1. WHO WE ARE AND WHO THIS POLICY APPLIES TO
1.1. This Policy describes how TESA (corporate name, CNPJ and registered office will be provided in the version in force) (“Tesa”, “we”) processes personal data on the t3sa.com website, in the technical documentation, in the dashboard and in the Tesa API (together, the “Service”). 1.2. The Service is intended exclusively for companies. Even so, we process personal data of natural persons connected to those companies, such as legal representatives, partners, directors and officers, ultimate beneficial owners, authorized users of the dashboard and the API, business contacts and website visitors (“you”). 1.3. This Policy supplements Tesa’s Terms of Use. Capitalized terms not defined here have the meaning given in the Terms of Use.2. OUR ROLE IN THE PROCESSING
2.1. Controller. Tesa is the controller of the personal data it processes to operate the Service, register and authenticate users, bill, provide support, ensure security, comply with legal obligations and communicate with clients and prospects. 2.2. Processor. If, under a contract, Tesa processes personal data exclusively on behalf of and on the instructions of a client, it will act as processor. In that case, the client’s privacy policy governs the processing, and the relationship between Tesa and the client is governed by a data processing agreement. 2.3. Independent third parties. Custodians, issuers of tokenized products, Circle and FX partners engaged by the client process data as independent controllers, under their own policies. Tesa does not control that processing.3. DATA WE PROCESS
3.1. Registration data of representatives and users: name, corporate email, phone number, job title, company, CPF (Brazilian taxpayer ID), documents evidencing powers of representation and records of acceptance of the Terms of Use. 3.2. Company verification data (KYB), where applicable: identification of partners, directors and officers and ultimate beneficial owners, identity document, politically exposed person status and results of sanctions list screening. 3.3. Authentication and credential data: user identifiers, authentication factors, API key identifiers. We do not store the full value of secret keys after issuance, only a hash or identifying fragment. 3.4. Access and API usage logs: IP address, source port when available, date and time with time zone, endpoint called, response code, credential identifier, user agent and technical request metadata. 3.5. Wallet addresses and blockchain data: wallet addresses connected by the client, balances, transactions and events recorded on public networks. These data are public by nature and, when they can be associated with an identifiable natural person, are treated as personal data. 3.6. Billing data: details of the person responsible for finance, billing history and tax documents. 3.7. Communications: content of support messages, emails, meetings and survey responses. 3.8. Browsing data on the website and documentation: cookies and similar technologies, pages visited, referral source, device type and browser, as described in Section 9. 3.9. Data we do not collect: we do not request or store private keys, key shares, recovery phrases or wallet passwords; we do not intentionally process sensitive personal data, except in the case described in item 3.2; and we do not process data of children and adolescents.4. PURPOSES AND LEGAL BASES
4.1. We process personal data only for legitimate, specific and disclosed purposes, based on the legal grounds in article 7 of the LGPD:
4.2. When we rely on legitimate interest, we assess in advance the necessity, proportionality and legitimate expectations of data subjects, and you may object to the processing as provided in article 18, paragraph 2, of the LGPD.