mandatary.ai
Product How it works Pricing About FAQ
Book a demo

Privacy Policy

Last updated: 21 September 2026 · Applies to mandatary.ai, the Mandatary console, API, SDK and MCP server.

The short version

  • We collect only what we need to verify who you are, run the service and keep the records regulators require.
  • No personal data ever goes on the blockchain. Only cryptographic hashes do.
  • We never hold your funds or your private keys.
  • We do not sell personal data. We share it only with providers that help us run the service, with parties you authorize, and with authorities when the law requires it.
  • Evidence of mandates and trade decisions is kept for 7 years, because that is what securities regulation requires.
  • You can ask to see, correct or delete your data at [email protected]. Some records cannot be deleted while a legal retention period runs; we will tell you which and why.
  1. Who we are
  2. What we collect
  3. What we never do
  4. Why we use your data
  5. Who we share it with
  6. Blockchain data
  7. How long we keep it
  8. Security
  9. Your rights
  10. International transfers
  11. Cookies
  12. Children
  13. Changes to this policy
  14. Contact

1. Who we are

Mandatary ("Mandatary", "we", "us") provides a mandate and evidence service for AI agents that trade tokenized securities. We are the data controller for the personal data described in this policy, except where we process data on behalf of a customer (for example, a trading platform that uses our API for its own users); in that case the customer is the controller and we act as processor under our agreement with them.

You can reach us at [email protected].

2. What we collect

What we collect depends on how you use Mandatary. Most people fall into one of these groups: a principal (a person or company that grants a mandate), an authorized representative or approver (someone who signs for a company), an agent operator (someone who registers an AI agent), a verifier (a platform or issuer that checks mandates), an auditor, or a website visitor.

CategoryExamplesWho it comes from
Contact and account dataName, work email, company, role, phone (optional), login credentials, API keys you createYou, when you contact us or open an account
Identity verification dataCompany legal name and LEI (from GLEIF), the result and reference of a KYC / KYB check, the name and authority of a signer, verification status and expiry dateYou, GLEIF, and identity-verification providers we use
Wallet and signature dataBlockchain addresses you use to sign, the signatures themselves, the agent identifiers you register (ERC-8004)You, through your wallet
Mandate dataThe content of each mandate: agent, permitted assets and actions, limits, hours, venues, approval thresholds, validity, version history, revocationsYou, when you create or change a mandate
Operational and evidence dataEvery verification request and decision (agent, principal, asset, action, amount, venue, time, result and reason), approvals, alerts, reports and dossiers generated, the transaction hash of executed tradesVerifiers (platforms) calling our API, and the service itself
Billing dataPlan, usage counts, invoices, payment references (we do not store card numbers)You and our payment providers
Technical and website dataIP address, browser and device type, pages visited, approximate location, timestamps, error logsYour browser or client, automatically

For personal principals we store a non-identifying label in the console rather than a full legal name wherever the service allows it.

3. What we never do

  • We never write personal data to a blockchain. What goes on-chain is a hash (a fingerprint) of a document or identifier. A hash cannot be reversed to reveal a name, an ID number or an amount.
  • We never hold your funds or your private keys. You sign with a wallet you control. The only key we own signs evidence and attestations.
  • We never sell or rent personal data, and we do not use it for advertising.
  • We never put personal data in logs or error messages. Logs contain identifiers and hashes only.

4. Why we use your data and on what legal basis

PurposeLegal basis
Creating and operating your account, mandates, agents and verificationsPerformance of a contract with you
Verifying the identity of companies, signers and operators, and screening against sanctions and politically-exposed-person listsLegal obligation and legitimate interest in preventing fraud and misuse
Recording every decision as evidence and producing books and records for regulatorsLegal obligation of our customers under securities regulation (SEC, MiCA, FCA and others) and legitimate interest
Sending alerts, approval requests and service noticesPerformance of a contract
Billing and usage measurementPerformance of a contract and legal obligation (tax and accounting)
Answering your questions and scheduling demosLegitimate interest, or consent where you opted in
Securing and improving the service, detecting abuse and Sybil patternsLegitimate interest
Website analytics and cookiesConsent, where required by law

5. Who we share it with

We share personal data only with:

  • Service providers that host and run the service under our instructions: cloud hosting, databases, email delivery, identity-verification providers (for KYC / KYB), payment processors and blockchain node providers. They may use the data only to provide their service to us.
  • Parties you authorize. When you grant a mandate, the platforms and counterparties named in it can verify that the mandate exists and what it allows. When a customer gives an auditor read-only access, that auditor sees only the scope and period the customer allowed, and every query is logged.
  • Regulators, courts and authorities when the law requires it or when a customer instructs us to deliver its books and records.
  • A successor if Mandatary is acquired or merges, under the same protections as this policy.

