Privacy Policy
Last Updated: September 17, 2026
TOHKN, operated by MIO3, Sociedad Anónima de Capital Variable, registered in the Definitive Registry of Digital Asset Service Providers of El Salvador (registration No. PSAD-0016), is committed to protecting the privacy and personal data of its Users, in compliance with the laws in force in the Republic of El Salvador and by adopting international principles and standards regarding data protection.
Introduction
This Privacy Policy (hereinafter, the "Policy") governs the collection, use, storage, disclosure, processing, transfer, and protection of the personal data of Users who access and use the mobile or desktop investment application (the "Application") known as "TOHKN."
TOHKN is a registered trademark owned by MIO3. The Application constitutes the sole digital ecosystem linked to the MIO3 Platform, through which Users may engage in Digital Asset investments, exchange transactions, custody services and, where applicable, receive returns.
This Policy forms an integral part of the TOHKN Terms and Conditions, and the User's express acceptance thereof is an essential requirement for registration, access to, and use of the products and services offered through the Application.
MIO3 may amend this Policy at any time. Any amendment will be published in the Application and notified to the User by email or by notice within the Application. Continued use of the services following such amendments shall constitute express acceptance of the revised Policy.
1. Information We Collect
TOHKN may collect the following categories of personal data:
Identification and Contact Data: full name or legal entity name, identification document, nationality, address, date of birth, email address, telephone number, and other similar information.
Sensitive Personal Data: data which, due to its nature, requires a heightened level of protection under applicable law, including, where applicable, biometric data used to identify, verify, or authenticate the User, such as facial images, photographs, or videos subject to technical identity verification processes, or other biometric identifiers used for identity verification, authentication, fraud prevention, or Platform security purposes.
Financial and Transactional Data: history of transactions conducted through the Application, source and destination of funds, Digital Assets, and addresses of custodial digital wallets.
Technical and Browsing Data: IP address, browser type, access device, operating system, network configuration, approximate location, and activities conducted through the Application, including data collected through cookies or similar technologies.
Data Obtained from Public Sources or Authorized Third Parties: public records, international sanctions lists, and identity verification providers.
Automatically Collected Data: usage preferences, interactions with notifications or electronic communications, and geolocation data, where the User has provided express consent.
2. Purposes of Processing
Personal data collected by TOHKN shall be processed lawfully and transparently for the specific and legitimate purposes set forth below:
- Regulatory Compliance: identity verification, KYC procedures, biometric verification and proof-of-life (liveness) checks, where applicable, prevention of money laundering (AML), terrorist financing (CFT), financing of the proliferation of weapons of mass destruction, sanctions compliance, and compliance with other applicable regulatory obligations.
- Account Registration and Management: creation, maintenance, and administration of the TOHKN Account and TOHKN Wallet.
- Execution of Transactions: purchase, sale, transfer, custody, and redemption of Digital Assets, as well as receipt of returns, where applicable.
- Security and Fraud Prevention: detection and prevention of unlawful activities, unauthorized access, identity theft or impersonation, fraud, or suspicious transactions, including the use of biometric authentication or verification mechanisms where enabled.
- Legal and Contractual Compliance: compliance with legal, tax, regulatory, and contractual obligations arising from the services.
- Improvement of the User Experience: statistical analysis, interface personalization, and delivery of operational and informational communications.
- Commercial and Promotional Purposes: delivery of commercial and advertising notifications, provided that the User has expressly authorized them.
- Supervision and Audit: recordkeeping and responding to requests from administrative, judicial, or regulatory authorities.
3. Disclosure and Transfer of Personal Data
MIO3 may disclose or transfer Personal Data to the following:
- Competent Authorities: in compliance with legal, regulatory, administrative, or judicial obligations.
- Service Providers: third parties acting as data processors, including cloud storage providers, payment processors, identity verification providers, among others.
- MIO3 Affiliates or Related Entities: provided that a legitimate purpose exists and an adequate level of data protection is ensured.
- Corporate Transactions: in connection with reorganizations, mergers, acquisitions, or asset transfers, subject to confidentiality agreements.
In all cases, MIO3 shall require third-party recipients of Personal Data to comply with confidentiality obligations and equivalent data protection standards.
4. Retention of Personal Data
Personal Data collected by MIO3 shall be retained for the period strictly necessary to fulfill the purposes for which it was collected. Thereafter, it shall be deleted or anonymized, unless applicable law or regulation requires its retention for an additional period.
Notwithstanding the foregoing, certain Personal Data may be retained for a longer period pursuant to applicable regulations, including regulations relating to the prevention of money laundering, terrorist financing, and financing of the proliferation of weapons of mass destruction.
Likewise, certain data may be retained for the period expressly established by competent administrative, judicial, or regulatory authorities in compliance with legal requirements or as part of supervision, inspection, or audit proceedings.
5. ARCOPOL Rights and Other Rights of the Personal Data Subject
The Data Subject may, at any time and free of charge, exercise the rights of Access, Rectification, Cancellation, Objection, Portability, Erasure, and Restriction of Processing (collectively, the "ARCOPOL Rights"), as well as any other rights recognized under applicable personal data protection laws.
Such rights may be exercised with respect to all categories of Personal Data processed by MIO3, including Sensitive Personal Data and biometric data, subject to the exceptions, restrictions, and retention obligations established under applicable law.
In accordance with applicable personal data protection laws, you may exercise, at any time and free of charge, the following rights with respect to your Personal Data:
- Right of Access: to obtain confirmation as to whether MIO3 processes your Personal Data and, if so, to access the corresponding information in a clear and intelligible manner.
