Skip to main content
Convenience translation. This English version is provided for convenience. The Portuguese version prevails.Preliminary version, not yet in force. This Policy is under legal review and is published for consultation. The version in force, with TESA’s corporate details, will be published before API keys are released. Questions: contact@t3sa.com.
Version: 0.1 (preliminary) Last updated: preliminary version of 09/26/2026

1. WHO WE ARE AND WHO THIS POLICY APPLIES TO

1.1. This Policy describes how TESA (corporate name, CNPJ and registered office will be provided in the version in force) (“Tesa”, “we”) processes personal data on the t3sa.com website, in the technical documentation, in the dashboard and in the Tesa API (together, the “Service”). 1.2. The Service is intended exclusively for companies. Even so, we process personal data of natural persons connected to those companies, such as legal representatives, partners, directors and officers, ultimate beneficial owners, authorized users of the dashboard and the API, business contacts and website visitors (“you”). 1.3. This Policy supplements Tesa’s Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use.

2. OUR ROLE IN THE PROCESSING

2.1. Controller. Tesa is the controller of the personal data it processes to operate the Service, register and authenticate users, bill, provide support, ensure security, comply with legal obligations and communicate with clients and prospects. 2.2. Processor. If, under a contract, Tesa processes personal data exclusively on behalf of and on the instructions of a client, it will act as processor. In that case, the client’s privacy policy governs the processing, and the relationship between Tesa and the client is governed by a data processing agreement. 2.3. Independent third parties. Custodians, issuers of tokenized products, Circle and FX partners engaged by the client process data as independent controllers, under their own policies. Tesa does not control that processing.

3. DATA WE PROCESS

3.1. Registration data of representatives and users: name, corporate email, phone number, job title, company, CPF (Brazilian taxpayer ID), documents evidencing powers of representation and records of acceptance of the Terms of Use. 3.2. Company verification data (KYB), where applicable: identification of partners, directors and officers and ultimate beneficial owners, identity document, politically exposed person status and results of sanctions list screening. 3.3. Authentication and credential data: user identifiers, authentication factors, API key identifiers. We do not store the full value of secret keys after issuance, only a hash or identifying fragment. 3.4. Access and API usage logs: IP address, source port when available, date and time with time zone, endpoint called, response code, credential identifier, user agent and technical request metadata. 3.5. Wallet addresses and blockchain data: wallet addresses connected by the client, balances, transactions and events recorded on public networks. These data are public by nature and, when they can be associated with an identifiable natural person, are treated as personal data. 3.6. Billing data: details of the person responsible for finance, billing history and tax documents. 3.7. Communications: content of support messages, emails, meetings and survey responses. 3.8. Browsing data on the website and documentation: cookies and similar technologies, pages visited, referral source, device type and browser, as described in Section 9. 3.9. Data we do not collect: we do not request or store private keys, key shares, recovery phrases or wallet passwords; we do not intentionally process sensitive personal data, except in the case described in item 3.2; and we do not process data of children and adolescents.
4.1. We process personal data only for legitimate, specific and disclosed purposes, based on the legal grounds in article 7 of the LGPD: 4.2. When we rely on legitimate interest, we assess in advance the necessity, proportionality and legitimate expectations of data subjects, and you may object to the processing as provided in article 18, paragraph 2, of the LGPD.

5. SHARING

5.1. We share personal data only to the extent necessary, with: a) Processors engaged by Tesa: cloud and hosting providers, email and communication providers, support providers, metrics and analytics providers, electronic signature providers and, if adopted, registration verification providers, under contracts with confidentiality and security obligations; b) Third parties designated by the client: custodians, FX partners and issuers, only when the client requests it or when necessary for a technical integration the client has enabled. These third parties act as independent controllers; c) Authorities: upon a legal request, court order or to comply with a legal or regulatory obligation; d) Corporate transactions: in the event of a merger, acquisition, spin-off or sale of assets, with the successor, which must respect this Policy. 5.2. Tesa does not sell personal data.

6. INTERNATIONAL TRANSFER

6.1. Some of Tesa’s providers store or process data outside Brazil, in particular in the United States and the European Union. These transfers comply with articles 33 to 36 of the LGPD and ANPD Resolution CD/ANPD No. 19/2024, based on: (i) standard contractual clauses approved by the ANPD; (ii) an adequacy decision, where one exists; or (iii) another applicable legal basis, such as necessity for the performance of a contract or for the regular exercise of rights (art. 33, IX). 6.2. The updated list of destination countries and mechanisms used is available on request to the data protection officer.

