related service (including digital wallet enrolment such as Google Pay), you acknowledge that you have read and understood this Policy and that your personal data will be processed as described here.

This Policy forms part of the X4T Card programme account agreement (the “Agreement”) published at https://x4t.com/en/card-terms-and-conditions. It should be read together with:

If there is any inconsistency between this Policy and another X4T document solely in relation to Card programme personal data, this Policy prevails.


Contents

1. Who we are

1.1 Programme administrator

X4T S.A. (“X4T”, “we”, “us” or “our”) administers the X4T Card programme, distributes Cards, operates the Card interface in the X4T application and website, and provides cardholder servicing and support.

Legal name X4T S.A.
Taxpayer ID (R.U.C.) 80117664-6
Registered office Calle Coronel Tito Bogado 2650, Asunción, Republic of Paraguay
Commercial office The Top Business Center, Av. Aviadores del Chaco esq. César López Moreira, Floor 16, Office 1602, Asunción 1529, Paraguay
Email support@x4t.com
Phone +595 992 443 344

X4T is licensed in Paraguay as a Virtual Asset Service Provider (VASP).

1.2 Issuer

The X4T Card is issued as a Visa card by:

Reap Technologies Limited, a company incorporated in Hong Kong with company registry number 2714427 (the “Issuer”).

The Issuer is the principal issuer of the Card on the Visa payment network. Any right, discretion or determination relating to issuance, authorisation, settlement, card scheme rules, credit or spend decisioning, tokenization or scheme compliance may be exercised by the Issuer, by X4T, or by either acting on behalf of the other.

1.3 Controllers

For Card programme personal data:

  • X4T is the controller (administrador / responsable del tratamiento) for programme administration, onboarding in the X4T application, customer support, marketing (where permitted), linking the Card to your X4T account or wallet, crypto-to-fiat conversion related to Card spend, complaints handling and X4T’s own AML/CFT and record-keeping obligations.
  • The Issuer is an independent controller (and, where applicable under scheme or issuing arrangements, a joint controller) for card issuance, PAN/token lifecycle, authorisation, clearing and settlement, scheme reporting, issuer-side fraud, credit or collateral assessment, and issuer regulatory obligations.
  • Visa International and its affiliated scheme entities process transaction and token data as independent controllers or processors according to Visa rules and Visa’s own privacy notices.
  • Digital wallet providers (for example Google) process wallet, device and token data under their own privacy policies. X4T does not control those processing activities.

Where X4T and the Issuer jointly determine purposes and means of processing, they act as joint controllers and will make available the essence of any joint-controller arrangement on request.

You may contact X4T for any Card privacy request. We will coordinate with the Issuer where the request relates to issuer-held data. You may also contact the Issuer through the channels published in the Issuer’s privacy policy at https://reap.global/resources/info/privacy-policy.

1.4 Who this Policy applies to

This Policy applies to:

  • the holder of a Program Account;
  • any Administrator appointed on a Program Account;
  • any Authorized User of an X4T Card;
  • applicants and persons whose data is provided during onboarding (including directors, beneficial owners, signatories and other related persons of a business applicant); and
  • any person who contacts us about a Card, dispute, chargeback or lost/stolen Card or device.

Capitalised terms not defined in this Policy have the meaning given in the Agreement or the Google Pay Terms.


2. Scope

This Policy covers personal data processed in connection with:

  • Card applications, eligibility checks and onboarding;
  • issuance of physical and virtual Visa Cards and linked Card Accounts;
  • authorisation, clearing, settlement, presentment, refunds, chargebacks and representment;
  • spend controls, limits, merchant-category and country restrictions;
  • PIN, CVV, 3-D Secure / additional authentication and step-up authentication;
  • tokenisation and digital wallets (including Google Pay / Google Wallet);
  • statements, transaction history, notifications and servicing;
  • fraud, dispute, collections and recoveries (where applicable);
  • creditworthiness, collateral, repayment or funding-source assessment (where the product includes a credit, charge or collateralised facility);
  • conversion of crypto-assets or fiat held with X4T to fund or settle Card spend;
  • AML/CFT, sanctions, PEP and proliferation-financing screening;
  • regulatory, tax, audit, scheme and law-enforcement requests; and
  • improvement, security and operation of the Card programme.

