Privacy Notice
Information pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR).
- Introduction
- Identity and Contact Details of the Controller
- EU Representative (Article 27 GDPR)
- Personal Data We Process, Purposes, Legal Bases and Retention Periods
- Recipients of Personal Data
- Transfers of Personal Data Outside the European Union
- Cookies and Similar Technologies
- Your Rights as a Data Subject
- Right to Lodge a Complaint with a Supervisory Authority
- Provision of Personal Data — Consequences of Non-Provision
- Automated Decision-Making and Profiling
- Security of Personal Data
- Contact
1. Introduction
Shieldrow LLC ("Shieldrow", "we", "us" or "our") is committed to protecting the privacy of individuals whose personal data we process. This Privacy Notice explains what personal data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have under applicable data protection law.
This Notice applies to personal data collected through the website shieldrow.global and through communications or professional engagements initiated via the website or by direct contact with us.
We may update this Notice from time to time. Any material changes will be reflected in the version number and date shown above. We encourage you to review this Notice periodically. The current version is always available at https://shieldrow.global/privacy-notice.
2. Identity and Contact Details of the Controller
The controller responsible for the processing of your personal data is:
Shieldrow LLC
412 W 7th St, Clovis, NM 88101, New Mexico, United States of America
Email: info@shieldrow.global
Website: https://shieldrow.global
Telephone: +1 (505) 405 0541
For all matters relating to the protection of your personal data, you may contact us at: info@shieldrow.global
3. EU Representative (Article 27 GDPR)
Shieldrow LLC is established in the United States of America and not in the European Union. As we offer services to individuals located in the EU, we have designated a representative in the EU pursuant to Article 27 GDPR. You may contact our EU Representative on all matters relating to the processing of your personal data:
Giuseppe Disabato
Email: info@shieldrow.global
Member State of establishment: Malta
Competent supervisory authority: Information and Data Protection Commissioner (IDPC), Malta
Contacting our EU Representative is an alternative to contacting us directly and does not restrict your right to contact us or any competent supervisory authority directly.
4. Personal Data We Process, Purposes, Legal Bases and Retention Periods
The table below sets out the purposes for which we process personal data, the categories of personal data involved, the legal basis for each processing activity under Article 6 GDPR, and the applicable retention periods.
| Purpose | Categories of personal data | Legal basis (Art. 6 GDPR) | Retention period |
|---|---|---|---|
| Operating and securing the website | Browsing data: IP address, browser type and version, pages visited, date and time of access | Art. 6(1)(f) — Legitimate interest in ensuring the technical operation and security of the website | Server logs: up to 12 months for security purposes |
| Managing pre-analysis requests submitted through the website contact form | First name, last name, email address, telephone number, reason for request | Art. 6(1)(b) — Processing necessary to take steps at the request of the data subject prior to entering into a contract | If no engagement follows: 24 months from the date of the request. If an engagement follows: see "Client engagements" below |
| Managing email correspondence with prospective and existing clients | Name, email address, telephone number, content of messages, professional and personal information voluntarily disclosed | Art. 6(1)(b) — Pre-contractual or contractual measures. Art. 6(1)(f) — Legitimate interest in maintaining accurate records of business communications | Prospective clients who do not proceed to an engagement: 36 months from the last communication. Existing and former clients: see "Client engagements" below |
| Client engagements — providing strategic advisory services | Identity data (name, date of birth, nationality, identity documents); contact data; financial and patrimonial data (assets, corporate structures, trusts, bank relationships, jurisdictions involved); professional data (business activities, roles held, shareholding structures); tax residence and domicile; immigration and relocation data where the service so requires | Art. 6(1)(b) — Performance of a contract to which the data subject is party, or pre-contractual measures at the request of the data subject | Duration of the engagement plus 7 years from the date of termination, to comply with applicable record-keeping obligations and to address any claims arising from the services provided |
| AML/KYC due diligence (where applicable) | Identity documents; proof of address; source of funds and wealth information; politically exposed person (PEP) status; beneficial ownership information | Art. 6(1)(c) — Compliance with a legal obligation. Art. 6(1)(b) — Performance of a contract where contractually required | Minimum 5 years from the end of the business relationship, in accordance with applicable AML legislation |
Where we rely on our legitimate interests as the legal basis for processing (Article 6(1)(f) GDPR), we are required by Article 13(1)(d) GDPR to identify those interests. They are:
- Website security and operation: the interest in keeping our website operational and secure, preventing unauthorised access, and detecting and responding to cyberattacks and other security incidents.
- Record-keeping of business communications: the interest in retaining accurate records of communications with prospective and existing clients for the purpose of managing the relationship effectively, responding to queries, and evidencing the content of discussions and instructions in the event of a dispute.
We have assessed that our legitimate interests in each case are not overridden by your interests or fundamental rights and freedoms, taking into account the nature of our services and the reasonable expectations of individuals who contact a professional advisory firm. You have the right to object to processing based on our legitimate interests: see Section 8 below.
5. Recipients of Personal Data
We do not sell, rent or disclose your personal data to third parties for their own commercial purposes.
We may share your personal data with the following categories of recipients:
- Service providers acting as data processors. We use third-party service providers for website hosting and email management. These providers process personal data solely on our instructions, under Data Processing Agreements pursuant to Article 28 GDPR, and are contractually required to maintain appropriate technical and organisational security measures.
