Legal

Anthid Privacy Policy

Version 2026-08-24-v1Effective August 24, 2026

1. Overview

Anthid LLC, a Delaware limited liability company ("Anthid," "we," "our," or "us"), provides software infrastructure for broker integrations, order and intent management, and real-time trading events (collectively, the "Services"). This Privacy Policy explains how we collect, use, disclose, and retain personal information when you visit our website, create or administer an account, use the Services, communicate with us, or otherwise interact with Anthid.

For purposes of this Privacy Policy, "personal information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual or household. It does not include information that applicable law excludes from the definition of personal information, such as lawfully made public information or information maintained in deidentified or aggregated form.

2. Scope and Our Role

This Privacy Policy applies to personal information for which Anthid determines the purposes and means of processing, including information relating to:

  • visitors to Anthid's website;
  • users, administrators, and representatives of customers that create or use Anthid accounts;
  • prospective customers, vendors, service providers, and business partners; and
  • people who contact Anthid for support, sales, security, or other inquiries.

Customer Data

Customers may submit, transmit, or connect information to the Services, including broker, account, order, position, execution, intent, and event-stream data ("Customer Data"). When Anthid processes personal information contained in Customer Data on behalf of a customer, the customer generally determines why and how that information is processed. In that context, and to the extent provided by applicable law, Anthid acts as a service provider or processor and processes the information under the customer's instructions and the applicable customer agreement or data processing addendum.

If your personal information was submitted to Anthid by or on behalf of an Anthid customer, please direct your privacy request to that customer. Anthid will assist the customer as required by applicable law and our agreement with the customer. This Privacy Policy does not replace a customer's own privacy notice.

This Privacy Policy does not govern the independent privacy practices of brokers, financial institutions, identity providers, payment processors, or other third-party services that you or your organization choose to connect to or use with the Services. Their privacy notices govern their independent processing.

3. Notice at Collection: Personal Information We Collect

The categories below describe personal information Anthid may collect and has collected during the preceding 12 months, depending on how a person interacts with Anthid. The examples are illustrative and do not mean that we collect every listed item from every person.

Identifiers and account information

Examples: Name, business email address, account and organization identifiers, username, IP address, device or session identifiers, API-key identifiers, and similar identifiers

Sources: You; your organization or account administrator; identity providers; automatically from the Services

Business purposes: Create and administer accounts; authenticate users; provide support; secure and operate the Services; communicate with users; enforce agreements

Retention: For the customer relationship or account lifecycle, plus a reasonable period for security, legal, audit, dispute, and enforcement needs

Customer-record and billing information

Examples: Business contact information, billing address, payment-provider customer identifiers, card brand and last four digits, invoices, tax-related information, and payment status. Full payment-card details are generally collected directly by our payment processor rather than stored by Anthid

Sources: You; your organization; payment and billing providers

Business purposes: Process subscriptions and payments; maintain financial records; prevent fraud; provide support; comply with tax, accounting, and legal obligations

Retention: Transaction and accounting records are generally retained for the period required by tax, accounting, contractual, and legal obligations

Commercial information

Examples: Subscription tier, service entitlements, transaction and purchase history, product usage, billing history, and customer-service history

Sources: You; your organization; Anthid's systems; payment providers

Business purposes: Provide, bill, support, analyze, and improve the Services; manage entitlements; enforce agreements

Retention: For the customer relationship and afterward as reasonably necessary for accounting, support, legal, audit, dispute, and enforcement purposes

Internet, electronic-network, and device activity

Examples: Request and authentication logs, timestamps, endpoints accessed, API and streaming usage, browser and device type, operating system, cookie or similar identifiers, referring pages, page interactions, error information, latency, and diagnostic or security events

Sources: Automatically from websites, applications, APIs, network systems, cookies, and similar technologies; security and infrastructure providers

Business purposes: Operate, monitor, troubleshoot, secure, and improve the Services; prevent abuse; enforce usage limits; generate operational analytics

Retention: Based on operational, security, and diagnostic need; sensitivity and volume; contractual commitments; incident or investigation needs; and legal requirements

Approximate location information

Examples: Country, region, or city inferred from an IP address. Anthid does not intentionally collect precise geolocation through the Services unless specifically disclosed at collection

Sources: Automatically from IP address or security providers

Business purposes: Security, fraud prevention, localization, compliance, and service operation

