Tesarus
{{ it.t }} Current
{{ it.d }}
{{ it.t }}
{{ it.d }}
{{ it.t }} Coming soon
{{ it.d }}
Team & Permissions
{{ it.t }} Current
{{ it.d }}
{{ it.t }}
{{ it.d }}
Who It's For Create company account
Home / Privacy Policy
Legal

Privacy Policy

How Tesarus handles personal information across the website, platform, APIs, onboarding and business relationships.

Last updated: 1 October 2026
Contents
1. Who we are and how to contact us 2. What this policy covers 3. Information we handle 4. Verification, sensitive information and external services 5. Where information comes from 6. Why we use information and our lawful bases 7. Cookies and similar technologies 8. Who receives information 9. Public blockchains and customer-encrypted information 10. International transfers of personal information 11. How long information is kept 12. Security 13. Your rights, requests and complaints 14. Additional US privacy information 15. Children and other websites 16. Changes to this policy

1. Who we are and how to contact us

Tesarus is the brand used for tesarus.com and related business software. Tesarus, we, us and our mean the operator responsible for the processing described here. We will make its legal name, geographic business address and contact email readily accessible on the website as part of this notice, as described in Terms section 1. That information is available to website visitors as well as Customers; it does not depend on accepting a service agreement.

For privacy questions, requests or complaints, email privacy-requests@tesarus.com or write to the operator's published business address, marked “Privacy”. For security reports, use the general contact email, marked “Security”. You do not need an account or active service access to contact us. Do not include signing keys or recovery secrets.

If a different operator becomes responsible for a service or its processing, it will identify itself and provide the applicable privacy information before that processing begins.

2. What this policy covers

This policy covers personal information handled through tesarus.com, the service, related APIs, support and business communications. It applies to visitors, prospective customers, company representatives, directors and beneficial owners, authorised users, counterparties and others whose information a company provides.

Personal information relates to an identified or identifiable individual. This can include business contact details, activity logs and public blockchain addresses, even when the information is public or used for business.

We act as a controller when deciding why and how to use information for our own purposes, including enquiries, customer relationships, user access, service security and our legal duties.

For information handled solely on a customer's behalf, such as counterparty, invoice and company transaction records, the customer is normally the controller and Tesarus its processor, or a service provider or contractor under applicable US law. Our Data Processing Addendum governs that processing; the customer's notice explains its purposes and legal basis.

These roles concern personal information, not custody of assets or authority over financial decisions. An independent provider's privacy notice governs its own processing. This policy does not request blanket consent or waive privacy rights.

3. Information we handle

This notice at collection describes the categories of personal information, their purposes and retention criteria. The information relevant to you depends on your interaction and the features your company uses. Our policy is not to sell any of these categories, share them for cross-context behavioural advertising or use them for targeted advertising, for adults or children.

The rest of this Privacy Policy explains our lawful bases, recipients, safeguards and rights. You can contact us under section 1 without accepting an invitation or maintaining service access.

These categories may also be used, only as necessary, to respond to rights requests, meet applicable legal duties, investigate misuse or protect legal rights. Limited relevant relationship and billing records may be used for the business transactions described in section 6. Section 11 explains deletion, legal holds and service closure.

Contact, demo and support requests

We use names, business contact details, company names, roles, addresses, messages and relationship history to answer enquiries, arrange demonstrations, provide support and manage relationships. We use business contacts and preferences for permitted Tesarus marketing. Company information may identify directors, signatories or beneficial owners. Technical and security information described below helps protect these interactions. Without the contact and enquiry details needed for your request, we may be unable to respond. Do not submit signing keys, recovery or authentication secrets, identity documents or unnecessary confidential information.

Enquiry and relationship records are kept while needed to respond and maintain the relationship, followed by justified follow-up or claim periods. Support, complaints and rights-request records are kept while needed to resolve the matter and meet applicable recordkeeping or claim requirements. Marketing contacts and preferences are kept until their purpose ends or you withdraw consent or object; a limited suppression record may remain to respect that choice. Submitting a form or requesting a receipt is not a marketing opt-in.

