AqNova Marketplace Policies & Disclosures
AqNova Marketplace | Arivon Holding Corporation
Global Compliance Edition | CLEAR Framework | GDPR Art.13/14 · CCPA/CPRA · PIPEDA · LGPD · NDPA · POPIA · DPDPA · 20+ Jurisdictions
| C COMPLIANT GLOBALLY | L LAWFUL BASIS FOR ALL | E EXPLICIT TRANSPARENCY | A ACCOUNTABLE PROCESSING | R RIGHTS-READY GLOBALLY |
|---|
| Document: Vendor Data Privacy Notice Version: 1.0 Effective Date: June 2026 | Data Controller: Arivon Holding Corporation DPO Contact: dpo@aqnovamarketplace.com Review Cycle: Annual + Regulatory Change | Jurisdictions: 20+ covered Laws: GDPR; CCPA; PIPEDA; LGPD; NDPA; POPIA; DPDPA; 20+ equivalents Applies To: All AqNova Vendors and Vendor Personnel |
|---|
| This Vendor Data Privacy Notice is provided under GDPR Art. 13/14 and equivalent global data protection laws. Vendors and vendor personnel are required to acknowledge receipt of this notice at onboarding and whenever it is materially updated. Acknowledgment does not constitute consent to marketing — lawful bases for mandatory processing are independent of consent. |
|---|
AqNova Marketplace | Arivon Holding Corporation | EIN: 41-3210066 | Huntington Park, CA, USA
Table of Contents
Controller Identity · DPO Contact · EU/UK Representative · 17-Law Compliance Framework Table
10 Categories of Personal Data (Identity · Contact · KYC · Financial · Communications · Technical)
Sensitive Data (Biometric · Criminal · Nationality) · 5 Categories of Business Data
8-Purpose Lawful Basis Table: GDPR Art.6 · UK/Swiss Equivalent · LGPD · Other Law Equivalents
Contract Performance · Legal Obligation (KYC/AML; Tax; Product Safety) · Legitimate Interests · Consent
Legitimate Interests Assessment (LIA) Summary
9 Recipient Categories (Payment Processors · KYC Providers · Cloud · Tax Authorities · Regulators)
14-Route International Transfer Table (EU→US DPF/SCCs; UK IDTAs; China PIPL SCC; Japan/Korea Adequacy)
Data Processing Agreement (DPA) Standards — GDPR Art.28 Compliance
10-Category Retention Schedule: KYC 5yr · Financial 7yr (8yr India; 10yr Saudi) · AML 5yr
Account 7yr post-closure · Communications 3yr · Dispute Records 7yr from resolution
12 Rights × 9 Jurisdictions: EU/UK GDPR · US CCPA · Canada · Brazil LGPD · Nigeria NDPA
South Africa POPIA · India DPDPA · Australia APPs — Yes/Limited/No with color coding
Rights Exercise Process: Email/Portal · 5-day acknowledgment · 30-day response
California CCPA/CPRA (categories; sensitive PI; no sale/share; authorized agent; B2B note)
Canada PIPEDA + Quebec Law 25 · Brazil LGPD + ANPD · Nigeria NDPA 2023 + NDPC
South Africa POPIA + PAIA + 8 Conditions · India DPDPA + DPBI · Middle East (UAE/Saudi/GCC)
Asia-Pacific (Australia NDB; Singapore 3-day; Japan; South Korea PIPA; China PIPL; Philippines; Thailand)
Latin America (Mexico LFPDPPP; Colombia Ley 1581; Argentina adequacy; Chile; Peru)
This Vendor Data Privacy Notice ("Notice") is issued by Arivon Holding Corporation, trading as AqNova Marketplace ("AqNova", "we", "us", "our"), the operator of the AqNova sustainable e-commerce platform. This Notice explains how we collect, use, store, share, and protect personal data relating to vendor businesses and their personnel ("Vendor Data") in the course of our commercial relationship.