Attestations that agents request from our public endpoints (identity, mandate existence and scope, validation, reputation) contain agent and operator identifiers and mandate scope, never the personal data of a principal.

6. Blockchain data

Mandates are registered and evidence is anchored on public blockchains (currently Base). Public blockchains are permanent: nothing written to them can be edited or deleted, by us or by anyone else. This is why we write only hashes and wallet addresses, never names, ID numbers, amounts or documents.

A wallet address is public by nature. If you use the same address elsewhere, third parties may be able to link it to you; we cannot control that. If you want to reduce this risk, use a dedicated address for Mandatary.

7. How long we keep it

DataRetention
Mandates, verification decisions, approvals, revocations, alerts and generated reports (the evidence vault)7 years from the date of the record, to match books-and-records rules in securities regulation. This period cannot be shortened on request.
Identity verification results and referencesFor as long as the related mandate or credential is valid, plus the 7-year evidence period
Account and contact dataWhile your account is active and for up to 12 months after closure, unless a longer period is required by law
Billing recordsAs required by tax and accounting law (typically 6 to 10 years)
Technical logsUp to 12 months
Contact-form and demo requestsUp to 24 months after our last exchange

Evidence is stored append-only and encrypted; we can add records but not alter or silently remove them.

8. Security

We apply technical and organizational measures appropriate to the sensitivity of financial records, including encryption in transit and at rest, append-only evidence storage chained by hash, role-based access with scoped and expiring keys, logging of every auditor query, tenant isolation at the database level, periodic backups, and independent security review of our smart contracts before any change. Our signing key is held in a managed key service, never on a developer's machine.

No system is perfectly secure. If we become aware of a breach affecting your personal data we will notify you and the relevant authority as required by law.

9. Your rights

Depending on where you live (for example under the GDPR, the UK GDPR, the California Consumer Privacy Act or Chile's Law 21.719), you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct data that is inaccurate or incomplete.
  • Delete data, where we are not legally required to keep it. Evidence records under a retention obligation will be kept, but we will restrict their use to that purpose.
  • Port your data to another service in a structured format. Mandates, decisions and reports can be exported as signed JSON or CSV at any time from the console.
  • Object to processing based on legitimate interest, or withdraw consent where consent is the basis.
  • Complain to your data-protection authority.

To exercise a right, write to [email protected]. We will answer within 30 days. We may ask you to confirm your identity, for example by signing a message with the wallet linked to your account.

If we process your data on behalf of a platform you use (as a processor), please contact that platform first; we will assist them in responding.

10. International transfers

Mandatary serves customers globally and our providers may process data in the United States, the European Union and other countries. Where data leaves the jurisdiction it was collected in, we rely on recognized safeguards such as standard contractual clauses or adequacy decisions, and we choose providers that commit to equivalent protection.

11. Cookies

Our website uses strictly necessary cookies (for example to remember a language choice) and, where you consent, analytics cookies that help us understand which pages are useful. The console uses session cookies and local storage to keep you signed in and to remember preferences. You can block or delete cookies in your browser; the website will still work, though some preferences will not be remembered.

12. Children

Mandatary is a business service for adults who can sign legally binding mandates. We do not knowingly collect data from anyone under 18. If you believe a minor has provided us with data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the service or the law changes. The current version is always published at mandatary.ai/privacy.html with its date. For material changes we will notify account holders by email before they take effect.

14. Contact

Mandatary · [email protected]

See also our Terms of Service.

mandatary.ai

Mandate and evidence layer for AI agents that trade tokenized securities.

[email protected]

Product

Real-time verification Mandates Evidence & reports Agent identity Pricing

Company

About FAQ Contact Privacy policy Terms of service
© 2026 mandatary.ai — All rights reserved.