Privacy Policy
Versão em português.
Date of publication: July, 17 2026
PRIVACY NOTICE
This Privacy Notice describes how Bladex, Inc. (collectively, “BLADEX”, “we”, “our”, or “us”) collect, use, share, and protect Personally Identifiable Information. This Privacy Policy applies to Personally Identifiable Information collected by BLADEX in the context of our online commercial banking services and governs the collection, use, and disclosure of the information provided by persons acting on behalf of our corporate clients, as well as by general website visitors.
Controller
BLADEX, in its role as Controller, is committed to the protection of Personally Identifiable Information and of all information that could compromise the personal integrity and/or privacy of its clients’ representatives, ensuring regulatory compliance in each of the jurisdictions where our organization has a presence.
Personally Identifiable Information collected
The Personally Identifiable Information that Bladex collects and processes through your use of our Customer Service platform includes:
- Account information (for example, username, selected password, and content preferences).
- Business contact information (first name, last name, identification document, telephone, email, mobile number, mailing address, and any other information the user chooses to provide when contacting us by email, postal mail, telephone, or other channels).
- Professional information (company, position, and role within the organization they represent).
- Transaction details (for example, information about complaints or suggestions).
- Call recording. Where local regulations require or permit it, we monitor or record your communications with us, including telephone calls and emails. We will use these recordings to verify instructions, improve our services, and for evidentiary, training, and quality-control purposes.
- We collect Personally Identifiable Information, device information, and other data from individuals who use our website, our Customer Service platform, and our Online Banking, as well as other related digital financial services. In the event you use our digital platforms, BLADEX may request certain Personally Identifiable Information and biometric data for identification verification and user validation purposes. We also collect information from site visitors through cookies and similar technologies (for more information, see our Cookies Policy)
- Video surveillance. We use security cameras within and around our facilities for the prevention and detection of crimes, which involves the collection of images in accordance with applicable legal regulations.
- Information obtained through surveys in response to questions we may send you, including those for feedback and research purposes.
- Any additional information the user chooses to provide, such as questions, suggestions, and comments.
Purpose. The Personally Identifiable Information we handle at BLADEX is requested from our clients for the sole purpose of properly providing the financial services and products we offer, as well as to comply with the bank’s regulatory obligations.
Personally Identifiable Information will only be subject to the processing authorized by law, by the existing contractual relationship, or by the prior, informed, and express consent of the Personally Identifiable Information subjects. In general terms, Personally Identifiable Information will be used to:
- Manage the relationship with our clients
- Manage our clients’ products and services
- Identification verification and validation of online banking service users
- Process our clients’ instructions or requests
- Research and analysis to improve our services
The Personally Identifiable Information received under the terms and for the purposes mentioned in this Privacy Policy will not be shared with third parties not directly related to the financial products or services arising from the contractual relationship between the data subject and BLADEX, without the prior and express authorization of the Personally Identifiable Information subject.
Exceptionally, Personally Identifiable Information may be shared when there is a court order and/or mandate, or in the cases established by applicable legislation and regulation, in which a judicial or regulatory authority has the right and the obligation to access the Personally Identifiable Information managed by BLADEX. In such cases, access will only be permitted to the Personally Identifiable Information specifically described and related to the situation in question, and not to all the personal information held by our organization.
BLADEX does not use automated decision-making systems, including profiling.
The Privacy Policy set out in this Privacy and Personally Identifiable Information Protection Notice also applies to the Personally Identifiable Information provided by individuals acting on behalf of our corporate clients, as well as to general website visitors. This Privacy and Personally Identifiable Information Protection Notice covers the information collected by BLADEX through the following channels (collectively, the “Services”):
- Our websites, including www.bladex.com
- Our online banking platform and related digital financial services.
- Our email communications.
- Actions
Collection. We collect the Personally Identifiable Information necessary for the proper provision of the services we offer and that are covered by the current contractual relationship between BLADEX and the organization to which the Personally Identifiable Information subject belongs. The information is obtained from forms completed by the Personally Identifiable Information subject when requesting information about a service and/or product; from the service provision contract; from the electronic correspondence; and from some visits to our website, through cookies. (see the Cookie Policy at www.bladex.com).
