Legal
Privacy Policy
Last Updated: June 15, 2026
This Privacy Policy (this “Policy”) describes how Alloco Limited and its applicable affiliates (“Alloco,” “we,” “us,” or “our”) collect, use, disclose, retain, and protect information in connection with:
- allocofi.com and any associated subdomains;
- app.allocofi.com;
- any interfaces, applications, dashboards, APIs, tools, features, and services operated by or on behalf of Alloco; and
- any related Onchain ETFT discovery, structuring, issuance, subscription, minting, redemption, trading, NAV, compliance, and account services,
collectively, the “Services.”
For purposes of this Policy, “you” and “your” refer to any person who accesses or uses the Services.
For personal information collected directly through the Services, Alloco is generally the data controller or business responsible for determining how and why that information is processed. A separate ETFT issuer, segregated portfolio, fund, special-purpose vehicle, broker, custodian, administrator, or other service provider may act as an independent controller of information it collects from you. Where applicable, its own privacy notice will govern its processing activities.
By accessing or using the Services, connecting a digital wallet, creating an account, submitting information, joining a waitlist, or requesting access to an Alloco product, you acknowledge that you have read and understood this Policy.
If you do not agree with this Policy, you should not access or use the Services or provide information to us.
We may update this Policy periodically. When we make material changes, we will update the “Last Updated” date and may provide additional notice through the Services, by email, or through another appropriate method.
This Policy does not apply to third-party websites, wallets, blockchains, protocols, exchanges, brokers, custodians, banks, payment providers, or other services that are not controlled by Alloco. Those parties maintain their own privacy practices, and you should review their policies separately.
1. Information We Collect
We may collect information directly from you, automatically through your use of the Services, from public blockchains, and from third-party service providers.
1.1 Information You Provide to Us
Information you provide may include:
Contact Information
- Name;
- email address;
- telephone number;
- residential or business address;
- company name;
- job title; and
- communication preferences.
Account and Profile Information
- Login credentials;
- linked email address;
- account identifiers;
- profile information;
- wallet address;
- authentication records; and
- information provided through an embedded wallet, authentication provider, or account provider.
Identity and Compliance Information
Where required to provide a product or Service, comply with applicable law, or conduct risk screening, we or our service providers may collect:
- Full legal name;
- date and place of birth;
- nationality;
- residential address;
- government-issued identification documents;
- photographs or identity verification images;
- tax identification information;
- employment or business information;
- beneficial ownership and control information;
- source-of-funds or source-of-wealth information;
- accredited, professional, qualified, or eligible investor status;
- sanctions, politically exposed person, adverse media, and financial crime screening results;
- jurisdiction and residency information; and
- other information reasonably required for know-your-customer, know-your-business, anti-money laundering, counter-terrorist financing, tax, securities, or sanctions compliance.
Identity verification may be conducted by a third-party provider. Alloco may receive verification results, risk indicators, document information, or confirmation that a verification process has been completed.
Financial and Transaction Information
Depending on the Services you use, we may collect:
- Subscription, minting, purchase, sale, redemption, or withdrawal instructions;
- transaction amounts;
- payment and settlement information;
- bank, stablecoin, wallet, or payment references;
- ETFT Unit balances;
- order, execution, claim, or refund status;
- applicable NAV, indicative NAV, protected NAV, buffer, fee, spread, and pricing information;
- custody or brokerage account references;
- transaction history;
- investor classification;
- account funding information; and
- information required to reconcile transactions between blockchain, banking, brokerage, custody, and fund-administration systems.
We generally do not receive or store your private wallet keys or seed phrases. You should never provide them to us.
Communications
We may collect information contained in:
- Customer support requests;
- emails;
- feedback;
- surveys;
- complaints;
- product applications;
- waitlist submissions;
- community communications; and
- other messages you send to us.
ETFT Creator and Product Information
If you use an ETFT launcher, submit an investment idea, or apply to become a product creator or manager, we may collect:
- Professional background;
- strategy information;
- portfolio information;
- track record information;
- product proposals;
- intellectual property submissions;
- risk parameters;
- business and ownership information;
- licensing or regulatory information; and
- supporting documentation.
1.2 Information Collected Automatically
When you access or use the Services, we and our service providers may automatically collect:
- IP address;
- browser type and version;
- device type;
- operating system;
- internet service provider;
- language and time-zone settings;
- device identifiers;
- pages viewed;
- links clicked;
- features accessed;
- session duration;
- referring and exit pages;
- date and time of access;
- error reports;
- server logs;
- security events;
- authentication events;
- interaction and performance data; and
- other technical and usage information.