This Policy does not replace:

  • the general X4T platform privacy disclosures for exchange, wallet and trading services;
  • Visa’s privacy notices;
  • the Issuer’s privacy policy;
  • Google’s privacy policy and Google Pay / Google Wallet terms; or
  • the privacy notices of merchants, acquirers, ATM operators or other independent third parties.

Blockchain transactions that you initiate outside the Card rails (for example an on-chain transfer from your X4T wallet) are public or semi-public by design. That processing is described in the general X4T terms, not in this Policy, except where those balances are used to fund or collateralise the Card.


3. Personal data we process

We process only what is needed for the purposes in Section 5. The categories below are illustrative. Exact items depend on product type (virtual / physical, consumer / business), jurisdiction, funding model and the checks required by the Issuer, Visa and applicable law.

3.1 Identity and KYC data

  • Full name, former names, date and place of birth, nationality, citizenship, tax residency, gender (where collected).
  • Government identity documents and extracts: cédula de identidad, passport, residence permit, driver’s licence or other accepted ID; document number, issuing country, issue and expiry dates; images of the document; MRZ / NFC chip data where used.
  • Selfie, liveness / video-identification recording and biometric templates derived solely to verify that the person presenting the ID is the applicant (see Section 8).
  • Signature, where collected.
  • For business Program Accounts: company name, trade name, legal form, registration number, R.U.C. / tax ID, registered and operating addresses, constitutional documents, ownership structure, directors, officers, authorised signatories, ultimate beneficial owners and their KYC data.

3.2 Contact and account data

  • Residential, postal and (for business) registered / operating addresses.
  • Email address, mobile number and other phone numbers.
  • X4T user ID, Program Account ID, Administrator / Authorized User role.
  • Language preference and communication channel preference.
  • Customer-support tickets, call recordings, chat logs, emails and complaint files.

3.3 Financial, credit and funding data

  • Occupation, employer, industry, source of funds / source of wealth declarations and supporting evidence.
  • Income, assets, liabilities and other affordability or creditworthiness information, where the product involves credit, a credit limit, repayment or collateral.
  • Credit-information reports and payment-behaviour data obtained from or reported to credit bureaux / sociedades de información crediticia, in accordance with Ley N° 6534/2020 and applicable bureau rules.
  • Card Account balances, available spend, reserved amounts, credit limits, collateral balances, repayment history, fees, interest (if any), FX conversions and chargebacks.
  • Linked X4T wallet / exchange balances used to fund or settle Card spend (asset type, amount, network, timestamp). Fiat funding and payout details (bank name, account identifier, payment reference), where used.
  • Statements and transaction reports.

3.4 Card and payment data

  • Primary Account Number (PAN), expiry date, service code, sequence number and card form factor (physical / virtual).
  • Card verification values (CVV/CVC) — processed only as required to complete a transaction or authentication and not stored after authorisation, except as permitted by PCI DSS.
  • PIN blocks — processed in encrypted form in PCI-compliant environments; PINs are not stored by X4T in clear text.
  • Device Card Number / payment token, token expiry, token requestor ID, wallet provider ID and token state (active, suspended, deleted).
  • Authorisation, clearing and settlement messages, including amount, currency, date/time, merchant name, merchant ID, acquirer ID, MCC, terminal ID, ATM ID, country, city, POS entry mode (chip, contactless, e-commerce, token, manual), authorisation code, response code, retrieval reference, chargeback reason codes and dispute documents.
  • 3-D Secure / authentication payloads, results and risk scores.
  • Cash-withdrawal data where ATM access is enabled.

