XYZ SOVEREIGNTY HOLDINGS B.V. (I.O.)
INFORMATION SECURITY / DATA PROTECTION
EUROPEAN PRIVACY STANDARD
PRIVACY / DATA PROTECTION INFORMATION STEWARDSHIP

YOUR DATA IS CAPITAL.

We intend to protect information about our investors with the same discipline with which we protect the capital they entrust to us. Collect what is necessary. Protect it aggressively. Retain it only as long as there is a legitimate reason to do so.

PRINCIPLE DATA MINIMISATION CONTROL ACCESS / ENCRYPTION / RETENTION RESPONSE DELETION REQUESTS / MAXIMUM SPEED
01 THE PRINCIPLE

An investor should not have to surrender their privacy merely because they choose to invest.

XYZ Sovereignty intends to operate on a strict data-minimisation principle. Information should be collected because there is a legitimate reason to collect it, not because modern systems make collecting everything convenient.

Investor information required for identification, due diligence, transaction processing, legal reporting or regulatory compliance will be handled through controlled systems and restricted access.

Information that no longer has a legitimate legal, regulatory or operational purpose should not remain in our systems merely because nobody bothered to remove it.

02 DATA ARCHITECTURE
01

MINIMISE

Collect only information required for a defined purpose.

02

PROTECT

Restrict access and apply appropriate technical and organisational safeguards.

03

SEPARATE

Keep investor identity separated from operational project information wherever legally and technically possible.

04

DELETE

Remove personal information when there is no continuing lawful reason to retain it.

05

DISCLOSE ONLY WHEN NECESSARY

Information is not distributed merely because another participant in the enterprise would find it useful.

03 IDENTITY SEPARATION

KNOW THE INVESTOR. PROTECT THE IDENTITY.

Financial integrity requires knowing who participates in the capital structure. Privacy requires not exposing that information unnecessarily.

XYZ therefore intends to maintain a deliberate separation between investor due-diligence information and the operational teams responsible for executing projects.

As a general architectural principle, African operating entities and project personnel should not receive investor identity information simply because capital has ultimately been deployed into an African project.

Disclosure may occur where required by applicable law, regulation, court order, financial institution, tax authority, insurer, auditor or other legitimate legal obligation.

IDENTITY



OPERATIONS
FIG. 03 INFORMATION SEGMENTATION
04 ERASURE

DELETE WITHOUT DELAY.

01

REQUEST

Investors and other individuals may submit a request concerning their personal information and applicable privacy rights.

02

VERIFY

Where necessary, identity may be verified before personal information is disclosed or deleted.

03

REVIEW

We determine whether any information is subject to a continuing legal, regulatory, contractual or legitimate business retention requirement.

04

ERASE

Where deletion is legally permissible, the information should be removed from active systems without unnecessary delay.

05

DOCUMENT

Where information cannot be deleted because a legal or regulatory retention obligation applies, that restriction will be respected and the information retained only for the required period.

05 THE EXCEPTION
06 SECURITY

Privacy is not a paragraph at the bottom of a website. It is an architectural requirement.

SECURITY 01

ACCESS CONTROL

Access should be limited according to legitimate role, purpose and operational necessity.

SECURITY 02

SECURE TRANSFER

Sensitive information should move through appropriately protected communication and data-transfer systems.

SECURITY 03

MINIMAL EXPOSURE

Information should not be copied, exported or distributed simply because a system makes it possible.

07 CURRENT STATUS

We protect the person behind the capital with the same discipline we apply to the capital itself.

INFORMATION STEWARDSHIP / HUMAN DIGNITY