Company invitations, registration and access

We use user identifiers, business contacts, company membership, roles, permissions, authentication events, sessions, passkey public credentials, API access and activity records to manage invitations, provide access, apply permissions and protect the service. Activity records can include instructions and decisions made by company users, and records identifying the representative, company, time, notice and document versions associated with contract acceptance and service orders. We use acceptance records to administer the agreement and establish the parties' rights, with the retention criteria below. Account access credentials can be sensitive personal information under California law. Without the identity and authentication details needed for access, we cannot establish or securely administer it.

These records are kept while needed to administer invitations and authorised access, then for the period needed to administer closure, resolve disputes and account for recorded actions. Ending access does not automatically delete company records. Section 9 explains customer-encrypted signing information; Tesarus does not possess usable customer signing keys or their decryption keys.

Company records, invoices and receipts

We handle company-account labels and public addresses; networks and assets; balances, transaction identifiers, amounts, times and status; counterparty contacts; invoices, references, user-authorisation records, statements and receipt requests. These records support the functions your company selects, including submission of customer-authorised transaction data. External connections can involve provider account identifiers, application references and status messages; these are information records, not assets held by Tesarus.

The issuing company supplies invoice or payment-request information and determines its use. Contact and transaction details you submit for a record or receipt are disclosed to that company. Without the details needed for the requested function, it may be unavailable. Tesarus acts as processor where it follows only the company's instructions; contact that company about its own purposes, privacy practices or records.

Records processed on a company's behalf follow its lawful retention instructions and the return/deletion arrangements in our Data Processing Addendum, subject to legal requirements that apply to Tesarus. Descriptions and transaction patterns can reveal sensitive matters; include personal information only where necessary, lawful and within the agreed scope. Public-link and blockchain disclosure risks are explained in sections 8–9.

Website, device, security and usage information

We use IP addresses, approximate IP-based location, browser and device characteristics, requested and referring pages, timestamps, errors, security events and communication metadata to operate and protect the service, investigate misuse, resolve errors and improve functions. Optional measurement requires the choices in section 7.

Security and technical records are kept only while needed to detect incidents, investigate credible threats, maintain service integrity or resolve related claims, taking account of their sensitivity and usefulness. Optional measurement records are kept only while needed for the disclosed measurement purpose. Device-storage lifetimes are disclosed under section 7 and can differ from retention of information already collected.

Billing and accounting information

We use billing contacts, software charges, invoices and payment records to administer Tesarus subscriptions, collect software fees and maintain accounts. These records are kept for periods required by applicable tax and accounting law and relevant legal limitation periods.

4. Verification, sensitive information and external services

Do not submit identity documents, biometric templates, health or criminal-offence records, or other sensitive information through ordinary service fields. Our standard service does not require these categories. Processing them on a customer's behalf requires a separately agreed scope and lawful instructions.

Our ordinary authentication uses credentials and authentication results, not fingerprint or facial templates. Where your device offers biometric sign-in, the device performs that check.

A provider you separately select may require verification. Consult its privacy notice for its handling of your information. Before Tesarus collects verification information for its own purposes, we will explain what we collect, why, the applicable legal basis and any disclosures. We remain responsible for our handling.

We will not process special-category or criminal-offence information for our own purposes without giving you a specific advance notice and satisfying the additional legal conditions. This policy does not authorise that processing.

We will not collect precise device location, record transaction screens through session-replay tools, or use confidential support or company records to train general-purpose AI models under this policy. We will tell you before introducing a different use and obtain consent where required. Customer Personal Data remains subject to the DPA's restrictions on secondary use.

