SHIELDROW LLC
412 W 7th St, Clovis, NM 88101, USA  ·  shieldrow.global
Legal · GDPR Articles 13 & 14

Privacy Notice

Information pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR).

Version 1.0 — August 2026

1. Introduction

Shieldrow LLC ("Shieldrow", "we", "us" or "our") is committed to protecting the privacy of individuals whose personal data we process. This Privacy Notice explains what personal data we collect, why we collect it, how we use it, with whom we share it, how long we retain it, and what rights you have under applicable data protection law.

This Notice applies to personal data collected through the website shieldrow.global and through communications or professional engagements initiated via the website or by direct contact with us.

We may update this Notice from time to time. Any material changes will be reflected in the version number and date shown above. We encourage you to review this Notice periodically. The current version is always available at https://shieldrow.global/privacy-notice.

2. Identity and Contact Details of the Controller

The controller responsible for the processing of your personal data is:

Shieldrow LLC

412 W 7th St, Clovis, NM 88101, New Mexico, United States of America

Email: info@shieldrow.global

Website: https://shieldrow.global

Telephone: +1 (505) 405 0541

For all matters relating to the protection of your personal data, you may contact us at: info@shieldrow.global

3. EU Representative (Article 27 GDPR)

Shieldrow LLC is established in the United States of America and not in the European Union. As we offer services to individuals located in the EU, we have designated a representative in the EU pursuant to Article 27 GDPR. You may contact our EU Representative on all matters relating to the processing of your personal data:

Giuseppe Disabato

Email: info@shieldrow.global

Member State of establishment: Malta

Competent supervisory authority: Information and Data Protection Commissioner (IDPC), Malta

Contacting our EU Representative is an alternative to contacting us directly and does not restrict your right to contact us or any competent supervisory authority directly.

4. Personal Data We Process, Purposes, Legal Bases and Retention Periods

The table below sets out the purposes for which we process personal data, the categories of personal data involved, the legal basis for each processing activity under Article 6 GDPR, and the applicable retention periods.

Purpose Categories of personal data Legal basis (Art. 6 GDPR) Retention period
Operating and securing the website Browsing data: IP address, browser type and version, pages visited, date and time of access Art. 6(1)(f) — Legitimate interest in ensuring the technical operation and security of the website Server logs: up to 12 months for security purposes
Managing pre-analysis requests submitted through the website contact form First name, last name, email address, telephone number, reason for request Art. 6(1)(b) — Processing necessary to take steps at the request of the data subject prior to entering into a contract If no engagement follows: 24 months from the date of the request. If an engagement follows: see "Client engagements" below
Managing email correspondence with prospective and existing clients Name, email address, telephone number, content of messages, professional and personal information voluntarily disclosed Art. 6(1)(b) — Pre-contractual or contractual measures. Art. 6(1)(f) — Legitimate interest in maintaining accurate records of business communications Prospective clients who do not proceed to an engagement: 36 months from the last communication. Existing and former clients: see "Client engagements" below
Client engagements — providing strategic advisory services Identity data (name, date of birth, nationality, identity documents); contact data; financial and patrimonial data (assets, corporate structures, trusts, bank relationships, jurisdictions involved); professional data (business activities, roles held, shareholding structures); tax residence and domicile; immigration and relocation data where the service so requires Art. 6(1)(b) — Performance of a contract to which the data subject is party, or pre-contractual measures at the request of the data subject Duration of the engagement plus 7 years from the date of termination, to comply with applicable record-keeping obligations and to address any claims arising from the services provided
AML/KYC due diligence (where applicable) Identity documents; proof of address; source of funds and wealth information; politically exposed person (PEP) status; beneficial ownership information Art. 6(1)(c) — Compliance with a legal obligation. Art. 6(1)(b) — Performance of a contract where contractually required Minimum 5 years from the end of the business relationship, in accordance with applicable AML legislation

Where we rely on our legitimate interests as the legal basis for processing (Article 6(1)(f) GDPR), we are required by Article 13(1)(d) GDPR to identify those interests. They are:

We have assessed that our legitimate interests in each case are not overridden by your interests or fundamental rights and freedoms, taking into account the nature of our services and the reasonable expectations of individuals who contact a professional advisory firm. You have the right to object to processing based on our legitimate interests: see Section 8 below.

5. Recipients of Personal Data

We do not sell, rent or disclose your personal data to third parties for their own commercial purposes.