Retention: Generally retained with the associated security or access record under the criteria described above

Professional or employment-related information

Examples: Company or organization affiliation, business role, job title, team membership, and account permissions

Sources: You; your organization or administrator; business partners

Business purposes: Manage organizations, roles, and access; provide sales and support; administer the customer relationship

Retention: For the relationship or account lifecycle, plus a reasonable period for business records, security, legal, dispute, and enforcement needs

Sensitive personal information

Examples: Account log-in credentials; authentication secrets; broker or integration credentials, access tokens, or other information that permits access to an account; and financial-account access information where supplied to enable a requested integration

Sources: You; your organization; identity providers; connected services

Business purposes: Authenticate users; establish and maintain customer-directed integrations; protect accounts and systems; detect fraud or unauthorized access; provide the requested Services

Retention: Until the account or integration is disconnected, deleted, expired, or superseded, subject to limited retention in protected backups, security records, or where legally required

Trading and integration information

Examples: Broker account identifiers; trading environment; order, intent, execution, fill, position, balance, and status information; event streams; integration configuration; and related metadata, to the extent linked or reasonably linkable to an individual

Sources: You; your organization; connected brokers and integrations; generated through use of the Services

Business purposes: Execute customer-authorized instructions; maintain order and event state; reconcile and report activity; provide streaming, ledger, support, security, audit, and reliability functions

Retention: According to the applicable service plan, product configuration, customer agreement, operational requirements, and legal or dispute-preservation obligations

Communications and support information

Examples: Contact-form submissions, support tickets, emails, feedback, survey responses, and associated attachments or metadata

Sources: You; your organization; communications and support providers

Business purposes: Respond to requests; provide support; improve products and documentation; maintain business records; protect Anthid's rights

Retention: For as long as reasonably necessary to resolve the matter, maintain business records, improve the Services, and address legal, security, or dispute needs

Inferences and derived information

Examples: Security, fraud, abuse, reliability, and usage signals derived from the information above; account or product preferences

Sources: Anthid's systems and service providers

Business purposes: Secure and operate the Services; prevent fraud and abuse; troubleshoot; understand and improve product use

Retention: For as long as the underlying purpose reasonably requires, using retention criteria appropriate to the source information

Please do not provide personal information that Anthid does not request or need, particularly Social Security numbers, government-issued identification numbers, biometric information, health information, or personal information about minors.

4. How We Use Personal Information

Anthid may use personal information to:

  • provide, operate, maintain, configure, support, and improve the Services;
  • create and administer accounts, organizations, permissions, subscriptions, and entitlements;
  • authenticate users and protect credentials, accounts, systems, and integrations;
  • transmit and process customer-authorized broker connections, trading instructions, and event data;
  • process payments, maintain transaction records, and administer billing;
  • monitor availability, performance, capacity, reliability, usage, and compliance with rate or resource limits;
  • diagnose errors, investigate incidents, prevent fraud and abuse, and protect the rights, safety, and property of Anthid, our customers, users, and others;
  • respond to support, sales, security, and other communications;
  • send administrative or operational messages and, where permitted by law, product or marketing communications. You may opt out of marketing communications, but not service-related communications necessary to administer an account or the Services;
  • conduct internal analytics, research, development, testing, and quality assurance;
  • negotiate, perform, and enforce agreements and establish, exercise, or defend legal claims;
  • comply with law, legal process, regulatory obligations, and valid governmental requests; and
  • evaluate or complete a financing, merger, acquisition, reorganization, sale of assets, or similar corporate transaction.

Anthid may create aggregated or deidentified information from personal information and use or disclose that information for lawful purposes. Where required by law, we will maintain such information in deidentified form and will not attempt to reidentify it except to test whether our deidentification processes comply with applicable law.

We will not use personal information for a materially different, unrelated, or incompatible purpose without providing any notice or obtaining any consent required by applicable law.