Processing. Personally Identifiable Information is processed for the purpose of providing the contracted services or executing the operations and/or transactions that the Personally Identifiable Information subject requires. It may also be used to improve our websites and other digital applications available to our clients, as well as to keep them informed about changes in our service hours and other banking services that, by their nature, must be communicated in a timely manner for their benefit. In any case, our policy limits access to the Personally Identifiable Information managed, permitting such access only to employees and third parties who, for legitimate reasons, need to have such personal information. For more information about the processing carried out by BLADEX, consult our Personally Identifiable Information Protection Policy published at www.bladex.com.
We use the Personally Identifiable Information we collect to:
- Provide and deliver our services; manage and administer client accounts; and create and maintain access credentials.
- Respond to requests and questions; communicate with you about the services; provide technical assistance and support; and provide important notices.
- Administer, maintain, and operate the services; diagnose and resolve technological problems; monitor the performance of the services; protect their security; detect and prevent fraud and other harmful activities; and understand how you access and use the services.
- Improve the services and expand our business; better understand our client base; develop new products and services; analyze trends and monitor usage.
- Design and manage marketing and promotional campaigns; assess the effectiveness of such campaigns; send advertisements and promotional materials; and conduct surveys for market research and customer satisfaction.
- Comply with legal requirements (including, but not limited to, FATCA and AMLA2020); defend against legal claims or lawsuits; respond to subpoenas, court orders, or any legal process; protect the rights of BLADEX, clients, or third parties; and detect, investigate, and prevent activities that may violate our policies or be fraudulent or illegal.
- Carry out internal administration, auditing, risk management, regulatory compliance, and operational activities.
- We may use (and occasionally share) information in aggregated or anonymized form for research, analysis, modeling, marketing, and improvement of our services. In all cases, Personally Identifiable Information will be anonymized before being used.
Identity verification through facial biometrics for online banking services (“liveness check”)
In compliance with the regulations in force regarding Personally Identifiable Information protection, including Law 81 of 2019 and Agreement 001-2022 of the Superintendency of Banks of Panama, BLADEX informs that the enrollment and/or authentication process in the online banking services may require an identity verification procedure through facial biometrics, by activating the camera of the client’s device.
This identity verification consists of a liveness check, which allows confirmation that you are a real person and that you correspond to the account holder, and its purpose is to protect your information, prevent fraud, and ensure that only you access our online banking services. During the enrollment and/or access process, we may ask you to carry out an identity verification using your device’s camera (mobile phone or computer).
The enrollment and/or identity authentication process for access to the online banking services may require a verification procedure through facial biometrics, by activating the camera of the client’s device to generate a biometric identifier (facemap), and it is performed only at the moment of verification and does not involve continuous monitoring or subsequent tracking. By accepting this notice, you expressly authorize:
- The activation of your device’s camera only during the verification process.
- The processing of biometric data derived from your face for the exclusive purpose of identity validation.
Conditions and particularities of the processing of biometric data.
- Your express consent, granted at the moment of first using the online banking service, by checking the acceptance box in the facial biometric identification authorization message.
- Identifier generation: The system processes the image in real time to generate a facial map (facemap) or unique biometric identifier.
- Limited use: This identifier is used exclusively to validate your identity.
- Purposes of the processing: identity validation, fraud prevention and detection, compliance with regulatory obligations, and authentication in future access to the online services.
- The processing and retention of the biometric identifier for subsequent logins to the online banking services will be carried out by a provider acting as Processor, and will be responsible for the management and administration of the verification platform.
- From the user’s deactivation, the data will be retained for the period established by the applicable regulation, unless a legal obligation requires a longer period and will be deleted in accordance with the secure deletion protocol described in the “Retention and Deletion of Personally Identifiable Information” section of this Notice.
- Security measures: We apply appropriate technical and organizational controls to protect your Personally Identifiable Information against unauthorized access, loss, or misuse.