This Notice applies to: all businesses that have registered or applied to register as vendors on the AqNova Marketplace platform; the individual representatives, contact persons, directors, beneficial owners, and employees of those vendor businesses whose personal data AqNova processes in connection with the vendor relationship; and all individuals who interact with AqNova through the Vendor Portal, AqNova vendor support communications, or any other channel in a vendor-related capacity.
| This Notice is separate from AqNova's Consumer Privacy Notice (which covers buyer and end-user data) and the Applicant Privacy Notice (which covers job applicants). If you are both a vendor contact person and a job applicant, both notices apply to your respective data. |
|---|
| Data Controller Element | Details |
|---|---|
| Legal Entity | Arivon Holding Corporation — the parent company of the AqNova Marketplace platform. All vendor data processing described in this Notice is performed by or on behalf of Arivon Holding Corporation as the data controller. |
| Registered Address | Huntington Park, California, USA. EIN: 41-3210066. |
| AqNova Platform | AqNova Marketplace — a curated global e-commerce marketplace for sustainable, organic, and ethically sourced products. Platform domains: aqnovamarketplace.com and all related subdomains. Vendor Portal: vendor.aqnovamarketplace.com. |
| EU/UK Representative | For vendors and vendor personnel located in the European Union or United Kingdom: AqNova has appointed [EU/UK Representative Name] as its representative under GDPR Art. 27 / UK GDPR Art. 27. Contact: eurep@aqnovamarketplace.com. |
| Data Protection Officer (DPO) | AqNova has appointed a Data Protection Officer as required under GDPR Art. 37 (and equivalent requirements under UK GDPR, Nigeria NDPA, and other applicable laws). DPO Contact: dpo@aqnovamarketplace.com. For postal correspondence: Data Protection Officer, AqNova Marketplace / Arivon Holding Corporation, Huntington Park, CA, USA. |
| Chief Compliance & Risk Officer (CCRO) | Ronke Olatoye serves as AqNova's Chief Compliance and Risk Officer. The CCRO oversees AqNova's global data protection compliance program, including this Notice and the underlying data processing activities. |
| Applicable Law | Scope and Application | Supervisory Authority |
|---|---|---|
| GDPR (EU) | EU General Data Protection Regulation 2016/679 — Art. 13/14 (transparency); Art. 6 (lawful basis); Art. 17 (erasure); Art. 20 (portability); Art. 46 (transfers). Applies to all EU/EEA-based vendors and vendor personnel. | Effective May 2018; most comprehensive global standard |
| UK GDPR + DPA 2018 | UK GDPR and Data Protection Act 2018 — substantially equivalent to EU GDPR post-Brexit. Applies to UK-based vendors and vendor personnel. | ICO (Information Commissioner's Office) enforcement |
| CCPA / CPRA (California) | California Consumer Privacy Act 2018 as amended by California Privacy Rights Act 2020 — effective January 2023. Applies to California-based vendor personnel and California-resident individuals whose data AqNova processes. Note: B2B data has limited exemptions under CCPA/CPRA. | CPPA enforcement; AG enforcement |
| PIPEDA (Canada) | Personal Information Protection and Electronic Documents Act — Canada's federal privacy law. Applies to personal information of Canadian vendor personnel. | OPC (Office of the Privacy Commissioner) |
| LGPD (Brazil) | Lei Geral de Proteção de Dados (Law 13.709/2018) — Brazil's general data protection law, effective August 2020. Modeled on GDPR; 10 lawful bases. Applies to Brazilian vendor personnel. | ANPD (Autoridade Nacional de Proteção de Dados) |
| NDPA 2023 (Nigeria) | Nigeria Data Protection Act 2023 — supersedes NDPR 2019; new comprehensive framework. Applies to Nigerian vendor personnel. | NDPC (Nigeria Data Protection Commission) |
| POPIA (South Africa) | Protection of Personal Information Act 4/2013 — fully effective July 2021. Applies to South African vendor personnel. | Information Regulator (South Africa) |
| DPDPA 2023 (India) | Digital Personal Data Protection Act 2023 — India's new privacy framework. Phased implementation. Applies to Indian vendor personnel. | Data Protection Board of India (phased operational dates) |
| PDPA (Singapore) | Personal Data Protection Act 2012 (revised 2021). Applies to Singapore-based vendor personnel. | PDPC (Personal Data Protection Commission) |
| APPI (Japan) | Act on the Protection of Personal Information (2003, revised 2020 and 2022). Applies to Japanese vendor personnel. | PPC (Personal Information Protection Commission) |
