- Ethical Technology
- Where the records sit
Ethical Technology · Sovereignty
Where the records sit
The group decides where its records are held, who can reach them and what happens when a supplier relationship ends. Production runs in two environments the group operates, with the long-term archive in George Town. Six jurisdictions require local residency and each has a local store. No supplier holds a key that decrypts group or client data.

Commitments
- Client records sit in environments the group operates or in stores it controls locally.
- No supplier, host or external administrator holds a key that decrypts group or client data.
- Every cross-border route for group data is registered, approved and reviewed each year.
- No service is bought unless its data can come back in a format the group can read.
- Every material outsourced service has an exit plan, and the plans are tested by restoring data.
- A client may ask where its records sit and which entity controls them, and is told in writing.
Two environments and an archive
Group production systems run from environments in Luxembourg and Singapore, each able to carry the whole workload if the other is unavailable. The long-term archive sits in George Town, where the holding company is domiciled, and holds model records, validation reports, board papers and closed client files.
Six of the 28 jurisdictions require that the records of a locally licensed entity remain in the jurisdiction. Each has a local store operated inside the group boundary. The local entity board is told in writing where its records sit, who administers the store and which group officers are able to reach it.
The design principle is control rather than distance. A record held two streets away by a supplier the group cannot audit is less within its control than a record held on another continent in a system the group operates itself. Distance is a fact about latency. Control is a fact about who can read the data and who can stop them.
The keys stay with the group
Encryption keys for group and client data are generated and held in key stores the group operates in Luxembourg and Singapore. No hosting provider, software supplier or external administrator holds a key that decrypts client data. Custody of the master keys is split between two officers of the group and neither can act alone.
A supplier that requires custody of the keys in order to deliver its service is not adopted, whatever the service does and whatever it saves. One proposal was rejected on that ground in the twelve months to 30 June 2026. Keys are rotated annually and on the departure of any officer holding custody, and every rotation is recorded and witnessed.
Every crossing is a registered route
Group data crosses a border only along a route recorded in the transfer register, which held 22 routes at 30 June 2026. Each entry names the origin, the destination, the categories of data, the lawful basis in the origin jurisdiction, the safeguards applied and the officer who approved it.
Routes are reviewed each year by the Group Data Protection Officer and closed when the activity that justified them ends. Two were closed in the twelve months to 30 June 2026. No route exists whose purpose is to place a record beyond the reach of the law that governs it, and a proposal of that kind is refused by the Information Governance Committee.
- No group data moves to a system the group cannot audit.
- No client record leaves a booking jurisdiction whose rules require it to remain.
- No route is opened to place a record beyond the reach of the law that governs it.
- No supplier adds a sub-processor in a new country without written consent.
Exit is designed before entry
The group buys fourteen material outsourced services. Each has an exit plan written before the contract is signed, naming the successor arrangement, the format in which the data returns, the time the migration takes and the cost of it. A service whose data cannot be returned in a usable format is not adopted.
Exit plans are tested on a two-year cycle by restoring a sample of the data into a group environment and reading it there. Three were tested in the twelve months to 30 June 2026. One test found an export format the group could not read without the supplier's own tooling, and the contract was amended before the next renewal.
Deletion at exit is evidenced rather than promised. A supplier returns the data, deletes its copies and certifies the deletion within 60 days of the end of the service, including copies held by sub-processors and copies in backups. A certificate that does not cover backups is not accepted.
What a client can ask
A client may ask which group entity controls its records, where those records are held, which suppliers can reach them and under which jurisdiction's law the arrangement sits. The answer is given in writing. Private-wealth clients booked in Nassau or Zurich receive it in the mandate documents at the outset.
Questions of this kind reach the group through the client team or at privacy@iguako.tech and are answered within 30 days. Seventeen clients asked in the twelve months to 30 June 2026, most of them institutions applying their own outsourcing rules to the group as a supplier of services to them.
Also on ethical technology