5. Where information comes from

We obtain information from you; your company and its authorised users; the operation of our website and service, including logs and section 7 technologies; relevant public blockchain records; and the provider categories in section 8 or an external connection your company selects.

For an invitation, the company named in it supplies your contact details and any name or role shown. We use them to manage the invitation securely. Contact that company about its own use; you need not accept the invitation to raise a privacy request with it or Tesarus.

When obtaining information indirectly as controller, we provide the required notice, ordinarily within one month or earlier at first contact or disclosure, unless a statutory exception applies. You may ask about its source, subject to lawful restrictions. Companies providing information about others must have lawful authority and provide required notices; this does not remove our own duties.

6. Why we use information and our lawful bases

For the controller processing described in section 3, lawful bases are as follows. Where we act solely as a processor, the customer's purposes, instructions and lawful basis govern instead.

  • Enquiries and business relationships: our legitimate interest in answering enquiries and supplying business software. Necessary steps you request before personally entering a contract rely on the pre-contractual basis instead.
  • Invitations, access and service delivery: our and the customer's legitimate interests in delivering the service securely. Contractual necessity applies only where you personally are a contracting party; an employer's contract is insufficient by itself.
  • Security and abuse prevention: our legitimate interest in protecting systems, investigating misuse and enforcing lawful terms, or a legal obligation where a specific law requires the processing. Section 4 applies to sensitive information.
  • Billing and accounting: our legitimate interest in administering software contracts, or a legal obligation for required tax and accounting records.
  • Support and improvement: our legitimate interest in resolving problems and maintaining the service. Optional device access and measurement require consent under section 7; this does not authorise unrestricted monitoring or reuse of company records.
  • Marketing: consent where required, otherwise our legitimate interest in promoting business software, subject also to electronic-marketing rules. Unsubscribe using the message link or contact us under section 1; operational messages are separate.
  • Rights requests, complaints and claims: the relevant legal duty for requests and complaints; our legitimate interest in protecting legal rights for claims, with an additional condition where sensitive information requires one.
  • Business transactions: our legitimate interest in evaluating or carrying out financing, reorganisation, merger or sale of our business, limited to relevant records and subject to confidentiality, data minimisation and applicable law.

We rely on legitimate interests only where processing is necessary and those interests are not overridden by your interests or fundamental rights. You may ask about the relevant assessment. You can object for reasons relating to your situation, and to direct marketing at any time, as explained in section 13.

You may withdraw consent at any time without affecting earlier lawful processing. Optional marketing choices do not determine core service access. We identify separately any information you are legally required to provide.

7. Cookies and similar technologies

Cookies, local or session storage, pixels and similar technologies store or access information on your device. Some send information to another provider when a page loads. Session storage normally lasts for a session; persistent storage remains until expiry or deletion.

Necessary technologies support requested functions, such as sign-in, security and remembering privacy choices. We use them without optional consent only under an applicable legal exception. Blocking them may prevent a requested function from working.

Optional preferences and measurement may remember additional choices or help us understand use of the service. They remain off unless you consent, even where a local exception might permit another approach. We do not use advertising trackers or cross-service tracking for targeted advertising.

If we offer optional technologies, “Cookie settings” will provide equally accessible accept and reject options and individual category choices. Scrolling, silence, browsing or accepting the Terms is not consent. Refusing optional technologies does not prevent functions that do not depend on them.

You can change or withdraw consent as easily as giving it through those settings, without affecting earlier lawful processing. Contact us under section 1 if you need help or settings are unavailable. Browser or device controls can remove or block storage. Clearing a preference or changing devices may require a new choice. Unsubscribing from email marketing and changing cookie choices are separate actions.

Information about technologies in use

Before requesting optional consent, we will explain the technologies, purposes, information handled, duration, activation, relevant third parties and choices through Cookie settings, including the controller identities required for consent. You will not need to sign in or accept optional technologies to read that information; it will remain accessible while the technologies are in use. We will explain necessary technologies at or before use. If no optional technologies are offered, we will not request optional consent.