| PIPA (South Korea) | Personal Information Protection Act. Applies to South Korean vendor personnel. | PIPC (Personal Information Protection Commission) |
| PIPL (China) | Personal Information Protection Law — effective November 2021. Applies to Chinese vendor personnel; significant extraterritorial scope for data exported from China. | CAC (Cyberspace Administration of China) |
| PDPL (UAE) | UAE Federal Decree-Law No. 45/2021 on Personal Data Protection. Also: DIFC Data Protection Law 2020 for DIFC-based vendors. | UAE TRA; DIFC Commissioner of Data Protection |
| PDPL (Saudi Arabia) | Saudi Arabia Personal Data Protection Law (PDPL) — effective September 2023. Applies to Saudi-based vendor personnel. | SDAIA (Saudi Data and AI Authority) / NCA |
| Australia Privacy Act | Privacy Act 1988 (Cth) + Australian Privacy Principles (APPs). Applies to Australian vendor personnel. | OAIC (Office of the Australian Information Commissioner) |
| New Zealand Privacy Act | Privacy Act 2020 — Information Privacy Principles. Applies to NZ vendor personnel. | Privacy Commissioner New Zealand |
| PDPA (Thailand) | Personal Data Protection Act B.E. 2562 (2019), fully effective June 2022. Applies to Thai vendor personnel. | PDPC Thailand |
| SECTION 2 | PERSONAL DATA AND BUSINESS DATA WE COLLECT ABOUT VENDORS |
|---|
AqNova collects personal data about individuals associated with vendor businesses. "Personal data" means any information that directly or indirectly identifies a natural person (an individual human being). The following categories of personal data may be collected and processed:
| Data Category | Examples | How and When Collected |
|---|---|---|
| Identity Data | Full legal name; preferred name; job title; role at the vendor organization; employer/business name; date of birth (for KYC/identity verification); gender (where required by applicable law); photograph or profile image (where uploaded voluntarily). | At vendor application and onboarding; on update by the vendor. |
| Contact Data | Work email address; work telephone number (mobile and landline); business mailing address; country of residence or work location; time zone. | Provided directly by vendor personnel or the vendor organization. |
| Account Credentials | Vendor Portal username; password (hashed; never stored in plaintext); two-factor authentication details; session identifiers; API keys and tokens. | Created at account registration; managed through the Vendor Portal. |
| Identity Verification Data (KYC) | Government-issued identity document details (passport number; national ID number; driver's license number — the document reference; not always a copy); proof of address; biometric data where required by applicable AML law (facial matching for identity verification — only where mandatory and with appropriate lawful basis); PEP (Politically Exposed Person) status and related screening results. | Collected at onboarding for KYC/AML compliance; provided by vendor personnel; verified against third-party databases. |
| Financial Data | Bank account details (account number; sort code or IBAN; SWIFT/BIC); payment method details; tax identification number (TIN; VAT number; EIN; Aadhaar-linked TAN; GSTIN); invoicing information; commission and payment history. | Provided by vendor at onboarding; updated through Vendor Portal settings. |
| Communications Data | Content of emails; messages through the Vendor Portal messaging system; live chat transcripts; vendor support tickets; recorded telephone calls (where call recording is disclosed and lawful in the applicable jurisdiction); responses to vendor surveys. | Generated through vendor interactions with AqNova; stored in AqNova's CRM and support systems. |
| Compliance and Due Diligence Data | Business licenses; product certifications; regulatory approvals; sustainability certifications; ethical sourcing documentation; anti-bribery and anti-corruption declarations; supplier code of conduct acknowledgments; sanctions screening results; adverse media screening results. | Collected at onboarding and during periodic due diligence reviews; provided by vendor; verified by AqNova. |
| Performance and Transaction Data | Vendor performance metrics (order fulfillment rate; response time; return rate; customer rating); sales data; order history; product listing data; inventory levels communicated to AqNova; dispute history; buyer reviews of vendor products. | Generated through vendor activities on the AqNova Marketplace platform. |
