GDPR Compliance & Data Privacy Policy

Effective: January 15, 2026 Last Updated: January 15, 2026

1. Overview & Scope

Aevum Zenth Conglomerate ("Aevum Zenth," "we," "our," or "us") is committed to protecting your personal data and respecting your privacy rights in full compliance with the European Union's General Data Protection Regulation (GDPR), UK GDPR, and applicable national data protection laws.

This policy applies to all personal data collected, processed, or stored through our websites, mobile applications, subsidiary platforms, customer portals, and related digital services accessible to residents of the European Economic Area (EEA), United Kingdom, Switzerland, and other jurisdictions with equivalent data protection standards.

Scope Note

This policy covers data subjects including customers, partners, employees, applicants, and website visitors. Where specific subsidiary operations collect data, they will reference this central policy alongside division-specific addenda.

2. Data Controller

For the purposes of the GDPR, the data controller responsible for your personal information is:

Aevum Zenth Conglomerate AG

Zenth Tower, Neo Geneva District

Registered in Switzerland &/or EU Member State (as applicable)

Email: privacy@aevumzenth.com

Where a specific division or subsidiary acts as an independent controller for particular processing activities, we will clearly identify that entity and its contact details at the point of data collection.

3. Data We Collect

We only collect personal data that is necessary for the purposes outlined below. Categories of data may include:

  • Identity Data: Name, username, title, date of birth, gender.
  • Contact Data: Billing address, delivery address, email address, telephone numbers.
  • Technical Data: IP address, browser type, device identifiers, login data, time zone, and operating system.
  • Transaction Data: Payment information, purchase history, service subscriptions, contract details.
  • Usage Data: Information about how you interact with our platforms, including clickstream data, page response times, and download errors.
  • Profile & Preference Data: Account settings, communication preferences, feedback, survey responses.
  • Special Category Data: Processed only with explicit consent or where strictly required by law (e.g., health data for specific division services).

We do not sell your personal data to third parties. Any sharing occurs strictly for operational, legal, or contractual purposes as detailed in Section 5.

5. Data Sharing & Disclosures

We may share your personal data with the following categories of recipients, all bound by strict data protection agreements:

  • Internal Divisions: Subsidiaries and operational units within the Aevum Zenth ecosystem for service delivery and account management.
  • Service Providers: Cloud infrastructure, payment processors, customer support platforms, and analytics providers acting as processors.
  • Professional Advisors: Legal counsel, auditors, insurers, and corporate advisors.
  • Regulatory & Government Authorities: Where required by law, court order, or regulatory investigation.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, data may be transferred to the acquiring entity under equivalent privacy safeguards.
Third-Party Links

Our platforms may contain links to external websites. We are not responsible for the privacy practices of third-party sites. We encourage you to review their policies before providing personal information.

6. International Data Transfers

Due to our global operations, your data may be transferred to and processed in countries outside the EEA and UK, including the United States, Switzerland, Singapore, and Japan. These jurisdictions may not provide equivalent data protection levels.

For all cross-border transfers, we implement appropriate safeguards as required by GDPR Article 46, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) for intra-group transfers
  • Transfer Impact Assessments (TIAs) and supplementary technical measures (encryption, pseudonymization)
  • Reliance on adequacy decisions where applicable

You can request a copy of our SCCs or BCR documentation by contacting our Data Protection Officer (Section 11).

7. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including meeting legal, regulatory, accounting, and reporting requirements.

Retention periods are determined by:

  • Active Relationships: Duration of contract/service plus statutory limitation periods (typically 3-7 years post-termination).
  • Marketing: Until consent is withdrawn or where legitimate interest no longer applies (periodic re-verification applies).
  • Legal/Regulatory: Up to 10 years for financial, tax, and compliance records.
  • Archival: Anonymized or aggregated data may be retained indefinitely for research, statistical, or historical purposes.

Upon expiration, data is securely deleted or irreversibly anonymized using industry-standard cryptographic methods.

8. Your Data Rights

Under the GDPR, you have the following rights regarding your personal data. These rights are not absolute and may be subject to legal exceptions.

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your data where no lawful basis retains it.

Right to Restriction

Limit how we process your data under specific circumstances.

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or direct marketing.

Automated Decisions

Not be subject to solely automated decision-making with legal effects.

Withdraw Consent

Revoke consent at any time where processing relies on it.

To exercise any of these rights, please contact our DPO (Section 11). We will respond within one month, extendable by two months for complex requests. No fee applies unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with a supervisory authority in your member state.

9. Cookies & Tracking Technologies

Our platforms use cookies, web beacons, and similar technologies to ensure functionality, analyze usage, and personalize content. We categorize them as follows:

  • Strictly Necessary: Required for authentication, security, and core functionality. Always active.
  • Analytics & Performance: Help us understand traffic and optimize user experience (aggregated, anonymized).
  • Functional: Remember preferences (language, region, display settings).
  • Marketing & Targeting: Used for personalized advertising and campaign measurement. Require explicit consent.

You can manage your cookie preferences through our Cookie Consent Manager, available via the banner on first visit or in your account settings. Browser settings also allow you to block or delete cookies, though this may impact functionality.

10. Security Measures

Aevum Zenth implements industry-leading technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. Safeguards include:

  • AES-256 encryption for data at rest and TLS 1.3+ for data in transit
  • Role-based access controls, multi-factor authentication, and zero-trust architecture
  • Regular penetration testing, vulnerability assessments, and ISO 27001/SOC 2 Type II audits
  • Strict data minimization, pseudonymization, and secure backup protocols
  • Employee privacy training and strict confidentiality agreements

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected data subjects without undue delay, as required by Article 33-34.

11. Data Protection Officer (DPO) & Contact

We have appointed a Data Protection Officer to oversee compliance, handle data subject requests, and serve as the primary point of contact for privacy matters.

Global Privacy Office

Address: Zenth Tower, Neo Geneva, Privacy Compliance Floor 4
Phone: +41 (0) 22 324 8900 (Mon-Fri, 09:00-17:00 CET)

For jurisdiction-specific inquiries, your local supervisory authority includes the Irish Data Protection Commission (lead EU), Information Commissioner's Office (UK), or your national regulatory body.

12. Updates & Effective Date

This policy was last updated on January 15, 2026. We may revise this policy periodically to reflect changes in legislation, our business practices, or technological developments.

When material changes occur, we will notify you via email, platform notification, or prominent website banner. Continued use of our services following such updates constitutes acceptance of the revised policy.

Legal Standing

This GDPR policy forms part of the Terms of Service for Aevum Zenth digital platforms. Where conflicts arise between division-specific notices and this central policy, this document prevails unless explicitly overridden by applicable national law.