Table of Contents
01 Introduction
Aevum Zenth Conglomerate ("we," "our," or "us") is committed to protecting your privacy and safeguarding your personal data. This Data Privacy & Protection Policy applies to all 400 subsidiaries, divisions, and affiliated entities operating under the Aevum Zenth umbrella across 62 countries.
Whether you are an employee, customer, investor, partner, or visitor to our digital platforms, we recognize that you share your personal information with a measure of trust. We honor that trust and strive to exceed your expectations through robust data protection practices.
Scope: This policy governs the collection, processing, storage, sharing, and deletion of personal data across all Aevum Zenth operations, including Energy, Technology, Aerospace, Healthcare, Financial Services, Real Estate, Agriculture, Logistics, Media, Construction, Research, and Robotics divisions.
We comply with and align our practices to global data protection frameworks including but not limited to:
- General Data Protection Regulation (GDPR) — European Union
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
- Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada
- Privacy Act 1988 and Australian Privacy Principles (APPs)
- Personal Data Protection Act (PDPA) — Singapore
- Lei Geral de Proteção de Dados (LGPD) — Brazil
- Japan's Act on Protection of Personal Information (APPI)
02 Data We Collect
We collect personal data only when necessary for legitimate business purposes. The categories of personal data we may collect include:
2.1 Identity Data
- Full name, title, and date of birth
- Government-issued identification numbers (e.g., passport, national ID, Social Security Number)
- Photographs and biometric data (where consent is given)
2.2 Contact Data
- Email address and mailing address
- Phone number and preferred contact method
- Emergency contact information
2.3 Financial Data
- Billing address and payment card details (encrypted, PCI-DSS compliant)
- Bank account information for payroll and vendor payments
- Tax identification numbers
- Investment account information (Aevum Capital Group)
2.4 Technical Data
- IP address, browser type, and device information
- Operating system and platform data
- Access logs and session information
- Network performance data
2.5 Usage Data
- Pages visited and features used across Aevum Zenth platforms
- Time spent on pages and clickstream data
- Download history and interaction preferences
- Customer support ticket history
2.6 Health & Employment Data
- Health insurance enrollment details (Zenth Health Sciences)
- Occupational health records (with explicit consent)
- Employment history, qualifications, and performance reviews
- Payroll and benefits information
2.7 Communications Data
- Records of correspondence (emails, letters, calls)
- Newsletter and marketing preference records
- Survey responses and feedback submissions
03 How We Use Your Data
We process your personal data under the following lawful bases and for the following specific purposes:
3.1 Service Delivery
To provide, operate, and maintain our products and services across all divisions, including but not limited to energy infrastructure management, healthcare services, financial transactions, real estate operations, and logistics fulfillment.
3.2 Business Operations
To manage our enterprise operations including human resources, supply chain management, financial reporting, regulatory compliance, and internal audit functions.
3.3 Security & Fraud Prevention
To protect the security and integrity of our systems, networks, and services; to detect, investigate, and prevent fraud, unauthorized access, and cyber threats.
3.4 Legal & Regulatory Compliance
To meet our obligations under applicable laws, regulations, and industry standards, including anti-money laundering (AML), know-your-customer (KYC), and sector-specific mandates.
3.5 Communication
To respond to your inquiries, provide customer support, send service-related notifications, and—with your consent—deliver marketing communications and news updates.
3.6 Improvement & Innovation
To analyze trends, improve our services, develop new products, and advance our R&D initiatives through aggregated, anonymized data analysis.
Lawful Processing: We always process your data under a valid legal basis—contractual necessity, legal obligation, legitimate interest, consent, or vital interest—and document the basis for each processing activity.
04 Data Sharing & Disclosure
We do not sell your personal data. We may share your information in the following limited circumstances:
4.1 Within the Conglomerate
Personal data may be shared among Aevum Zenth subsidiaries and divisions on a need-to-know basis to deliver integrated services. All intra-company transfers are governed by Binding Corporate Rules (BCRs) and intercompany data processing agreements.
4.2 Service Providers & Vendors
We engage trusted third-party service providers who assist us in operating our business, including:
- Cloud infrastructure providers (Zenth Digital Systems)
- Payment processors and financial institutions
- Customer service platforms and analytics tools
- Logistics and supply chain partners
All vendors are required to adhere to strict data protection standards and sign Data Processing Agreements (DPAs) aligned with this policy.
4.3 Legal Authorities
We may disclose personal data when required to do so by law, regulation, court order, subpoena, or governmental request.
4.4 Business Transfers
In the event of a merger, acquisition, divestiture, or sale of assets, personal data may be transferred as part of the transaction, with appropriate notice and safeguards in place.
4.5 With Your Consent
We may share your data with third parties when you have provided explicit, informed consent for a specific purpose.
Third-Party Responsibility: While we carefully vet our partners, we are not responsible for the privacy practices of third-party websites or services accessible through our platforms. Please review their policies independently.
05 Data Protection Measures
Aevum Zenth invests $12B annually in R&D, a significant portion of which funds our cybersecurity and data protection infrastructure. Our approach is defense-in-depth, incorporating multiple layers of protection:
🔒 Our Data Protection Architecture
5.1 Technical Safeguards
- Encryption: All data encrypted in transit (TLS 1.3+) and at rest (AES-256). Field-level encryption for sensitive data.
- Zero-Trust Architecture: Every access request is authenticated, authorized, and encrypted regardless of origin.
