Contact Us
Company

Data Privacy

Data governance, handling standards, and privacy controls used in Rabinnson operations and engagements.

Policy details

Read by section

Use quick links to jump between sections. Expand each section for full details.

1. Data privacy principles

Rabinnson follows privacy-by-design principles across advisory delivery and internal operations.

  • Data minimization: collect only what is necessary for defined purposes.
  • Purpose limitation: avoid incompatible reuse without legal basis or consent.
  • Access control: restrict data to authorized personnel with legitimate business need.
2. Data classification and handling

Information is handled according to sensitivity, business criticality, and contractual obligations.

  • Data categories include public, internal, confidential, and client-restricted information.
  • High-sensitivity data receives additional controls for transfer, storage, and access logging.
  • Retention and disposal follow legal, contractual, and operational requirements.
3. Cross-border transfers and subprocessors

When data is processed by third parties or across regions, we apply contractual and control safeguards.

  • Subprocessors are selected based on security and compliance suitability.
  • Appropriate terms are used to govern processing responsibilities and restrictions.
  • International transfer mechanisms follow applicable legal frameworks.
4. Retention and deletion

Data is retained for the minimum period necessary and securely deleted when no longer required.

  • Retention periods vary by contract type, statutory requirement, and evidence obligations.
  • Deletion requests are reviewed against legal hold and compliance constraints.
  • Archived records are protected with appropriate safeguards and controlled access.
5. Incident response and breach handling

Potential privacy incidents are triaged, investigated, and addressed under defined response workflows.

  • Incidents are logged, severity-classified, and escalated based on impact.
  • Where required, affected stakeholders and authorities are notified within applicable timelines.
  • Corrective actions are tracked through closure with preventive control improvements.