1. About this policy
This Privacy Policy explains how Opaya AI LLC and its affiliates (“Opaya,” “we,” “us” or “our”) collect, use, disclose and protect personal information.
Our affiliates include two regulated companies, together our “regulated affiliates”:
- Puissance Capital Management LP, a registered investment adviser, which provides advisory services; and
- Angel Pond Capital LLC, a FINRA-registered U.S. broker-dealer, which provides brokerage services.
What this policy covers
This policy applies when:
- you visit opaya.ai (the “Site”);
- you write to us, ask for a demo, or start the process of becoming a client;
- you are a client, or a former client, of one of our regulated affiliates;
- you contact us on behalf of a business, or work for a business that uses Opaya Enterprise.
Our product sites
Each Opaya product has its own site, and each site has its own privacy notice:
| Product | Site |
|---|---|
| Opaya Wealth | opaya.app |
| Opaya Private Wealth | dvgria.com |
| Opaya Enterprise | angelpond.com |
When you use a product, the privacy notice on that product’s site applies to that product. If it differs from this policy, the product’s notice governs for that product. The Consumer Privacy Notice in Section 3 always applies to clients of our regulated affiliates.
What this policy does not cover
- Enterprise Customer Data. This is information we process on behalf of an institution that uses Opaya Enterprise, under our written agreement with it. That institution’s own privacy notice and our agreement govern it. See Section 4.4.
- Opaya personnel. Separate notices apply.
- Sites and services we do not control. This includes third-party sites we link to. Their own policies apply.
How this policy fits with other documents
- Clients. Your client agreement may contain additional privacy terms. For your account, that agreement and the Consumer Privacy Notice control if anything conflicts with the rest of this policy.
- Everyone. Our Terms of Use also apply to your use of the Site. Our Disclosures explain our services and their risks.
2. Privacy at a glance
- We do not sell personal information. We do not share it for cross-context behavioral advertising.
- We collect what we need. We use it to respond to you, to open and serve accounts, to run our agents, to meet our legal obligations and to keep accounts secure.
- Our agents work within limits. They use your information only to do the work you and your agreement allow. People at Opaya supervise them.
- A person can review. If an automated check contributes to a decision not to open your account, or a decision that you are not eligible for an investment, you can ask a member of our team to review it.
- You have choices. You can unsubscribe from marketing at any time. You can ask to access, correct or delete your information, within the limits that the law and our recordkeeping duties allow.
- Questions? Email [email protected].
3. Consumer Privacy Notice
This notice applies to individuals who obtain, or have obtained, a financial product or service from Puissance Capital Management LP or Angel Pond Capital LLC for personal, family or household purposes, including through Opaya Wealth and Opaya Private Wealth.
Rev. January 1, 2026
| Facts | WHAT DOES OPAYA DO WITH YOUR PERSONAL INFORMATION? |
|---|---|
| Why? | Financial companies choose how they share your personal information. Federal law gives consumers the right to limit some but not all sharing. Federal law also requires us to tell you how we collect, share, and protect your personal information. Please read this notice carefully to understand what we do. |
| What? | The types of personal information we collect and share depend on the product or service you have with us. This information can include:
When you are no longer our customer, we continue to share your information as described in this notice. |
| How? | All financial companies need to share customers’ personal information to run their everyday business. In the section below, we list the reasons financial companies can share their customers’ personal information; the reasons Opaya chooses to share; and whether you can limit this sharing. |
| Reasons we can share your personal information | Does Opaya share? | Can you limit this sharing? |
|---|---|---|
| For our everyday business purposes—such as to process your transactions, maintain your account(s), respond to court orders and legal investigations, or report to credit bureaus | Yes | No |
| For our marketing purposes—to offer our products and services to you | Yes | No |
| For joint marketing with other financial companies | No | We don’t share |
| For our affiliates’ everyday business purposes—information about your transactions and experiences | Yes | No |
| For our affiliates’ everyday business purposes—information about your creditworthiness | No | We don’t share |
| For our affiliates to market to you | No | We don’t share |
| For nonaffiliates to market to you | No | We don’t share |
| Questions? | Go to opaya.ai/privacy. |
|---|
| Who is providing this notice? | Puissance Capital Management LP and Angel Pond Capital LLC |
|---|
| How does Opaya protect my personal information? | To protect your personal information from unauthorized access and use, we use security measures that comply with federal law. These measures include computer safeguards and secured files and buildings. We limit access to people who need it for their work, and we require our service providers to protect the information they receive from us. |
|---|---|
| How does Opaya collect my personal information? | We collect your personal information, for example, when you
We also collect your personal information from others, such as credit bureaus, affiliates, or other companies. |
| Why can’t I limit all sharing? | Federal law gives you the right to limit only
State laws and individual companies may give you additional rights to limit sharing. See below for more on your rights under state law. |
| Affiliates | Companies related by common ownership or control. They can be financial and nonfinancial companies.