1.3 Wallet and Blockchain Information
When you connect or interact with a digital wallet, we may collect or process:
- Your public wallet address;
- blockchain network;
- token balances;
- ETFT Unit balances;
- transaction hashes;
- transaction history;
- smart-contract interactions;
- approvals and signatures;
- asset transfers;
- timestamps;
- associated public addresses;
- public protocol activity; and
- risk indicators associated with the wallet or transaction.
1.4 Information from Third Parties
We may receive information from:
- Wallet and authentication providers;
- identity verification providers;
- KYC, KYB, AML, sanctions, fraud prevention, and blockchain intelligence providers;
- ETFT issuers and segregated portfolios;
- fund administrators;
- transfer agents;
- brokers and execution venues;
- custodians;
- banks;
- fiat and stablecoin conversion providers;
- payment and settlement providers;
- oracle, NAV, pricing, and market-data providers;
- analytics providers;
- professional advisers;
- business partners;
- public databases;
- regulators and government authorities; and
- publicly available blockchain records.
Information received from these parties may include identity information, verification status, risk indicators, transaction information, location information, account status, eligibility information, and information necessary to provide or reconcile the Services.
2. How We Use Information
We may use personal information to:
2.1 Provide and Operate the Services
This includes using information to:
- Create and administer accounts;
- authenticate users;
- connect wallets;
- display product information;
- process applications;
- determine product eligibility;
- facilitate subscription, minting, purchase, redemption, claim, refund, and settlement requests;
- reconcile onchain and offchain transactions;
- calculate or display NAV and transaction information;
- provide support;
- maintain records; and
- communicate Service-related information.
2.2 Perform Compliance and Risk Management
We may use information to:
- Verify identity and eligibility;
- conduct KYC and KYB checks;
- screen wallets and transactions;
- comply with AML, counter-terrorist financing, sanctions, securities, tax, and financial-services requirements;
- determine geographic restrictions;
- identify suspicious, fraudulent, abusive, or unlawful activity;
- investigate security incidents;
- enforce transaction limits;
- comply with regulatory requests; and
- protect Alloco, ETFT issuers, service providers, users, and the financial system.
2.3 Secure and Maintain the Services
We may use information to:
- Detect unauthorized access;
- prevent fraud and account takeover;
- monitor smart-contract and wallet interactions;
- maintain system integrity;
- diagnose errors;
- prevent misuse;
- test security controls; and
- protect our infrastructure, users, and counterparties.
2.4 Improve and Develop the Services
We may use information to:
- Analyze product usage;
- understand user behavior;
- measure feature adoption;
- conduct research;
- test new features;
- improve user interfaces;
- develop product, risk, pricing, routing, and operational models; and
- create aggregated or de-identified analytics.
2.5 Communicate with You
We may use information to:
- Respond to inquiries;
- provide account, transaction, security, legal, or compliance notices;
- announce product or Service updates;
- request additional information;
- provide educational or promotional communications where permitted; and
- administer events, programs, or waitlists.
You may opt out of non-essential marketing communications at any time. You may continue to receive necessary operational, compliance, security, and transaction-related communications.
2.6 Establish, Exercise, or Defend Legal Rights
We may use information to:
- Enforce our Terms of Service;
- establish or defend legal claims;
- respond to disputes;
- protect our legal rights;
- comply with court orders and legal process; and
- cooperate with regulators, law enforcement, and other competent authorities.
2.7 Automated Screening and Decision Support
We or our service providers may use automated systems to support:
- Identity verification;
- fraud detection;
- wallet risk assessment;
- sanctions screening;
- geographic screening;
- transaction monitoring;
- account security; and
- product eligibility determinations.
These systems may produce risk indicators or recommendations. Where required by applicable law, we will provide appropriate safeguards in relation to decisions based solely on automated processing that have legal or similarly significant effects.
3. Legal Bases for Processing
Where applicable data protection law requires us to identify a legal basis, we process personal information on one or more of the following grounds:
Contractual Necessity
Processing may be necessary to provide the Services, administer your account, process a request, or perform a contract with you.
Legal Obligation
Processing may be necessary to comply with legal, regulatory, tax, sanctions, AML, recordkeeping, reporting, or court requirements.
Legitimate Interests
We may process information where necessary for legitimate interests such as:
- Operating and improving the Services;
- maintaining security;
- preventing fraud;
- conducting risk management;
- enforcing agreements;
- supporting corporate transactions; and
- protecting users, issuers, and counterparties,
- provided those interests are not overridden by your rights and interests.
Consent
We may rely on your consent for certain communications, cookies, or other activities where consent is required. You may withdraw consent at any time, without affecting processing conducted before withdrawal.
Establishment and Defense of Legal Claims
We may process information where necessary to establish, exercise, or defend legal claims.
4. How We Disclose Information
We do not sell personal information for monetary consideration.
