IGUAKO Capital is a work of institutional fiction by the Iguako Institute for Applied Unreality. No financial services are offered, no accounts exist and nothing here is an offer, a contract or advice.About this work
George Town · 36 cities · English Domiciles Documents Iguako Network Site Index

Ethical Technology · Privacy

Privacy built into the systems

Privacy in the group is a property of the systems rather than a promise made about them. Fields carry a sensitivity class and a purpose tag. Access is logged with a reason. Retention runs as a scheduled job that produces a certificate. In the twelve months to 30 June 2026 the group answered all 47 individual requests within the period.

Commitments

  • Forms ask only for what a mandate or a law requires, and untraceable fields are removed.
  • Every field carries a sensitivity class and a purpose tag enforced by the platform.
  • Every access to a client record is logged with a reason and reviewed monthly.
  • Development runs on masked or synthetic records unless the Group Data Protection Officer approves otherwise.
  • Requests to privacy@iguako.tech are answered within 30 days or the shorter local period.
  • Individuals affected by a breach are told within five business days, whatever the reporting threshold.

Collect less at the point of collection

The cheapest way to protect a record is not to hold it. Client onboarding forms ask for what the mandate and the law require and stop there, and each field on each form traces to a requirement in the client due diligence rules. A field that cannot be traced is removed from the form at the next revision rather than kept for a future purpose.

Where a document proves a fact, the group records the fact and the evidence reference rather than copying every page into the file. Where a screening provider returns a full profile, only the matched elements enter the client record. This discipline reduced the fields held on a private-wealth relationship by a fifth at the 2025 forms review.

Classification and purpose in the schema

Every field in the client record store carries a sensitivity class and a purpose tag. The class decides the encryption, the retention rule and who may read it. The purpose tag names the processing activity that justifies holding it, and it links directly to the entry in the processing register that carries the origin and the lawful basis.

A query that reaches fields tagged for a purpose the requester is not working on is refused by the platform, not reviewed after the event. This is the restraint principle expressed as a schema rather than as a training message. New tables cannot be created in the client store without the tags, and the deployment pipeline rejects a change that leaves a field untagged.

The same tagging governs what a model may take as an input. A model whose inventory entry does not list a purpose tag cannot read the fields carrying it, which is how the group prevents a system built for one lawful use from quietly acquiring another. Fourteen model input requests were narrowed at design in the twelve months to 30 June 2026.

Access, logging and the development boundary

Every access to a client record is logged with the identity of the person and the reason for the access, chosen from a fixed list rather than typed freely. Local data protection officers review the logs monthly against the mandates their offices run. Personal data is encrypted at rest and in transit and is not stored on portable media or on personal devices.

Development and testing run in an environment separated from production. Where realistic data is needed, the group uses masked or synthetic records built to the shape of the real ones. Copying production records into a development environment requires the written approval of the Group Data Protection Officer, and three such approvals were given in the twelve months to 30 June 2026, each for a defined period.

Rights that work in practice

An individual may ask what the group holds, ask for it to be corrected, object to a use, ask for erasure where no legal obligation requires retention, and ask for a copy in a usable form. Requests go to privacy@iguako.tech or to a local privacy contact in any office. The group answers within 30 days or within the shorter period a local law sets.

The systems are built so that answering is quick. A single query assembles everything held about a person across the client store, the correspondence archive and the screening records, because the purpose tags make the search exhaustive rather than approximate. All 47 requests in the twelve months to 30 June 2026 were answered inside the period.

Where an erasure request meets a legal retention duty, the group says which duty and when it ends, rather than declining without explanation. Where a correction is made, it is pushed to every system holding the field, and the log of the correction is retained so that a decision taken on the old value can be traced.

When something goes wrong

A breach is any loss, unauthorised access, unauthorised disclosure or unlawful destruction of personal data, whether it happens inside the group or at a third party holding data on its behalf. Staff report a suspected breach to the Group Data Protection Officer within 24 hours of discovery. Delay to gather more facts is not permitted.

The Group Data Protection Officer assesses within 72 hours and decides with the General Counsel whether the supervisory authority in each jurisdiction concerned and the individuals affected must be told. The group recorded three breaches in the twelve months to 30 June 2026. None reached the threshold for supervisory notification, and each was reported to the individuals affected within five business days.