|
|---|---|
| Nonaffiliates | Companies not related by common ownership or control. They can be financial and nonfinancial companies.
|
| Joint marketing | A formal agreement between nonaffiliated financial companies that together market financial products or services to you.
|
| California residents. We will not share information we collect about you with nonaffiliated third parties, except as California law permits. Permitted sharing includes sharing with your consent, sharing to service your account, and other purposes the law allows. |
| Vermont residents. We will not share information we collect about you with nonaffiliated third parties, except as Vermont law permits, unless you authorize it. Permitted sharing includes processing your transactions and servicing your account. We will not share information about your creditworthiness with our affiliates unless you authorize it. |
4. Information we collect and how we use it
What we collect depends on your relationship with us. A client has usually also been a visitor to the Site, so more than one subsection may apply to you.
4.1 Visitors to opaya.ai
What we collect automatically. When you browse the Site, our servers and tools record:
- technical information, such as your IP address, browser and device type, operating system, device identifiers and language settings;
- usage information, such as pages viewed, links clicked, referring and exit pages, and the date, time and length of visits;
- approximate location, derived from your IP address. We do not collect precise location from the Site.
See Section 8 for the cookies and similar technologies we use.
What you give us. You may give us your name, email address and the contents of your message when you write to us.
How we use it. We use this information to:
- operate, secure and troubleshoot the Site;
- remember your preferences;
- understand which content is useful, so we can improve the Site;
- detect and prevent fraud, abuse and attacks;
- respond to you;
- meet our legal obligations.
4.2 When you get in touch or get started
Enquiries and demo requests. When you write to [email protected] or ask for a demo, we collect your name and email address. You may also give us your phone number, your organization, the product you are interested in, and a short message.
Getting started. Most applications happen on the product’s own site. If you begin with us, we collect what we need to evaluate and open your relationship. This may include:
- Identity and contact details. Legal name, addresses, email and phone number; date of birth, citizenship and country of tax residence; Social Security number or taxpayer identification number; government-issued identification.
- Identity verification. We may ask you for a photo taken with your device. Our verification provider compares it with your identification document. See Section 13 for how long biometric information is kept.
- Financial profile. Income, net worth, liquid assets, and sources of funds and wealth; investment experience, objectives, time horizon, risk tolerance and liquidity needs; tax status.
- Investor eligibility. Information and documents showing whether you qualify for certain investments, for example as an accredited investor or qualified purchaser.
- Employment and affiliations. Employer and occupation; whether you are a director, officer or major shareholder of a public company; whether you are, or are related to, someone who holds a senior public role.
- Screening results. Results of identity, sanctions, fraud and background checks performed by us or our providers.
How we use it. We use this information to:
- respond to your request;
- decide whether we can offer you our services;
- verify your identity and meet our anti-money-laundering, sanctions and know-your-customer obligations;
- determine whether you are eligible for particular investments;
- keep in touch with you about your request.
If we do not go ahead, we keep only what we need, for the periods described in Section 13.
4.3 Clients of our regulated affiliates
When you become a client, we continue to use the information you gave us when you applied. We also collect:
- Account information. Account numbers, balances, positions and transactions; cost basis and tax lots; deposits and withdrawals; bank account details used for funding.
