Last Updated: October 1, 2025
Your privacy matters. This Privacy & Cookies Policy explains how AncoraOak Studio Inc. and its affiliates, other companies of the AncoraOak group, and licensees of the AncoraOak brand (together, “AncoraOak,” “we,” “us,” “our”) collect, use, disclose, and safeguard information when you access or use our websites, investor portal, data rooms, APIs, and related services (the “Services”).
By using the Services, you consent to this Policy. Capitalized terms not defined here have the meanings in our General Terms of Service.
This Policy is designed to meet transparency obligations under the GDPR, CCPA/CPRA, and similar privacy regimes.
It explains: who we are, your privacy rights, marketing preferences, what data we collect, how and why we use data, cookies and trackers, data sharing, retention, security, children’s privacy, links, integrations, and updates to this Policy.
Controller:
AncoraOak Studio Inc. is the controller of, and the organization accountable for, your personal data for the Services listed in this Policy. Where an affiliate, another company of the AncoraOak group, or a licensee of the AncoraOak brand processes your personal data for its own purposes, that entity is the controller of that processing.
Contact:
📧 Email: privacy@ancoraoak.studio
📍 Mail: AncoraOak Studio Inc., Attn: Privacy, 150 King St W, Toronto, ON, Canada.
EU/UK representative:
We will appoint one where Article 27 GDPR/UK GDPR applies.
Depending on your jurisdiction, you may have the right to:
Access, correct, delete, or restrict your personal data
Object to processing
Request portability
Limit use/disclosure of Sensitive Personal Information (SPI)
Opt out of “sharing” for cross-context advertising
Withdraw consent at any time
We verify each request and respond within the required timeframes. If we decline, you may appeal via the contact above.
We do not discriminate against anyone for exercising these rights.
To exercise your rights, email us at privacy@ancoraoak.studio with the subject line “Privacy Request”. You can manage cookie preferences at any time via the “Manage cookies” link in the site footer.
You may manage your marketing subscriptions via unsubscribe links or by contacting us directly.
Transactional or service-related messages are not considered “marketing” and cannot generally be opted out of.
We collect data in three main ways:
We may collect:
Identity data: Name, aliases, title, date/place of birth, government identifiers (where lawful), signatures, identity documents, photos.
Contact data: Personal or work addresses, email, phone numbers.
Professional background: Employment and education history, credentials, affiliations.
Online presence: Links to public profiles or personal websites you share.
**Financial data: **Bank or payment details processed via secure systems; wealth/asset attestations for eligibility verification.
**Transaction data: **Purchases, subscriptions, payments, and investment transactions made via our Services.
**Investment data: **Investor status, objectives, experience, prior investments, entities, beneficial owners, and tax information contained in KYC/subscription files.
Content data: Account profiles, messages, comments, uploads, and metadata (e.g., timestamps).
**Marketing and communications data: **Preferences, opt-in/out records, correspondence history.
Behavioral segments: Categories derived from how you interact with our site.
**Technical data: **IP address, approximate geolocation, device/browser info, OS, plugins, logs, and diagnostics.
We may receive data from:
**Identity and compliance providers: **KYC/AML results, identity and sanctions checks.
Fund or administrative partners: Subscription status and investor records related to AOS-hosted vehicles.
Credit or reporting agencies: Identity, contact, and financial indicators.
Analytics or advertising partners: Pseudonymous identifiers, device/usage metrics, and interest segments.
Affiliates: Account or relationship context required to operate Services.
Data brokers or social media: Identity and contact details you have made public or consented to share.
We may also generate or receive aggregated or de-identified data that cannot identify you, unless re-linked.
We avoid processing “special categories” of personal data unless legally required (e.g., for identity verification). Sensitive Personal Information (SPI) is used only for limited lawful purposes such as compliance and security.
We use your data to:
Deliver, secure, and improve our Services
Operate investment and payment processes
Conduct research and development
Communicate service, security, and marketing information (where permitted)
Enforce terms and comply with legal obligations
Legal bases include contract performance, legitimate interests, consent (where obtained), and legal obligations.
Calls and electronic communications with AOS may be monitored or recorded where permitted by law, for compliance and record-keeping.
We use cookies, pixels, local storage, and similar technologies for authentication, analytics, preferences, and (where applicable) advertising.
Categories of cookies:
Essential: Required for sign-in, security, and core functionality.
Functionality: Remember preferences and UX settings.
**Analytics/Performance: **Measure usage and improve the product.
**Advertising/Targeting: **Deliver or measure ads (if enabled).
**Social Media: **Enable sharing or embedded content.
You can manage cookies through your browser or device settings.
We honor cookie preferences where required by law but do not currently respond to “Do Not Track” signals.
If this changes, we will update this Policy.
We may share your personal data with:
AOS affiliates - for platform operations and customer support.
Service providers - for hosting, storage, backups, KYC/compliance, payments, and administration.
