European Union General Data Protection Regulation
MADAXA is fully committed to compliance with the European Union's General Data Protection Regulation (GDPR) and equivalent data protection laws in other jurisdictions. We recognize that protecting personal data is not just a legal obligation but a fundamental aspect of maintaining client trust.
Our GDPR Principles: We process personal data lawfully, fairly, and transparently. We collect data only for specified, explicit purposes and maintain it no longer than necessary. We implement appropriate technical and organizational measures to ensure data security.
We process your personal data based on one or more of the following legal grounds:
Processing is necessary to perform our advisory agreement with you, including:
Processing is required to comply with applicable laws and regulations:
Processing serves our legitimate business interests while respecting your rights:
In certain cases, we obtain your explicit consent for processing, such as:
As a data subject under GDPR, you have comprehensive rights regarding your personal data:
You can request:
You can request correction of inaccurate or incomplete personal data. We will update your information within 30 days and notify relevant third parties when necessary.
You can request deletion of your personal data when:
Note: This right may be limited by legal retention requirements (e.g., tax, AML laws).
You can request temporary suspension of data processing when:
You can request your personal data in a structured, commonly used, machine-readable format to:
This right applies to data processed based on consent or contract performance.
You can object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds that override your rights.
You have the right not to be subject to decisions based solely on automated processing. MADAXA does not use fully automated decision-making for any critical advisory functions. All significant recommendations involve human review.
To exercise any of your GDPR rights:
As a global advisory firm, we may transfer your data outside the European Economic Area (EEA). We ensure adequate protection through:
We use European Commission-approved SCCs with all non-EEA service providers and affiliates, ensuring they provide equivalent data protection.
We transfer data to jurisdictions deemed by the European Commission to provide adequate data protection levels.
Our internal policies establish uniform data protection standards across all MADAXA offices globally.
In certain circumstances, we may seek your explicit consent for specific international transfers.
We implement comprehensive technical and organizational measures:
In the event of a data breach:
If the breach poses a risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours of becoming aware of the breach.
If the breach poses a high risk to your rights and freedoms, we will notify you directly without undue delay, providing:
We conduct DPIAs for processing activities that may pose high risks to data subjects, including:
Our services are directed at adults. We do not knowingly collect data from individuals under 16 without parental consent, except when processing is necessary for family wealth management purposes (e.g., succession planning involving minor beneficiaries).
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or where an alleged infringement occurred.
For EU clients, you may contact:
Your national data protection authority
or
European Data Protection Board (EDPB)
Website: edpb.europa.eu
We review and update our GDPR compliance measures regularly. Material changes will be communicated via:
For GDPR-related questions, concerns, or to exercise your rights:
Data Protection Officer
Email: dpo@madaxa.org
Address: 5 Parvis Alan Turing, 75013 Paris, France
Our Commitment: MADAXA views GDPR compliance not as a regulatory burden but as an essential component of our fiduciary duty. We continuously invest in people, processes, and technology to ensure your personal data receives the highest level of protection.