We may disclose information to the following categories of recipients.
4.1 ETFT Issuers and Product Entities
Information may be shared with an issuer, segregated portfolio, fund, special-purpose vehicle, manager, administrator, transfer agent, or other entity involved in issuing or administering an ETFT product.
These parties may require information to:
- Determine eligibility;
- process subscriptions or redemptions;
- maintain investor registers;
- calculate NAV;
- satisfy legal or regulatory requirements; and
- administer product rights.
4.2 Service Providers
We may disclose information to vendors that provide:
- Cloud hosting;
- data storage;
- cybersecurity;
- analytics;
- authentication;
- wallet infrastructure;
- identity verification;
- KYC and AML screening;
- blockchain analytics;
- sanctions screening;
- customer support;
- communication;
- software development;
- accounting;
- audit;
- legal;
- administration; and
- compliance services.
These providers are authorized to process information only for agreed purposes, subject to applicable contractual and legal requirements.
4.3 Financial and Transaction Counterparties
We may disclose information to:
- Brokers;
- custodians;
- banks;
- payment providers;
- stablecoin or fiat conversion providers;
- execution venues;
- liquidity providers;
- market makers;
- settlement providers;
- fund administrators;
- auditors;
- pricing and NAV providers; and
- other counterparties involved in executing, funding, settling, safeguarding, or reconciling a transaction.
4.4 Affiliates and Business Partners
We may share information with affiliates and business partners where reasonably necessary to provide, operate, develop, finance, or support the Services.
4.5 Legal and Regulatory Authorities
We may disclose information to regulators, tax authorities, courts, law enforcement agencies, financial intelligence units, sanctions authorities, or other government bodies where:
- Required or permitted by law;
- necessary to respond to legal process;
- necessary to report suspicious activity;
- necessary to protect rights, property, security, or safety; or
- reasonably necessary to prevent unlawful conduct.
4.6 Corporate Transactions
If Alloco is involved in a merger, acquisition, financing, restructuring, insolvency, sale of assets, or similar transaction, personal information may be disclosed or transferred as part of that transaction, subject to applicable law.
4.7 With Your Direction or Consent
We may disclose information where you direct us to do so or provide consent.
5. Cookies and Similar Technologies
We and our service providers may use:
- Cookies;
- local storage;
- software development kits;
- pixels;
- web beacons;
- session technologies; and
- similar technologies.
These technologies may be used to:
- Authenticate users;
- maintain sessions;
- remember preferences;
- improve performance;
- understand how the Services are used;
- measure communications;
- detect fraud;
- prevent security threats; and
- comply with legal obligations.
Where required by law, we will obtain consent before using non-essential cookies or similar technologies.
You may control cookies through your browser settings or a cookie-preference interface made available through the Services. Disabling certain cookies may prevent some features from operating correctly.
Where applicable, we will recognize legally required opt-out preference signals, such as Global Privacy Control, for processing to which such signals apply.
6. International Transfers
Alloco, its affiliates, ETFT issuers, and service providers may operate in multiple jurisdictions. Your information may be transferred to, stored in, or processed in a country other than the country in which you reside.
Those countries may have data protection laws that differ from the laws of your jurisdiction.
Where required, we use appropriate safeguards for international transfers, which may include:
- Standard contractual clauses;
- UK international data transfer mechanisms;
- contractual data protection obligations;
- adequacy decisions;
- consent;
- necessity for contractual performance; or
- other legally recognized transfer mechanisms.
7. Data Retention
We retain personal information only for as long as reasonably necessary to:
- Provide the Services;
- maintain transaction and investor records;
- comply with legal, regulatory, AML, tax, sanctions, accounting, audit, and recordkeeping requirements;
- resolve disputes;
- investigate misconduct;
- enforce agreements; and
- establish, exercise, or defend legal claims.
The applicable retention period depends on:
- The nature and sensitivity of the information;
- the purpose for which it was collected;
- the duration of our relationship with you;
- applicable limitation periods;
- legal and regulatory requirements; and
- whether the information is needed for security, fraud prevention, or dispute resolution.
Compliance and financial transaction records may be retained for several years after your relationship with us ends where required by law.
Information recorded on a public blockchain may remain permanently available and cannot be deleted or altered by Alloco.
We may retain aggregated or de-identified information for longer periods where it no longer reasonably identifies you.
8. Data Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information from:
- Unauthorized access;
- loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
These measures may include access controls, encryption, monitoring, authentication, vendor controls, incident-response procedures, and internal security policies.
No internet, blockchain, wallet, software, or information-storage system is completely secure. We cannot guarantee that information transmitted to or through the Services will never be accessed, disclosed, altered, or destroyed without authorization.