- Specialist professionals engaged for a specific client mandate. Our service model involves coordinating a network of qualified professionals — including lawyers, accountants, trustees and bankers — to carry out specific tasks within an engagement. We share your personal data with these professionals only to the extent strictly necessary for their specific task. Each professional is bound by professional confidentiality obligations and applicable data protection law. In most cases, these professionals act as independent controllers in respect of their own services. We will inform you of the professionals involved before sharing your data with them and will seek your consent where required by applicable law or by the nature of the data to be shared.
- Competent authorities. Where required by applicable law, including anti-money laundering legislation, we may be required to disclose personal data to competent authorities such as financial intelligence units or regulatory bodies. Such disclosures are made only to the extent required by the applicable legal obligation and may be subject to confidentiality restrictions that prevent us from notifying you in advance.
- Professional advisers. We may share personal data with our own legal, tax or financial advisers where necessary, subject to professional confidentiality obligations.
- Embedded third-party content. Our website displays a small number of photographs served directly from Unsplash Inc.'s servers. Loading these images causes your browser to communicate directly with Unsplash and to share your IP address and basic technical information with it. We have no data processing agreement with Unsplash, and Unsplash acts as an independent controller — not as our processor — with respect to this data. Unsplash's own collection and use of this information is governed exclusively by its privacy policy, available at unsplash.com/privacy.
6. Transfers of Personal Data Outside the European Union
Shieldrow LLC is established in the United States of America. Personal data collected from individuals located in the EU is transferred to and processed by the Controller in the USA.
The United States does not benefit from a general adequacy decision under Article 45 GDPR. We ensure that transfers of personal data from the EU to the USA are made on the basis of the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914. A copy of the applicable clauses may be requested by contacting us at info@shieldrow.global.
Where we engage specialist professionals located in countries outside the EU other than the USA, we assess and document the appropriate safeguards applicable to each transfer. Details of the safeguards applicable to specific transfers are available on request at info@shieldrow.global.
7. Cookies and Similar Technologies
Our website uses cookies and similar technologies solely to the extent necessary for its technical operation. We do not currently deploy analytics, advertising or behavioral tracking cookies.
If we deploy non-essential cookies in the future, we will publish a separate Cookie Policy and obtain your prior informed consent before any such cookies are set. You may withdraw any consent given at any time.
8. Your Rights as a Data Subject
Under the GDPR, you have the following rights in relation to your personal data. These rights are not absolute and are subject to the conditions and exceptions set out in the GDPR.
Right of access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data concerning you and, if so, to receive a copy of that data together with information about the purposes of processing, the categories of data, the recipients, the retention periods, and the existence of your other rights.
Right to rectification (Article 16 GDPR)
You have the right to obtain the rectification of inaccurate personal data concerning you and, where relevant, to have incomplete personal data completed.
Right to erasure (Article 17 GDPR)
You have the right to obtain the erasure of your personal data where one of the grounds listed in Article 17(1) GDPR applies — for example, where the data is no longer necessary for the purposes for which it was collected. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defense of legal claims.
Right to restriction of processing (Article 18 GDPR)
You have the right to obtain restriction of processing in the circumstances listed in Article 18(1) GDPR — for example, where you contest the accuracy of the data, for a period enabling us to verify it.
Right to object (Article 21 GDPR)
You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests (Article 6(1)(f) GDPR). We will cease processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defense of legal claims.
Rights related to automated decision-making (Article 22 GDPR)
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or that similarly significantly affect you.
Right to withdraw consent
Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.
How to exercise your rights
To exercise any of the above rights, please contact our EU Representative at info@shieldrow.global.
We will respond within one month of receipt of your request. Where requests are complex or numerous, we may extend this period by a further two months; in that case we will notify you within the first month and explain the reason for the extension. We may ask you to verify your identity before processing your request. We will not charge a fee unless the request is manifestly unfounded or excessive.
9. Right to Lodge a Complaint with a Supervisory Authority
If you consider that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority without prejudice to any other administrative or judicial remedy. You may lodge a complaint with:
The Information and Data Protection Commissioner (IDPC) of Malta — the supervisory authority competent for our EU Representative:
Level 2, Airways House, High Street, Sliema SLM 1549, Malta
Website: https://idpc.org.mt
Email: idpc.info@gov.mt
Or with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement, in accordance with Article 77 GDPR.
Lodging a complaint with a supervisory authority does not affect your right to seek a judicial remedy before the courts.
10. Provision of Personal Data — Consequences of Non-Provision
Certain personal data is necessary for us to assess a pre-analysis request, to enter into a service agreement with you, or to comply with our legal obligations. If you do not provide the data required in connection with a pre-analysis request, we may not be able to evaluate your request or proceed with an engagement. If you do not provide data necessary for the performance of an existing engagement, we may not be able to continue providing the relevant service.
Where the provision of personal data is optional, we will indicate this at the point of collection.
11. Automated Decision-Making and Profiling
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or that similarly significantly affects you within the meaning of Article 22 GDPR.
12. Security of Personal Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, having regard to the nature, scope, context and purposes of the processing and the risks involved.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with Article 34 GDPR.
13. Contact
For any questions or concerns regarding this Privacy Notice or the processing of your personal data:
Email: info@shieldrow.global
Post: Shieldrow LLC, 412 W 7th St, Clovis, NM 88101, New Mexico, USA
EU Representative: info@shieldrow.global
This Privacy Notice is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It reflects the state of our processing activities as at the date of issue and will be updated whenever there is a material change. Version history is maintained internally.