X4T and the Issuer apply tokenisation and PCI DSS controls so that full PAN is not stored in X4T’s general application environment where it can be avoided. Display in the app is truncated (typically first 6 / last 4 or last 4 only).

3.5 Device, technical and security data

  • Device type, manufacturer, model, OS version, app version, browser type, language, time zone.
  • Device identifiers, advertising or instance IDs (where used), IP address, approximate network location.
  • Jailbreak / root / integrity / emulator / malware signals.
  • Login timestamps, session tokens, 2FA / OTP events, failed authentication attempts.
  • Diagnostic logs and crash reports related to Card features.

3.6 Location data

  • Coarse location inferred from IP, BIN country or merchant country.
  • More precise device location only where you enable location services for a Card feature (for example wallet provisioning, fraud challenge, ATM finder or in-app map) or where a wallet provider collects it under its own policy.

3.7 Digital-wallet data

When you add a Card to Google Pay or another supported wallet we (and/or the Issuer, Visa and the wallet provider) process:

  • wallet account identifiers;
  • device eligibility and security posture;
  • provisioning and additional-authentication results;
  • Device Card Number / network token;
  • wallet transaction authorisation messages;
  • device-unbind, suspend and delete events.

Google’s processing is governed by Google’s terms and privacy policy. X4T does not control Google’s systems.

3.8 Fraud, risk and compliance data

  • Sanctions, PEP, adverse-media and watchlist hits and disposition notes.
  • Internal and vendor fraud / credit / AML risk scores and rules-engine outputs.
  • Device fingerprinting and behavioural signals (typing cadence, navigation patterns, velocity of spend or login) used to detect account takeover and card fraud.
  • Case files for investigations, SAR/ROS equivalents, law-enforcement requests and scheme reports.
  • Records of restricted jurisdictions and blocked merchants or MCCs.

3.9 Marketing and preference data (optional)

  • Marketing consents and withdrawals.
  • Product-interest flags and campaign interaction (open, click), where permitted.

3.10 Data we do not intentionally collect

We do not require political opinions, religious beliefs, health data, sexual orientation or union membership to issue or operate the Card. If such data appears incidentally (for example a merchant name that reveals a medical or religious purchase), we do not use it to infer sensitive attributes for marketing. Sensitive data is treated under Section 8.

We do not sell personal data.


4. Where the data comes from

  • You, when you apply, onboard, use the Card, contact support or upload documents.
  • Your Administrator or Program Account holder, if you are an Authorized User.
  • Your X4T account profile, where Card onboarding re-uses existing KYC instead of collecting it twice.
  • The Issuer, Visa, token service providers, acquirers, merchants and ATM operators, through scheme messages.
  • Digital wallet providers.
  • Identity-verification, liveness, document-authenticity, AML screening, fraud and credit-bureau providers.
  • Public and official sources: sanctions lists, PEP lists, company registries, adverse media, court or insolvency records, to the extent permitted by law.
  • Devices and logs generated automatically when you use the app, website or Card.
  • Persons you authorise (for example an attorney-in-fact acting under a power of attorney accepted by X4T).

If you provide personal data about another person (Authorized User, director, UBO, family member, referee), you must have the authority to do so and must ensure that person is informed of this Policy.


We process personal data only where at least one legal basis applies. Because the programme serves customers in Paraguay and other permitted jurisdictions, we apply:

  • the Constitution of Paraguay (including habeas data);
  • Ley N° 1.682/2001 (private information) and its amendments;
  • Ley N° 6.534/2020 (protección de datos personales crediticios) and BCP regulations on credit bureaux, where credit information is processed;
  • consumer-protection rules administered by SEDECO and any applicable card-transparency rules;
  • AML/CFT and VASP obligations applicable to X4T, including SEPRELAD requirements;
  • Hong Kong and other issuer-jurisdiction requirements applicable to the Issuer;
  • Visa scheme rules and PCI DSS;
  • where a data subject is in the EEA, UK or another GDPR-equivalent jurisdiction, or where we have publicly committed to GDPR-style standards, the principles of Regulation (EU) 2016/679 (GDPR) as a contractual / best-practice standard.