5. How We Disclose Personal Information

Anthid may disclose personal information to the following categories of recipients for the purposes described in this Privacy Policy:

  • Service providers and contractors. Providers supporting cloud hosting, data storage, networking, identity and access management, security, monitoring and observability, communications, customer support, billing, payment processing, analytics, accounting, and other business operations. They may process personal information only for contracted services or as otherwise permitted by applicable law.
  • Your organization and its administrators. Account owners, administrators, and authorized users may access information associated with the organization and may manage users, permissions, integrations, billing, and Customer Data.
  • Connected brokers and integration providers. We disclose the information necessary to establish and operate an integration or process instructions when you or your organization directs us to connect a service.
  • Professional advisers. Lawyers, auditors, accountants, insurers, financial advisers, and consultants where reasonably necessary to obtain professional advice, manage risk, or protect legal interests.
  • Government authorities and other lawful recipients. Courts, regulators, law enforcement, or other parties when we reasonably believe disclosure is required or permitted by law; necessary to respond to valid legal process; or appropriate to protect rights, safety, property, users, or the public.
  • Corporate-transaction participants. Actual or prospective buyers, investors, lenders, advisers, and other participants in a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections where required.
  • Other recipients at your direction. Any other person when you or your organization directs or authorizes the disclosure or when we obtain consent as required by law.

Disclosures for Business Purposes in the Preceding 12 Months

During the preceding 12 months, Anthid may have disclosed the following categories of personal information for business purposes to the corresponding categories of recipients:

Personal-information categories

Categories of recipients

Identifiers, account information, professional information, and communications

Cloud, identity, security, communications, support, and business-operations providers; your organization and its administrators

Billing, customer-record, and commercial information

Payment, billing, accounting, cloud, support, and professional-service providers; your organization and its administrators

Internet, network, device, approximate-location, and derived information

Cloud, networking, monitoring, analytics, security, and support providers

Sensitive authentication or integration information

Cloud, identity, security, and connected-integration providers, only as appropriate to provide and protect the requested functionality

Trading and integration information

Cloud, storage, database, networking, monitoring, security, and support providers; your organization; connected brokers and integration providers

The disclosures described in this section do not include information disclosed solely because of legal process, at a person's direction, or as part of a corporate transaction, although Anthid may make those disclosures as described above.

6. No Sale, Sharing, or Targeted Advertising

Anthid does not sell personal information for money or other valuable consideration. Anthid also does not "share" personal information for cross-context behavioral advertising as "sharing" is defined by the California Consumer Privacy Act ("CCPA"), and we do not process personal information for targeted advertising as defined by applicable U.S. state privacy laws. Anthid has not sold or shared personal information during the preceding 12 months.

Anthid does not have actual knowledge that it sells or shares personal information of anyone under 16 years of age.

Anthid uses and discloses sensitive personal information only for purposes reasonably necessary and proportionate to provide the Services requested, authenticate users, maintain integrations, protect security and integrity, prevent fraud or illegal activity, maintain service quality and safety, and perform other purposes permitted without a right to limit under applicable law. Anthid does not use sensitive personal information to infer characteristics about individuals. Accordingly, Anthid does not currently provide a separate "Limit the Use of My Sensitive Personal Information" mechanism.

If our practices change in a way that requires an opt-out or limitation mechanism, we will update this Privacy Policy and provide the required mechanism before engaging in the new practice.

7. Cookies, Similar Technologies, and Privacy Signals

Anthid and providers working on our behalf may use cookies, local storage, pixels, software development kits, logs, and similar technologies to maintain sessions, authenticate users, remember preferences, secure the Services, understand use, diagnose problems, and measure performance. Providers that supply identity, payment, security, infrastructure, support, or analytics functionality may collect information directly through these technologies when their services are used.

You can control many cookies through your browser settings. Blocking necessary cookies may prevent parts of the Services from functioning correctly.

Because there is no uniform industry standard for legacy browser "Do Not Track" signals, the Services do not currently respond to those signals. Where required by applicable law, Anthid recognizes legally valid opt-out preference signals, such as Global Privacy Control. Because Anthid does not sell or share personal information for cross-context behavioral advertising, receiving such a signal does not change our current practices. If those practices change, we will process applicable preference signals as required by law.

8. Data Retention

Anthid retains personal information only for as long as reasonably necessary and proportionate for the purposes described in this Privacy Policy. In determining a retention period, we consider:

  • the duration of the account, customer relationship, integration, or transaction;
  • the retention functionality included in a service plan, product configuration, or customer agreement;
  • the nature, sensitivity, volume, and operational value of the information;
  • security, fraud-prevention, reliability, audit, backup, and business-continuity needs;
  • applicable statutes of limitation and the need to establish, exercise, or defend legal claims; and
  • tax, accounting, contractual, regulatory, and other legal requirements.