| Technical Data | IP address; device type and operating system; browser type and version; Vendor Portal login timestamps and session data; clickstream data; error logs; API call logs; cookies and similar tracking technologies (see Section 10). | Automatically collected when vendor personnel access the Vendor Portal or AqNova systems. |
| Beneficial Ownership Data | Names; nationalities; and percentage ownership of individuals holding 25%+ ownership in the vendor entity (or a lower threshold where required by applicable AML regulation). Collected for anti-money laundering compliance. | Collected at onboarding; subject to annual review for active vendor accounts. |
| Sensitive Data Element | Standard |
|---|---|
| Sensitive Data We May Process | AqNova may process the following categories of sensitive personal data in limited circumstances: (a) Biometric data: facial matching for identity verification where required by law. AqNova does not collect biometric data beyond what is strictly required for legally mandated KYC. (b) Criminal conviction data: sanctions screening may reveal information about criminal convictions or offenses by vendor beneficial owners. This is processed on the lawful basis of compliance with a legal obligation. (c) National origin/nationality: collected as part of KYC and beneficial ownership documentation. Where applicable local laws require explicit consent for sensitive data: AqNova obtains consent separately. Sensitive data is processed under the most restrictive standard in the relevant jurisdiction (including GDPR Art. 9 for EU/EEA vendors; CCPA sensitive personal information rules for California vendors). |
| Business Data Category | Examples | Source |
|---|---|---|
| Business Registration Data | Legal entity name; company registration number; country and date of incorporation; registered office address; corporate structure; ownership structure. | Company registration documents; public company registries. |
| Product and Inventory Data | Product names; descriptions; SKUs; pricing; inventory levels; product images and videos; product specifications; country of origin; materials and ingredients; sustainability attributes. | Vendor uploads to Vendor Portal; product catalog submissions. |
| Certification and Compliance Data | Product safety test certificates; organic/sustainability certifications (USDA Organic; EU Ecolabel; Fair Trade; ISO; REACH compliance; etc.); country-specific regulatory approvals (CE mark; FCC; BIS India; NAFDAC Nigeria; SFDA Saudi Arabia). | Uploaded by vendor during onboarding and product listing. |
| Commercial Data | Agreed commission rates; pricing agreements; promotional deal terms; referral partner agreements; payment terms. | Set in the Vendor Agreement and Vendor Portal settings. |
| Logistics Data | Shipping carrier preferences; delivery timelines; warehouse locations; fulfillment center details; return address. | Provided by vendor through Vendor Portal logistics settings. |
| SECTION 3 | WHY WE PROCESS YOUR DATA — PURPOSES, LAWFUL BASES & GLOBAL EQUIVALENTS |
|---|
| AqNova processes vendor personal data on the following lawful bases under GDPR Art. 6 (and equivalent provisions under applicable global data protection laws). Where multiple lawful bases apply to a single processing activity, the primary basis is listed first. |
|---|
| Processing Purpose | GDPR Basis (Art.6) | UK/Swiss Equivalent | LGPD (Brazil) | Other Law Equivalent | Data Categories Used |
|---|---|---|---|---|---|
| Vendor Onboarding, Account Setup & Vendor Portal Access: creating and managing the vendor account; verifying the vendor's identity and business; providing access to the Vendor Portal; communicating onboarding requirements. | Art.6(1)(b) Contract Performance | UK GDPR Art.6(1)(b); Swiss nFADP Art.31 | LGPD Art.7(V) — Contract execution | PIPEDA Schedule 1 Principle 4.3 (consent implied by contract); CCPA Bus.&Prof.§1798.140(e) B2B exemption; NDPA §25(1)(b); POPIA Condition 5; DPDPA §7(b) | Identity; Contact; Account Credentials; Communications |
| KYC / AML / Sanctions Compliance: verifying vendor identity and beneficial owners; screening against sanctions lists (OFAC; UN; EU; DFAT; HM Treasury); PEP screening; adverse media screening; ongoing monitoring; filing suspicious activity reports where required by law. | Art.6(1)(c) Legal Obligation | UK GDPR Art.6(1)(c); POCA 2002; MLR 2017 | LGPD Art.7(II) — Legal obligation; COAF compliance | US BSA; FinCEN; OFAC; UK MLR 2017; EU AMLD5/6; UAE CBUAE; CBN AML 2022 Nigeria; FICA South Africa; MAS Singapore; FATF globally | Identity Verification (KYC); Beneficial Ownership; Financial Data; Compliance Data |