Typical purpose / basis mapping:

Purpose Main legal basis
Assessing the application; issuing and personalising the Card; opening and operating the Card Account; executing transactions, refunds and chargebacks; providing statements and in-app Card controls Performance of the Agreement (contract). For pre-contract checks: steps at your request before entering the Agreement
Linking the Card to your X4T wallet / exchange account and converting crypto or fiat to fund or settle spend Contract; where conversion is optional, consent or contract for that feature
KYC/CDD, ongoing monitoring, sanctions / PEP screening, record-keeping, suspicious-activity reporting Legal obligation (AML/CFT, VASP, issuer and scheme rules)
Creditworthiness, credit-limit, collateral and repayment assessment; reporting and consulting credit information Contract; legal obligation under Ley 6534/2020 and bureau rules; where required, your express authorisation
Strong customer authentication, 3-D Secure, OTP, device binding, tokenisation Contract; legal obligation (fraud / SCA rules where applicable); legitimate interests in preventing unauthorised payments
Fraud, account-takeover and dispute prevention; scheme risk programmes Legitimate interests of X4T, the Issuer, Visa, merchants and other cardholders; legal obligation
Digital-wallet provisioning and operation Contract (wallet terms you accept); legitimate interests in secure tokenisation; consent where a wallet or OS requires it (biometrics remain on-device where possible)
Customer support, complaints, chargebacks, recordings of calls / chats Contract; legitimate interests; legal obligation (consumer and scheme complaint handling)
Regulatory, tax, audit, scheme, court and law-enforcement requests Legal obligation; legitimate interests in defending claims
Product analytics, service improvement, aggregated management information Legitimate interests; consent where a cookie / SDK requires it
Service messages (security alerts, OTP, limit warnings, statements) Contract; legal obligation
Marketing of X4T or Card features by email / push / WhatsApp / SMS Consent, or other basis permitted by Paraguayan law; you can opt out at any time
Corporate transactions (merger, sale of programme) Legitimate interests; legal obligation

Legitimate interests are balanced against your rights. You may object (Section 12). We will not use legitimate interests where a law requires consent or a specific authorisation (in particular, dissemination of financial-solvency data under Ley 1682/2001 and credit-data rules under Ley 6534/2020).

If you do not provide data marked as required, we cannot assess the application, issue the Card, authorise transactions or keep the Card Account open.


6. Automated decision-making and profiling

We and the Issuer use automated systems, rules engines and scoring models to:

  • decide whether to approve, decline, suspend or limit an application, Card, device, wallet token or individual transaction;
  • set or change spend limits, MCC / country blocks and 3-D Secure challenges;
  • detect fraud, mule activity, sanctions exposure and unusual spend; and
  • (where the product includes credit or collateral) estimate credit or collateral risk.

These systems may produce a decision with legal or similarly significant effect, for example a declined application or a blocked payment.

You may request human review of a decision that affects you, express your point of view and contest the outcome by contacting support@x4t.com, unless the decision is required by law (for example a mandatory sanctions hit) or is necessary to enter into or perform the Agreement and suitable safeguards apply.

We do not use Card transaction data to make automated decisions about unrelated matters (for example employment) and we do not sell inferred profiles.


7. How we share personal data

We share personal data only as described below and on a need-to-know basis.

7.1 The Issuer and programme partners

  • Reap Technologies Limited and its affiliated issuing, processing and programme-manager entities.
  • Visa Inc., Visa International Service Association and other Visa-group companies, plus Visa Token Service and related token service providers.
  • Card personalisation / printing and fulfilment vendors for physical Cards.
  • Authorisation, clearing, settlement and dispute processors.
  • 3-D Secure / ACS providers and OTP / SMS / email gateway providers.