Deletion from active systems may not immediately remove information from protected backups. We may retain information for longer when subject to a legal hold, required by law, needed to resolve a dispute or security incident, or necessary to enforce an agreement. We may retain aggregated or deidentified information where permitted by law.

9. Data Security

Anthid uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized or unlawful access, acquisition, loss, misuse, alteration, or disclosure. Depending on the information and system, these safeguards may include encryption in transit and at rest, access controls, authentication, logical separation of customer data, monitoring, logging, and protected credential-management practices.

No security program, transmission method, or storage system is completely secure. Anthid therefore cannot guarantee that personal information will never be accessed, used, or disclosed in an unauthorized manner. You are responsible for protecting your credentials, using appropriate access controls, and promptly notifying Anthid if you suspect unauthorized account or credential use.

10. Privacy Rights

Depending on where you live and subject to applicable law, you may have the right to:

  • confirm whether Anthid processes your personal information and access or obtain a copy of it;
  • know the categories of personal information collected, the sources, the purposes, and the categories of recipients;
  • correct inaccurate personal information;
  • delete personal information, subject to legal exceptions;
  • obtain certain personal information in a portable format;
  • opt out of the sale of personal information, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling;
  • limit certain uses or disclosures of sensitive personal information;
  • appeal Anthid's denial of a privacy request; and
  • receive equal service and not be discriminated or retaliated against for exercising a privacy right.

These rights are not absolute. Applicable law may permit or require us to deny or limit a request, including where we cannot verify the request, where retaining information is required by law or necessary for security, fraud prevention, service delivery, legal claims, or another permitted purpose, or where the information is Customer Data controlled by an Anthid customer.

Submitting a Request

To submit a privacy request, email [email protected] with the subject line Privacy Request and describe the right you wish to exercise. To appeal a decision, use the subject line Privacy Appeal and explain why you believe the decision should be reconsidered.

We may ask for information reasonably necessary to verify your identity, authority, account, or relationship with Anthid. We will use verification information only to process, document, and protect against fraudulent requests. If we cannot verify a request, we may be unable to fulfill it. We will respond within the time required by applicable law.

An authorized agent may submit a request on your behalf. We may require proof of the agent's authority and may also require you to verify your identity or confirm directly that you authorized the request, except where applicable law provides otherwise.

California Residents

If Anthid is subject to the CCPA with respect to your personal information, California law may provide rights to know, access, correct, and delete personal information; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to be free from discrimination or retaliation for exercising those rights, subject to applicable exceptions.

Sections 3 through 8 provide Anthid's disclosures regarding the preceding 12 months, including categories collected, sources, purposes, retention criteria, recipient categories, sale and sharing, and sensitive personal information. Because Anthid does not sell or share personal information and limits its use of sensitive personal information as described above, the corresponding opt-out and limitation rights do not apply to our current practices. You may nevertheless contact us with any question or request.

Anthid operates exclusively online. Requests to know, access, correct, or delete personal information may be submitted through the email method described above. Anthid will confirm and respond to verifiable requests within the periods required by applicable law.

11. International Processing

Anthid is based in the United States. We and our providers may process personal information in the United States and other countries whose privacy laws may differ from those where you live. Where applicable law requires a transfer mechanism or other safeguards, Anthid will use appropriate safeguards for covered transfers. Nothing in this section limits rights that cannot lawfully be waived.

12. Children

The Services are intended for business and professional users and are not directed to children under 16. Anthid does not knowingly collect personal information from children under 16. If you believe a child has provided personal information to Anthid, contact us so that we can investigate and take appropriate action.

13. Changes to This Privacy Policy

Anthid may update this Privacy Policy to reflect changes in the Services, our practices, or applicable law. We will post the revised version and update the "Last Updated" date. If a change is material, we may provide additional notice through the Services, by email, or by another method appropriate to the circumstances and required by law. Any revised Privacy Policy applies from its stated effective date.

14. Contact Us

For questions, concerns, or privacy requests, contact:

Anthid LLC

Email: [email protected]

Website: https://anthid.com

Nothing in this Privacy Policy limits any non-waivable right under applicable law. Additional commitments concerning Customer Data, if any, are governed by the applicable customer agreement or data processing addendum.