3. Information We Collect

📅 Effective: January 15, 2026 🔒 Part III of the Aevum Zenth Privacy Framework 🌍 Global Applicability

Overview

Aevum Zenth Conglomerate collects information to deliver, secure, and improve our multidivisional services, maintain regulatory compliance across 62 jurisdictions, and enable cross-subsidiary innovation. We collect data only when necessary and in accordance with applicable privacy laws including GDPR, CCPA, HIPAA (where applicable), and sector-specific regulations.

⚠️ Note: Data collection practices may vary slightly by division, subsidiary, or geographic region due to local legal requirements. This section outlines our global baseline standards.

1. Personal Identifiers

We collect standard personal identifiers to verify identity, manage accounts, and process transactions across our platforms and physical facilities.

  • Full legal name, username, or alias
  • Government-issued ID numbers (where legally required for KYC/AML compliance)
  • Date of birth or age range
  • Gender identity (optional, for demographic analysis)
  • Employee or contractor identification numbers (for internal subsidiaries)

2. Contact & Directory Data

Communication and operational continuity require accurate contact information. We maintain centralized directory systems for authorized interdivisional coordination.

  • Physical and mailing addresses
  • Email addresses and phone numbers
  • Emergency contact information
  • Organizational title, department, and subsidiary affiliation
  • Mailing preferences and communication opt-in/opt-out records

3. Financial & Payment Data

Process transactions securely through our Capital Group, retail divisions, and B2B procurement networks. We adhere to PCI-DSS Level 1 standards.

  • Credit/debit card numbers, expiration dates, and billing addresses
  • Bank account and routing information for direct deposits or wire transfers
  • Payment transaction history, invoices, and receipts
  • Creditworthiness indicators and billing status
  • Refund, chargeback, and dispute records

Note: We do not store full primary account numbers (PANs) on our primary servers. Payment data is tokenized and processed by PCI-compliant third-party payment gateways.

4. Usage & Device Information

Automated technologies and cookies collect technical data to optimize user experience, ensure platform security, and drive R&D insights across our digital ecosystem.

  • IP address, browser type, and operating system
  • Device identifiers, hardware model, and screen resolution
  • Pages visited, clickstream data, session duration, and navigation paths
  • Error logs, crash reports, and performance metrics
  • Referring URLs, campaign IDs, and ad interaction data

5. Location Data

Location information enables logistics routing, facility access, targeted services, and emergency response coordination.

  • GPS coordinates (when explicitly permitted via mobile/desktop interfaces)
  • Wi-Fi access points, Bluetooth beacons, and cell tower triangulation
  • Check-in records for corporate campuses, data centers, and retail locations
  • Delivery addresses and shipment tracking coordinates

6. Special/Protected Categories

We only collect sensitive data when explicitly authorized by law or with explicit user consent, primarily within our Health Sciences, Research, and specialized insurance divisions.

  • Health records, medical history, and biometric data (Healthcare Division)
  • Employment eligibility verification and immigration status
  • Genetic information and clinical trial participation records
  • Protected health information (PHI) under HIPAA-equivalent frameworks

All sensitive data is encrypted at rest (AES-256), access-controlled via role-based permissions, and subject to annual third-party security audits.

7. Information from Third Parties

To maintain our global supply chain, compliance networks, and service integrations, we receive data from authorized external sources.

  • Credit reporting agencies and financial institutions
  • Identity verification providers and background check services
  • Business partners, vendors, and subcontractors
  • Public records, government databases, and regulatory filings
  • Social media platforms and analytics partners (where permitted)

We ensure all third-party data transfers comply with cross-border data transfer mechanisms (SCCs, BCRs, or equivalent).

8. How We Collect Data

Data collection occurs through direct submission, automated technologies, and authorized network integrations.

Direct Collection

  • Account registration, profile updates, and preference centers
  • Purchase transactions, checkout forms, and payment portals
  • Customer support tickets, surveys, and feedback channels
  • Event registrations, trade show check-ins, and conference attendance

Automated Collection

  • Cookies, web beacons, SDKs, and fingerprinting technologies
  • Server logs, API usage metrics, and telemetry data
  • IoT devices, sensors, and smart infrastructure endpoints

Network & Partner Collection

  • Interdivisional data sharing protocols
  • Supply chain and vendor management systems
  • Compliance and regulatory reporting pipelines

9. Collection Summary Table

Data Category Collection Method Primary Purpose Legal Basis
Personal Identifiers Direct Submission Account Management, Identity Verification Contractual Necessity, Legitimate Interest
Contact Data Direct, Automated Communication, Directory Services Consent, Contractual Necessity
Financial Data Direct (Tokenized) Payment Processing, Fraud Prevention Contractual Necessity, Legal Obligation
Usage & Device Automated Security, UX Optimization, Analytics Legitimate Interest, Consent
Location Data Automated, Direct Logistics, Facility Access, Services Consent, Contractual Necessity
Special/Protected Direct, Third-Party Healthcare, R&D, Compliance Explicit Consent, Legal Obligation

10. Policy Updates

This section is reviewed and updated periodically to reflect changes in our business operations, technological infrastructure, and evolving global privacy regulations. Material changes will be communicated via email, platform notices, or direct correspondence where required by law.

Last Updated: January 15, 2026
Document Version: 3.4.1
Governing Framework: Aevum Zenth Global Privacy Charter

For questions regarding data collection, contact our Data Protection Office at dpo@aevumzenth.com or via our secure contact portal.