- Transfers and subcontractors: The transfer of Personally Identifiable Information and access by third-party subcontractors will be carried out under the highest security standards, always subject to contractual guarantees and appropriate legal mechanisms.
BLADEX and its data processors implement appropriate technical and organizational measures to guarantee the confidentiality, integrity, and availability of Personally Identifiable Information, in accordance with the applicable regulatory standards. These measures include compliance with applicable legal and regulatory obligations, including fraud-prevention measures, encryption in transit and at rest, access control, data segregation, access logs, security testing, periodic audits, and due diligence.
Refusal to provide consent for the processing of biometric data may prevent enrollment in or access to the online banking services, insofar as this mechanism constitutes an essential identification and security control.
Transfer of Personally Identifiable Information
BLADEX operates internationally, so we need to share information with our offices in different countries to carry out our activities and provide support to our clients.
In providing global services, Personally Identifiable Information may be accessible from our international offices when necessary to complete a transaction with the client or to comply with legal or regulatory requirements. Any other transfer of Personally Identifiable Information must be previously authorized by its subject.
For contracting external storage services, BLADEX requires its providers to have levels of Personally Identifiable Information protection equal to or higher than those established in the Republic of Panama. We will not store information on servers located in countries whose Personally Identifiable Information protection legislation is less strict than that of Panama. In addition, all communication between our systems and external servers, whether inside or outside the country, will be carried out under the highest industry security standards.
Disclosure of Personally Identifiable Information
We only share the information collected in the following cases:
With service providers that we consider require access to perform technological, commercial, or professional functions, such as IT, accounting, auditing, tax, and other professional services. In these cases, we will share only the strictly necessary information, based on the legitimate interest established by regulation or service contract. These providers act as Processors and under strict instructions from BLADEX. The access of the Processor and its subcontractors is carried out with contractual guarantees and high security standards.
With our corporate clients, if you are their representative, for the proper provision of the services. In these cases, we only share business contact information.
With entities within our corporate group, to comply with the terms of the service contract and this Privacy Notice, and to the extent permitted by law and regulation.
In the event of corporate events, we reserve the right to transfer to another entity, its affiliates, or its service providers, the information of our corporate clients in connection with, or during the negotiations of, any merger, acquisition, sale of assets or of a line of business, change in share control, or financing transaction. In these cases, some or all of your Personally Identifiable Information may be shared. However, should this occur, we will require these third parties to comply with protection measures equivalent to or higher than ours.
For legal purposes with governmental entities; when necessary to comply with the law; in response to court orders, subpoenas, requirements of law-enforcement authorities, or legal processes, including those for national security purposes; to establish, protect, or exercise our legal rights; as required to enforce our terms or other contracts; to defend against legal claims or lawsuits; or to detect, investigate, prevent, or take action against unlawful activities, fraud, or situations that involve potential threats to the rights, property, or personal safety of any person.
Retention and Deletion of Personally Identifiable Information
Personally Identifiable Information will be retained based on the existing contractual relationship and within the legal and/or regulatory retention periods established for that purpose. Upon the expiration of such periods and within the term provided by the laws in force, the Personally Identifiable Information will be securely deleted from our systems and/or returned to its subjects upon express request. Unless expressly authorized by the Personally Identifiable Information subjects, Law 81 of 2019 establishes that BLADEX may not carry out any processing of the stored Personally Identifiable Information when there is no legitimate interest to perform such processing.
To ensure compliance with the regulations in force and based on industry-recognized security standards, as soon as the legitimate interest for the processing ceases, the Personally Identifiable Information and the documents containing it will be deleted. During the deletion process, the Personally Identifiable Information will be extracted from the databases and repositories used by BLADEX’s operational platforms and applications, and stored securely to initiate the secure deletion protocol that ensures the Personally Identifiable Information cannot be recovered once deleted.
Personally Identifiable Information collected in physical format is always stored securely, and our employees have been instructed not to leave it unattended, nor to place it in transit areas or open spaces within the facilities. For information in physical format, there is a disposal protocol with appropriate security measures that guarantee its protection until the moment of its final disposal.