- Linked external accounts. You may link accounts held at other institutions. With your authorization, we then receive balances, holdings and transactions from those accounts through an account aggregation provider. The provider handles your login credentials. We do not store your passwords for other institutions.
- Goals, limits and preferences. Your goals, the limits you set for our agents, your approvals and instructions, and any investment restrictions.
- Planning information. Estate, family and business details you choose to share, and information about beneficiaries, trustees and other people you authorize.
- Private-market investment records. Subscription documents, commitments, capital calls and distributions; valuations and tax documents, such as Schedules K-1; and information that fund sponsors, administrators and transfer agents need to accept and administer your investment.
- Communications. Messages, emails and meeting notes; recordings of calls or video meetings, where we tell you we are recording; and the questions and instructions you give our agents.
- Security information. Sign-ins, device information, multi-factor authentication events and security alerts.
Sources. We get this information from:
- you;
- custodians, brokers, banks and other financial institutions that hold or process your assets;
- fund sponsors, general partners, administrators and transfer agents;
- account aggregation, identity verification and screening providers;
- professionals you authorize to share information with us, such as your accountant or attorney.
How we use it. We use this information to:
- provide the services described in your client agreement;
- let our agents watch your accounts, explain what changed and prepare options, as described in Section 7;
- place, settle and record transactions;
- process subscriptions and administer private-market investments;
- prepare statements, reports and tax documents;
- calculate and collect fees;
- answer your questions;
- supervise our services and keep the records the law requires;
- protect your accounts;
- improve our services.
4.4 Business contacts and Opaya Enterprise
Business contact information. We collect information about people who work for an institution that uses, or is considering, Opaya Enterprise. This includes name, job title, employer, business email and phone number, sign-in and usage information, billing details, correspondence, and attendance at demos and events.
We use it to provide, secure and support our services, to administer accounts and billing, to send service communications, and to tell business contacts about our services. You can opt out of marketing at any time.
Enterprise Customer Data. An institution may upload or connect data to Opaya Enterprise, including data about its portfolios, transactions, employees and clients. Where Opaya processes that data, we do so as a service provider, on the institution’s behalf, under its documented instructions and our agreement with it.
- We do not sell Customer Data.
- We do not use Customer Data for our own marketing.
- We do not use one institution’s Customer Data to serve another, except in de-identified and aggregated form where the agreement allows it.
- We keep Customer Data logically separated by customer and protect it under the security program described in Section 12.
If you are a client of an institution that uses Opaya Enterprise, please contact that institution with questions about how it handles your information. We will help it respond.
Users of Opaya Enterprise. If you use Opaya Enterprise through your employer, your employer can see information about your use of it.
4.5 Information about other people
You may give us information about another person, such as a spouse, family member, beneficiary, trustee, co-investor or authorized agent. By doing so, you confirm that you have the authority to share it and that you have told that person how we will use it.
This includes information about minors, for example when you name them as beneficiaries. We handle that information under this policy.
5. How we use personal information
In addition to the uses described in Section 4, we use personal information to:
- Provide our services. We operate, maintain and support the Site and our products.
- Communicate with you. We send service and account messages, respond to your requests and, where the law permits, tell you about our services. You can opt out of marketing.
- Personalize your experience. For example, we remember your settings and show content relevant to your relationship with us.
- Run our agents. Our agents watch, reason, prepare and explain, as described in Section 7.
- Analyze and improve. We study how our services are used, test new features, and evaluate the quality, accuracy and fairness of our agents and their outputs.
- Protect people and systems. We monitor for and prevent fraud, unauthorized access and misuse, and we investigate and respond to security incidents.
- Comply with law and supervise our business. This includes recordkeeping, audits, responding to regulators and legal process, tax reporting, and anti-money-laundering and sanctions programs.
- Enforce our agreements and protect rights. We enforce our Terms of Use and client agreements, and we establish or defend legal claims.
- Complete corporate transactions. For example, a financing, merger, acquisition or reorganization.
