Data Collection & Lawful Basis

Last Updated: 15 November 2026
Applicable To: All Aevum Zenth Subsidiaries & Global Operations
Document Type: Data Protection & Privacy Notice

Aevum Zenth Conglomerate and its 400+ global subsidiaries are committed to processing personal data transparently, fairly, and in strict compliance with applicable data protection laws, including the GDPR, CCPA/CPRA, LGPD, PIPL, and other regional frameworks.

This document outlines the categories of personal data we collect, the purposes for which we process it, and the specific lawful basis under which each processing activity is conducted.

1. Categories of Personal Data We Collect

We collect and process data across our energy, technology, aerospace, healthcare, financial, real estate, agricultural, logistics, media, construction, research, and robotics divisions. Data is collected directly from you, through automated technologies, or from third-party sources where legally permissible.

2. Purposes & Lawful Basis for Processing

Under data protection law, we may only process personal data when we have a lawful basis. The table below maps our primary processing activities to their corresponding legal justification.

Processing Purpose Lawful Basis Explanation & Scope
Service Delivery & Contract Fulfillment
All Divisions
Contract (Art. 6(1)(b) GDPR) Processing necessary to perform a contract with you or take steps at your request prior to entering into a contract (e.g., ordering products, subscribing to SaaS platforms, booking logistics, accessing healthcare services).
Legal & Regulatory Compliance
Finance, Energy, Aerospace, Healthcare
Legal Obligation (Art. 6(1)(c) GDPR) Processing required to comply with anti-money laundering (AML), know-your-customer (KYC), tax reporting, export controls, environmental regulations, HIPAA/GDPR health mandates, and aviation/space safety directives.
Direct Marketing & Commercial Communications
Media, Tech, Real Estate, Retail
Consent (Art. 6(1)(a) GDPR)
Legitimate Interest (Art. 6(1)(f))
We rely on explicit opt-in consent for email marketing, promotional SMS, and profiling. For existing B2B clients, we may rely on legitimate interest for direct marketing of similar services, where permitted by law, with an easy opt-out mechanism.
Security, Fraud Prevention & Analytics
Global IT & Operations
Legitimate Interest (Art. 6(1)(f) GDPR) Processing network logs, authentication attempts, and transaction patterns to prevent cyberattacks, detect fraudulent activity, ensure system integrity, and optimize platform performance.
Employment & Human Resources
All Subsidiaries
Contract (Art. 6(1)(b))
Legal Obligation
Consent
Payroll, benefits, and performance management require a contract or legal mandate. Biometric access, health accommodations, or voluntary wellness programs rely on explicit employee consent.
Critical Infrastructure & Safety
Energy, Construction, Logistics
Vital Interests (Art. 6(1)(d) GDPR) Processing location data, emergency contacts, or safety-critical health information during facility operations, emergency response drills, or hazardous environment management to protect life and physical safety.
Public Task & Government Contracts
Aerospace, Defense, Infrastructure
Public Task (Art. 6(1)(e) GDPR) When acting as a public body or fulfilling a government-mandated infrastructure, defense, or public safety program, we process data strictly within the scope of that statutory authority.

Note on Special Category Data: Health, biometric, genetic, or trade union data is only processed under explicit consent, employment/social security law, vital interests, or where expressly permitted by sector-specific regulations (e.g., HIPAA, EU AI Act, ISO 27791).

3. Data Retention Principles

We retain personal data only for as long as necessary to fulfill the purposes outlined in this notice, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods vary by division and jurisdiction:

4. Your Rights & How to Exercise Them

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  1. Right of Access: Request a copy of the personal data we hold about you.
  2. Right to Rectification: Correct inaccurate or incomplete data.
  3. Right to Erasure ('Right to be Forgotten'):) Request deletion where no longer necessary or if consent is withdrawn.
  4. Right to Restrict Processing: Limit how we use your data pending verification or legal review.
  5. Right to Data Portability: Receive your data in a structured, machine-readable format.
  6. Right to Withdraw Consent: Opt out at any time without affecting the lawfulness of prior processing.
  7. Right to Lodge a Complaint: Submit a grievance to your local Data Protection Authority.

To exercise any of these rights, please contact our Group Data Protection Office (GDPO) using the details below. We will respond within 30 days, or sooner if required by local law.

5. International Data Transfers

As a global conglomerate, data may be transferred across borders to Aevum Zenth subsidiaries, cloud providers, or service partners. We ensure transfers comply with applicable frameworks, including EU Standard Contractual Clauses (SCCs), UK IDTA, adequacy decisions, and localized data residency requirements (e.g., PIPL in China, LGPD in Brazil).

6. Contact & Supervisory Authority

For questions about this policy, data subject requests, or privacy concerns:

Policy Governance: This document is maintained by the Aevum Zenth Legal & Compliance Division. Updates will be published here with revised dates. By using our services, you acknowledge that you have read and understand this Data Collection & Lawful Basis notice.