Legal
Privacy policy
What we collect, why we hold it, who processes it and what you can ask us to do with it.
Last updated 20 August 2026
1.Scope
This policy describes how TANO handles information when you visit this website or use the platform. It applies to the current sandbox deployment and to any future live deployment operated by the same entity.
2.Information we collect
Account information you provide: name, email address and the credentials used to access your account.
Verification information, where identity verification is required: government identification details and screening results returned by the compliance provider.
Platform activity: deposits, allocations, orders, fills, fees, redemptions, withdrawals and assistant conversations recorded against your account.
Technical information: device, browser, IP address, and log data used for security and fraud prevention.
3.Why we use it
To operate your account, execute allocations and maintain the ledger. To meet legal, anti-money-laundering and record-keeping obligations. To protect the platform against fraud and unauthorised access. To provide support and to send service notifications you have not opted out of.
4.Legal bases
Where applicable law requires a legal basis, we rely on performance of a contract with you, compliance with legal obligations, our legitimate interest in operating and securing the platform, and your consent where consent is the appropriate basis.
5.Who processes your data
Service providers acting on our instructions may process data on our behalf: custody providers, identity verification providers, cloud hosting, notification delivery and AI model providers. Each is bound by contract to use the data only for the services provided. We do not sell personal data.
6.AI assistant data
Assistant conversations are stored against your account and are scoped to that account only. Data from other clients is never included in your session context. In the sandbox deployment the assistant runs locally and no conversation data leaves the platform.
7.Retention
Account, ledger and verification records are retained for the period required by applicable financial record-keeping rules, and thereafter deleted or anonymised. Technical logs are retained for a shorter operational period.
8.Your rights
Subject to applicable law you may request access to your data, correction of inaccurate data, deletion where retention is not legally required, a portable copy, and restriction or objection to certain processing. Requests can be made through the contact page.
9.Security
Data is encrypted in transit and at rest. Access is limited to personnel who need it, operator actions are logged, and authentication controls including two-factor authentication are applied to account access in live deployments.
10.International transfers
Where data is transferred across borders, we use recognised transfer mechanisms and require equivalent protection from the receiving processor.
11.Changes
We will update this page when our practices change and revise the date shown above. Material changes affecting client accounts will also be notified by email.
12.Contact
Privacy questions and data requests can be sent through the contact page or to the privacy address published there.