We may share your personal data with the following categories of recipients:

6. Transfers of Personal Data Outside the European Union

Shieldrow LLC is established in the United States of America. Personal data collected from individuals located in the EU is transferred to and processed by the Controller in the USA.

The United States does not benefit from a general adequacy decision under Article 45 GDPR. We ensure that transfers of personal data from the EU to the USA are made on the basis of the Standard Contractual Clauses adopted by the European Commission pursuant to Commission Implementing Decision (EU) 2021/914. A copy of the applicable clauses may be requested by contacting us at info@shieldrow.global.

Where we engage specialist professionals located in countries outside the EU other than the USA, we assess and document the appropriate safeguards applicable to each transfer. Details of the safeguards applicable to specific transfers are available on request at info@shieldrow.global.

7. Cookies and Similar Technologies

Our website uses cookies and similar technologies solely to the extent necessary for its technical operation. We do not currently deploy analytics, advertising or behavioral tracking cookies.

If we deploy non-essential cookies in the future, we will publish a separate Cookie Policy and obtain your prior informed consent before any such cookies are set. You may withdraw any consent given at any time.

8. Your Rights as a Data Subject

Under the GDPR, you have the following rights in relation to your personal data. These rights are not absolute and are subject to the conditions and exceptions set out in the GDPR.

Right of access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process personal data concerning you and, if so, to receive a copy of that data together with information about the purposes of processing, the categories of data, the recipients, the retention periods, and the existence of your other rights.

Right to rectification (Article 16 GDPR)

You have the right to obtain the rectification of inaccurate personal data concerning you and, where relevant, to have incomplete personal data completed.

Right to erasure (Article 17 GDPR)

You have the right to obtain the erasure of your personal data where one of the grounds listed in Article 17(1) GDPR applies — for example, where the data is no longer necessary for the purposes for which it was collected. This right is subject to exceptions, including where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defense of legal claims.

Right to restriction of processing (Article 18 GDPR)

You have the right to obtain restriction of processing in the circumstances listed in Article 18(1) GDPR — for example, where you contest the accuracy of the data, for a period enabling us to verify it.

Right to object (Article 21 GDPR)

You have the right to object at any time to the processing of your personal data where that processing is based on our legitimate interests (Article 6(1)(f) GDPR). We will cease processing unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defense of legal claims.

Rights related to automated decision-making (Article 22 GDPR)

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or that similarly significantly affect you.

Right to withdraw consent

Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before the withdrawal.

How to exercise your rights

To exercise any of the above rights, please contact our EU Representative at info@shieldrow.global.

We will respond within one month of receipt of your request. Where requests are complex or numerous, we may extend this period by a further two months; in that case we will notify you within the first month and explain the reason for the extension. We may ask you to verify your identity before processing your request. We will not charge a fee unless the request is manifestly unfounded or excessive.

9. Right to Lodge a Complaint with a Supervisory Authority

If you consider that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority without prejudice to any other administrative or judicial remedy. You may lodge a complaint with:

The Information and Data Protection Commissioner (IDPC) of Malta — the supervisory authority competent for our EU Representative:

Level 2, Airways House, High Street, Sliema SLM 1549, Malta

Website: https://idpc.org.mt

Email: idpc.info@gov.mt

Or with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement, in accordance with Article 77 GDPR.

Lodging a complaint with a supervisory authority does not affect your right to seek a judicial remedy before the courts.

10. Provision of Personal Data — Consequences of Non-Provision

Certain personal data is necessary for us to assess a pre-analysis request, to enter into a service agreement with you, or to comply with our legal obligations. If you do not provide the data required in connection with a pre-analysis request, we may not be able to evaluate your request or proceed with an engagement. If you do not provide data necessary for the performance of an existing engagement, we may not be able to continue providing the relevant service.

Where the provision of personal data is optional, we will indicate this at the point of collection.

11. Automated Decision-Making and Profiling

We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or that similarly significantly affects you within the meaning of Article 22 GDPR.

12. Security of Personal Data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, having regard to the nature, scope, context and purposes of the processing and the risks involved.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay in accordance with Article 34 GDPR.

13. Contact

For any questions or concerns regarding this Privacy Notice or the processing of your personal data:

Email: info@shieldrow.global

Post: Shieldrow LLC, 412 W 7th St, Clovis, NM 88101, New Mexico, USA

EU Representative: info@shieldrow.global

This Privacy Notice is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR). It reflects the state of our processing activities as at the date of issue and will be updated whenever there is a material change. Version history is maintained internally.