IIF CAPITAL – COMPREHENSIVE PRIVACY NOTICE & DATA PROTECTION POLICY
Effective Date: July 11, 2026
Review Cycle: Annual
1. Introduction & Scope of Application
IIF Capital ("we", "us", "our", or the "Firm") is committed to protecting the privacy, confidentiality, and security of all Personal Information ("PI") and Sensitive Personal Information ("SPI") entrusted to us. This Comprehensive Privacy Notice outlines how we collect, store, use, disclose, and protect data across our global investment operations.
1.1 Covered Individuals
This Policy applies strictly to all natural persons whose data is processed by IIF Capital, including but not limited to:
-
Individual Investors: Prospective, current, and former investors who engage with our funds directly or through intermediaries.
-
Corporate Representatives: Employees, directors, officers, beneficial owners, and authorized signatories of corporate clients, institutional investors, and portfolio companies.
-
Vendors & Service Providers: Individual contractors, legal consultants, tax advisors, and employees of third-party vendors supplying services to the Firm.
-
Digital Visitors: Anyone interacting with our official website (www.iifcapital.com), client portals, proprietary analytics platforms, or official communication channels.
1.2 Legal Capacities under Global Laws
Depending on the jurisdiction and the specific structure of our business engagement, IIF Capital companies may act in the following capacities:
-
Data Controller (Business): When we determine the purposes and means of processing your personal data (e.g., standard investor onboarding, KYC, and direct client communications).
-
Data Processor (Service Provider): When we process data strictly on behalf of an institutional partner under a formalized corporate service agreement.
2. Taxonomy of Data Collected
We only collect data that is necessary for the execution of our investment mandates, regulatory compliance, and business optimization. We categorize this information as follows:
-
Identification & Demographic Data: Full legal name, aliases, gender, date of birth, place of birth, nationality, and marital status.
-
Government-Issued Identifiers: Passport numbers, driver’s licenses, national identity card numbers, social security numbers (SSN), and corporate/personal tax identification numbers (TIN).
-
Contact Infrastructure: Permanent residential address, registered business address, telephone numbers, and corporate/personal email addresses.
-
Financial & Wealth Profiling: Institutional bank account numbers, routing numbers, transaction histories, credit scores, audited wealth statements, source of funds documentation, and historical investment profiles.
-
Professional & Employment Background: Current job title, corporate affiliation, employment history, educational background, professional accreditations, and professional social media identifiers (e.g., LinkedIn URLs).
-
Technical & Digital Footprint: Internet Protocol (IP) addresses, unique device identifiers, browser types, language settings, access timestamps, system access logs, and tracking data derived from cookies or clear GIFs.
-
Electronic Monitoring Logs: To the extent permitted under local jurisdictions, we record and log electronic communications, including corporate emails, instantly archived messaging platforms, and virtual/telephonic meeting recordings.
-
Physical Security Logs: Closed-circuit television (CCTV) footage captured at our corporate offices, building badge entry timestamps, and visitor logbooks.
-
Sensitive Personal Information (SPI): Processed exclusively under strict regulatory mandates. This includes Politically Exposed Person (PEP) status, relevant criminal background checks required for anti-money laundering compliance, and critical dietary or accessibility accommodations for corporate events.
3. Granular Purposes and Legal Bases for Processing
We process your data strictly under lawful, predefined legal frameworks established by global data protection laws (such as the UK Data Protection Act, EU GDPR, and applicable U.S. frameworks):
+---------------------------------------------------------------------------------------+
| LAWFUL BASES |
+------------------------------------+--------------------------------------------------+
| 1. Performance of a Contract | Required to execute terms, agreements, or fund |
| | subscriptions. |
+------------------------------------+--------------------------------------------------+
| 2. Regulatory Obligations | Mandatory under global financial, AML, and tax |
| | compliance statutes. |
+------------------------------------+--------------------------------------------------+
| 3. Legitimate Firm Interests | Necessary for business improvement, security, and|
| | ongoing relationship management. |
+------------------------------------+--------------------------------------------------+
Detailed Processing Framework
A. Investor Onboarding & Risk Mitigation
-
Specific Activities: Executing background checks, verifying investor identities, performing Anti-Money Laundering (AML) and Counter-Terrorism Financing (CTF) screening, checking international sanction lists, and preventing corporate fraud.
