LEGAL // PRIVACY & DATA PROTECTION / PRIVACY_POLICY

Privacy Policy

How TODEY collects, uses, protects and shares personal information across its websites, data services, developer products, portals and related platform services.

Privacy and Data Protection

This Privacy Policy explains how TODEY collects, uses, stores, protects and, where applicable, shares personal information when individuals interact with TODEY websites, applications, dashboards, portals, APIs, developer services and other related products or services.

For purposes of this Privacy Policy, “TODEY,” “we,” “us” and “our” refer to the TODEY entity responsible for the relevant processing of personal information.

This Privacy Policy applies to personal information processed by TODEY in its own capacity as a data controller. Where TODEY processes personal information solely on behalf of an enterprise customer or other organization under that organization's instructions, the customer may be the data controller and TODEY may act as a data processor. Such processing may be governed by a separate agreement, including a Data Processing Agreement.

This Privacy Policy does not create contractual rights or obligations beyond those required by applicable law or expressly established by a separate agreement.

Categories of Personal Information

Depending on how you interact with TODEY, we may process the following categories of personal information:

Personal information may be collected directly from you, generated automatically when you use a TODEY service, received from organizations or other third parties, or submitted to TODEY by a customer or other organization using TODEY as a service provider.

01 / ACCOUNT & IDENTITY INFORMATION

Information associated with an account or authenticated service, which may include name, business contact details, email address, account identifiers, organization or project affiliation, authentication information and account preferences.

02 / DEVELOPER & API INFORMATION

Information associated with developer access and API usage, which may include API account identifiers, authentication credentials or tokens, usage records, requests, rate-limit activity, logs, integration information and related technical metadata.

03 / PORTAL & SERVICE INFORMATION

Information generated when authorized users access TODEY portals, dashboards or other restricted services, which may include account activity, service usage, configuration information, access records and related operational metadata.

04 / CONTACT & SUPPORT INFORMATION

Information voluntarily provided when contacting TODEY or requesting support, which may include name, email address, organization, message content, attachments and other information included in the communication.

05 / COMMUNITY & CONTRIBUTIONS

Information voluntarily submitted through community features, feedback, voting, ecosystem curation, reports, reviews or other participation mechanisms, including the information associated with the relevant contribution.

06 / TECHNICAL & USAGE INFORMATION

Technical information associated with use of the platform, which may include IP address, browser type, device and operating-system information, approximate location derived from IP address, referring pages, timestamps, pages or features accessed, interaction data, diagnostic information and security-related logs.

07 / COOKIE & ANALYTICS INFORMATION

Information collected through cookies and similar technologies, where applicable, including identifiers, usage patterns, preferences and analytics information subject to applicable consent and other legal requirements.

08 / BUSINESS & TRANSACTION INFORMATION

Information associated with commercial relationships, subscriptions or service arrangements, which may include billing contacts, organization details, contract-related information, service-plan information and payment or billing records handled through applicable payment providers.

09 / INFORMATION FROM OTHER SOURCES

Information may also be received from organizations, business partners, service providers, public sources or other third parties where permitted by applicable law.

DATA BOUNDARY

TODEY does not intentionally request or collect private cryptographic keys, wallet recovery phrases or payment-card authentication credentials through its public platform. TODEY does not require users to provide customer KYC or identity-verification documents for ordinary use of its public information services. Any information required for a specific service will be described in the applicable service documentation or collection notice.

Sensitive Information

TODEY does not intentionally request sensitive categories of personal information through its ordinary public services. Users should not provide sensitive personal information unless it is specifically requested for a documented service purpose and there is an appropriate legal basis for processing it.

Where TODEY is required to process sensitive personal information on behalf of an enterprise customer, that processing will be governed by the applicable agreement and relevant data-protection requirements.

Business Contact Information

Where we interact with representatives of businesses, partners, customers or prospective customers, we may process professional contact information such as name, work email address, job title, organization, business communications and relationship history for purposes of managing the relevant business relationship and providing or discussing TODEY services.

How We Use Personal Information

TODEY processes personal information only for specified purposes and on an applicable legal basis. The legal basis depends on the nature of the processing and the relationship between TODEY and the individual or organization.

[A] PROVIDING AND ADMINISTERING SERVICES

We may process account, contact, authentication, service-usage and related information to create and maintain accounts, provide dashboards and portals, provide developer and API access, respond to support requests, administer subscriptions or services, and perform our obligations under an applicable agreement. The legal basis may be performance of a contract or taking steps at the individual's request before entering into a contract.

[B] SECURITY, ABUSE PREVENTION AND SERVICE INTEGRITY

We may process technical, authentication and usage information to secure our systems, detect and investigate abuse, prevent unauthorized access, protect users and customers, maintain service integrity and investigate security incidents. Where applicable, this processing may be based on our legitimate interests and on legal obligations.

[C] PRODUCT DEVELOPMENT AND ANALYTICS

We may use technical and usage information to understand how our services are used, diagnose technical issues, improve platform performance, develop products and improve user experience. Where required by applicable law, analytics technologies that require consent will be used only after the relevant consent has been obtained.