7.2 Digital wallets

Google and any other wallet provider you choose. Their processing is independent and subject to their policies.

7.3 Identity, fraud, AML and credit providers

  • Document-authenticity, liveness and KYC vendors.
  • Sanctions, PEP and adverse-media screening vendors.
  • Fraud-prevention networks and consortiums (which may use hashed or tokenised identifiers to detect multi-institution fraud).
  • Credit bureaux / sociedades de información crediticia, where permitted or required by Ley 6534/2020 and your Agreement. We may consult and, where legally required or authorised, report payment behaviour (positive and negative) related to the Card Account.

7.4 X4T infrastructure and professional advisers

  • Cloud hosting, monitoring, customer-support, e-mail and communications providers.
  • Custody and conversion infrastructure used when Card spend is funded from crypto balances (including Fireblocks as custody technology provider, to the extent Card funding touches those systems).
  • Compliance analytics providers (for example on-chain analytics used to assess source of funds).
  • Auditors, lawyers, accountants and consultants under confidentiality duties.

7.5 Your organisation (business cards)

If the Card is issued under a company or Program Account, transaction and control data is visible to the Administrator and to other persons the Administrator authorises. X4T is not responsible for how that organisation uses data internally.

7.6 Merchants, acquirers and ATM operators

When you pay or withdraw cash, the merchant / ATM operator and its acquirer receive the data needed to accept, reconcile and dispute the transaction (name on card or token, truncated PAN or token, amount, device data as sent through the scheme). Their privacy practices are their own.

7.7 Authorities and compulsory disclosure

We disclose data where we are required or permitted to do so by law, scheme rules or a competent authority, including SEPRELAD, the Banco Central del Paraguay, SEDECO, tax authorities, courts, police, financial-intelligence units and equivalent foreign authorities, and Visa risk / compliance programmes.

7.8 Corporate events

If X4T or the Card programme is involved in a reorganisation, assignment, financing or sale, personal data may be disclosed to counterparties and their advisers under confidentiality arrangements, and transferred to the successor operator of the programme.

We do not share personal data with unaffiliated parties for their own direct marketing unless you consent.


8. Sensitive data and biometrics

Under Ley 1682/2001 and comparable standards, sensitive data includes racial or ethnic origin, political opinions, religious or philosophical beliefs, health, sexual life and, where used to uniquely identify a person, biometric data.

  • Identity biometrics (selfie / liveness) are used only to verify identity and prevent impersonation. Templates, if retained, are stored by us or our KYC processor with access controls and are not used for unrelated identification.
  • Device biometrics (fingerprint, face unlock) used to open the X4T app or to confirm Google Pay are processed on your device by the operating system or wallet. X4T does not receive the raw biometric template from Google Pay or from the device OS.
  • We do not use sensitive data for marketing.
  • Publication or dissemination of financial-solvency data is restricted as required by Ley 1682/2001 and Ley 6534/2020.

9. International transfers

Card programme data is processed in Paraguay and is transferred to, stored in or accessed from other countries, including:

  • Hong Kong and other locations where the Issuer and its processors operate;
  • countries where Visa, token service providers and scheme processors operate (including the United States);
  • countries where Google and other wallet providers operate;
  • countries where our cloud, KYC, fraud, SMS and support vendors operate (which may include the EEA, United Kingdom, United States and others).

These countries may not have a data-protection regime identical to Paraguay’s. We use one or more of the following safeguards:

  • transfers necessary to perform the Agreement with you (you cannot use a global Visa card without scheme routing);
  • transfers required by law or scheme rules;
  • contractual confidentiality and data-processing terms with vendors;
  • where GDPR-style standards are applied, appropriate transfer tools (for example standard contractual clauses) and supplementary measures;
  • your informed acknowledgement that a global card programme requires cross-border processing.

