CORPORATE GOVERNANCE
PRIVACY & DATA SECURITY POLICY
LINDEN HOF ADVISORY PRACTICE | DATA PROTECTION FRAMEWORK
Document ID: LH-GOV-DAT-2026-V6 | Classification: Confidentiality / Governance
Effective Date: January 2026 | Review Cycle: Annual | Owner: Data Protection Desk
1.0 DATA CONFIDENTIALITY & ARCHITECTURE
-
1.1 Institutional Commitment: Linden Hof operates in high-stakes capital environments involving proprietary financial models, confidential data rooms, and strategic infrastructure designs.
-
1.2 Security Standard: All transactional and operational data is treated with absolute confidentiality under bank-grade, ISO 27001-aligned information security protocols.
2.0 SCOPE OF TRANSACTIONAL DATA PROCESSED
-
2.1 Virtual Data Room (VDR) Assets: During pre-close forensics or Lender's Technical Due Diligence (TDD), the firm processes proprietary PVSYST files, DIgSILENT grid simulations, financial models, single-line diagrams (SLDs), and EPC contracts provided through secure Virtual Data Rooms.
-
2.2 Institutional Inquiries: Information submitted through terminal forms (such as corporate credentials, asset capacities, and transaction timelines) is processed strictly for transaction scoping and direct institutional communication.
-
2.3 Aggregated Telemetry: Standard web analytics are processed in an anonymized, aggregated format solely to maintain terminal performance and platform security.
3.0 DATA ISOLATION & STATUTORY COMPLIANCE
-
3.1 Zero Commercialization: Client data, model files, and advisory outputs are never sold, leased, commercialized, or shared with any third party, equipment vendor, or market participant.
-
3.2 Information Firewalls: Project documentation is strictly firewalled, restricting access exclusively to the principal engineers and legal-technical advisors assigned directly to the active mandate.
-
3.3 Statutory Alignment: Data processing complies strictly with international and regional data privacy legislation, including the EU GDPR, South Africa’s POPIA, Kenya’s Data Protection Act, Nigeria’s NDPA, and DFI information security standards.
4.0 DATA SUBJECT RIGHTS & BREACH PROTOCOL
-
4.1 Rights Enforcement: Authorized client representatives maintain full statutory rights to access, review, rectify, or request the secure erasure of their personal transactional credentials.
-
4.2 Breach SLA: In the event of a confirmed information security breach affecting client telemetry, Linden Hof enforces a mandatory 72-hour formal notification SLA to impacted client data officers.
5.0 DATA RETENTION & SECURE PURGING
-
5.1 Post-Mandate Disposal: Native files and data room exports are either encrypted for archived legal reliance periods or securely purged in accordance with institutional retention schedules upon contract closure.
AUTHORITY: LINDEN HOF INFORMATION SECURITY OFFICER (CISO)
ROUTING: SECURE ADVISORY TERMINAL
NOTICE: VIRTUAL DATA ROOMS ARE MONITORED AND AUDITED UNDER STRICT NDAS.
