GDPR Policy

Naviti Global Ventures Inc., GDPR Policy

Effective Date: December 29, 2025

Naviti Global Ventures Inc. (“Naviti”, “we”, “us”, “our”), a USA corporation, respects your privacy and strives to comply with the EU General Data Protection Regulation (GDPR) and applicable data protection laws. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data when you visit our website (navitiglobalventures.com), contact us, subscribe to communications, or engage with our services.

1. Information We Collect

We collect personal data necessary for our business operations, including:

Contact and Professional Information:

  • Name, email address, phone number
  • Company name, job title, LinkedIn profile
  • Investment interests and business objectives

Technical Information:

  • IP address, browser type and version
  • Operating system, pages visited, time spent
  • Cookie data and device identifiers

Communication Data:

  • Email correspondence content
  • Webinar registrations and attendance
  • Meeting notes and follow-up interactions

2. How We Collect Information

We obtain data through the following methods:

Direct Collection:

  • Website contact forms and newsletter signups
  • Email inquiries and partnership discussions
  • Event registrations and webinar attendance

Automated Collection:

  • Cookies and similar tracking technologies
  • Server logs capturing IP addresses and browsing behavior
  • Analytics tools monitoring site usage patterns

Third-Party Sources:

  • LinkedIn professional profiles (with consent)
  • Business directories and public records
  • Referral partners providing contact introductions

3. How We Use Your Information

Naviti processes personal data for legitimate business purposes:

Business Development:

  • Share relevant investment opportunities and market insights
  • Facilitate introductions to potential partners and investors
  • Manage investor relationship communications

Marketing and Communications:

  • Send newsletters, whitepapers, and event invitations
  • Personalize content based on professional interests
  • Analyze engagement to improve service delivery

Website Operations:

  • Ensure site functionality and security
  • Analyze usage patterns for performance optimization
  • Prevent fraud and unauthorized access

Legal Compliance:

  • Verify investor accreditation (KYC/AML)
  • Meet regulatory reporting requirements
  • Respond to lawful data subject requests

Legal Basis for Processing:

  • Legitimate interests in business development
  • Consent for marketing communications
  • Contractual necessity for service delivery
  • Legal obligation for compliance

4. Data Sharing and Disclosure

We share data only with trusted recipients under strict contractual protections:

Service Providers:

  • Email platforms (e.g., Mailchimp)
  • CRM systems (e.g., HubSpot)
  • Analytics providers (e.g., Google Analytics)
  • Cloud storage and security services

Business Partners:

  • With explicit consent for specific opportunities
  • Under data processing agreements (DPAs)
  • Only necessary data for legitimate purposes

Legal Requirements:

  • Government authorities with lawful requests
  • Law enforcement in compliance with regulations
  • Professional advisors (legal, accounting, tax)

We never sell personal data to third parties.

5. International Data Transfers

Naviti operates globally. Data transfers occur to:

United States (Primary Location):

  • Protected by Standard Contractual Clauses (SCCs)
  • EU-US Data Privacy Framework participant

Other Jurisdictions:

  • Singapore (adequacy decision)
  • United Kingdom (adequacy decision)
  • Transfers only with appropriate safeguards

All international transfers comply with GDPR Chapter V requirements.

6. Data Retention Periods

We retain data only as long as necessary:

Business Relationships:

  • Investor contacts: 7 years after last interaction
  • Partnership discussions: 5 years post-conversation

Marketing:

  • Newsletter subscribers: Until unsubscribed
  • Event attendees: 3 years post-event

Technical:

  • Analytics data: 26 months maximum
  • Security logs: 12 months

7. Your Legal Rights

GDPR grants you comprehensive data rights:

Right of Access: Receive confirmation of processing and data copy
Right to Rectification: Correct inaccurate or incomplete data
Right to Erasure: Delete data when no longer needed
Right to Restriction: Limit processing during disputes
Right to Data Portability: Receive data in structured format
Right to Object: Oppose processing based on legitimate interests
Right to Withdraw Consent: Revoke marketing consent anytime

8. Security Safeguards

Naviti implements industry-standard protections:

Technical Measures:

  • Data encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication for all accounts
  • Regular security audits and penetration testing

Organizational Controls:

  • Role-based access permissions
  • Employee data protection training
  • Incident response protocols

Third-Party Security:

  • Vendor security assessments
  • Regular DPA reviews
  • Breach notification within 72 hours

9. Cookies and Tracking Technologies

Essential Cookies: Enable core website functionality (always active)

Analytics Cookies: Google Analytics (optional, consent-based)

Marketing Cookies: LinkedIn tracking (opt-out available)

Cookie Management: Use browser settings or our cookie consent banner.

10. Children’s Privacy

Our services target business professionals. We do not knowingly collect data from children under 16. Parents/guardians may contact us to delete their data.

11. Policy Changes

We may update this policy. Continued use of the website constitutes acceptance.

DISCLAIMER: This provision of this policy is done in an effort to comply with GDPR Article 13/14 transparency requirements. For legal advice, consult qualified counsel. Naviti Global Ventures Inc. reserves the right to update per business needs while striving to maintain compliance.