| Tax Compliance and Financial Reporting: processing invoices; calculating commissions; withholding taxes where required (US 1099/W-8; EU DAC7; UK MTD; Brazil nota fiscal; India GST TDS); filing mandatory tax reports with revenue authorities. | Art.6(1)(c) Legal Obligation | UK GDPR Art.6(1)(c); HMRC obligations | LGPD Art.7(II); Receita Federal; eSocial obligations | US IRS; UK HMRC; DAC7 EU; FIRS Nigeria; SARS South Africa; CBDT India; ZATCA Saudi Arabia; FTA UAE; CRA Canada; ATO Australia | Financial Data; Identity Data; Transaction Data; Business Registration Data |
| Product Compliance and Consumer Safety: verifying that vendor products meet applicable product safety standards; processing compliance documentation; removing non-compliant products; reporting to product safety authorities where required by law. | Art.6(1)(c) Legal Obligation | UK GDPR Art.6(1)(c); UK General Product Safety Regs 2005 | LGPD Art.7(II); PROCON; INMETRO compliance | EU GPSR; UK GPSR; US CPSC; NAFDAC Nigeria; SFDA Saudi Arabia; TGA Australia; FDA India; DSM Malaysia; various jurisdiction-specific product safety authorities | Certification and Compliance Data; Product Data; Identity Data |
| Platform Operations, Dispute Resolution and Fraud Prevention: managing marketplace listings; processing orders; facilitating payments; resolving vendor-buyer disputes; investigating fraud; preventing abuse of the platform; maintaining platform integrity. | Art.6(1)(f) Legitimate Interests | UK GDPR Art.6(1)(f); Six-part LIA test applied | LGPD Art.7(IX) — Legitimate interests | PIPEDA Schedule 1 §4.2 (vendor-provided; consent implied); CCPA §1798.140(e) business purpose; NDPA §25(1)(f); POPIA Condition 5(1)(d); PDPA Singapore legitimate interests | All data categories — as minimum necessary for the specific operational purpose |
| Vendor Performance Management and Analytics: measuring vendor performance against platform KPIs; generating analytics; compiling seller ratings; generating aggregated insights on product categories and market trends. Aggregated insights only — not individual profiling for automated decisions. | Art.6(1)(f) Legitimate Interests | UK GDPR Art.6(1)(f); LIA documented | LGPD Art.7(IX) | CCPA — analytics as business purpose exception to sale; NDPA §25(1)(f); POPIA Condition 5(1)(d) | Performance and Transaction Data; Technical Data; Product Data |
| Marketing Communications to Vendors: sending AqNova product updates; promotional opportunities; platform feature announcements; newsletters; and event invitations to vendor contact persons. Separate consent obtained; opt-out available at any time. | Art.6(1)(a) Consent | UK GDPR Art.6(1)(a); PECA 2003 (email) | LGPD Art.7(I) — consent; ANPD guidelines | CASL Canada — express consent; CAN-SPAM Act (US); PIPEDA consent; NDPA §25(1)(a); POPIA §69; DPDPA consent under applicable rules; PDPA Singapore | Contact Data; Communications Data; Account Data |
| Security, Incident Response and Legal Claims: maintaining records for legal defense and prosecution of claims; responding to data breaches; responding to law enforcement requests; enforcing the Vendor Agreement; exercising or defending legal rights. | Art.6(1)(f) + Art.6(1)(c) | UK GDPR Art.6(1)(f) for legal defense; Art.6(1)(c) for mandatory disclosure | LGPD Art.7(VI) — regular exercise of rights in judicial/administrative proceedings | All jurisdictions recognize legal defense and enforcement as a legitimate basis for data processing; statutory limitations periods govern retention for this purpose | All data categories relevant to the specific claim; incident; or legal matter |
Where AqNova relies on legitimate interests (GDPR Art. 6(1)(f)) as a lawful basis, AqNova has conducted a Legitimate Interests Assessment for each processing activity. The LIA confirms: (a) AqNova has a genuine; identifiable legitimate interest in the processing; (b) the processing is necessary for that interest and cannot be achieved by a less intrusive means; and (c) the processing does not override the fundamental rights and freedoms of data subjects — because vendor personnel, as business representatives entering a commercial relationship, have a reduced expectation of data privacy in their professional capacity compared to private individuals, and have adequate safeguards including the rights described in this Notice.
