Datazoic Large

Data Privacy Framework

Version 1.0 · Last updated: 06 Oct 2026

1. Our commitment to the Data Privacy Framework

Datazoic Inc (“Datazoic”, “we”, “us”, or “our”) complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. Datazoic has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (the “DPF Principles”) with regard to the processing of personal data received from the European Union and the United Kingdom (and Gibraltar) in reliance on the EU-U.S. DPF and the UK Extension.

If there is any conflict between the terms in this policy and the DPF Principles, the DPF Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

Datazoic is responsible for the processing of personal data it receives under the EU-U.S. DPF and the UK Extension and subsequently transfers to a third party acting as an agent on its behalf. Datazoic complies with the DPF Principles for all onward transfers of personal data from the EU and the UK, including the onward transfer liability provisions.

2. Scope and personal data we process

This policy applies to personal data Datazoic receives under the EU-U.S. DPF and the UK Extension. Datazoic obtains this personal data indirectly from a UK-based data provider, a third party UK-provider of holdings/ shareholding data, rather than directly from the individuals concerned.

We process the following categories of personal data relating to individuals connected with holdings in UK-listed companies (including investment managers, beneficial owners at either fund or individual level, and, where applicable, individual fund managers):

  • name and an internal name identifier;
  • city and country;
  • investor type; and
  • where applicable, an associated entity identifier and shareholding information.

We do not collect contact details (such as postal address, email address, telephone number), financial account data, or special-category (sensitive) personal data through this data.

3. Purposes for which we use personal data

We use this personal data to produce holdings analytics, perspectives and metrics that we provide to our clients

We process personal data only for the purposes described in this policy, or for a purpose that is compatible with those purposes, consistent with the Purpose Limitation and Data Integrity requirements of the DPF Principles.

4. Notice

Consistent with the Notice Principle, this policy informs individuals about: the types of personal data we process; the source of that data; the purposes for which we process it; the types of third parties to which we may disclose it; the right of individuals to access their personal data; the choices we offer for limiting use and disclosure; how individuals may contact us; and the independent dispute resolution body that addresses complaints. Because we obtain personal data indirectly, we provide this notice by making this policy publicly available.

5. Choice

Consistent with the Choice Principle, individuals may opt out of (i) the disclosure of their personal data to a third party, or (ii) the use of their personal data for a purpose materially different from the purpose for which it was originally collected or subsequently authorised. To exercise choice, individuals may contact us using the details in Section 11.

We do not process special-category (sensitive) data through this data; accordingly, the requirement to obtain affirmative express (opt-in) consent for sensitive data does not apply.

6. Accountability for onward transfer

Where we transfer personal data to third parties acting as our agents (for example, cloud hosting and IT service providers), we do so consistent with the Accountability for Onward Transfer Principle. We enter into contracts with such third parties requiring them to provide the same level of protection as the DPF Principles and to process the personal data only for limited and specified purposes consistent with the consent provided by the individual.

Our third-party service providers may include: Azure Cloud hosting and Sendgrid – mail relay for publishing bulk email

In the context of an onward transfer, Datazoic remains responsible and liable under the DPF Principles if its agent processes such personal data in a manner inconsistent with the DPF Principles, unless Datazoic proves that it is not responsible for the event giving rise to the damage.

7. Security

Consistent with the Security Principle, we take reasonable and appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, disclosure, alteration and destruction, considering the risks involved in the processing and the nature of the personal data.

8. Data integrity and purpose limitation

Consistent with the Data Integrity and Purpose Limitation Principle, we limit the personal data we process to that which is relevant for the purposes described in this policy. We take reasonable steps to ensure the personal data is reliable for its intended use, accurate, complete and current, and we retain it only for as long as it serves the purposes for which it was collected, or as otherwise permitted under the DPF Principles.

9. Access, correction and deletion

Consistent with the Access Principle, individuals have the right to access the personal data we hold about them, and to correct, amend, or delete that data where it is inaccurate or has been processed in violation of the DPF Principles. To make such a request, please contact us using the details in Section 11. We may take reasonable steps to verify the identity of the individual making the request before responding. Because we obtain personal data indirectly from a source, some correction requests may also be directed to that source.

10. Recourse, enforcement and liability

In compliance with the DPF Principles, Datazoic commits to resolve complaints about our collection or use of your personal data transferred in reliance on the EU-U.S. DPF and the UK Extension. Individuals with inquiries or complaints should first contact Datazoic using the details in Section 11.

If a privacy complaint or dispute relating to Personal Data received by Datazoic, Inc. in reliance on the Data Privacy Framework (or any of its predecessors) cannot be resolved through our internal processes, we have agreed to participate in the https://verasafe.com/public-resources/dispute-resolution/dispute-resolution-procedure/ Subject to the terms of the VeraSafe Data Privacy Framework Dispute Resolution Procedure, VeraSafe will provide appropriate recourse free of charge to you. To file a complaint with VeraSafe and participate in the VeraSafe Data Privacy Framework Dispute Resolution Procedure, please submit the required information here: https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/

If your dispute or complaint related to your Personal Data that we received in reliance on the Data Privacy Framework cannot be resolved by us, nor through the dispute resolution mechanism mentioned above, you may have the right to require that we enter into binding arbitration with you under the Data Privacy Framework “Recourse, Enforcement and Liability” Principle and Annex I of the Data Privacy Framework.

The Federal Trade Commission (FTC) has jurisdiction over Datazoic’s compliance with the EU-U.S. DPF and the UK Extension. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

11. How to contact us

For any questions about this policy, or to exercise any of the rights described above, please contact:

Datazoic Inc
230 Park Avenue, 3rd Floor West, New York, NY 10169, USA
Email: support@datazoic.com

12. Changes to this policy

We may update this policy from time to time. Where we continue to rely on the EU-U.S. DPF and the UK Extension, any updated policy will remain consistent with the DPF Principles. The “Last updated” date at the top of this policy indicates when it was last revised.