You are responsible for protecting your devices, login credentials, wallet credentials, private keys, seed phrases, and authentication methods.
If you believe your account, wallet connection, or personal information has been compromised, contact us promptly.
9. Your Rights and Choices
Depending on your jurisdiction and subject to applicable exceptions, you may have the right to:
Access
Request confirmation of whether we process personal information about you and obtain a copy of that information.
Correction
Request correction of inaccurate or incomplete information.
Deletion
Request deletion of information, subject to legal, regulatory, contractual, security, blockchain, and recordkeeping exceptions.
Portability
Request certain information in a structured, commonly used, and machine-readable format.
Restriction
Request that processing be restricted in certain circumstances.
Objection
Object to certain processing based on legitimate interests or to direct marketing.
Withdrawal of Consent
Withdraw consent where processing is based on consent.
Opt Out of Marketing
Unsubscribe from marketing communications by using the unsubscribe mechanism in the communication or contacting us.
Automated Decisions
Request information about, or challenge, certain decisions based solely on automated processing where applicable law provides that right.
Complaint
Submit a complaint to an applicable data protection regulator or supervisory authority.
To exercise a privacy right, contact us at [email protected].
We may request information reasonably necessary to verify your identity, wallet ownership, account relationship, jurisdiction, or authority to act on behalf of another person.
We will not unlawfully discriminate against you for exercising a privacy right.
Certain requests may be denied or limited where information must be retained for legal compliance, financial crime prevention, security, contractual performance, legal claims, or because the information is recorded on a public blockchain outside our control.
10. California Privacy Disclosures
If you are a California resident and the California Consumer Privacy Act, as amended, applies to our processing, you may have rights to:
- Know the categories and specific pieces of personal information collected;
- know the sources, purposes, and categories of recipients;
- request correction;
- request deletion;
- obtain a portable copy;
- opt out of the sale or sharing of personal information;
- limit certain uses of sensitive personal information; and
- be free from unlawful discrimination for exercising your rights.
Categories of personal information we may collect include:
- Identifiers;
- customer-record information;
- commercial and transaction information;
- internet or electronic network activity;
- approximate geolocation;
- professional or employment information;
- financial information;
- legally protected classification information where required for compliance;
- sensitive personal information used for identity, account, and regulatory purposes; and
- inferences used for fraud, eligibility, compliance, or security purposes.
We do not sell personal information for monetary consideration.
We do not use or disclose sensitive personal information for purposes unrelated to providing the Services, security, fraud prevention, legal compliance, or other purposes permitted without a right to limit under applicable law.
An authorized agent may submit a request on your behalf, subject to verification of the agent’s authority and your identity.
11. EEA, United Kingdom, and Switzerland
If you are located in the European Economic Area, United Kingdom, or Switzerland, applicable data protection law may provide rights described in Section 9.
You may lodge a complaint with the supervisory authority responsible for your habitual residence, place of work, or the location of an alleged infringement.
Before submitting a complaint, we encourage you to contact us so we can attempt to address your concern.
Where required by applicable law, Alloco will appoint an EU or UK representative or data protection officer and publish the relevant contact information.
12. Cayman Islands Privacy Rights
Where the Cayman Islands Data Protection Act applies, personal data will be processed in accordance with applicable requirements concerning:
- Fair and lawful processing;
- purpose limitation;
- data minimization;
- accuracy;
- retention;
- data subject rights;
- security; and
- international transfers.
You may also have the right to submit a complaint to the Cayman Islands Ombudsman, subject to the applicable law and procedures.
13. Children
The Services are intended only for persons who are at least 18 years old and have reached the legal age required to enter into binding financial transactions in their jurisdiction.
We do not knowingly collect personal information from children.
If you believe a child has provided personal information to us, contact us, and we will take appropriate steps to investigate and delete the information where required.
14. Third-Party Services
The Services may link to or integrate with:
- Wallet providers;
- blockchains;
- decentralized protocols;
- exchanges;
- brokers;
- custodians;
- banks;
- payment providers;
- identity verification providers;
- analytics services; and
- other third-party platforms.
Alloco does not control the privacy, security, availability, or data-processing practices of those third parties. Your interaction with a third party is governed by that party’s policies and terms.
15. Changes to This Policy
We may modify this Policy to reflect changes in:
- The Services;
- our business;
- applicable law;
- technology;
- product structures; or
- data-processing practices.
The updated Policy becomes effective when posted, unless a later date is stated.
Where required, we will provide additional notice or obtain consent before applying a material change.
16. Contact Us
NOTE 5
Questions, concerns, complaints, and privacy requests may be sent to:
Alloco Limited
Email: [email protected]
For product-specific privacy matters, you may also be directed to the applicable ETFT issuer, segregated portfolio, administrator, or service provider.