Data Protection & Privacy Policy

📅 Effective: January 15, 2026 🔄 Last Updated: March 04, 2026 📜 Version 4.2.1

1 Introduction & Scope

Aevum Zenth Conglomerate ("Aevum Zenth", "we", "our", or "us") is committed to protecting the privacy and security of personal data across all 400 subsidiaries and global operations. This Data Protection & Privacy Policy outlines how we collect, process, store, and safeguard information in compliance with GDPR, CCPA/CPRA, LGPD, PIPL, and other applicable data protection regulations.

Global Compliance Framework: This policy applies to all individuals interacting with Aevum Zenth entities, including clients, partners, employees, contractors, website visitors, and service users across all divisions.

2 Information We Collect

We collect data only when necessary for legitimate business purposes, legal compliance, or with your explicit consent. Categories include:

  • Identifiers: Name, email, phone, mailing address, IP address, device identifiers
  • Professional & Transactional: Employment records, contract details, payment history, service usage metrics
  • Technical & Behavioral: Browser type, OS, cookie data, clickstream analytics, session recordings (where consented)
  • Special Category Data: Health, biometric, or sensitive information only when strictly required for healthcare division operations, with enhanced safeguards and explicit consent

3 How We Use Your Data

Personal data is processed to:

  • Deliver, maintain, and improve products and services across our divisions
  • Process transactions, manage accounts, and send service-related communications
  • Comply with legal, regulatory, and contractual obligations
  • Conduct analytics, research, and innovation initiatives (aggregated/anonymized where possible)
  • Prevent fraud, ensure security, and protect our infrastructure and users
  • Communicate updates, marketing materials (with opt-in consent), and corporate announcements

5 Data Sharing & Third Parties

We do not sell personal data. Sharing occurs only when necessary and under strict contractual and technical safeguards:

  • Affiliates & Subsidiaries: Internal cross-divisional operations require data sharing for integrated service delivery
  • Service Providers: Cloud hosting, payment processors, logistics partners, and IT vendors bound by DPA/CCPA-compliant agreements
  • Legal & Regulatory: Law enforcement, government agencies, or auditors when legally compelled
  • Business Transfers: Mergers, acquisitions, or restructuring, with prior notice and continued privacy obligations
Vendor Management: All third-party processors undergo annual security audits, penetration testing, and compliance certifications (ISO 27001, SOC 2 Type II, GDPR DPA execution).

6 Data Security & Encryption

Aevum Zenth implements industry-leading security controls to protect data at rest, in transit, and in use:

  • Encryption: AES-256 for storage, TLS 1.3+ for transit, end-to-end encryption for sensitive healthcare/financial data
  • Access Control: Zero-trust architecture, MFA enforcement, RBAC/ABAC policies, and privileged access management
  • Monitoring: 24/7 SOC operations, AI-driven anomaly detection, automated incident response playbooks
  • Resilience: Geo-redundant backups, immutable logging, quarterly disaster recovery drills

7 Your Rights & Choices

Depending on your jurisdiction, you may exercise the following rights:

  • Access, rectify, or erase your personal data
  • Restrict or object to processing
  • Data portability in structured, machine-readable formats
  • Withdraw consent at any time without affecting prior lawful processing
  • Opt out of automated decision-making or profiling
  • Lodge a complaint with a supervisory authority

Requests are verified for identity and security, processed within 30 days (or jurisdictional limits), and delivered via secure channels.

8 Data Retention & Deletion

We retain personal data only as long as necessary:

  • Transactional/Account Data: Duration of relationship + 7 years (financial/legal requirements)
  • Marketing/Consent Data: Until withdrawal or 36 months of inactivity
  • Employment Records: As required by labor laws + statutory retention periods
  • Security/Logs: 12–24 months depending on risk classification

Upon expiration, data is securely deleted or irreversibly anonymized using NIST-approved sanitization protocols.

9 International Data Transfers

As a global conglomerate, data may transfer across borders. We ensure lawful transfers via:

  • EU Standard Contractual Clauses (SCCs) and adequacy decisions
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Local data residency options where mandated (China, India, EU, etc.)
  • Transparency registers mapping cross-border data flows

10 Cookies & Tracking Technologies

Our platforms use cookies and similar technologies for:

  • Essential: Security, session management, load balancing
  • Analytics: Performance metrics, user journey optimization
  • Functional: Preferences, language, accessibility settings
  • Marketing: Retargeting, campaign attribution (consent-based only)

Manage preferences via our Cookie Center or browser settings. Third-party scripts are blocked until explicit consent is granted.

11 Data Protection Officer & Contact

Our Global Data Protection Office oversees compliance, handles inquiries, and manages data subject requests.

Global Data Protection Office

dpo@aevumzenth.com
Zenth Tower, Suite 4800, Neo Geneva (Global HQ)
+41 22 780 9000 (Privacy Hotline)

Secure submission portal: /secure/dpr

12 Policy Updates

We periodically review this policy to reflect technological, operational, or legal changes. Material updates will be communicated via email, in-app notices, or website announcements. Continued use of our services constitutes acknowledgment of revised terms.

For the complete version history, audit logs, and regulatory compliance certificates, visit our Compliance Register.