-
Data Categories Used: Identification Data, Government Identifiers, Financial Data, SPI.
-
Legal Basis: Regulatory Obligation and Legitimate Interests (Ensuring the Firm does not process illicit funds or facilitate financial crime).
B. Investment Management & Service Execution
-
Specific Activities: Processing fund subscriptions, managing capital calls, distributing investment returns, facilitating commercial real estate conveyancing, and executing corporate M&A buyouts.
-
Data Categories Used: Identification Data, Financial Data, Contact Infrastructure, Professional Background.
-
Legal Basis: Performance of a Contract.
C. Corporate Communication & Relationship Management
-
Specific Activities: Issuing mandatory fund performance reports, notifying partners of changes to operational terms, responding to incoming queries, and providing technical portal support.
-
Data Categories Used: Contact Infrastructure, Technical Footprint, Professional Background.
-
Legal Basis: Performance of a Contract and Legitimate Interests (Maintaining high-quality client services).
D. Systems Security & Platform Integrity
-
Specific Activities: Monitoring server loads, troubleshooting database errors, preventing unauthorized system intrusions, maintaining network firewalls, and managing server data hosting.
-
Data Categories Used: Technical & Digital Footprint, Electronic Monitoring Logs.
-
Legal Basis: Legitimate Interests (Ensuring the uninterrupted continuity and security of the Firm's digital infrastructure).
E. Strategic Analytics (Non-Attributable Data)
-
Specific Activities: Centralizing data from multiple corporate systems into a secure data repository to conduct macroeconomic analysis, evaluate pipeline efficiency, and optimize market forecasting models.
-
Data Categories Used: Technical Footprint, Professional Background.
-
Legal Basis: Legitimate Interests (Identifying structural market trends without profiling specific individuals).
4. Data Sharing, Dissemination, and Third-Party Disclosures
IIF Capital does not trade, rent, or sell personal data to third parties for commercial gain. Data disclosures occur strictly to facilitate our fiduciary and regulatory obligations:
-
Affiliated Group Entities: Shared internally across regional branches of the IIF Capital network to streamline global administrative operations.
-
Appointed Professional Advisors: Disclosed to licensed third-party professionals acting on behalf of the Firm, including external legal counsels (e.g., CWJ), accounting and tax advisors (e.g., Perry's), institutional brokers, and corporate consultants.
-
Outsourced Service Providers: Trusted IT hosting providers, compliance screening vendors, payment gateways, and cloud data center providers operating under rigorous confidentiality agreements.
-
Statutory and Regulatory Authorities: Disclosed to government agencies, tax authorities (e.g., IRS, HMRC), financial market watchdogs (e.g., FCA, SEC), or competent courts when mandated by local or international law.
-
Corporate Restructuring: In the event of an active merger, asset acquisition, joint venture, or structural reorganization, data may be disclosed to prospective buyers, sellers, and their professional advisory teams.
5. Global Data Transfers & Cross-Border Governance
As an international asset management firm, IIF Capital operates across multiple geographic jurisdictions. Consequently, your data may be transferred to, stored in, or accessed from countries outside your place of residence (including the United States, the European Economic Area, the United Kingdom, and regional financial centers in Asia).
To guarantee that your data receives an equivalent level of protection regardless of location, we implement rigorous cross-border safeguards:
-
Standard Contractual Clauses (SCCs): Incorporating the European Commission and UK-approved standard clauses into agreements with international vendors and internal group entities.
-
Adequacy Decisions: Relying on recognized framework determinations where jurisdictions are certified as maintaining robust, equivalent data privacy structures.
-
Strict Technical Auditing: Conducting comprehensive security assessments on all international processing hubs to ensure compliance with our institutional data safety benchmarks.
