Data Protection & Privacy

Privacy Policy

Comprehensive data protection framework, GDPR compliance, and next-of-kin information security

Last Updated: January 2025

1. Information We Collect
Types of data collected through website and web portal

1.1 Personal Information

  • • Full name, date of birth, and nationality
  • • Contact information (email, phone, address)
  • • Government-issued identification documents
  • • Financial information and source of funds documentation
  • • Investment preferences and risk tolerance

1.2 Next-of-Kin Information

  • • Next-of-kin personal details and contact information
  • • Relationship documentation and verification
  • • Next-of-kin identification documents
  • • E-notarization records and legal documentation
  • • Inheritance planning and succession information

1.3 Technical Information

  • • IP addresses, browser information, and device data
  • • Portal usage patterns and navigation data
  • • Login timestamps and security event logs
  • • Performance analytics and system diagnostics
  • • Cookie and session management data
2. How We Use Your Information
Purposes and legal basis for data processing

2.1 Investment Services

  • • KYC/AML verification and compliance monitoring
  • • Investment processing and profit distribution
  • • Investment window participation and priority access
  • • Performance tracking and reporting
  • • Customer support and investor relations

2.2 Web Portal Operations

  • • Account authentication and security management
  • • Personalized dashboard and analytics
  • • Real-time performance monitoring
  • • Document management and secure storage
  • • Communication and notification services

2.3 Legal and Regulatory Compliance

  • • Anti-money laundering (AML) compliance
  • • Regulatory reporting and documentation
  • • Tax reporting and documentation
  • • Audit trail maintenance and record keeping
  • • Legal proceedings and dispute resolution
3. Data Protection and Security
Comprehensive security measures and protection framework

3.1 Technical Security Measures

  • • AES-256 encryption for all data transmission and storage
  • • Multi-factor authentication and biometric verification
  • • Bank-level security infrastructure and monitoring
  • • Regular security audits and penetration testing
  • • Secure backup systems with 99.9% uptime guarantee

3.2 Access Controls

  • • Role-based access control for all systems
  • • Comprehensive audit trails and activity logging
  • • Regular access reviews and permission updates
  • • Secure session management and automatic timeouts
  • • Employee background checks and security training

3.3 Data Breach Response

In the unlikely event of a data breach, we will notify affected individuals within 72 hours and take immediate steps to secure systems, assess impact, and prevent future incidents.

4. GDPR Compliance and Your Rights
European data protection rights and compliance

4.1 Your Data Rights

  • Right to Access: Request copies of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of personal data (subject to legal requirements)
  • Right to Portability: Receive your data in a structured format
  • Right to Object: Object to processing for specific purposes
  • Right to Restrict: Limit how we process your data

4.2 Legal Basis for Processing

  • Contract Performance: Investment services and profit distribution
  • Legal Obligation: KYC/AML compliance and regulatory reporting
  • Legitimate Interest: Security monitoring and fraud prevention
  • Consent: Marketing communications and optional services

4.3 Data Retention

We retain personal data for as long as necessary to provide services and comply with legal obligations. Investment records are typically retained for 7 years after account closure, while next-of-kin information is maintained for inheritance purposes.

5. Next-of-Kin Information Protection
Special protections for inheritance planning data

5.1 Enhanced Security Measures

  • • Separate encrypted storage for next-of-kin information
  • • Additional access controls and approval processes
  • • E-notarization records with legal-grade security
  • • Regular verification and update procedures
  • • Secure communication channels for next-of-kin contact

5.2 Next-of-Kin Rights

  • • Right to be informed about data processing
  • • Right to update or correct their information
  • • Right to withdraw consent for non-essential processing
  • • Right to access their stored information
  • • Right to data protection in inheritance proceedings
6. Data Sharing and Third Parties
Limited data sharing for essential services

6.1 Service Providers

  • • KYC/AML verification services (identity verification)
  • • Cloud infrastructure providers (secure data hosting)
  • • Payment processors (investment transactions)
  • • E-notarization services (legal documentation)
  • • Audit and compliance firms (regulatory requirements)

6.2 Legal and Regulatory Disclosure

We may disclose information when required by law, court order, or regulatory investigation. We will notify you of such disclosures unless legally prohibited.

6.3 No Sale of Personal Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is used exclusively for investment services and legal compliance.

7. Cookies and Tracking Technologies

7.1 Essential Cookies

  • • Authentication and session management
  • • Security monitoring and fraud prevention
  • • Portal functionality and user preferences
  • • Load balancing and performance optimization

7.2 Analytics and Performance

We use analytics cookies to understand portal usage and improve user experience. You can manage cookie preferences through your browser settings or portal preferences.

8. Privacy Contact and Complaints

8.1 Data Protection Officer

Email: dpo@vidardc.com
Address: VIDA RDC Ltd, Data Protection Officer
123 Business District, Financial Center, Suite 4500
International City, IC 12345

8.2 Complaint Process

If you have concerns about our data processing, please contact our Data Protection Officer first. You also have the right to lodge a complaint with your local data protection authority.

8.3 Response Timeline

We will respond to privacy requests within 30 days and data subject requests within the timeframes required by applicable law (typically 30 days for GDPR requests).

9. Policy Updates

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes through the web portal and email. Continued use of our services after updates constitutes acceptance of the revised policy.

Current Version: This Privacy Policy was last updated in January 2025 and reflects our enhanced data protection framework for the 3-year focused business model with investment windows and comprehensive web portal integration.

Built with v0