[D] COMMUNICATIONS AND SUPPORT

We may process contact information and communications to respond to inquiries, provide customer support, communicate about services and administer our relationship with customers, developers, partners and other users.

[E] LEGAL AND REGULATORY COMPLIANCE

We may process personal information where necessary to comply with legal obligations, respond to lawful requests, establish or defend legal claims, enforce applicable terms, protect our rights and interests, or maintain records required by law.

[F] BUSINESS OPERATIONS

We may process business and account information to administer commercial relationships, contracts, billing, account management, enterprise services and internal business operations. Where appropriate, processing may be based on contractual necessity or our legitimate interests.

[G] CONSENT-BASED PROCESSING

Where applicable law requires consent, TODEY will request consent before processing personal information for the relevant purpose. Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

Legitimate Interests

Where TODEY relies on legitimate interests as a legal basis, those interests may include operating, securing and improving our services, preventing misuse, protecting our systems and users, communicating with business contacts, administering commercial relationships and defending our legal rights. TODEY will consider applicable legal requirements and the rights and interests of individuals when relying on this basis.

Cookies and Similar Technologies

TODEY may use cookies, pixels, local storage and similar technologies to provide essential website functionality, remember preferences, understand service usage, maintain security and, where permitted, measure and improve the performance of our services.

Technologies that are strictly necessary for the operation of a service may be used without consent where permitted by applicable law. Non-essential analytics, advertising or similar technologies will be used only where the required consent or other lawful basis has been obtained.

Where consent is required, users may manage their preferences through the applicable consent interface and may withdraw consent in accordance with the available controls. Additional information about cookies, purposes, providers, retention periods and consent choices may be provided through TODEY's Cookie Policy or cookie-management interface.

Third-Party Services and Links

TODEY may link to or integrate with third-party websites, APIs, applications, payment providers, infrastructure providers, analytics services and other external services. Those third parties may collect and process personal information independently of TODEY.

TODEY is not responsible for the privacy practices of third parties that operate independently from TODEY. Users should review the applicable third-party privacy notices and terms before providing personal information or using an external service.

Service Providers and Other Recipients

TODEY may share personal information with service providers and other recipients where necessary to operate the platform, provide services, maintain security, process billing or payment-related information through applicable service providers, support customer relationships, provide hosting and infrastructure, provide analytics, communicate with users, or comply with legal obligations.

Depending on the services used by TODEY, recipients may include hosting and cloud infrastructure providers, security and fraud-prevention providers, analytics providers, customer-support and communications providers, authentication providers, payment and billing providers, professional advisers, auditors, legal advisers, corporate service providers and competent public authorities where disclosure is legally required or otherwise permitted.

TODEY does not sell personal information as a standalone personal-data product. TODEY may, however, provide commercial access to non-personal, aggregated, derived or otherwise lawfully licensed data and intelligence products under applicable service terms and agreements.

Legal Disclosures

TODEY may disclose personal information where reasonably necessary to comply with applicable law, legal process or lawful requests from public authorities, or where necessary to establish, exercise or defend legal claims, protect the rights and safety of TODEY or others, or investigate fraud, abuse or security incidents.

Corporate Transactions

TODEY may disclose personal information where reasonably necessary in connection with a merger, acquisition, financing, restructuring, sale of assets, investment transaction or other corporate transaction, subject to applicable law and appropriate confidentiality and data-protection requirements.

Customer Data and Processor Services

Certain TODEY services may allow enterprise customers, developers, partners or other organizations to submit, transmit or make personal information available through TODEY systems.

Where TODEY processes personal information on behalf of a customer and under that customer's documented instructions, the customer may act as the data controller and TODEY may act as a data processor. In such cases, the processing of that customer data will be governed by the applicable agreement and, where required, a Data Processing Agreement.

TODEY will process customer-controlled personal information only to the extent permitted by the applicable agreement and applicable data-protection law.

How Long We Keep Information

TODEY retains personal information only for as long as reasonably necessary for the purposes for which it was collected, including to provide services, maintain business and financial records, resolve disputes, enforce agreements, maintain security, prevent abuse and comply with legal obligations.

Retention periods vary depending on the category and purpose of the information. For example, account and contract information may be retained for the duration of the relevant relationship and for an additional period where necessary for legal, accounting or dispute-resolution purposes; security and technical logs may be retained for a shorter operational period unless longer retention is reasonably necessary for security, investigation or legal purposes; and information processed on the basis of consent will generally be retained until consent is withdrawn or the relevant purpose ends, subject to applicable legal requirements.

Where a specific retention period applies, TODEY may describe that period in the relevant service documentation, collection notice, Cookie Policy, Data Processing Agreement or other applicable documentation.

Data Security

TODEY maintains reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration or disclosure, taking into account the nature of the information and the risks associated with the relevant processing.