7. RETENTION

7.1. We keep personal data for as long as necessary for the purposes of this Policy, according to the following criteria: a) Application access logs: at least 6 (six) months, under article 15 of Law No. 12,965/2014, and up to 12 (twelve) months for security and fraud prevention; b) Registration data, acceptance records and contractual data: for the duration of the relationship and for the applicable limitation periods after it ends, which may be up to 10 (ten) years (article 205 of the Brazilian Civil Code); c) Tax and billing data: for the periods required by tax legislation; d) Registration verification data: for the period required by applicable regulations or, in the absence of a specific rule, for 5 (five) years after the end of the relationship; e) Cookies: according to the periods indicated in the preferences panel. 7.2. Once these periods end, the data will be deleted or anonymized, except in the retention cases under article 16 of the LGPD. 7.3. Technical limits of blockchains. Data recorded on public blockchain networks are not controlled by Tesa and, as a rule, cannot be altered or deleted. Tesa can delete from its own systems the association between an address and an identifiable person, but not the public record on the network.

8. DATA SUBJECT RIGHTS

8.1. You may, at any time, request from Tesa, under article 18 of the LGPD: a) confirmation that processing takes place; b) access to the data; c) correction of incomplete, inaccurate or outdated data; d) anonymization, blocking or deletion of unnecessary or excessive data, or data processed in breach of the LGPD; e) portability, under ANPD regulations; f) deletion of data processed based on consent, except in the legal retention cases; g) information about the entities with which we share your data; h) information about the possibility of not giving consent and its consequences; i) withdrawal of consent; j) objection to processing based on a legal ground other than consent, in the event of non-compliance with the LGPD; k) review of decisions made solely on the basis of automated processing that affect your interests, under article 20 of the LGPD. 8.2. How to exercise your rights. Send your request to contact@t3sa.com or to the data protection officer’s email indicated in Section 11, with the subject “LGPD Rights”. We may ask for information to confirm your identity and prevent fraud. 8.3. Timeframes. Confirmation of processing or access to data will be provided in simplified form immediately or, by means of a complete statement, within 15 (fifteen) days of the request (article 19 of the LGPD). Other requests will be answered within the period set by regulation or within a reasonable time. 8.4. If the data are processed by Tesa as a processor for a client, we will forward the request to the responsible client and inform you. 8.5. You may also file a petition with the ANPD (article 18, paragraph 1, of the LGPD).

9. COOKIES AND SIMILAR TECHNOLOGIES

9.1. The website and the documentation use: (i) strictly necessary cookies, for operation, security and preferences, which do not depend on consent; and (ii) metrics cookies, which are activated only after your consent in the cookie banner, and which you may revoke at any time in the website’s cookie preferences. 9.2. The list of cookies, providers and retention periods is available on request by email to contact@t3sa.com.

10. SECURITY AND INCIDENTS

10.1. We adopt technical and administrative measures capable of protecting personal data against unauthorized access and accidental or unlawful situations (article 46 of the LGPD), including encryption in transit and at rest, role-based access control, multi-factor authentication for administrative access, event logging and monitoring, vulnerability management and environment segregation. 10.2. In the event of a security incident that may pose a significant risk or harm to data subjects, Tesa will notify the ANPD and the affected data subjects under article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024, which provides for notification within 3 (three) business days of becoming aware of the incident, subject to the rules for small-scale processing agents. 10.3. No system is completely secure. You must also protect your credentials and immediately report any suspected misuse.

11. DATA PROTECTION OFFICER

11.1. Data protection officer: to be appointed; until then, the channel is the email below Email: contact@t3sa.com

12. CHILDREN AND ADOLESCENTS

12.1. The Service is not intended for children or adolescents and Tesa does not intentionally process their data. If we identify such processing, the data will be deleted.
13.1. The Service may contain links to or integrations with third-party websites and services, including issuers, custodians, Circle, blockchain explorers and FX partners. This Policy does not apply to them. We recommend reading their policies.

14. CHANGES TO THIS POLICY

14.1. We may update this Policy. The version in force will always be available at https://t3sa.com/docs/en/legal/politica-de-privacidade, with the date of the last update. Material changes will be communicated to clients by email or through the dashboard with reasonable notice and, where required by law, we will request new consent.

15. CONTACT

15.1. Questions about this Policy: contact@t3sa.com or the data protection officer’s email indicated in Section 11. TESA Corporate details to be provided in the version in force.