By applying for and using the Card you understand that scheme authorisation messages will leave Paraguay in real time.


10. Retention

We keep personal data only as long as needed for the purpose collected, and thereafter as required for legal, tax, AML, scheme, accounting and dispute purposes.

Indicative periods (the longest applicable period prevails):

Record type Typical retention
Application / KYC / CDD file Duration of the relationship plus at least 5 years after the Card Account is closed (or longer if AML or issuer rules require)
Transaction, authorisation, settlement and statement data At least 5 years after the transaction or closure, and longer if a dispute, chargeback or investigation is open
Credit-information consultations and reports As required by Ley 6534/2020 and bureau / BCP rules
Support recordings and complaint files Typically up to 5 years after closure of the ticket, or longer if a claim is reasonably anticipated
Fraud and investigations files Until the investigation and any limitation period ends
Marketing consents and suppression lists For the period the consent is valid, and thereafter as needed to honour opt-outs
PCI cardholder data Only as permitted by PCI DSS; CVV and full track data are not stored after authorisation
Device / security logs Short operational period unless needed for security investigation
Backups Rolling cycles, then overwritten

When a period expires we delete, destroy or irreversibly anonymise the data, unless a hold is required (litigation, regulator request, scheme audit).

Closure of the Card or removal of a wallet token does not immediately erase historical transaction and KYC records.


11. Security

We and the Issuer implement organisational and technical measures appropriate to the risk, including:

  • PCI DSS controls in environments that store, process or transmit cardholder data;
  • tokenisation and truncation of PAN;
  • encryption in transit (TLS) and encryption or equivalent protection at rest for sensitive fields;
  • network segmentation, firewalls, vulnerability management and periodic testing;
  • access control, least-privilege, logging and staff confidentiality obligations;
  • vendor due diligence;
  • business-continuity and backup arrangements.

No method of transmission or storage is completely secure. You must also protect your devices, PINs, OTPs, passwords, 2FA and wallet unlock methods, and notify us immediately of loss, theft or suspected misuse.

If a personal-data or cardholder-data incident is likely to result in a relevant risk, we will notify affected persons and competent authorities as required by applicable law, Visa operating regulations and PCI requirements.


12. Your rights

Subject to legal exceptions (AML tipping-off rules, scheme confidentiality, rights of others, legally mandated retention), you may exercise:

  1. Access / information — confirmation of whether we process your data and a copy of the main data and recipients.
  2. Rectification — correction of inaccurate or incomplete data.
  3. Erasure / cancellation — deletion where the data is no longer needed and no overriding legal basis applies.
  4. Opposition — objection to processing based on legitimate interests or to direct marketing (marketing objection is absolute).
  5. Restriction — limitation of processing in the cases provided by applicable law.
  6. Withdrawal of consent — where processing is based on consent; withdrawal does not affect prior lawful processing.
  7. Portability — a structured, commonly used copy of data you provided, where technically feasible and where the processing is based on consent or contract and is automated.
  8. Review of significant automated decisions — as described in Section 6.
  9. Credit-data rights under Ley 6534/2020 — access to credit information held about you, rectification of inaccurate credit data, and information about recipients of credit data, including through the relevant bureau.
  10. Habeas data — constitutional action to access and, where appropriate, update or suppress data in public or private registries.

How to exercise your rights

Email support@x4t.com with the subject line “X4T Card privacy request”, or write to the commercial office address in Section 1, or call +595 992 443 344.

Please include:

  • your full name and X4T user ID / Card last four digits;
  • a copy of your identity document if we cannot match you from the account;
  • the right you wish to exercise and what you want us to do;
  • whether the request also concerns Issuer-held data.

We may ask for additional information to verify your identity and will not fulfil a request if we cannot verify it. We will respond within the period required by applicable law. If the request concerns data held only by the Issuer, Visa or a wallet provider, we will tell you and, where appropriate, relay the request.

Exercising your rights is free of charge unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse.