- Act on your instructions or with your consent.
De-identified information. We may create de-identified or aggregated information from personal information and use it to analyze our business, improve our services, and evaluate and develop our agents. We keep it in de-identified form and do not try to re-identify it, except as the law permits, for example to test our de-identification methods.
6. How we disclose personal information
We disclose personal information only as described below.
- Affiliates. We share within Opaya, including with our regulated affiliates, consistent with this policy and the Consumer Privacy Notice.
- Service providers. These are vendors that perform services for us, including cloud hosting and storage, security monitoring, identity verification and screening, account aggregation, customer relationship management, communications and email delivery, analytics, AI model and infrastructure providers, document management and professional services. Our contracts require them to use personal information only to provide services to us, and to protect it.
- Financial institutions and counterparties. These are custodians, clearing firms, broker-dealers, banks, card networks and issuers, fund sponsors, general partners, fund administrators, transfer agents and tax document providers. We share with them so that they can open and service your accounts, process your transactions and investments, and meet their own legal obligations.
- People you authorize. For example, your accountant, attorney, other advisers, family members, or anyone you give access to your account.
- Your employer, for Enterprise users. As described in Section 4.4.
- Legal, regulatory and safety reasons. We disclose information when we believe it is necessary to comply with law, regulation, legal process or regulatory examinations and inquiries; to protect the rights, property or safety of our clients, Opaya or others; or to detect, prevent or respond to fraud, security issues or technical problems.
- Business transfers. We may disclose information as part of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business. Any successor must handle your information in a way consistent with this policy.
- With your consent. We share in other ways when you direct us to or agree to it.
We do not sell personal information. We do not share it for cross-context behavioral advertising, and we do not disclose it to third parties for their own direct marketing.
7. Our agents and AI processing
Opaya is agent-native. This section explains what our agents do, what information they use, and the safeguards around them.
7.1 What our agents do
Our products use a fleet of specialised AI agents. Each has a defined role:
- The Watcher keeps an eye on your accounts and the markets, so nothing important slips by.
- The Analyst works out what changed, and why it matters.
- The Planner prepares clear options for you to choose from.
- The Guardian checks every step against your limits and the rules.
- The Explainer tells you what happened, in plain words.
The agents use machine learning models, large language models and conventional software. We also use AI to support our own operations, for example to review documents, prepare account-opening files, answer support questions and assist compliance reviews.
7.2 What information our agents use
- Visitors to opaya.ai. Any AI feature on the public Site uses only what you type in, together with general market and educational information. It does not use account information. Please do not enter Social Security numbers, account numbers, passwords or other sensitive information into public features.
- Clients. Agents may use your profile, holdings, transactions, goals, limits, preferences and conversations with us, so that their work is relevant to you.
- Enterprise customers. Agents use Customer Data as described in our agreement with each institution.
7.3 Limits you set and human oversight
- Your limits. Agents act only within the limits you set and the authority your agreement gives. Anything outside those limits waits for your approval.
- People in charge. People at Opaya design, test, approve and supervise our agents. They review samples of agent work for accuracy, consistency and fairness, and correct problems they find.
- Advice under your agreement. Your client agreement describes how our agents and our team work together in managing your account, and which actions need your approval.
7.4 Third-party AI providers
Some agents use models and infrastructure from third-party providers. When they do:
- we send only the information needed to produce the output;
- our contracts require the provider to use that information only to provide services to us, and to keep it confidential and secure;
- the provider may keep the information only for the limited period our contract allows, for example for abuse monitoring.
7.5 How we improve our agents
We improve our agents through quality reviews, client feedback, error reports and testing.
7.6 Automated decisions
We use automated checks, for example to verify identity and screen for fraud and sanctions. If an automated check contributes to a decision not to open your account, or a decision that you are not eligible for a particular investment, you can ask a member of our team to review it. Contact [email protected].
7.7 Your choices about agents
- You can set and change the limits your agents work within, as your product allows.
- You can ask us how an agent’s output was produced and what kinds of information it relied on.
