Privacy Policy
Comprehensive data protection framework, GDPR compliance, and next-of-kin information security
Last Updated: January 2025
1.1 Personal Information
- • Full name, date of birth, and nationality
- • Contact information (email, phone, address)
- • Government-issued identification documents
- • Financial information and source of funds documentation
- • Investment preferences and risk tolerance
1.2 Next-of-Kin Information
- • Next-of-kin personal details and contact information
- • Relationship documentation and verification
- • Next-of-kin identification documents
- • E-notarization records and legal documentation
- • Inheritance planning and succession information
1.3 Technical Information
- • IP addresses, browser information, and device data
- • Portal usage patterns and navigation data
- • Login timestamps and security event logs
- • Performance analytics and system diagnostics
- • Cookie and session management data
2.1 Investment Services
- • KYC/AML verification and compliance monitoring
- • Investment processing and profit distribution
- • Investment window participation and priority access
- • Performance tracking and reporting
- • Customer support and investor relations
2.2 Web Portal Operations
- • Account authentication and security management
- • Personalized dashboard and analytics
- • Real-time performance monitoring
- • Document management and secure storage
- • Communication and notification services
2.3 Legal and Regulatory Compliance
- • Anti-money laundering (AML) compliance
- • Regulatory reporting and documentation
- • Tax reporting and documentation
- • Audit trail maintenance and record keeping
- • Legal proceedings and dispute resolution
3.1 Technical Security Measures
- • AES-256 encryption for all data transmission and storage
- • Multi-factor authentication and biometric verification
- • Bank-level security infrastructure and monitoring
- • Regular security audits and penetration testing
- • Secure backup systems with 99.9% uptime guarantee
3.2 Access Controls
- • Role-based access control for all systems
- • Comprehensive audit trails and activity logging
- • Regular access reviews and permission updates
- • Secure session management and automatic timeouts
- • Employee background checks and security training
3.3 Data Breach Response
In the unlikely event of a data breach, we will notify affected individuals within 72 hours and take immediate steps to secure systems, assess impact, and prevent future incidents.
4.1 Your Data Rights
- • Right to Access: Request copies of your personal data
- • Right to Rectification: Correct inaccurate or incomplete data
- • Right to Erasure: Request deletion of personal data (subject to legal requirements)
- • Right to Portability: Receive your data in a structured format
- • Right to Object: Object to processing for specific purposes
- • Right to Restrict: Limit how we process your data
4.2 Legal Basis for Processing
- • Contract Performance: Investment services and profit distribution
- • Legal Obligation: KYC/AML compliance and regulatory reporting
- • Legitimate Interest: Security monitoring and fraud prevention
- • Consent: Marketing communications and optional services
4.3 Data Retention
We retain personal data for as long as necessary to provide services and comply with legal obligations. Investment records are typically retained for 7 years after account closure, while next-of-kin information is maintained for inheritance purposes.
5.1 Enhanced Security Measures
- • Separate encrypted storage for next-of-kin information
- • Additional access controls and approval processes
- • E-notarization records with legal-grade security
- • Regular verification and update procedures
- • Secure communication channels for next-of-kin contact
5.2 Next-of-Kin Rights
- • Right to be informed about data processing
- • Right to update or correct their information
- • Right to withdraw consent for non-essential processing
- • Right to access their stored information
- • Right to data protection in inheritance proceedings
6.1 Service Providers
- • KYC/AML verification services (identity verification)
- • Cloud infrastructure providers (secure data hosting)
- • Payment processors (investment transactions)
- • E-notarization services (legal documentation)
- • Audit and compliance firms (regulatory requirements)
6.2 Legal and Regulatory Disclosure
We may disclose information when required by law, court order, or regulatory investigation. We will notify you of such disclosures unless legally prohibited.
6.3 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is used exclusively for investment services and legal compliance.
7.1 Essential Cookies
- • Authentication and session management
- • Security monitoring and fraud prevention
- • Portal functionality and user preferences
- • Load balancing and performance optimization
7.2 Analytics and Performance
We use analytics cookies to understand portal usage and improve user experience. You can manage cookie preferences through your browser settings or portal preferences.
8.1 Data Protection Officer
8.2 Complaint Process
If you have concerns about our data processing, please contact our Data Protection Officer first. You also have the right to lodge a complaint with your local data protection authority.
8.3 Response Timeline
We will respond to privacy requests within 30 days and data subject requests within the timeframes required by applicable law (typically 30 days for GDPR requests).
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes through the web portal and email. Continued use of our services after updates constitutes acceptance of the revised policy.
Current Version: This Privacy Policy was last updated in January 2025 and reflects our enhanced data protection framework for the 3-year focused business model with investment windows and comprehensive web portal integration.