- Multi-Factor Authentication (MFA): Required for all employee and privileged user access.
- Network Segmentation: Micro-segmented networks isolate critical systems and data.
- AI-Powered Threat Detection: Machine learning models monitor for anomalies, threats, and unauthorized access patterns 24/7.
- Quantum-Resistant Cryptography: Forward-looking investment in post-quantum cryptographic algorithms.
5.2 Organizational Safeguards
- Data Protection Officer (DPO): Independent DPO reporting directly to the Board of Directors.
- Privacy by Design: Privacy impact assessments (PIAs) integrated into all product development lifecycles.
- Employee Training: Mandatory annual privacy and security training for all 340,000+ employees.
- Vendor Risk Management: Continuous third-party risk assessment and compliance monitoring.
- Incident Response: Dedicated Security Operations Center (SOC) with 24/7 monitoring and documented breach response procedures.
- Regular Audits: Internal and external audits including SOC 2 Type II, ISO 27001, and ISO 27701 certification.
06 Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you, including details of how it is processed.
Right to Rectification
Request correction of inaccurate or incomplete personal data we hold.
Right to Erasure
Request deletion of your personal data when it is no longer necessary or when you withdraw consent.
Right to Restrict Processing
Request that we limit the processing of your personal data under certain conditions.
Right to Data Portability
Receive your data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Right Regarding Automated Decisions
Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Right to Withdraw Consent
Withdraw previously given consent at any time, without affecting the lawfulness of prior processing.
How to Exercise Your Rights: Submit a request via our secure portal, email, or postal mail. We will respond within 30 days (or the timeframe required by applicable law). ID verification may be required to protect your data.
07 Cookies & Tracking Technologies
Our websites and applications use cookies and similar tracking technologies to enhance your experience, analyze usage, and deliver relevant content. You can manage your preferences at any time through our Cookie Preference Center.
| Category | Purpose | Duration | Consent |
|---|---|---|---|
| Strictly Necessary | Essential for website functionality, security, and load balancing | Session to 1 year | Required |
| Performance | Anonymous analytics to understand site usage and improve performance | Up to 2 years | Analytics |
| Functional | Remember user preferences, language settings, and accessibility options | Up to 1 year | Preference |
| Targeting | Deliver personalized content and measure marketing campaign effectiveness | Up to 13 months | Marketing |
08 Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable laws and regulations.
Retention Periods by Category
- Customer Data: Duration of business relationship + 7 years for contractual/financial obligations
- Employment Data: Duration of employment + statutory period (varies by jurisdiction)
- Financial Transaction Records: 7–10 years per regulatory requirements
- Healthcare Records: Per HIPAA and local health data regulations (typically 6–10 years)
- Marketing Communications: Until consent is withdrawn or 2 years of inactivity
- Website Analytics: Anonymized after 26 months (Google Analytics standard)
- Security Logs: 12 months for active monitoring, then aggregated and anonymized
Upon expiration of the retention period, personal data is securely deleted or permanently anonymized using industry-standard methods including cryptographic erasure and physical media destruction.
09 International Data Transfers
As a global conglomerate operating in 62 countries, we may transfer personal data across international borders. We ensure adequate protection for all international transfers through:
- EU Standard Contractual Clauses (SCCs): For transfers from the European Economic Area (EEA) to jurisdictions without an adequacy decision.
- Binding Corporate Rules (BCRs): Approved intra-group data transfer mechanisms covering all EEA-to-global transfers.
- Adequacy Decisions: Leveraging existing EU Commission adequacy findings where applicable.
- Supplementary Measures: Technical (encryption) and organizational measures to ensure equivalent protection levels.
- Transfer Impact Assessments (TIAs): Conducted for each transfer route to evaluate legal risks and implement mitigations.
Global Compliance: All international transfers undergo rigorous legal review. Data never leaves a jurisdiction without equivalent safeguards, regardless of the receiving subsidiary's location.
10 Children's Privacy
Aevum Zenth is committed to protecting the privacy of children. Our services are generally not directed to individuals under the age of 16 (or the age of consent in applicable jurisdictions).
We do not knowingly collect personal data from children without verified parental or guardian consent. If we discover that we have inadvertently collected personal data from a child, we will take steps to delete such data promptly. If you believe we may have collected information from a child, please contact our DPO immediately.
Our Media & Entertainment division (Zenth Media Group) maintains additional child-specific safeguards including COPPA compliance for online services and parental consent verification systems.
11 Policy Changes
We may update this Data Privacy & Protection Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations.
When we make material changes, we will notify you through one or more of the following methods:
- Publication on this webpage with an updated "Last Updated" date
- Direct email notification to registered users
- Conspicuous notice on our websites and applications
- Press release or official communication for significant changes
We encourage you to review this policy periodically. Your continued use of our services following the posting of changes constitutes acceptance of the revised policy.
12 Contact Us
If you have questions, concerns, or requests regarding this policy or our data practices, please reach out through any of the following channels:
🔒 Aevum Zenth Data Protection Office
Our dedicated team is available to assist with privacy inquiries, data subject requests, and security concerns.
Neo Geneva, NV 1202
Switzerland
If you are in the European Economic Area and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority. For US residents, you may contact the Federal Trade Commission (FTC) at ftc.gov.
Response Commitment: We aim to acknowledge all privacy inquiries within 5 business days and resolve data subject access requests within 30 days. Complex requests may be extended by up to 60 additional days with notification.