Privacy Policy
About this Policy
At Xenith IG, we are committed to respecting your privacy, and recognise the need for the appropriate protection and management of any Personal Data that you may provide us. This Privacy Policy (“Policy”) applies to all persons, entities and group companies that are working for us or on our behalf in any capacity, including directors, officers and employees of all levels, agency workers, interns, agents, contractors, suppliers, consultants, third party representatives, business partners, sponsors or any other person associated with us, wherever located (“you”).
This Policy explains our practices with respect to the Personal Data we collect and process in connection with your relationship with us, including as a director, officer, employee, job applicant, agency worker, intern, agent, contractor, supplier, consultant, third party representative, business partner, sponsor or as a user of our website or social media page.
Your Personal Data
We may collect Personal Data from you and about you from a variety of sources. This includes, but is not limited to:
The Personal Data we collect from you and about you includes, but is not limited to:
In addition, we use “cookies” on our Website to track website visitor ship, usage and experience, which are small data files containing information you have supplied yourself, which will assist us in improving your experience and navigation in the Website, and may enable features in the Website to fully function. If you do not wish to receive any cookies, you may set your browser to disable it.
We strive to only collect Personal Data that is adequate, relevant, and limited to achieve the purpose(s) for which it was collected. In addition, we strive to keep all Personal Data accurate, complete, and reliable for its intended purpose, and we only retain your Personal Data for as long as necessary to achieve the purpose(s) for which it was collected.
If you do not provide your Personal Data (including by disabling cookies), you may do so but we may not be able to: (a) communicate with you; (b) process your requests; (c) provide to you the services that you may require, or (d) enable all features in the Website to function.
How we use your Personal Data
We may use and process your Personal Data in accordance with applicable law for different purposes, including:
Storage and disclosure of your Personal Data
The Personal Data we have collected from you may be recorded and stored in digital or electronic format and physical copies. Digital and electronic copies of your Personal Data a restored in our servers, while physical copies are stored in secured cabinets within the offices of our operations department and/or relevant department. Access to information is limited to32026.1our operations and relevant department personnel, to the extent that they require your Personal Data for the relevant purposes.
Generally, we may disclose your Personal Data to third parties as follows:
We will not sell your Personal Data to any third parties, whether for monetary or other valuable consideration, and have never done so in the past. If we disclose your Personal Data as outlined above, we do so to facilitate the relevant services or our employment relationship with you and not for direct remuneration. Where we engage any service provider that will require access to and use of Personal Data to provide certain services for and under our instructions, we take reasonable steps to ensure such service provider complies with applicable data protection and privacy laws.
We, however, reserve the right to disclose your Personal Data if required to do so by law, in the good faith belief that such action is reasonably necessary to comply with applicable law, legal process, or to protect the rights, property, or safety of Xenith IG, its employees, customers, or the public.
Cross-border transfer of your Personal Data
Considering the global reach of our business, we may transfer your Personal Data between our affiliated companies in different regions, including locations where the data privacy legislation may differ from that in your country or jurisdiction. In addition, we may transfer your Personal Data to certain other third parties, as outlined in paragraph 4 above, to a region where the data privacy legislation may differ from that in your country or jurisdiction.
However, in transferring your Personal Data outside the country, we will comply with our legal and regulatory obligations in relation to your Personal Data, including having a lawful basis for transferring your Personal Data. We shall implement safeguards required under applicable laws and regulations when transferring your Personal Data, including measures to ensure that your Personal Data is protected to an equivalent level of protection to the laws of your country or jurisdiction where necessary.
Legal bases for processing your Personal Data
We process your Personal Data for, or based on, one or more legal bases as set out under applicable laws, including:
How we protect your Personal Data
We employ reasonable and appropriate physical, technical, and organisational safeguards designed to promote the security of our systems and protect the confidentiality, integrity, availability, and resilience of your Personal Data. These safeguards include: (i) the encryption of personal information where we deem appropriate; (ii) the deployment of technical safeguards; (iii) taking steps to ensure Personal Data is backed up and remains available in the event of a security incident; and (iv) periodic testing, assessment and evaluation of the effectiveness of our safeguards.
However, no method of safeguarding information is completely secure. While we use measures designed to protect your Personal Data, we, unfortunately, cannot guarantee that our safeguards will be effective or sufficient. In the event of a data breach that is likely to result in significant harm to individuals or is of significant scale, we will: (a) notify the relevant supervisory authority upon becoming aware of the breach; and (b) notify affected individuals as soon as practicable. We will also document all data breaches, including those that do not require notification, and take prompt steps to contain and remediate the breach. In addition, you should be aware that internet data transmission is not always secure, and we cannot warrant that the information you transmit to us is or will be secure.
How long we retain your Personal Data
We retain your Personal Data for only as long as necessary to carry out the processing activities described in this Policy. This includes but is not limited to: (i) provide services to you or to the business with which you are associated; (ii) enter into or perform contracts with you or with the business with which you are associated; (iii) comply with applicable laws, regulations, rules, and requests of relevant law enforcement and/or other governmental agencies; and (iv) protect our rights, property, or safety, and the rights, property, and safety of our customers, users, and other third parties.
Your rights
Depending on applicable laws, you may be entitled to a variety of legal rights regarding the collection and processing of your Personal Data. These rights may include:
You may exercise these rights, to the extent they apply to you, by contacting us as outlined in the “Contact us” section in paragraph 11 below. We will endeavour to respond to a valid request relating to your rights within one month of receipt, or within three months where a request is complex or challenging.
Changes to this Policy
We reserve the right to change the terms of this Policy at any time. If we do make changes, though, we will take steps to indicate that the Policy has been updated on our website. Where required by applicable law, material changes to this Policy will be communicated to affected individuals directly, such as by email, prior to taking effect.
Contact us
If you have any query or complaint about this Policy, or would like to submit a request regarding your Personal Data or exercise your rights, you may at any time contact our designated Data Protection Officer (“DPO”), who is a member of the Legal and Compliance Department, at legal@xenithig.com.