Security measures may include access controls, authentication mechanisms, encryption in appropriate circumstances, logging and monitoring, infrastructure protections, secure development practices, backup and recovery controls, employee and contractor controls, and procedures for responding to security incidents.

No method of transmission, storage or security can be guaranteed to be completely secure. Accordingly, TODEY cannot guarantee absolute security of personal information.

International Data Transfers

TODEY may use service providers or operate systems in jurisdictions outside the European Economic Area. Where personal information is transferred to a jurisdiction that does not benefit from an applicable adequacy decision, TODEY will rely on an appropriate transfer mechanism available under applicable data-protection law, such as Standard Contractual Clauses or another lawful safeguard.

Depending on the applicable service and transfer, additional safeguards may be implemented where required. Information about relevant transfer mechanisms may be made available upon request or through applicable contractual documentation.

Your Privacy Rights

Depending on your location and applicable law, you may have rights in relation to your personal information, including the right to request access to personal information we hold about you, correction of inaccurate information, deletion of personal information, restriction of processing, portability of certain information, and objection to certain processing.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

Where TODEY processes personal information on the basis of legitimate interests, you may have the right to object to that processing on grounds relating to your particular situation, subject to applicable law.

You may also have rights relating to automated decision-making and profiling where applicable. TODEY will not subject individuals to decisions based solely on automated processing that produce legal effects or similarly significant effects unless permitted by applicable law and appropriate safeguards are in place.

To exercise your rights, contact TODEY using the details provided in the Contact section below. We may take reasonable steps to verify your identity before responding to a request.

Right to Lodge a Complaint

You may have the right to lodge a complaint with the data protection supervisory authority in the country where you live, work or believe that a violation of applicable data-protection law has occurred. Individuals in the European Union may contact their competent supervisory authority through the applicable authority's official channels.

Automated Systems and Profiling

TODEY may use automated systems to organize, analyze, classify, detect patterns in or otherwise process information in connection with its products and services.

Where automated processing involves personal information, TODEY will process that information in accordance with applicable data-protection requirements and any applicable rights concerning profiling or automated decision-making.

TODEY does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects for individuals unless permitted by applicable law and appropriate safeguards are provided.

Children's Privacy

TODEY's services are directed primarily toward businesses, developers, professionals and other users of its information and technology services and are not intentionally directed toward children where prohibited by applicable law.

TODEY does not knowingly collect personal information from children in circumstances where such collection is prohibited by applicable law. If you believe that a child has provided personal information to TODEY in a manner that should not have occurred, please contact us so that we can review and take appropriate action.

Community Contributions and Public Information

If you submit information, feedback, reviews, votes, reports or other material through TODEY community or participation features, TODEY may process the personal information associated with that contribution for purposes of operating, moderating, securing and improving those features.

Some contributions may be displayed publicly or shared with other users depending on the design of the relevant feature. The information and visibility associated with a particular contribution will be described in the applicable interface, feature documentation or community rules.

Do not submit personal information about another person unless you have a lawful basis to do so and are authorized to provide that information.

Accuracy and Corrections

TODEY seeks to maintain accurate and relevant personal information where appropriate to the purposes for which it is processed. If you believe that personal information held by TODEY is inaccurate or incomplete, you may contact us and request correction in accordance with applicable law.

Where TODEY receives personal information from third parties or processes information provided by customers, developers, partners or community participants, TODEY may rely on those sources for the accuracy of the information supplied.

Information Obtained From Other Sources

Where permitted by applicable law, TODEY may receive personal information from third parties such as customers, business partners, service providers, public sources or other ecosystem participants.

Where applicable law requires TODEY to provide additional information concerning the source, category or purpose of such personal information, TODEY will provide that information in the applicable privacy notice or other required communication.

Personal Data Incidents

TODEY maintains procedures designed to identify, assess, contain and respond to personal-data incidents. Where applicable law requires notification of a personal-data breach to a supervisory authority or affected individuals, TODEY will make the required notifications within the applicable legal timeframes.

Marketing Communications

Where permitted by applicable law, TODEY may use contact information to send service-related communications and, where appropriate, marketing or product communications.

Where marketing consent is required, TODEY will obtain that consent before sending the relevant communications. You may unsubscribe from marketing communications at any time using the available unsubscribe mechanism or by contacting TODEY.

Changes to This Privacy Policy

TODEY may update this Privacy Policy from time to time to reflect changes in our services, technologies, data-processing practices, legal requirements or other relevant circumstances.

When we make changes, we will publish the revised Privacy Policy and update the “Last Updated” date shown below. Where applicable law requires additional notice or consent for a material change, TODEY will provide that notice or obtain the required consent.

Your continued use of a TODEY service after an updated Privacy Policy becomes effective does not, by itself, constitute consent where consent is required by applicable law.

Privacy Contact

For privacy questions, requests concerning your personal information, or inquiries concerning this Privacy Policy, contact:

PRIVACY CONTACT

gm@todey.xyz

LAST UPDATED // SEPTEMBER - 2026 | EFFECTIVE DATE // SEPTEMBER 2026