The LIA records are maintained by AqNova's DPO. Vendor personnel may request a summary of the LIA relevant to any specific processing activity by contacting dpo@aqnovamarketplace.com.
| SECTION 4 | DATA SHARING, INTERNATIONAL TRANSFERS & SAFEGUARDS |
|---|
| Transfer Route | Mechanism and Details | Legal Instrument |
|---|---|---|
| Transfers within EU / EEA | No transfer safeguard required — adequacy between EU member states. Data processed within EU by AqNova's EU infrastructure is not a third-country transfer. | N/A — Intra-EU |
| EU / EEA → United States | EU-US Data Privacy Framework (DPF 2023 — European Commission adequacy decision July 2023): AqNova's US-based infrastructure providers that are DPF-certified may receive EU data under the adequacy decision. For non-DPF certified providers: EU Standard Contractual Clauses (SCCs — Commission Decision 2021/914) + Transfer Impact Assessment (TIA) as required. | EU-US DPF; EU SCCs 2021/914 |
| EU / EEA → United Kingdom | UK Adequacy Regulations — the EU has granted adequacy for the UK. Data flows to UK without additional safeguard. | EU-UK Adequacy Decision June 2021 |
| UK → Third Countries | UK International Data Transfer Agreements (IDTAs) — UK GDPR equivalent of EU SCCs. AqNova uses IDTAs for transfers from UK to non-adequate countries. UK Adequacy Regulations (e.g., EU; US via UK-US framework): apply where applicable. | UK IDTAs; UK Adequacy Regulations |
| Transfers to Nigeria; Ghana; Kenya | EU SCCs + Transfer Impact Assessment. For Nigerian vendors: NDPA §43 — cross-border transfers require that the receiving country has "an adequate level of protection" or contractual safeguards (NDPC-approved mechanisms). AqNova uses SCCs as the primary safeguard. | EU SCCs; NDPA §43 contractual safeguards |
| Transfers to South Africa | EU SCCs + contractual data processing agreements meeting POPIA operator requirements. POPIA §72 conditions for cross-border transfers. | EU SCCs; POPIA §72 operator contract |
| Transfers to India | EU SCCs + TIA. DPDPA 2023: cross-border transfers restricted to countries approved by the Indian government — AqNova monitors the approved country list as the DPDPA framework develops and uses SCCs for interim compliance. | EU SCCs; DPDPA §16 (pending approved country notification) |
| Transfers to China | PIPL Chapter 3 cross-border transfer rules — Chinese vendor data exported from China requires: government security assessment (for sensitive/large-scale data); standard contract filed with CAC; or certification. AqNova implements PIPL-compliant standard contract for transfers involving Chinese vendor personal data. | PIPL SCC (Cyberspace Administration of China standard contract) |
| Transfers to South Korea | EU has granted South Korea an adequacy decision (2021). EU→Korea transfers: adequacy applies. Other-origin transfers: PIPA cross-border transfer requirements — recipient country assessment or consent. | EU-Korea Adequacy Decision January 2021 |
| Transfers to Japan | EU has granted Japan an adequacy decision (2019 — renewed 2023). EU→Japan transfers: adequacy applies. | EU-Japan Adequacy Decision January 2019 (renewed) |
| Transfers to UAE; Saudi Arabia; Qatar | No adequacy decision from EU. EU SCCs + TIA. UAE PDPL Art. 26 cross-border transfer: allows transfer where adequate protection is ensured (contractual terms). Saudi PDPL Art. 17: SDAIA may authorize transfers by regulation — AqNova uses contractual safeguards pending regulatory framework development. | EU SCCs; UAE PDPL Art.26; Saudi PDPL Art.17 |
| Transfers to Australia; New Zealand | No EU adequacy decision. EU SCCs + TIA for EU-origin data. Australia Privacy Act: entities bound by APPs must ensure overseas recipients provide comparable protection. AqNova's data processing agreements include APP-equivalent protections. | EU SCCs; APP Schedule 1 Principle 8 |