- You can ask a member of our team to review an agent’s recommendation before you act on it.
- You can correct inaccurate information we hold about you, which improves future outputs.
- Depending on where you live, you may have more rights related to profiling and automated decision-making. See Sections 10 and 11.
8. Cookies and similar technologies on opaya.ai
8.1 What we use
The Site uses cookies, local storage, server logs and similar technologies. They help us run the Site and understand how people use it. Some pages load fonts, scripts or media from content delivery providers, which receive your IP address as part of delivering that content.
| Category | What it does | Can you turn it off? |
|---|---|---|
| Strictly necessary | Security and fraud prevention, load balancing, form submission and remembering your privacy choices. | No. The Site will not work properly without these. |
| Functional | Remembers preferences, such as whether you paused motion or video. | Yes |
| Analytics | Measures how the Site is used so we can improve it. Where our tools allow it, we limit what is collected, for example by shortening IP addresses. | Yes |
| Advertising | We do not allow third-party advertising cookies or pixels on the Site. If that changes, we will update this policy first and provide any required choices. | Not applicable |
8.2 Your choices
You can manage non-essential cookies through our cookie preferences tool, where we offer one, or through your browser settings. Blocking some cookies may affect how the Site works.
8.3 Global Privacy Control and Do Not Track
Global Privacy Control (GPC). We treat a GPC signal as a request to opt out of the sale or sharing of personal information and of targeted advertising. It applies to the browser that sends the signal, and to your account if we can link the browser to you. We do not sell or share personal information in any case. In practice, a GPC signal also turns off any non-essential third-party cookies that the law could treat as a sale or share.
Do Not Track. There is no common industry standard for Do Not Track signals. Other than GPC, we do not respond to them.
8.4 Email
Our emails may contain small pixels that tell us whether an email was opened. You can block these by turning off image loading in your email program.
9. Your choices
- Marketing emails. Use the unsubscribe link in any marketing email, or write to [email protected]. We will still send messages about your account, our services and legal matters.
- Text messages. Reply STOP to opt out. You do not have to agree to marketing texts to use our services.
- Calls. Tell us if you do not want marketing calls.
- Your information. Clients can update most details in their product, or by contacting us.
- Enquiries. You can withdraw a request at any time by writing to [email protected].
- Cookies. See Section 8.
- Agents. See Section 7.7.
- Privacy rights. See Sections 10 and 11.
10. California privacy rights
10.1 Scope
This section applies to California residents and supplements the rest of this policy. It is our notice at collection and our privacy policy under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”).
Information covered by federal financial privacy law. The CCPA does not apply to personal information collected, processed, sold or disclosed under the federal Gramm-Leach-Bliley Act and its implementing regulations. Much of what we collect from clients to provide financial services is therefore covered by the Consumer Privacy Notice (Section 3) instead of this section. This section applies to other personal information, such as:
- information about visitors to the Site;
- information from enquiries and applications that is not covered by federal financial privacy law;
- information about business contacts and Enterprise users.
10.2 Categories of personal information
In the past 12 months, we collected the following categories of personal information.
| Category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Name, email and postal address, phone number, IP address, device identifiers, account username, Social Security number, government ID number | Affiliates, service providers, financial institutions and counterparties, parties you authorize, legal and regulatory recipients |
| Customer records (Cal. Civ. Code § 1798.80(e)) | Signature, financial information, bank account number, employment information | Affiliates, service providers, financial institutions and counterparties, parties you authorize |
| Protected classification characteristics | Age or date of birth, citizenship, marital status | Affiliates, service providers, financial institutions and counterparties |
| Commercial information | Services considered or obtained, investment and transaction history | Affiliates, service providers, financial institutions and counterparties |
| Internet or other electronic network activity | Pages viewed, interactions with the Site, emails and agents | Affiliates, service providers |
| Geolocation data | Approximate location derived from IP address | Affiliates, service providers |
| Audio, electronic or visual information | Call and meeting recordings (with notice), identification photos | Affiliates, service providers |
| Professional or employment information | Employer, job title, occupation, public company affiliations | Affiliates, service providers, financial institutions and counterparties |
| Inferences | Investment preferences, risk tolerance, interest in particular services | Affiliates, service providers |
| Sensitive personal information | Social Security number, driver’s license or passport number, account login, financial account information, citizenship or immigration status | Affiliates, service providers, financial institutions and counterparties, legal and regulatory recipients |
- Sources. See Section 4.
