Data Privacy & GDPR Compliance
1. Scope & Applicability
This Data Privacy & GDPR Compliance Notice applies to all individuals interacting with Aevum Zenth Conglomerate ("we," "our," or "Aevum Zenth"), including visitors to our websites, users of our applications, clients, vendors, employees, contractors, and investors.
As a multidivisional enterprise operating across 62 countries and 400+ subsidiaries, we maintain a unified privacy governance framework that complies with the EU General Data Protection Regulation (GDPR), UK GDPR, CCPA/CPRA, LGPD, PIPL, and other applicable global data protection laws.
🌍 Global Standard: Where local regulations exceed GDPR requirements, we apply the stricter standard to ensure consistent protection for all data subjects.
2. Data Controller & Data Protection Officer
Aevum Zenth Conglomerate acts as the primary Data Controller for personal data processed in relation to corporate governance, investor relations, public websites, and cross-divisional operations. Specific business units may act as separate controllers or processors depending on the context of collection.
Our appointed Global Data Protection Officer (DPO) oversees compliance, audits, data subject requests, and regulatory liaison across all jurisdictions.
3. Information We Collect
We collect personal data only when necessary for legitimate business purposes, legal compliance, or with your explicit consent.
3.1 Directly Provided
- Identity & contact details (name, email, phone, postal address)
- Professional & corporate information (company, role, tax/VAT ID)
- Financial & billing data (payment methods, invoicing preferences)
- Communication records (emails, support tickets, meeting notes)
3.2 Automatically Collected
- Device & connection data (IP address, browser type, OS, hardware IDs)
- Usage analytics (page views, click patterns, session duration)
- Location data (approximate geolocation via IP, precise location only with consent)
- Log files & security telemetry
3.3 Third-Party Sources
- Credit reference & KYC/AML screening agencies
- Business registries & public databases
- Partner networks & referral platforms
4. Legal Basis & Purposes for Processing
Under Article 6 GDPR, we rely on the following lawful bases:
- Contractual Necessity: Fulfilling agreements, processing payments, delivering services, and managing client/vendor relationships.
- Legal Obligation: Tax compliance, AML/KYC, employment law, securities regulation, and court orders.
- Legitimate Interests: Fraud prevention, network security, business analytics, corporate communications, and subsidiary optimization.
- Consent: Marketing newsletters, cookies, precise location tracking, and non-essential profiling.
We conduct a Data Protection Impact Assessment (DPIA) for all high-risk processing activities, particularly those involving AI/ML, biometrics, or large-scale employee monitoring.
5. Your Data Subject Rights
Depending on your jurisdiction, you may exercise the following rights:
- Right of Access: Request a copy of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): Request deletion where no legal basis for retention exists.
- Right to Restrict Processing: Limit how we use your data during disputes or verification.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Opt out of direct marketing or legitimate interest processing.
- Right to Withdraw Consent: At any time, without affecting prior lawful processing.
- Right to Lodge a Complaint: With your local supervisory authority (e.g., ICO, CNIL, BfDI).
Verification Required: To protect your privacy, we may request additional verification before fulfilling a Data Subject Request (DSR). Identity verification does not delay your right to a response within the statutory period (typically 30 days).
6. Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes outlined in this notice, comply with legal obligations, resolve disputes, and enforce agreements.
- Client/Contract Data: Retained for the duration of the contract + 7 years (statutory limitation period).
- Financial/Tax Records: 7–10 years depending on jurisdiction.
- Marketing Consent: Until withdrawal or after 24 months of inactivity.
- Security Logs: 12 months (anonymized thereafter).
Upon expiry, data is securely deleted or irreversibly anonymized using industry-standard cryptographic shredding or k-anonymity techniques.
7. Security & Data Breach Protocol
Aevum Zenth implements a zero-trust security architecture across all divisions. Safeguards include:
- AES-256 encryption for data at rest and TLS 1.3 for data in transit.
- Strict role-based access control (RBAC) and multi-factor authentication (MFA).
- Continuous threat monitoring, penetration testing, and ISO 27001 / SOC 2 Type II certification.
- Regular employee privacy training and vendor security audits.
In the event of a personal data breach likely to result in risk to individuals, we will notify the relevant supervisory authority within 72 hours and affected data subjects without undue delay, as required by Article 33–34 GDPR.
8. International Data Transfers
Due to our global operations, personal data may be transferred to and processed in countries outside the European Economic Area (EEA) and the UK.
For all cross-border transfers, we ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs) (Commission Implementing Decision 2021/914)
- UK International Data Transfer Agreements
- Binding Corporate Rules (BCRs) for intra-group transfers
- Transfer Impact Assessments (TIAs) conducted prior to each transfer
We do not transfer data to jurisdictions lacking adequate safeguards without implementing supplementary technical, contractual, and organizational measures.
9. Third-Party Sharing & Subsidiary Access
We may share personal data with:
- Aevum Zenth Subsidiaries: For unified service delivery, compliance, and cross-divisional analytics under strict data minimization principles.
- Service Providers: Cloud infrastructure, payment processors, CRM platforms, and legal/audit firms (all bound by DPIAs and strict processing agreements).
- Regulatory & Law Enforcement: When required by law, court order, or to protect vital interests.
- Business Transfers: In connection with mergers, acquisitions, or asset sales (data subjects will be notified and may exercise opt-out rights where applicable).
10. Cookies & Tracking Technologies
We use cookies and similar technologies to ensure website functionality, analyze traffic, and personalize content.
- Essential: Required for security, authentication, and load balancing. No consent required.
- Analytics: Aggregate usage statistics to improve UX. Processed under legitimate interest.
- Marketing/Targeting: Delivered via consent-only mechanisms. You may withdraw consent at any time via our Cookie Preference Center.
Detailed information on cookie vendors, retention periods, and opt-out mechanisms is available in our Cookie Policy.
11. Children's Privacy
Aevum Zenth does not intentionally collect personal data from individuals under the age of 16 (or the applicable age of consent in your jurisdiction). If we discover we have collected data from a minor without parental consent, we will take immediate steps to delete it. Parents or guardians who believe this has occurred may contact our DPO office for verification and removal.
12. Updates to This Notice & Contact
We may update this privacy notice to reflect changes in technology, business practices, or legal requirements. Material changes will be communicated via email or prominent website notice, with an updated effective date.
For questions, complaints, or to exercise your rights:
Postal Address
Aevum Zenth Conglomerate
Attn: Global Data Protection Officer
Zenth Tower, Neo Geneva, CH-1201
© 2026 Aevum Zenth Conglomerate. All rights reserved. This document is provided for informational purposes and does not constitute legal advice.