Company

Data Privacy

Data governance, handling standards, and privacy controls used in Rabinnson operations and engagements.

Effective date: August 15, 2026Last updated: August 15, 2026Contact: helpdesk@rabinnson.com

1. Data privacy principles

Rabinnson follows privacy-by-design principles across advisory delivery and internal operations.

  • Data minimization: collect only what is necessary for defined purposes.
  • Purpose limitation: avoid incompatible reuse without legal basis or consent.
  • Access control: restrict data to authorized personnel with legitimate business need.

2. Data classification and handling

Information is handled according to sensitivity, business criticality, and contractual obligations.

  • Data categories include public, internal, confidential, and client-restricted information.
  • High-sensitivity data receives additional controls for transfer, storage, and access logging.
  • Retention and disposal follow legal, contractual, and operational requirements.

3. Cross-border transfers and subprocessors

When data is processed by third parties or across regions, we apply contractual and control safeguards.

  • Subprocessors are selected based on security and compliance suitability.
  • Appropriate terms are used to govern processing responsibilities and restrictions.
  • International transfer mechanisms follow applicable legal frameworks.

4. Retention and deletion

Data is retained for the minimum period necessary and securely deleted when no longer required.

  • Retention periods vary by contract type, statutory requirement, and evidence obligations.
  • Deletion requests are reviewed against legal hold and compliance constraints.
  • Archived records are protected with appropriate safeguards and controlled access.

5. Incident response and breach handling

Potential privacy incidents are triaged, investigated, and addressed under defined response workflows.

  • Incidents are logged, severity-classified, and escalated based on impact.
  • Where required, affected stakeholders and authorities are notified within applicable timelines.
  • Corrective actions are tracked through closure with preventive control improvements.