πŸ”’ GDPR & CCPA Compliant

Data Protection & Privacy Policy

πŸ“… Effective: πŸ”„ Last Revised: December 15, 2025 🌐 Applies to: All Aevum Zenth Divisions & Subsidiaries

1. Scope & Applicability

This Data Protection & Privacy Policy governs how Aevum Zenth Conglomerate ("Aevum Zenth," "we," "our," or "us") collects, uses, processes, stores, and discloses personal data across all 400+ subsidiaries, divisions, and affiliated entities. This policy applies to all individuals interacting with our services, including employees, contractors, clients, suppliers, investors, and website visitors.

Where specific national or regional data protection laws impose additional requirements (e.g., GDPR, CCPA/CPRA, LGPD, PIPEDA), those regulations will take precedence where they exceed the protections outlined herein.

Important Note

By accessing our platforms, engaging with our services, or submitting personal information, you acknowledge that you have read and understood this policy. Continued use following any updates constitutes acceptance of the revised terms.

2. Data We Collect

We collect personal data only when necessary, proportionate, and transparent. Categories include:

  • Identity Data: Name, title, date of birth, gender, government IDs (where legally required)
  • Contact Data: Email, phone number, mailing address, IP address, social handles
  • Financial & Transactional Data: Payment details, billing information, credit ratings, transaction history
  • Technical & Usage Data: Browser type, OS, device identifiers, login timestamps, cookies, clickstream data
  • Sensitive/Special Category Data: Health records (Healthcare Division), biometric data (where consented), criminal records (background checks), genetic information
  • Employment & Contractor Data: HR records, performance metrics, security clearances, tax information

4. How We Use Your Data

Personal data is processed strictly for defined, explicit, and legitimate purposes:

  • Delivering, maintaining, and improving our products and services
  • Processing transactions, managing accounts, and issuing invoices
  • Verifying identity, preventing fraud, and ensuring regulatory compliance
  • Communicating service updates, security alerts, and policy changes
  • Conducting market research, analytics, and product development
  • Administering employment relationships and workplace safety
  • Responding to inquiries, support tickets, and partnership proposals

5. Sharing & Third Parties

We do not sell personal data. Sharing occurs only under strict contractual safeguards, Data Processing Agreements (DPAs), or legal requirement:

  • Subsidiaries & Affiliates: Cross-divisional operations require controlled data sharing for unified service delivery
  • Service Providers: Cloud hosting, payment processors, logistics partners, cybersecurity vendors, and HR platforms
  • Regulatory & Legal Authorities: When mandated by law, court order, or regulatory investigation
  • Business Transfers: In event of merger, acquisition, or restructuring, data transfers comply with contractual and regulatory obligations

6. International Transfers

As a global conglomerate operating in 62 countries, data may transfer across borders. All transfers comply with GDPR Chapter V, utilizing:

  • European Commission Standard Contractual Clauses (SCCs) 2021
  • Adequacy decisions where applicable
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Supplementary technical measures: end-to-end encryption, pseudonymization, access restrictions, and transfer impact assessments

7. Data Retention

Data is retained only as long as necessary for the purposes outlined herein, or as required by law:

  • Transactional/Client Data: 7 years post-relationship (tax & audit compliance)
  • Employment Records: Duration of employment + 6 years
  • Marketing/Consent-Based Data: Until withdrawal or 2 years of inactivity
  • Security & Log Data: 12 months (anonymized thereafter for threat modeling)
  • Legal Hold: Indefinite retention where litigation or regulatory investigation is pending

Upon expiry, data is securely deleted or irreversibly anonymized using industry-standard cryptographic erasure or k-anonymity protocols.

8. Security Measures

Aevum Zenth implements a defense-in-depth security architecture aligned with ISO 27001, NIST CSF, and GDPR Article 32:

  • AES-256 encryption at rest and TLS 1.3+ in transit
  • Zero-trust network architecture with multi-factor authentication (MFA)
  • Role-based access control (RBAC) and principle of least privilege
  • Continuous monitoring, SIEM integration, and automated threat response
  • Annual third-party penetration testing and vulnerability assessments
  • Employee data protection training and insider threat programs

In the event of a personal data breach, we will notify affected individuals and relevant supervisory authorities within 72 hours where required by law.

9. Your Rights (GDPR & Equivalent Frameworks)

Depending on your jurisdiction, you may exercise the following rights:

  • Right of Access: Request a copy of personal data we hold
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure ("Right to be Forgotten"): Request deletion where legally permissible
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive data in a structured, machine-readable format
  • Right to Object: Opt out of direct marketing or legitimate interest processing
  • Right to Withdraw Consent: Revoke previously granted consent at any time
  • Right to Lodge a Complaint: Contact your local data protection authority

Requests will be processed within 30 days. Extensions may apply for complex or numerous requests. No fee is charged for standard requests.

10. Automated Decision-Making & Profiling

Where we employ automated decision-making or profiling that significantly affects individuals (e.g., credit scoring, hiring algorithms, risk assessments), we ensure:

  • Transparency regarding logic, significance, and envisaged consequences
  • Opportunity for human review and meaningful intervention
  • Regular bias audits, fairness testing, and model validation
  • Compliance with GDPR Article 22 and equivalent AI regulations

11. Children's Data

Our services are not directed at individuals under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If we discover such data, it will be promptly deleted. Parents/guardians may contact our DPO for verification and removal requests.

12. Policy Updates

This policy is reviewed quarterly and updated as technology, regulations, or business operations evolve. Material changes will be communicated via email, platform notices, or website publication. The "Last Revised" date at the top indicates the current version.

πŸ“§ Data Protection Officer & Compliance Contact

For privacy inquiries, data subject requests, breach reporting, or DPA execution, please contact our centralized Privacy Office:

Dr. Elena Voss, Global DPO
/privacy-portal
Zenth Tower, Neo Geneva, Privacy Compliance Dept.