Storage and Protection
We implement physical, technical, and administrative measures to protect the Personally Identifiable Information collected through our services, digital platforms, and websites. Although we apply rigorous security measures, we cannot guarantee the absolute security of networks, systems, servers, and databases.
In the event of security incidents, we will notify the affected Personally Identifiable Information subjects in a timely manner.
Rights and Actions of the Personally Identifiable Information Subjects
For the purposes of this Privacy Policy, Personally Identifiable Information subjects are the natural persons whose Personally Identifiable Information is subject to any type of processing by BLADEX. BLADEX guarantees the subjects the exercise of the ARCOP Rights, allowing them, upon prior verification of identity and legitimacy, and at no cost, to fully access their Personally Identifiable Information.
Rights. The regulations in force in the Republic of Panama recognize and establish the rights of Personally Identifiable Information subjects, known as ARCOP Rights (Access, Rectification, Cancellation, Objection, and Portability).
Privacy choices when using our services through the website
Personal data subjects have the following choices regarding how we collect and use their information:
- Modify cookie preferences: You can adjust your browser settings to disable or reject cookies on the Internet; however, some features of our services may not operate correctly or be available. Please note that you must configure the preferences on each device you use to access our services.
- Opt out of marketing emails: If you no longer wish to receive promotional emails from BLADEX, you can click the unsubscribe link at the end of our emails.
- Opt out of text messages: If you do not wish to receive transactional text messages, such as account notifications, you can reply STOP to any message or adjust your communication preferences in your account settings. Please note that opting out of transactional messages may affect your ability to use certain features of the services.
- Update account information: If you have an account at BLADEX, you can access, review, and update certain data associated with your account, such as your contact information, by logging into your account.
Exercise and Actions. Based on the rights mentioned, BLADEX declares that Personally Identifiable Information subjects have the right to:
- Know and access, free of charge, the Personally Identifiable Information that BLADEX is processing in any manner. If the subject requests the information on a storage device (USB, CD, etc.), they must provide the medium onto which the information will be transferred or bear the cost of the request. The medium must be unformatted and without prior information. According to the regulations in force, if the Controller obtained the Personally Identifiable Information from a source other than the subject, whether public or private, with or without legitimate interest, the subject may exercise the rights of Objection and/or Cancellation, but not the right of Portability.
- Request, at any time, the update or rectification of their Personally Identifiable Information, when it is incomplete, incorrect, inaccurate, fragmented, irrelevant, outdated, or false.
- Be informed by BLADEX about the use that has been given to their Personally Identifiable Information.
- Object to any unauthorized or expressly prohibited processing of Personally Identifiable Information.
- Withdraw their consent without justification and/or request the deletion of their Personally Identifiable Information, when the scope of the processing consent, the ARCOP Rights, or the applicable regulations are not respected.
- Request and verify, at any time, the express consent granted to BLADEX for the processing of their Personally Identifiable Information.
Procedure for exercising ARCOP Rights
The Personally Identifiable Information subject must access the Request Form available at www.bladex.com or in printed format at BLADEX’s offices to find out which Personally Identifiable Information is stored and/or to request its update, correction, rectification, and/or deletion.
Each request to exercise the ARCOP Rights will receive an internal number, which will be used by the subject when checking the status of their request. BLADEX will have a period of two (2) business days to acknowledge receipt of the request submitted through the website and/or email, register it, and indicate the request number to the subjects. When the request is made in printed format, the internal number will be assigned at the time of delivery.
In the same email indicating the assigned number, or in an email sent within the two (2) days following the delivery of the printed form, the applicant will be notified if it is necessary to correct the request and/or clarify any point of it and/or attach additional documents. The subject will have a period of ten (10) business days, counted from the day following the sending of the email, to comply with the requirement. If, upon the expiration of this period, no response is received or the failure to meet the requirements persists, the status of the request will be recorded and it will be noted in the Request Registry that the subject has not corrected their request.