For embedded content requiring consent, we will identify the provider and purpose, give its relevant privacy information and obtain consent before activation. We will update the information when technologies or purposes change and request a fresh choice where required. An identifier's expiry does not itself delete information already collected; sections 3 and 11 explain retention.

Signing and recovery material

Local storage may contain the only usable signing or recovery material for your account setup. Keep and test the independent backups your company needs before clearing site data, resetting a device, access revocation or service closure. Tesarus cannot reconstruct secrets it does not possess or guarantee independent recovery. A traditional “Do Not Track” browser signal does not change the processing described here.

8. Who receives information

We disclose information to the following recipients where relevant to the purposes above:

Your company and authorised users. People with relevant permissions can manage access and see profile, role, activity and company records. Your company may lawfully retain work records after access ends; requests about those records and our own processing may have different controllers.

Service providers. Providers in these categories receive information relevant to their functions:

  • Hosting, storage, content delivery and backup providers handle service records and technical information to operate the software.
  • Authentication, cybersecurity and monitoring providers handle identifiers, access events, logs and incident information to protect access and systems.
  • Support, scheduling and communications providers handle contact details, correspondence and submitted enquiry or support information.
  • Analytics providers handle permitted usage, device and event information to improve the service; optional device tracking requires consent.
  • Business-contact and email-marketing providers handle contact details, preferences and permitted campaign information for communications under section 6, without advertising tracking or unrelated reuse of company records.
  • Billing, accounting and tax providers handle contacts, invoices and payment records for Tesarus software fees and accounting obligations.

Providers acting on our behalf are subject to confidentiality, security and data-processing restrictions. Not every provider receives everyone's information. A provider is named when its separate service is selected or its identity is needed for consent or another required disclosure.

External providers selected by a company. A connection or application exchanges the information identified for that workflow with the relevant provider. Its notice governs its independent processing; our disclosure remains subject to this policy and applicable law.

Counterparties and recipients. Company instructions can share transaction, invoice, account-label, public-address or receipt information. Anyone obtaining a public or shareable link may be able to view, copy or forward its contents without signing in. Before sharing, check recipients and access settings, include only information your company may lawfully disclose and provide the privacy notices those people require. Disabling a link cannot retrieve existing copies.

Professional advisers and corporate transaction parties. We may disclose necessary information to professional advisers or to a prospective acquirer, investor and their advisers for the transaction described in section 6, subject to appropriate restrictions.

Courts, regulators, law enforcement and other legally authorised recipients. We disclose information required by a valid legal obligation or where another lawful basis permits a necessary disclosure to protect rights, investigate wrongdoing or respond to legal proceedings.

Public blockchain participants. Information included in a transaction submitted to a public blockchain becomes available to network participants and potentially anyone worldwide. Section 9 explains the consequences.

Customers receive Subprocessor identities and relevant processing details through the DPA's disclosure and authorisation process. Individuals may request actual recipient information under section 13. These categories do not restrict legally required disclosures of recipient identities.

9. Public blockchains and customer-encrypted information

Public blockchain addresses, amounts, times and transaction data can remain permanently accessible and be linked to people. Tesarus cannot remove records held by independent network participants. Deleting a profile or off-chain record does not erase blockchain history. We remain responsible for requests concerning information we control.

Customer-encrypted material and its metadata can remain personal information even where we cannot decrypt it. Other service records may be readable by Tesarus. Ask your company's administrator about information controlled through its keys. We remain responsible for requests concerning records and metadata we control.

10. International transfers of personal information

The provider categories above may process information in other countries. Remote access can be an international transfer even without moving the main hosting location.

Before making a restricted transfer, we will complete the required assessments and put the applicable safeguards in place. We will use a valid adequacy basis or appropriate safeguards, with any supplementary measures required for that recipient and transfer.