- Purposes for collecting and using. See Sections 4, 5 and 7.
- How long we keep each category. See Section 13.
10.3 Sale, sharing and sensitive personal information
Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioral advertising. We have not done either in the past 12 months. We have no actual knowledge of selling or sharing the personal information of consumers under 16.
Sensitive personal information. We use and disclose it only for purposes the CCPA permits, such as providing the services you request, verifying your identity, security and fraud prevention, and meeting legal obligations. We do not use it to infer characteristics about you. For this reason, the right to limit the use of sensitive personal information does not apply.
10.4 Your rights
Subject to verification and legal exceptions, California residents have the right to:
- Know and access. Learn what personal information we have collected about you, including the categories, the sources, the purposes, the categories of recipients and the specific pieces of information.
- Delete. Ask us to delete personal information we collected from you.
- Correct. Ask us to correct inaccurate personal information.
- Opt out of sale or sharing. We do not sell or share, but we will still honor your request and any GPC signal.
- Limit the use of sensitive personal information. Where the law gives this right.
- Automated decision-making. From the dates the law requires, you may have rights related to our use of automated decision-making technology for significant decisions about you, including the right to receive notice, to opt out and to access information.
- Equal treatment. We will not discriminate or retaliate against you for exercising your rights.
10.5 How to make a request
You can make a request in any of these ways:
- email [email protected];
- write to Opaya AI LLC, Attn: Privacy, 30 E 85th St, 30th Floor, New York, NY 10028.
Verification. We will ask for information to confirm your identity and match it with our records. Clients may be asked to confirm a request through their product’s secure channel. Requests for specific pieces of information, and deletion requests, need a higher level of verification.
Authorized agents. An authorized agent may make a request for you. We will need proof that you gave the agent permission, such as a signed authorization or power of attorney, and we may ask you to confirm your identity with us directly.
Timing. We will confirm receipt within 10 business days and respond within 45 calendar days. If we need up to 45 more days, we will tell you why.
Exceptions. We may deny or limit a request where the law allows. For example, we may need to keep information to meet legal and regulatory recordkeeping obligations, to complete a transaction, to protect against fraud or security threats, or to establish or defend legal claims. If we deny a request, we will explain why.
10.6 Other California notices
Shine the Light (Cal. Civ. Code § 1798.83). We do not disclose personal information to third parties for their own direct marketing purposes.
Accessibility. This policy is available in alternative formats on request. See Section 18.
11. Privacy rights in other US states
Residents of many US states have rights under comprehensive consumer privacy laws. These states include Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia.
The rights differ by state. Depending on where you live, they may include the right to:
- confirm whether we process your personal information, and access it;
- correct inaccuracies;
- delete personal information;
- get a copy of your personal information in a portable format;
- opt out of targeted advertising, the sale of personal information, and profiling used for decisions that have legal or similarly significant effects;
- get a list of the specific third parties, or categories of third parties, to which we disclosed your information;
- question the result of certain profiling decisions, review the data used, and have the decision reconsidered;
- appeal our decision on your request.
Information covered by federal financial privacy law. Many state laws do not apply to financial institutions subject to the Gramm-Leach-Bliley Act, or to information collected under it. Even where a law does not apply, we will consider your request and explain our decision.
Sensitive data. Where state law requires your consent before we process sensitive data, we ask for it first, unless an exception applies.
How to make a request. Use the methods in Section 10.5. Verification and authorized-agent rules work the same way.
Appeals. If we decline your request, you may appeal. Reply to our decision, or email [email protected] with the subject line “Privacy appeal.” We will respond within the time your state’s law requires. If you disagree with the outcome, you may contact your state attorney general.
