MINIMISE
Collect only information required for a defined purpose.
We intend to protect information about our investors with the same discipline with which we protect the capital they entrust to us. Collect what is necessary. Protect it aggressively. Retain it only as long as there is a legitimate reason to do so.
An investor should not have to surrender their privacy merely because they choose to invest.
XYZ Sovereignty intends to operate on a strict data-minimisation principle. Information should be collected because there is a legitimate reason to collect it, not because modern systems make collecting everything convenient.
Investor information required for identification, due diligence, transaction processing, legal reporting or regulatory compliance will be handled through controlled systems and restricted access.
Information that no longer has a legitimate legal, regulatory or operational purpose should not remain in our systems merely because nobody bothered to remove it.
Collect only information required for a defined purpose.
Restrict access and apply appropriate technical and organisational safeguards.
Keep investor identity separated from operational project information wherever legally and technically possible.
Remove personal information when there is no continuing lawful reason to retain it.
Information is not distributed merely because another participant in the enterprise would find it useful.
Financial integrity requires knowing who participates in the capital structure. Privacy requires not exposing that information unnecessarily.
XYZ therefore intends to maintain a deliberate separation between investor due-diligence information and the operational teams responsible for executing projects.
As a general architectural principle, African operating entities and project personnel should not receive investor identity information simply because capital has ultimately been deployed into an African project.
Disclosure may occur where required by applicable law, regulation, court order, financial institution, tax authority, insurer, auditor or other legitimate legal obligation.
Investors and other individuals may submit a request concerning their personal information and applicable privacy rights.
Where necessary, identity may be verified before personal information is disclosed or deleted.
We determine whether any information is subject to a continuing legal, regulatory, contractual or legitimate business retention requirement.
Where deletion is legally permissible, the information should be removed from active systems without unnecessary delay.
Where information cannot be deleted because a legal or regulatory retention obligation applies, that restriction will be respected and the information retained only for the required period.
A deletion request does not override legal or regulatory obligations. Certain financial, accounting, tax, anti-money laundering, counter-terrorist financing, corporate or dispute-related records may have to be retained for a prescribed period.
Where such an obligation applies, XYZ will retain only what is required, restrict access appropriately and delete the information when the lawful retention period expires.
The existence of a legal retention requirement is therefore an exception to our normal preference for rapid erasure — not a reason to retain information indefinitely.
Privacy is not a paragraph at the bottom of a website. It is an architectural requirement.
Access should be limited according to legitimate role, purpose and operational necessity.
Sensitive information should move through appropriately protected communication and data-transfer systems.
Information should not be copied, exported or distributed simply because a system makes it possible.
XYZ Sovereignty Holdings B.V. is currently in its structural formation phase. The principles on this page describe the privacy and information-security environment the enterprise intends to implement.
Specific technical safeguards, processors, hosting providers, retention schedules, contractual arrangements and responsible privacy contacts will be documented as the relevant systems become operational.
The final privacy notice and data processing documentation will govern the actual processing of personal information once the relevant operations commence.
We protect the person behind the capital with the same discipline we apply to the capital itself.
INFORMATION STEWARDSHIP / HUMAN DIGNITY