You can request information about the destinations, recipients and applicable safeguards, or a copy of those safeguards, using the contact details in section 1. We may redact confidential information while preserving a meaningful explanation of the protection.

The global visibility of public blockchain information is explained in section 9. It does not provide a blanket exemption from transfer rules for Tesarus's own processing or disclosures.

11. How long information is kept

The category-specific retention criteria are in section 3. We keep personal information only for as long as needed for its purpose and applicable legal requirements. An unanswered enquiry is not a reason for indefinite retention.

Specific disputes, investigations or legal holds may justify retaining relevant records with restricted use. Otherwise, records are deleted or made genuinely anonymous when no longer needed. Backups awaiting deletion are protected and put beyond ordinary use, except for necessary lawful recovery. Section 9 addresses public blockchain records.

Suspension, access revocation or service closure does not remove applicable data-security, return, deletion or privacy-request duties. Required data return can use a secure separate channel without restoring application access. A records export is not a backup of signing keys or a guarantee of independent account recovery.

12. Security

We will apply technical and organisational safeguards appropriate to the information and the risks involved. Our security obligations include limiting access to authorised purposes, protecting information during storage and transmission, managing service-provider access and responding to incidents, with review as the service and risks change. This policy does not promise a particular certification or that every item is encrypted beyond Tesarus's access.

No system or transmission method can eliminate every security risk. This statement does not exclude a responsibility or remedy imposed by applicable law. Where a personal information incident triggers a notification duty, we notify the relevant authority, customer or affected individuals as required.

Protect access to your devices, email and recovery information. Report suspected compromise promptly through the contact details in section 1.

13. Your rights, requests and complaints

Depending on applicable law, you may have rights to access or obtain a copy of information; correct it; request deletion or restriction; receive a portable copy; withdraw consent; or challenge certain automated decisions. Rights depend on the lawful basis and processing involved.

Your right to object

You can object to legitimate-interest processing for reasons relating to your situation. We must stop unless we demonstrate overriding lawful grounds or need the information for legal claims. You can object to direct marketing, including related profiling, at any time; we will stop that use.

How to make a request

Contact us under section 1, including after access is suspended or the service closes; no active account is needed. We provide actual recipient identities where the right requires them, subject to lawful exceptions. We may proportionately verify identity or authority; never send a private key or recovery secret.

We normally respond within one month. We explain any legally permitted extension or adjustment and its reason. Requests are ordinarily free; fees or refusals apply only where lawful. If we cannot act, we explain why and the available complaint routes unless disclosure is lawfully restricted.

For information processed solely on a customer's behalf, we direct the request to that customer or assist it under our agreement and applicable law. You can still ask us about our own controller processing.

Complaints

Contact us under section 1 with your concern and reply details. Where UK data-protection complaints requirements apply, we acknowledge receipt within 30 days, make appropriate enquiries, provide appropriate progress information and communicate the outcome without undue delay.

Automated decisions

Our standard service does not make solely automated decisions about individuals with legal or similarly significant effects. It can apply company-configured permissions and record company users' decisions. Before introducing a qualifying automated decision, we will explain its purpose, information used, logic, consequences and available human-review, objection or challenge rights. Independent providers explain their own decisions and challenge routes.

14. Additional US privacy information

California

This subsection applies where the California Consumer Privacy Act, as amended (CCPA), covers your information. A business relationship alone does not exclude a California resident's information.

The section 3 information falls within these CCPA categories: identifiers; personal information described in California Civil Code section 1798.80(e); commercial information; internet or other electronic network activity; approximate geolocation inferred from an IP address; and professional or employment-related information. Account credentials and certain financial information can be sensitive personal information. These labels do not mean we collect every statutory example.

The notice at collection describes categories, purposes and retention criteria. Sections 5–6 cover sources and lawful bases; section 8 covers recipients; section 11 explains deletion and legal holds. You may request details of actual collection, use and disclosure under section 1.

