Privacy Notice
This notice explains how Tesseras Labs handles information collected through the corporate website.
Baseline version
Who controls the information
Tesseras Labs S.A., registered at PH Oceania Business Plaza, Torre 1000, Oficina 40-A, Panama City, Republic of Panama, doing business as Tesseras Labs, is responsible for information collected through www.tesseras.xyz under Panama’s Law 81 data-protection framework.
Privacy and operational questions may be sent to hello@tesseras.xyz.
Territorial scope
The services described here are directed at business users in the Americas and are not directed at the European Union, European Economic Area, or United Kingdom. We review the applicability of additional privacy laws as the service and its audience change.
The public website is cookieless by default: it does not use advertising trackers or cross-site cookies, and analytics are aggregate and cookie-free.
Mailing-list subscriptions
When you voluntarily subscribe, we process your email address; consent, confirmation, and unsubscribe state and timestamps; source provenance; delivery and suppression metadata; and limited security and request metadata used for validation, rate limiting, abuse prevention, and incident investigation.
A subscription remains marketing-ineligible until confirmation succeeds. Duplicate requests are handled without creating unnecessary records, and you can unsubscribe without creating an account or signing in.
Corporate inquiries
When you submit a corporate inquiry, we process your name, email address, optional company, message, source, submission time, and limited security metadata. Corporate inquiries do not create marketing consent and do not automatically enroll you in the mailing list.
Website analytics
We use a third-party provider for aggregate, cookie-free website measurement. Depending on configuration, measurements may include page or route, filtered query parameters, referrer, coarse geolocation, device type, operating system, browser, event time, and analytics script version.
We do not intentionally send email addresses, confirmation tokens, inquiry content, or other personal information through analytics events or URLs.
Information not requested here
The corporate website does not request identity documents, wallet keys, financial account credentials, regulated onboarding evidence, or payment data. Submit those materials only through an approved product workflow with its own notice and access controls.
How we use information
We use information to:
- provide and secure the website;
- respond to corporate, enterprise, and partnership inquiries;
- send mailing-list updates requested and confirmed by the subscriber;
- maintain evidence of consent or withdrawal and enforce suppressions;
- diagnose failures, prevent abuse, and protect the service; and
- understand aggregate website usage and improve the public experience.
Third-party providers and disclosures
We use third-party providers for website hosting and aggregate analytics, contact and subscription data storage, and requested email delivery. Those providers process information under their own service terms and, where applicable, data-processing terms.
We do not sell mailing-list or corporate-inquiry information. We may disclose information when required by law, necessary to protect the service or legal rights, or involved in an approved corporate transaction, subject to applicable notice and safeguards.
International processing
Website, database, analytics, and email providers may process information in countries other than your country.
Retention
We retain information only for its approved purpose and applicable legal or security requirements. The baseline retention schedule for this notice is:
- Record
- Unconfirmed mailing-list request
- Retention rule
- Delete or irreversibly suppress after 12 months, except for minimal abuse evidence.
- Record
- Confirmed subscription
- Retention rule
- Retain while subscribed, then apply the withdrawal and suppression rule.
- Record
- Unsubscribe or suppression evidence
- Retention rule
- Retain the minimum identifier and timestamp needed to prevent unwanted sends.
- Record
- Corporate inquiry
- Retention rule
- Retain for up to 24 months based on response and relationship needs; never treat it as marketing consent.
- Record
- Security and delivery logs
- Retention rule
- Retain for up to 12 months, subject to incident, audit, and provider limits.
- Record
- Aggregate analytics
- Retention rule
- Retain within the approved provider reporting window and internal aggregation policy.
| Record | Retention rule |
|---|---|
| Unconfirmed mailing-list request | Delete or irreversibly suppress after 12 months, except for minimal abuse evidence. |
| Confirmed subscription | Retain while subscribed, then apply the withdrawal and suppression rule. |
| Unsubscribe or suppression evidence | Retain the minimum identifier and timestamp needed to prevent unwanted sends. |
| Corporate inquiry | Retain for up to 24 months based on response and relationship needs; never treat it as marketing consent. |
| Security and delivery logs | Retain for up to 12 months, subject to incident, audit, and provider limits. |
| Aggregate analytics | Retain within the approved provider reporting window and internal aggregation policy. |
Choices and rights
You can withdraw mailing-list consent through the unsubscribe link in each marketing email. Withdrawal does not affect processing already completed before withdrawal.
Depending on applicable law and location, you may have rights to request access, correction, deletion, restriction, objection, portability, or information about processing. Send a request to hello@tesseras.xyz. We may need to verify your identity before completing it.
Security
We use access controls, server-only credentials, encrypted provider connections, environment separation, rate limiting, audit evidence, and operational monitoring appropriate to the website workflow. No system is perfectly secure.
Children
The corporate website and mailing list are not directed to children.
Changes and contact
We may update this notice when the corporate website or our legal posture changes. The published version identifies its effective date, and material changes follow the applicable notification and consent review.
For privacy questions or requests, email hello@tesseras.xyz.