Processing of requests to exercise ARCOP Rights
BLADEX will respond to any access request within a period of ten (10) business days from its submission. If the request is admitted, BLADEX will execute the action within a maximum of five (5) business days, counted from the day following the receipt of the request. Otherwise, the subject will be notified of the reasons why the request is inadmissible.
If the bank does not comply with the request related to the exercise of the ARCOP Rights, or if the subject is dissatisfied with the decision adopted, they may file a complaint with the Superintendency of Banks. To do so, they will have a period of 30 calendar days, counted from the date on which they received the bank’s formal response or from the date on which the bank did not resolve their request within the corresponding period.
Withdrawal of Consent for the Processing of Personally Identifiable Information
The Personally Identifiable Information subject may, at any time, withdraw their consent for any processing of their Personally Identifiable Information by BLADEX. To do so, they must complete the Processing Authorization Revocation Form available at www.bladex.com and send it by email, duly signed, to oficialpdp@bladex.com, or deliver it in person at BLADEX’s offices.
Data Protection Officer
BLADEX, as Controller of Personally Identifiable Information, and in compliance with the regulations in force, has designated a Data Information Protection Officer, whose functions are as follows:
- Maintain a record of any event that affects the protection of the Personally Identifiable Information processed by the bank.
- Report any deficiency detected in the Personally Identifiable Information protection measures to Senior Management, as well as to the Risk Management Unit and the Internal Audit Unit.
- Coordinate with the Information Security area on security events that impact the protection of Personally Identifiable Information.
- Propose corrective measures that can be implemented to remedy the deficiencies detected in the processing of Personally Identifiable Information.
- Maintain communication with the risk, internal audit, and regulatory compliance areas to identify necessary improvements in the Personally Identifiable Information protection controls.
- Cooperate with the Information Security Officer in the management of security incidents that affect the processing of Personally Identifiable Information.
- Be the liaison with the Superintendency of Banks on matters related to the processing of Personally Identifiable Information.
- Coordinate the annual training plan on Personally Identifiable Information protection.
- Be the contact channel for Personally Identifiable Information subjects, and may receive administrative support from the person responsible for the Complaints Management System, when applicable.
To contact the PDP Officer, write to oficialpdp@bladex.com or call: Panama: +(507) 210-8500
Notice on the use of social media and instant messaging applications
Social media and instant messaging applications are complementary platforms for the dissemination of information and the exchange of digital communication with clients and the general public, but they are not under BLADEX’s responsibility.
Therefore, BLADEX will not send personalized messages through social media and/or instant messaging applications, and any information provided by users through these platforms does not constitute, nor form part of, the Personally Identifiable Information protected by BLADEX, being the sole responsibility of the person who provides the information and of the companies that manage such platforms.
Use of Social Media
BLADEX may use these platforms as a complementary means of promoting products and services. The posts made on social media are directed at the general public.
BLADEX’s official social media profiles are public and use the channels managed by the companies responsible for such platforms, which may make the posts more visible to certain types of clients, according to the Personally Identifiable Information processing consents granted by users when subscribing to such networks.
Use of Instant Messaging Applications
BLADEX may use these platforms to streamline internal communication among employees and with clients. However, since BLADEX has no control over the access to and use of the information by the companies that own these applications, it discourages its employees and clients from sharing sensitive information and documents containing Personally Identifiable Information through these networks.
To ensure information security, it must be shared through secure email or any other protected communication channel implemented by BLADEX.
Right to file complaints for regulatory non-compliance
Based on the provisions of paragraph 6 of article 11 of SBP Agreement 001-2022, BLADEX informs Personally Identifiable Information subjects that, in the event of any non-compliance with the regulations in force and/or with the provisions of this document, they may file complaints with the Superintendency of Banks of Panama.
If the Personally Identifiable Information subject is in a jurisdiction other than the Republic of Panama, they may resort to the Personally Identifiable Information Protection Authority of their jurisdiction.
Updates to this Privacy Policy
We may make modifications to this Privacy Policy from time to time. The date indicated at the top of this Policy reflects the latest revision.
If we make substantial changes, we will notify you in accordance with legal requirements through written, electronic, or other means.