MTAX AI by Tenpaso Ltd

MTAX AI — Privacy Notice

Effective 15 September 2026 · Version pilot-privacy-2026-09-15

1. Who we are and how to contact us

Tenpaso Ltd. operates mtaxai.com and the AITAX Windows application, together referred to here as MTAX AI. We are registered in Malta under company number C 116371, with registered office at SOHO ST. JULIANS PUNCHBOWL CENTRE UNIT P033, TRIQ ELIJA ZAMMIT, SAN GILJAN, STJ 3154, Malta.

For privacy enquiries or to exercise your rights, email operations@tenpaso.com. This notice covers visitors, pilot applicants, authorised users and people whose information is included in enquiries or support communications.

Tenpaso is the controller for website applications, account administration, support and service security. When an organisation uses MTAX AI to process information about its clients under its instructions, that organisation determines its purposes and lawful basis; Tenpaso processes that content to provide the requested service. The organisation remains responsible for its own notices and authority to disclose client information. This notice does not replace any required data-processing agreement.

2. Information we process

Website applications and correspondence: contact details, organisation, professional role, interest text, consent records and information you send to support. The application form is for contact details, not a tax question or client documents.

Accounts and access: email and account identifiers, organisation membership, licence/access status, device and execution-session identifiers, authentication events and related security information.

Research: questions, clarification messages, confirmed facts and dates, AI-generated responses, research artifacts and source references. These can contain personal information you enter or information generated about people mentioned in the enquiry. We also keep operational records needed to coordinate, recover and investigate research sessions.

Technical information: IP addresses and network/request information processed by our hosting and connection providers, device/application information, timestamps, error information and security records. We do not ask you to put passwords, API keys or payment details into your questions or support messages.

Information comes from you, your organisation and your use of the service. Authentication and connected-service providers supply relevant account and connection status. AI processing generates research and related records.

3. Why we use it and our lawful bases

We use application details to assess requests for complimentary early access and contact selected applicants, based on the consent given on the form. You may withdraw that consent at any time by emailing us; this does not affect processing that was lawful before withdrawal.

We use account and support information to provide the service you request and administer your access. Where you contract directly with us, the basis is taking requested pre-contractual steps or performing our agreement. Where your organisation is the customer, our legitimate interests are administering that business relationship and enabling its authorised users to use the service.

We process technical and security information for our legitimate interests in protecting accounts, preventing abuse, diagnosing failures and maintaining the service. We use only information relevant to those purposes and consider the effects on the individuals concerned. We may also retain or disclose information where needed to comply with a legal obligation or establish, exercise or defend a legal claim.

For research content processed on behalf of a professional customer, we act on the customer's instructions to provide the research service; the customer must establish its lawful basis for the personal information it supplies. Do not submit information you are not authorised to disclose. Minimise personal information and avoid unnecessary identifiers, special-category data and criminal-offence information.

4. How AI processing works

MTAX AI uses your selected AI connection. Your intake conversation is sent to that provider before you confirm the research question. Confirmation starts the research stage; it is not the point at which all data processing first begins.

The Windows application communicates with Tenpaso's central service, which stores case and operational information, and with the connected AI provider. Provider credentials are managed by the desktop connection. This is not an entirely local or offline service.

Provider handling depends on the account type, settings, applicable terms and tools used by the connection. API and subscription connections may have different data controls. We do not promise that every connection has zero retention, identical training settings or processing confined to the EEA. Review your provider's controls before submitting confidential information.

AI research and AI review are automated. They are not approval by a human accountant, senior manager, auditor or tax authority. MTAX AI does not itself file returns or make a legally binding tax decision about you.

AI can make mistakes. Have this response reviewed and confirmed by a qualified tax professional before relying on it.

5. Who receives information

Information is available to authorised Tenpaso personnel where needed for administration, support, security or legal responsibilities, and to the organisation responsible for your account as required to provide its service.

Our current service providers include:

Tenpaso operates the central application host. We may disclose relevant information to professional advisers or public authorities when necessary for a legal obligation or claim. We do not publish your private research on the website. Downloading an installer does not make other users' research accessible to you.

6. International processing

Providers operate internationally, including in the United States. A European database or storage region does not mean that all related support, logs or processing stay in Europe.

International transfers must use a mechanism permitted by applicable data-protection law, such as an applicable adequacy decision or appropriate contractual safeguards. Provider documentation describes their arrangements: Supabase, Cloudflare, Vercel, Resend, and Google. A provider's published terms do not mean that all its services or account types use the same arrangements.

Contact operations@tenpaso.com for information about safeguards applicable to processing by Tenpaso and how to obtain a relevant copy, subject to protection of confidential information. For the AI account you connect yourself, also consult the provider's account terms and data controls.

7. How long information is kept

We use the following criteria to determine retention:

Completed research is not automatically erased when an answer appears. Closing the app, uninstalling it or disabling an account does not itself delete central records. The current pilot uses case-by-case review of retention and deletion requests; we do not promise a fixed automatic purge period that the system does not implement. Records must not be kept merely because storage remains available.

Where deletion is appropriate, the review includes relevant copies and backups under our control. Backup or legally preserved copies may need to remain restricted until they can be removed under the applicable process. Information retained for a specific obligation or claim is limited to that purpose. Separate provider retention may apply to your independently connected AI account; you may need to make a request to that provider too.

8. Your rights

Subject to the applicable conditions, you may request access, correction, erasure, restriction or portability of your personal information, object to processing based on legitimate interests, and withdraw consent where consent is used. Email operations@tenpaso.com. You do not need to use a technical API to make a request.

We may ask for proportionate information to verify your identity. We must also protect other people's information and account security. We respond within the time required by applicable law; where a permitted extension is needed, we explain it. Where we act on your organisation's instructions, we may refer the request to that organisation and assist it appropriately.

You can complain to Malta's Information and Data Protection Commissioner, or another competent supervisory authority. Contacting us first is not a condition of that right.

9. Cookies, security and your choices

The website uses a secure, HTTP-only form-protection cookie with a two-hour lifetime to protect submissions. Hosting and connection providers also process information needed to deliver and protect the website. Our application form does not require advertising tracking consent.

We use authenticated access, encrypted public connections and access controls to protect the service. No system can guarantee absolute security. Keep your credentials private and contact us promptly if you suspect unauthorised access. Send only information necessary for your enquiry and avoid confidential client details in the website form.

Providing contact information is necessary for us to assess and reply to an application. Account information is needed for access, and relevant research facts are needed to address your question. If you withhold essential information, we may be unable to provide the corresponding service. The pilot is intended for professional users, not children.

10. Changes to this notice

We identify this notice by its effective date and version. We will communicate material changes appropriately and retain identifiable prior versions. A later revision does not silently change the text associated with an earlier acceptance.