Sale, sharing and sensitive information. A CCPA sale can include an exchange for valuable consideration; sharing includes cross-context behavioural advertising without payment. The no-sale, no-sharing and no-targeted-advertising policy in section 3 applies to every category. We do not offer incentives or price differences in exchange for personal information.

We use or disclose sensitive information only for requested services, security, fraud prevention and other purposes permitted without a CCPA right-to-limit mechanism, not to infer characteristics about you. Before introducing a use outside those limits, we will provide a separate notice and the choices required by law.

We recognise Global Privacy Control and other opt-out signals as required by law. Our no-sale and no-sharing policy applies with or without a signal. Contact us under section 1 for requests; signals do not replace separately required consent.

Your rights and requests. You may request categories and specific pieces of information collected about you, sources, purposes and disclosures; deletion or correction; opt-out of sale or sharing; and limits on certain sensitive-information uses. Statutory conditions and exceptions apply. We do not retaliate for exercising protected rights or require their waiver as a condition of service.

Use the privacy email or postal contact route in section 1. An authorised agent may act subject to legally permitted evidence of authority and verification. Verification information is used only for verification and permitted related recordkeeping, security or fraud prevention. Sale/sharing opt-outs do not require ordinary identity verification.

For requests to know, delete or correct, we acknowledge receipt within 10 business days and normally respond within 45 calendar days of receipt. Verification does not restart that period. We explain a permitted extension of up to 45 further days within the initial period. Opt-out and limitation requests follow their shorter statutory periods. We explain refusals, limitations and any applicable review route.

Other US states

Where another state's privacy law applies, you may have rights to confirm processing; access, correct or delete information; obtain a portable copy; learn about third-party disclosures; withdraw consent; or opt out of sales, targeted advertising or profiling for decisions with legal or similarly significant effects. Rights depend on the state, processing and exemptions; exclusions for commercial or employment information in some states do not create a general privacy-law exemption.

Contact us under section 1 to exercise a right. Where an appeal right applies, reply to a refusal or use the same contact methods with the subject “Privacy appeal”. We give a reasoned response within your state's required period and, if denied, the relevant attorney general or regulator complaint route. Our no-sale, no-targeted-advertising and signal policies also apply.

15. Children and other websites

Tesarus is intended for companies and their adult authorised representatives. It is not directed to children under 18. If you believe a child has provided personal information through the service, contact us so that we can assess the matter and take the steps required by law. The intended audience does not remove protections that apply to information about a child.

External websites and services have their own privacy notices. A link alone does not make their processing part of Tesarus's service. Where Tesarus itself discloses information to them, that disclosure remains subject to this policy and applicable law.

16. Changes to this policy

We review this policy at least annually and update it when our practices or applicable requirements change, showing the updated date above. We keep the linked operator and contact details current. We give notice of changes where required, including before using information for a materially different purpose. Where consent is required for a new use, we obtain it separately. Updating this notice does not by itself amend an agreed contract. Continued use of the website does not, by itself, provide consent or waive an existing privacy right.

Tesarus

Hyper-finance platform for stablecoin-enabled businesses that need control, delegation, and clear records.

Tesarus provides non-custodial software for businesses and is not a bank or licensed financial institution. Tesarus does not take custody of customer assets, access or control customers' private keys, or possess the keys needed to decrypt customer-encrypted data. Customers control and authorise their own transactions. Tesarus does not execute or arrange cryptoasset or fiat exchanges.

Tesarus platform does not act as a cryptoasset exchange provider or custodian wallet provider.

Third-party services, where available, are subject to the relevant providers' terms. Customers are responsible for safeguarding access credentials and recovery information and for the lawful management and use of their assets. To the extent permitted by applicable law, Tesarus is not liable for losses caused by customers' actions or omissions or software used. Nothing in this notice excludes liability that cannot lawfully be excluded.

© 2026 Tesarus. All rights reserved.