- Right to Rectification: to request the correction or updating of inaccurate, incomplete, or outdated Personal Data.
- Right to Cancellation or Deletion: to request the deletion of your Personal Data when it is no longer necessary for the purposes for which it was collected, when you have withdrawn your consent, when the processing is no longer necessary for the purpose for which the data was collected, when you object to the processing of your data, when the processing is unlawful, or when the data must be deleted pursuant to a legal obligation, unless otherwise provided by law.
- Right to Erasure ("Right to be Forgotten"): to request the deletion of your Personal Data, including removal from internal search engines, indexes, databases, active copies, electronic profiles, and other systems where legally appropriate, unless a legal or regulatory retention obligation applies.
- Right to Object: to request the cessation of the processing of your Personal Data where legitimate grounds exist relating to your particular circumstances or where the processing is carried out for direct marketing, profiling, or other purposes permitted by law.
- Right to Restriction of Processing: to request that the processing of your Personal Data be restricted in specific circumstances, including where you contest its accuracy, the processing is unlawful, TOHKN no longer requires your data, or while a legitimate objection raised by you is being resolved.
- Right to Data Portability: to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit such data to another controller, where technically feasible and provided that the processing is based on consent or the performance of a contractual relationship.
- Right Not to Be Subject to Automated Decision-Making: to request not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, except where expressly permitted by law, including the right to request human intervention, express your point of view, and challenge the decision where legally applicable.
- Right to Withdraw Consent: the Data Subject may withdraw at any time the consent granted for purposes for which the processing is based exclusively on such consent, without affecting the lawfulness of any processing carried out prior to such withdrawal.
- Right to Lodge Complaints: the Data Subject may lodge complaints with the competent personal data protection authority where the Data Subject considers that the processing of his or her Personal Data infringes applicable law.
To exercise any of these rights, you may submit a request to support@tohkn.com or through the corresponding form available in the official TOHKN Application. The Data Subject shall reasonably establish his or her identity or authority to act on behalf of another person where necessary to protect the confidentiality of Personal Data. MIO3 may request additional information where a request is ambiguous, excessive, or insufficient to identify the Data Subject or the data subject to the exercise of the applicable right.
TOHKN shall respond to the request within the maximum period established under the Personal Data Protection Law of the Republic of El Salvador.
6. Authorization to Share Information
Upon investing in or acquiring Digital Assets corresponding to an Issuance, the User acknowledges, consents to, and expressly authorizes MIO3 to disclose to the relevant Issuer such Personal Data and User identification information as may be necessary and proportionate for the Issuer to comply with its applicable legal and regulatory obligations relating to know-your-customer (KYC), anti-money laundering, counter-terrorist financing, and other related compliance obligations, including, as applicable, the User's full name or legal entity name, identification document, nationality, and jurisdiction of residence.
The information disclosed shall be used by the Issuer exclusively for purposes of complying with such legal and regulatory obligations relating to KYC, anti-money laundering, counter-terrorist financing, and related compliance requirements, and shall be processed in accordance with applicable confidentiality, data protection, and information security obligations.
This authorization does not include the transfer to the Issuer of the User's KYC file, due diligence documentation, risk assessments, source-of-funds information, or any other internal compliance documentation maintained by MIO3, unless such disclosure is required under applicable law or by a competent authority.
7. Security Measures
TOHKN implements appropriate technical and administrative measures to protect Personal Data against loss, misuse, unauthorized access, disclosure, alteration, or destruction. Such measures include:
- Encryption of information during transmission and storage;
- Multi-factor authentication (MFA) for account access;
- Access controls based on the principles of necessity and proportionality;
- Periodic audits and continuous monitoring of systems; and
- Internal privacy policies, personnel training, and confidentiality agreements.
You are also responsible for maintaining the confidentiality of your access credentials and for immediately notifying TOHKN of any unauthorized use of your Account.
8. International Transfers of Personal Data
Where it becomes necessary to transfer Personal Data to jurisdictions other than El Salvador, MIO3 shall verify that the recipient country provides an adequate level of protection in accordance with applicable local and international regulations. In the absence of an adequate level of protection, contractual clauses or other valid legal mechanisms shall be implemented to safeguard the secure processing of Personal Data in accordance with applicable law.
TOHKN shall maintain an updated record of international transfers carried out, in accordance with the principles of accountability and traceability.
9. Changes to the Privacy Policy
MIO3 may amend this Policy at any time. Material amendments shall be notified to the User through the Application, by email, or through other enabled communication channels. Where an amendment involves a new processing purpose or requires additional consent under applicable law, MIO3 shall obtain such consent again before commencing the relevant processing. In all other cases, amendments shall become effective upon publication or on the date specified in the applicable notice.
10. Governing Law and Jurisdiction
This Policy shall be governed by and construed in accordance with the laws of the Republic of El Salvador. Any dispute relating to the interpretation of or compliance with this Policy shall be submitted to the jurisdiction of the competent courts of the Republic of El Salvador.
11. Contact
To exercise ARCOPOL Rights, withdraw consent, or submit inquiries regarding the processing of Personal Data, the Data Subject may contact MIO3 through:
Email: support@tohkn.com
Data Protection Officer: José Alejandro Rodriguez Gomar
MIO3 may additionally make available forms, features within the Application, or other electronic means to facilitate the exercise of the Data Subject's rights.