Public legal record
Privacy policy
The categories of personal information Tomorrow handles, why they are needed, who may receive them and the choices available to you.
In this document
01. Scope
This policy applies to personal information processed by Here Tomorrow LLC through its public website, membership application, member services, events, communications, research tools and transaction-related workflows. A separate agreement, notice or law may govern a particular service, counterparty relationship or jurisdiction and will control if it conflicts with this policy.
- Personal information
- Information that identifies, relates to or can reasonably be linked with a person or household.
- Transaction information
- Information connected with a requested, proposed, quoted, documented or completed position.
02. Information we collect
Depending on how you interact with Tomorrow, we may collect:
- Identity and contact information: name, address, email, telephone number, date of birth and authorized representatives.
- Eligibility and compliance information: identity documents, entity records, tax status, professional role, source-of-funds information and materials used to assess legal or counterparty eligibility.
- Membership information: application responses, preferences, mandates, event participation, club alias and account settings.
- Financial and transaction information: financial qualifications, portfolio or exposure information you choose to provide, requested terms, quotes, positions, settlement records and related documentation.
- Communications: correspondence, support requests, declarations, comments and records of consent or acknowledgment.
- Device and usage information: IP address, device and browser characteristics, authentication and security events, pages viewed and interaction timestamps.
- Derived information: classifications, preferences or analytical outputs created from permitted data for the purposes described below.
Please do not provide information that Tomorrow has not requested or does not need.
03. Sources
We may receive personal information:
- directly from you or an authorized representative;
- from counterparties, professional advisers, referral partners and service providers;
- from public records, sanctions and compliance sources, and licensed information providers;
- automatically from devices, browsers and security systems when you use the services.
Information supplied by another person must be provided lawfully and with any required notice or authority.
04. How we use information
We use personal information as reasonably necessary to:
- review membership applications, verify identity and assess eligibility;
- provide, personalize, secure and improve the services;
- prepare research, analytical outputs, mandates and transaction specifications requested by users;
- support introductions, due diligence, documentation, consent, reporting and settlement where applicable;
- administer subscriptions, events, benefits, communications and support;
- detect fraud, abuse, security incidents, conflicts and prohibited conduct;
- meet legal, regulatory, recordkeeping and contractual obligations;
- establish, exercise or defend legal claims and protect users, Tomorrow and others.
Where law requires a legal basis, processing may rely on contract, legal obligation, legitimate interests, consent or another available basis.
06. Automated and AI-assisted processing
Tomorrow may use automated and AI-assisted tools for analysis, document support, security, classification, personalization and service operations. Relevant information may be processed by contracted service providers under applicable restrictions.
Automated outputs may be incomplete or incorrect and are not guarantees. Where applicable law provides a right concerning a decision with legal or similarly significant effects, Tomorrow will provide the required information, review or means to contest that decision.
07. Security
Tomorrow uses administrative, technical and physical safeguards designed to protect personal information in light of its sensitivity and the nature of the services. Access is limited to people and providers with an appropriate need, and service providers are expected to protect information under contractual and legal obligations.
No security measure is infallible. You are responsible for safeguarding credentials, using appropriate authentication controls and promptly reporting suspected unauthorized access. Where required, Tomorrow will provide legally mandated security-incident notices.
If a breach occurs
In the event of a personal-data breach affecting your information, we will:
- notify affected individuals without unreasonable delay, and in no event later than required by applicable state and federal law;
- notify applicable regulatory authorities, including the CFTC, NFA and relevant state attorneys general, as required by law;
- describe the nature of the breach, the categories of data affected, the likely consequences, and the measures taken or proposed to address it and mitigate its effects;
- cooperate with law enforcement and regulatory investigations as appropriate.
08. Retention and international transfers
We retain personal information for as long as reasonably necessary for the purposes described, including membership administration, contractual performance, dispute resolution, fraud prevention and applicable legal or regulatory recordkeeping. Retention depends on the record, relationship, jurisdiction and outstanding obligations; information is deleted, anonymized or securely disposed of when no longer required.
Information may be processed outside your state or country. Where applicable law requires a transfer mechanism or additional safeguard, Tomorrow will use an available lawful mechanism. This statement does not claim participation in any optional certification framework.
10. Rights and choices
Depending on your location and relationship with Tomorrow, you may have rights to:
- request access to, correction of or deletion of personal information;
- receive a portable copy of certain information;
- object to or restrict certain processing;
- withdraw consent where processing depends on consent;
- appeal or complain to an applicable privacy authority;
- opt out of non-essential marketing communications.
Rights are subject to verification and legal exceptions, including regulatory retention, security, fraud prevention, legal claims and outstanding contractual obligations. Submit a request through the private contact page. Authorized agents must provide evidence of authority where required.
California residents (CCPA/CPRA)
In addition to the rights above, if you are a California resident you have:
- The right to limit use of sensitive personal information. You have the right to limit our use of sensitive personal information to purposes necessary to perform the Service.
- The right to non-discrimination. We will not discriminate against you for exercising any of your CCPA rights.
We do not sell personal information for money, and we do not share it for cross-context behavioral advertising.
We will respond to verified requests within forty-five (45) days, with one extension of up to forty-five (45) additional days where reasonably necessary.
11. Children
The services are not directed to children and are not intended for anyone below the age of majority in the applicable jurisdiction. If you believe a child has provided personal information, contact Tomorrow so the matter can be reviewed and addressed.
12. Changes and contact
Tomorrow may update this policy as services, law and data practices change. The current version and effective date appear above. Material changes will be communicated when and as required.
Questions, requests and complaints may be submitted through the private contact page. Transaction-specific notices and contractual privacy terms may provide additional contacts.