Nevada residents. You may ask us not to sell covered information. We do not sell it, and you may still send a request to [email protected].
12. Data security
We maintain a written information security program. It includes administrative, technical and physical safeguards that match the sensitivity of the information we hold.
Our safeguards include:
- encryption of personal information in transit and at rest;
- multi-factor authentication for client and staff access;
- role-based access that limits information to people who need it;
- logging and monitoring of systems;
- regular vulnerability management and security testing;
- security reviews of service providers, and contractual protections;
- security and privacy training for our staff;
- an incident response plan, which we test.
If an incident occurs. If a security incident affects your personal information, we will notify you, and any regulators, as the law requires.
Your part. Keep your sign-in details private, turn on multi-factor authentication, be cautious of messages that ask for personal information, and report anything suspicious to [email protected].
We will never ask for your password or a one-time passcode by email, text, phone or social media.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Data retention
How long we keep personal information depends on why we collected it, how long we need it to provide our services, our legal, regulatory, tax and recordkeeping obligations, and whether we need it to resolve disputes, enforce agreements or protect against fraud.
| Information | General retention approach |
|---|---|
| Site usage and device data | Kept for limited periods for analytics and security, then deleted or aggregated. |
| Enquiries and applications that do not lead to a relationship | Generally deleted within 24 months after our last contact, unless the law requires us to keep them longer or you ask us to stay in touch. |
| Account-opening, identity verification and screening records | Kept for the periods required by anti-money-laundering and recordkeeping laws. These usually run for several years after an account closes or an application ends. |
| Biometric information from identity verification | Destroyed by our verification provider promptly after verification is complete, and always within the period the law requires. |
| Client account records and communications | Kept for at least the periods required by applicable books-and-records laws. These usually run for several years after a record is created or an account closes. We keep them longer if needed for legal claims or regulatory inquiries. |
| Business contact information | Kept while the business relationship continues, and for a reasonable period after it ends. |
| Enterprise Customer Data | Kept as set out in the institution’s agreement, and returned or deleted when the agreement ends, subject to its terms. |
When we no longer need personal information, we delete it securely or de-identify it. Copies in backup systems are overwritten on a regular schedule.
14. Children’s privacy
Our services are intended for adults. They are not directed to children, and we do not knowingly collect personal information directly from children under 13. We do not let anyone under 18 open an account.
If we learn that we have collected personal information directly from a child, we will delete it, unless the law requires us to keep it. If you believe a child has given us information, contact [email protected].
Clients sometimes give us information about minors, for example as beneficiaries. We handle that information under Section 4.5.
15. International visitors and transfers
Opaya is based in the United States, and we store and process personal information there. Some of our service providers may process information in other countries. When they do, we require safeguards that protect it consistently with this policy.
If you visit the Site from outside the United States, your information will be transferred to, and processed in, the United States, where privacy laws may differ from those where you live. Where a product is offered outside the United States, its site may include additional privacy terms for your region.
16. Linked sites and services
The Site links to our product sites, which have their own privacy notices (see Section 1). It may also link to sites and services we do not control, such as custodian portals, fund sponsor materials, account aggregation providers and social media. Their own privacy policies apply, not this one. We encourage you to read them.
17. Changes to this policy
We may update this policy from time to time. When we do, we will post the new version here and change the “Last updated” date.
- If we make material changes, we will give notice before they take effect, by email or by a prominent notice on the Site, where the law requires notice.
- We review this policy at least once a year.
- Any change to how we share information under the Consumer Privacy Notice will come with the notice, and any opt-out opportunity, that the law requires.
18. Contact us
If you have questions about this policy, or want to use your privacy rights, contact us:
- Privacy: [email protected]
- General enquiries: [email protected]
- Legal notices: [email protected]
- Mail: Opaya AI LLC, Attn: Privacy, 30 E 85th St, 30th Floor, New York, NY 10028
If you need this policy in another format because of a disability, contact us at [email protected]. We will provide it in a format that works for you.