Data Collection & Lawful Basis
Aevum Zenth Conglomerate and its 400+ global subsidiaries are committed to processing personal data transparently, fairly, and in strict compliance with applicable data protection laws, including the GDPR, CCPA/CPRA, LGPD, PIPL, and other regional frameworks.
This document outlines the categories of personal data we collect, the purposes for which we process it, and the specific lawful basis under which each processing activity is conducted.
1. Categories of Personal Data We Collect
We collect and process data across our energy, technology, aerospace, healthcare, financial, real estate, agricultural, logistics, media, construction, research, and robotics divisions. Data is collected directly from you, through automated technologies, or from third-party sources where legally permissible.
- Identity & Contact Data: Name, title, email, phone number, postal address, national ID/tax number.
- Financial & Transaction Data: Billing information, payment history, credit references, account balances, procurement records.
- Technical & Usage Data: IP addresses, device identifiers, browser types, operating systems, log files, cookies, and analytics data.
- Profile & Preference Data: Customer preferences, purchase history, loyalty program participation, service usage patterns.
- Health & Biometric Data (Healthcare/R&D Divisions): Medical records, genetic information, biometric identifiers, clinical trial data (processed under strict safeguards).
- Employment & HR Data: Resumes, performance records, payroll information, background checks, training certifications.
- Marketing & Communications Data: Email opens, click-through rates, webinar attendance, survey responses, opted-in communications.
2. Purposes & Lawful Basis for Processing
Under data protection law, we may only process personal data when we have a lawful basis. The table below maps our primary processing activities to their corresponding legal justification.
| Processing Purpose | Lawful Basis | Explanation & Scope |
|---|---|---|
| Service Delivery & Contract Fulfillment All Divisions |
Contract (Art. 6(1)(b) GDPR) | Processing necessary to perform a contract with you or take steps at your request prior to entering into a contract (e.g., ordering products, subscribing to SaaS platforms, booking logistics, accessing healthcare services). |
| Legal & Regulatory Compliance Finance, Energy, Aerospace, Healthcare |
Legal Obligation (Art. 6(1)(c) GDPR) | Processing required to comply with anti-money laundering (AML), know-your-customer (KYC), tax reporting, export controls, environmental regulations, HIPAA/GDPR health mandates, and aviation/space safety directives. |
| Direct Marketing & Commercial Communications Media, Tech, Real Estate, Retail |
Consent (Art. 6(1)(a) GDPR) Legitimate Interest (Art. 6(1)(f)) |
We rely on explicit opt-in consent for email marketing, promotional SMS, and profiling. For existing B2B clients, we may rely on legitimate interest for direct marketing of similar services, where permitted by law, with an easy opt-out mechanism. |
| Security, Fraud Prevention & Analytics Global IT & Operations |
Legitimate Interest (Art. 6(1)(f) GDPR) | Processing network logs, authentication attempts, and transaction patterns to prevent cyberattacks, detect fraudulent activity, ensure system integrity, and optimize platform performance. |
| Employment & Human Resources All Subsidiaries |
Contract (Art. 6(1)(b)) Legal Obligation Consent |
Payroll, benefits, and performance management require a contract or legal mandate. Biometric access, health accommodations, or voluntary wellness programs rely on explicit employee consent. |
| Critical Infrastructure & Safety Energy, Construction, Logistics |
Vital Interests (Art. 6(1)(d) GDPR) | Processing location data, emergency contacts, or safety-critical health information during facility operations, emergency response drills, or hazardous environment management to protect life and physical safety. |
| Public Task & Government Contracts Aerospace, Defense, Infrastructure |
Public Task (Art. 6(1)(e) GDPR) | When acting as a public body or fulfilling a government-mandated infrastructure, defense, or public safety program, we process data strictly within the scope of that statutory authority. |
Note on Special Category Data: Health, biometric, genetic, or trade union data is only processed under explicit consent, employment/social security law, vital interests, or where expressly permitted by sector-specific regulations (e.g., HIPAA, EU AI Act, ISO 27791).
3. Data Retention Principles
We retain personal data only for as long as necessary to fulfill the purposes outlined in this notice, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by division and jurisdiction:
- Customer/Contract Data: Retained for the duration of the business relationship plus 7 years post-termination (tax & audit compliance).
- Marketing Data: Retained until consent is withdrawn, or after 24 months of inactivity, whichever comes first.
- Security & Log Data: Retained for 12 months, unless required for an active investigation.
- Healthcare/Clinical Data: Retained per applicable medical records laws (typically 10–25 years) or study protocols.
- Employment Records: Retained for the duration of employment plus statutory periods (varies by country, typically 5–10 years).
4. Your Rights & How to Exercise Them
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'):) Request deletion where no longer necessary or if consent is withdrawn.
- Right to Restrict Processing: Limit how we use your data pending verification or legal review.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Withdraw Consent: Opt out at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: Submit a grievance to your local Data Protection Authority.
To exercise any of these rights, please contact our Group Data Protection Office (GDPO) using the details below. We will respond within 30 days, or sooner if required by local law.
5. International Data Transfers
As a global conglomerate, data may be transferred across borders to Aevum Zenth subsidiaries, cloud providers, or service partners. We ensure transfers comply with applicable frameworks, including EU Standard Contractual Clauses (SCCs), UK IDTA, adequacy decisions, and localized data residency requirements (e.g., PIPL in China, LGPD in Brazil).
6. Contact & Supervisory Authority
For questions about this policy, data subject requests, or privacy concerns:
- Group Data Protection Office (GDPO): privacy@aevumzenth.com
- Phone: +41 22 800 0100 (Swiss HQ) / +1 800 555 0199 (Americas)
- Postal: Zenth Tower, Level 42, Neo Geneva, CH-1202 Switzerland
- Supervisory Authority: You have the right to lodge a complaint with your local data protection regulator (e.g., ICO UK, CNIL France, BfDI Germany, CAI Italy).
Policy Governance: This document is maintained by the Aevum Zenth Legal & Compliance Division. Updates will be published here with revised dates. By using our services, you acknowledge that you have read and understand this Data Collection & Lawful Basis notice.