Who This Policy Covers
This Policy applies to visitors to the TokenWay website, people who submit enterprise inquiries, customer representatives, Authorized Users, and other individuals whose personal data is processed through an approved TokenWay service.
It covers the website, enterprise onboarding, Token API, Token Factory, customer portal interactions, support, and related communications operated by AIDAT TECHNOLOGY PTE. LTD. (UEN 202345489M), Singapore.
Our Role
TokenWay acts as a controller for website, inquiry, account-administration, commercial, billing, security, and operational data when we determine why and how that data is processed.
When a customer submits personal data in Customer Content and determines the purpose of that processing, TokenWay may act as a processor or service provider. The applicable Enterprise Agreement or data-processing agreement defines the parties' roles and instructions for that processing.
Information We Collect
We collect contact and organization information, inquiry and onboarding communications, contract and billing records where applicable, Authorized User identifiers, support communications, device and network data, security logs, and service metadata such as model, region, request identifier, token counts, latency, and status.
We receive information directly from you or your organization, automatically from the website and approved services, and from service providers involved in authentication, infrastructure, security, communications, billing, or service delivery.
Service Inputs and Outputs
Inputs, Outputs, and uploaded files may contain personal data. They are processed when needed to perform an approved request, provide an enabled feature, secure or troubleshoot the service, respond to your authorized support request, or comply with law.
The content processed, whether it is stored, and how long it is retained depend on the approved product, model, feature, deployment, and Enterprise Agreement. Do not submit sensitive, regulated, or restricted information until the applicable data configuration has been confirmed.
How We Use Information
- Respond to inquiries and assess whether Token API or Token Factory fits the proposed workload.
- Establish, administer, meter, secure, support, and improve approved enterprise services.
- Authenticate Authorized Users and protect credentials, systems, customers, and providers.
- Detect fraud, abuse, prohibited activity, outages, and security events.
- Manage contracts, billing, tax, accounting, legal, and compliance obligations.
- Send requested operational communications and, where permitted, marketing communications that include an opt-out.
Upstream Service and Model Providers
Token API requests may be transmitted to one or more approved Upstream Service and Model Providers. Their processing locations, retention periods, training positions, and legal terms can differ. The applicable configuration is confirmed through enterprise onboarding, service documentation, or the Enterprise Agreement.
TokenWay does not use Customer Content to train models unless the customer has expressly authorized that use in writing. This statement does not describe or override the independent practices of an approved upstream provider.
Where routing among approved providers is enabled, the provider that processes a particular request may depend on the approved model, region, availability, performance, or customer configuration.
Other Service Providers and Disclosures
We may disclose personal data to providers of cloud or data-center infrastructure, security, authentication, communications, customer support, billing, professional services, and other functions needed to operate TokenWay. They receive only the information appropriate to the services they supply and are subject to applicable contractual obligations.
We may also disclose information when required by law, to respond to lawful process, to investigate a violation, to protect rights, safety, or systems, or in connection with a merger, financing, acquisition, reorganization, or sale of business assets subject to appropriate safeguards.
We do not sell personal data for money or use Customer Content to build third-party advertising profiles.
International Transfers
TokenWay, its customers, and its service providers may process personal data outside the country where an individual is located. Token API processing regions can vary by approved model and provider; Token Factory processing is defined by the approved deployment boundary.
Where applicable law requires a transfer mechanism, the parties will use the relevant Enterprise Agreement, data-processing agreement, contractual clauses, adequacy decision, consent, or other lawful mechanism.
Retention
We retain personal data only for as long as reasonably necessary for the service, security, contractual, accounting, legal, or compliance purpose for which it was collected. Retention can vary by information category and deployment.
Enterprise-specific retention and deletion rules are documented in the applicable service scope or data-processing agreement. Information may remain in security records, legal holds, or backups for a limited period after deletion where permitted or required.
Security
We use reasonable administrative, technical, and organizational measures intended to protect personal data, including access controls and protections for data in transit where appropriate to the service.
No system can be guaranteed completely secure. Customers are responsible for protecting their own environments, credentials, integrations, Authorized Users, and downstream applications as allocated in the Enterprise Agreement.
Your Rights and Choices
Depending on applicable law, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. You may also have the right to complain to a data-protection authority.
Contact privacy@tokenway.ai to submit a request. We may need to verify your identity and authority, and some requests may be limited by legal, security, contractual, or record-keeping obligations. If TokenWay processes the relevant data only for an enterprise customer, we may direct the request to that customer.
Marketing and Cookies
You may opt out of marketing email by using the unsubscribe method in the message or contacting us. This does not stop service, security, billing, or other transactional communications.
The website may use cookies or similar local technologies that are necessary for security, preferences, session continuity, or approved measurement. Where applicable law requires consent for a non-essential technology, we will request it before use.
Children
TokenWay is an enterprise service and is not directed to children. Authorized Users must be legally able to act for their organization. Do not submit a child's personal data unless the processing is lawful, necessary for an approved enterprise use case, and covered by the required notices, consents, and safeguards.
Changes and Contact
We may update this Policy by publishing a revised effective date. Material changes affecting an active enterprise service will be handled in accordance with the Enterprise Agreement and applicable law.
Privacy questions, data-subject requests, and complaints may be sent to privacy@tokenway.ai. Legal notices may be sent to legal@tokenway.ai.