Professional advisers - legal, audit, banking, insurance, and tax consultants.
Fund managers or vehicle operators - if you engage with investment vehicles.
Advertising and analytics partners - to measure campaigns (subject to opt-outs).
API or integration partners - for features you enable.
Regulators, authorities, or courts - for compliance and dispute resolution.
Corporate transactions - during mergers, financing, or reorganizations.
Researchers (under NDA) - for market or academic research.
Other users - when you choose to share data publicly.
If you ask us to delete your data, we’ll notify relevant third parties where possible.
We retain your data only as long as necessary to fulfill the purposes listed above, while your account is active, or as required by law. After that, data is securely deleted or de-identified.
Certain records (including investor verification and subscription records) are retained as required by applicable securities, tax, and anti-money-laundering legislation, and erasure rights are limited to that extent. Where AOS collects financial or accreditation-verification information, it does so with express consent and retains it only in accordance with the schedule above.
We primarily operate from Canada and the United States, but may use subprocessors in other jurisdictions.
By using the Services, you consent to lawful cross-border transfers subject to appropriate safeguards (e.g., SCCs, adequacy decisions).
We implement administrative, technical, and physical safeguards aligned with industry standards (access control, encryption, monitoring, incident response).
While we take strong precautions, no system is completely secure.
Our Services are not intended for children under 16. We do not knowingly collect data from them; if we do, we delete it promptly.
Our Services may link to third-party sites. We are not responsible for their privacy practices or content. Please review their own policies.
If you connect third-party accounts (like Google, Microsoft, LinkedIn, GitHub), we only access minimal data needed for that feature - typically your name, email, and profile photo.
You may also allow read-only access to contacts, calendars, or files to use optional scheduling or file-sharing tools.
We store tokens securely, never your passwords. You can disconnect these integrations anytime by contacting privacy@ancoraoak.studio or by revoking access directly from the third-party account.
We may update this Policy periodically. Updates take effect upon posting.
Material changes will be highlighted or otherwise communicated where required by law.
Check the “Last Updated” date above for the most current version.
We do not “sell” personal data. You can opt out of data “sharing” for cross-context behavioral advertising.
Sensitive Personal Information (SPI) is used only for essential purposes (compliance, security, service delivery).
Your rights under applicable laws (CPRA, VCDPA, CPA, etc.) include:
Access and deletion
Correction
Portability
Opt-out of targeted advertising or profiling
Limiting SPI use
Appealing denied requests
Nevada residents may opt out of “sale” of data under NRS 603A by contacting privacy@ancoraoak.studio
Legal bases: Contract, legitimate interests, consent, and legal obligations.
Transfers: When data is moved outside your jurisdiction, we use SCCs or other lawful mechanisms.
**Your rights: **Access, correction, deletion, restriction, portability, and the right to object.
You may also file complaints with your local data protection authority (e.g., via EDPB).
Under PIPEDA (Canada), you may access, correct, or withdraw consent (subject to legal limits). Commercial messages comply with CASL.
Quebec. For the purposes of An Act respecting the protection of personal information in the private sector (Quebec), we have designated a person in charge of the protection of personal information (title: Privacy Officer), who may be contacted at privacy@ancoraoak.studio.
We keep tracking on this site to a minimum. Here is what is actually deployed:
We use a consent-mode scaffold (Google Consent Mode v2) with all non-essential storage defaulted to “denied” until you make a choice. Your choice is stored locally in your browser (key: aos-cookie-consent) so we can honor it on later visits.
Duration: until you clear your browser storage or change your choice.
The site is hosted on Vercel. Our hosting infrastructure may set strictly necessary technical items and collect standard server logs (e.g., IP address, request metadata) to serve pages, balance load, and protect against abuse.
When you submit a form (e.g., contact, access requests, applications), we process the information you provide in order to respond to and administer your request.
We send transactional email (e.g., confirmations, notices, service updates). These messages are service communications, not marketing.
We do not currently deploy analytics, session-replay, or advertising trackers on this site. Analytics tools, if introduced, will load only after consent and this annex will be updated first.
Adjust your preferences in our cookie banner or via the “Manage cookies” link in the site footer.
You can delete or block cookies in your browser (blocking essential items may affect functionality).
We do not currently respond to “Do Not Track.”
Material updates will be posted here and in the banner when required.
Data we collect:
Who we share with:
We will notify you in case of any data breach as required by law.
Please check the “Last Updated” date for changes.
Commercial electronic messages are sent by or on behalf of AncoraOak Studio Inc., 150 King St W, Toronto, ON, Canada. Questions about our messages or this Policy: privacy@ancoraoak.studio. You may unsubscribe from commercial electronic messages at any time by using the unsubscribe link included in each message or by emailing privacy@ancoraoak.studio; unsubscribe requests are given effect without delay and in any event within 10 business days.