6. Data Security Controls & Threat Mitigation
We implement an advanced, multi-layered defensive infrastructure to preserve the confidentiality, integrity, and availability of our data environments. Our controls include:
6.1 Technical Defense Layer
-
Advanced Encryption: Implementing industry-standard SSL/TLS protocols for data in transit and AES 256-bit encryption models for data at rest.
-
Network Segmentation: Separating critical investor financial databases from general corporate networks to prevent lateral threat progression.
-
Endpoint Protection: Deploying real-time endpoint detection and response (EDR) software across all corporate hardware.
6.2 Administrative & Physical Layer
-
Role-Based Access Control (RBAC): Restricting data access strictly to authorized personnel who require the information to perform their specific duties.
-
Continuous Threat Training: Conducting mandatory simulations and training for all staff regarding social engineering, phishing vectors, credential management, and password hygiene.
-
Physical Barriers: Securing on-premise hardware facilities using biometric authentication, commercial alarms, and continuous CCTV surveillance.
7. Data Retention Framework
IIF Capital retains personal data only for as long as necessary to fulfill the operational purposes detailed in this policy, or as mandated by statutory limitation timelines.
To determine appropriate retention schedules, we assess the following parameters:
-
The active duration of our corporate relationship with you or your organization.
-
Statutory retention mandates dictated by anti-money laundering, corporate tax, and financial services laws (typically ranging from 5 to 10 years post-relationship termination).
-
Applicable legal limitation periods within which disputes or regulatory investigations may be initiated.
Once these windows expire, all relevant data is permanently deleted or irreversibly anonymized.
8. Your Legal Rights & Request Mechanisms
Depending on your geographic location, you possess specific, legally enforceable rights regarding how we manage your personal information:
-
Right to Know & Access: The right to request formal confirmation that we are processing your data, alongside a comprehensive report detailing what data is stored and how it is used.
-
Right to Portability: The right to receive a copy of your personal data in a structured, machine-readable, and commonly used electronic format.
-
Right to Rectification: The right to demand the immediate correction of inaccurate, outdated, or incomplete personal data.
-
Right to Erasure ("Right to be Forgotten"): The right to request the total deletion of your records, provided there are no overriding regulatory retention mandates or active legal defenses requiring its preservation.
-
Right to Object or Restrict: The right to limit the scope of our processing under specific parameters, or object entirely to processing activities driven by legitimate firm interests.
-
Universal Opt-Out Signals: Where technically required by law, our systems are configured to recognize and respect automated browser-level privacy controls (e.g., Global Privacy Control).
How to Submit a Valid Request
To exercise any of your statutory rights, please contact our data privacy team at Contact Us
For security reasons, we will require you to verify your identity using multi-factor verification tools before your request can be processed. This protects your data from unauthorized third-party disclosure. Authorized agents submitting requests on your behalf must provide written power of attorney signed by you.
9. Audited Privacy Metrics
In the interest of regulatory transparency, IIF Capital publishes its historical compliance metrics regarding individual privacy requests below:
| Request Category | Total Requests Received | Complied (In Full or Part) | Requests Denied | Median Response Timeline |
| Access / Right to Know | 2 | 2 | 0 | 17.9 Days |
| Erasure / Deletion | 10 | 10 | 0 | 17.9 Days |
| Opt-Out (Sharing/Targeting) | 3 | 3 | 0 | 17.9 Days |
| Limit Sensitive PI Use | 0 | 0 | 0 | 0.0 Days |
10. Institutional Contact & Appeals
The Compliance and Privacy Department oversees the enforcement of this Data Protection Policy. If you have any questions regarding these provisions, wish to appeal a data request decision, or need to report a potential compliance concern, please reach out to us directly:
IIF Capital Group Attn: Chief Privacy & Compliance Officer
Official Intake Email: Compliance@iifcapital.com If you believe that your concerns have not been adequately resolved by our internal teams, you retain the legal right to file a formal complaint with the competent data protection authority or privacy ombudsman in your local jurisdiction.