Complaints

You may lodge a complaint with:

  • X4T at the contacts above;
  • SEDECO (Secretaría de Defensa del Consumidor y el Usuario), for consumer issues;
  • the authority competent for credit-information protection under Ley 6534/2020 / BCP rules (and any successor national data-protection authority);
  • for Issuer-side processing, the channels in the Issuer’s privacy policy, including its DPO function (XpertDPO Ltd, dpo@xpertdpo.com, 20 Harcourt Street, Dublin, D02 H365, Ireland, as published by Reap);
  • if GDPR applies to a specific processing activity, a supervisory authority in the EEA or UK, in particular in your place of residence.

This does not limit any other remedy available under Paraguayan law.


13. Marketing

We will send commercial communications about the Card or other X4T products only where permitted.

You can opt out at any time by:

  • using the unsubscribe link in an email;
  • changing notification settings in the X4T application; or
  • emailing support@x4t.com.

Service, security and legal notices are not marketing and will continue.


14. Children

The X4T Card is not offered to persons who do not meet the minimum age and eligibility requirements in the Agreement. We do not knowingly collect personal data from children to issue a Card. If you believe we have collected such data, contact us and we will delete it unless we are legally required to retain it.


15. Cookies and in-app trackers

The X4T website and application use cookies and similar technologies as described in the general X4T terms / cookie notice. Card-specific features may set additional strictly necessary cookies or local storage items to keep you logged in, remember Card preferences and protect sessions. Analytics or advertising SDKs run only with the consent required by the applicable notice.


Merchants, Apple / Google / other wallet providers, Visa, acquirers, ATM operators and browsers are independent controllers for their own processing. Their terms and privacy policies apply. X4T is not responsible for their practices.

Public blockchain networks are not controlled by X4T. If you fund the Card from crypto, on-chain data may be visible to third parties indefinitely.


17. Authorized Users and Administrators

If you are an Administrator you must:

  • only enrol Authorized Users who have agreed to the Agreement and this Policy;
  • keep Authorized User data accurate; and
  • ensure your organisation has a lawful basis to share employee / contractor data with X4T and the Issuer.

Authorized Users acknowledge that the Program Account holder and Administrator can see their Card transactions and can freeze, limit or cancel their Card.


18. Changes to this Policy

We may update this Policy to reflect changes in the programme, the Issuer, Visa rules or the law. The current version is published at https://x4t.com/en/card-privacy-policy and shows the version number and effective date.

Material changes will be notified through the X4T application, website or email. Continued use of the Card after the effective date constitutes acceptance of the updated Policy, except where applicable law requires a specific consent.

If you do not agree, you must stop using the Card and request closure in accordance with the Agreement. Historical processing remains subject to the Policy in force at the time of processing, unless the new Policy is more favourable to you or is required by law.


19. Language and governing law

This Policy is issued in English. English is the official and binding language of this Policy. If a translation is published later, it is for convenience only and the English version prevails in case of conflict.

This Policy is governed by the laws of the Republic of Paraguay. Courts of the city of Asunción have jurisdiction, without prejudice to mandatory consumer forums and to any dispute-resolution clause in the Agreement.

Issuer processing may additionally be subject to the laws applicable to Reap Technologies Limited.


20. Contact

For Card privacy questions, requests or complaints:

X4T S.A.
The Top Business Center
Av. Aviadores del Chaco esq. César López Moreira
Floor 16, Office 1602
Asunción 1529, Paraguay

Email: support@x4t.com
Phone: +595 992 443 344

Lost or stolen Card or device: notify us immediately through the X4T application or at the contacts above. Delay increases your liability under the Agreement.

Issuer privacy policy: https://reap.global/resources/info/privacy-policy
Google privacy policy: https://policies.google.com/privacy
Visa privacy centre: https://www.visa.com/privacy (or the Visa privacy notice for your region)


End of X4T Card Privacy Policy — Version 1.0