| Transfers to Brazil (LGPD) | ANPD has not yet published its list of adequate countries. LGPD Art. 33 cross-border transfers: permitted where the receiving country provides an adequate level of protection; or where contractual clauses; BCRs; or other safeguards are in place. AqNova uses LGPD-compliant contractual clauses modeled on EU SCCs. | LGPD Art.33 contractual clauses; ANPD guidance |
| Transfers to Canada | PIPEDA: Canada has adequacy for EU purposes. EU→Canada transfers under adequacy decision. PIPEDA §4.2: organizations may transfer to third parties under contract. | EU-Canada Adequacy Decision; PIPEDA §4.2 |
All third parties who process vendor personal data on AqNova's behalf do so as data processors under written data processing agreements that comply with: GDPR Art. 28 (and equivalent provisions under UK GDPR; LGPD Art. 39; NDPA §33; POPIA operator obligations; DPDPA fiduciary-processor provisions). These agreements impose: (a) instructions-only processing; (b) confidentiality obligations; (c) security standards equivalent to AqNova's own; (d) sub-processor notification and approval obligations; (e) audit rights for AqNova; (f) data return or deletion on contract termination; and (g) cooperation with data subject rights requests.
| SECTION 5 | RETENTION PERIODS — HOW LONG WE KEEP YOUR DATA |
|---|
| AqNova retains vendor data for no longer than necessary for the purpose for which it was collected or as required by applicable law. The retention periods below represent the standard retention schedule. Specific legal requirements (e.g., tax authority record-keeping obligations) may require longer retention in specific jurisdictions. Where a longer period is legally required: the legally-mandated period governs. |
|---|
| Data Category | Standard Retention Period | Justification / Legal Basis for Retention Period | Summary |
|---|---|---|---|
| Vendor Account and Identity Data (active account) | Duration of active vendor relationship (while the vendor account is active on the AqNova platform) + 7 years after account closure. | 7 years post-closure covers the standard contractual limitation period in most jurisdictions (UK: 6 years; EU generally: 3-5 years; US: varies by state; AqNova adopts 7 years as the global standard). South Africa: PAIA requires 3-year minimum; AqNova retains 7 years. | Active account + 7 years |
| KYC / AML Verification Data (identity verification; sanctions screening; PEP checks) | 5 years from the date the business relationship ends (whichever is later: account closure or last transaction). | EU AMLD5 Art. 40: 5 years retention mandatory. UK MLR 2017 Reg. 40: 5 years. FinCEN (US): 5 years from date of transaction. CBN AML Guidelines (Nigeria): 5 years. MAS AML Notice (Singapore): 5 years. AqNova adopts the global maximum-minimum of 5 years post-relationship for all AML data. | 5 years from end of relationship |
| Financial Records (invoices; payment records; commission statements) | 7 years from the tax year to which the record relates. | IRS (US): generally 7 years. HMRC (UK): 6 years from end of accounting period (AqNova retains 7 as a global standard). Receita Federal (Brazil): 5 years; FIRS (Nigeria): 6 years; CBDT (India): 8 years (AqNova retains 8 years for India); ZATCA (Saudi Arabia): 10 years. Note: Saudi Arabia 10-year requirement governs for Saudi financial records. | 7 years (8 years India; 10 years Saudi Arabia) |
| Transaction and Order Data (order history; fulfillment records; shipping records) | 7 years from the date of the transaction. | Tax and commercial record-keeping laws globally (France: 10 years for commercial accounting; AqNova retains 10 years for France-origin records). US: 7 years standard. Australia: 5 years (Tax Administration Act); AqNova retains 7 years globally. | 7 years (10 years France) |
| Communications Data (emails; support tickets; messages; call recordings) | 3 years from the date of the communication. | Standard limitation periods for contract claims; supported by GDPR principle of storage limitation (Art. 5(1)(e)). Call recordings: 90 days for general quality monitoring; 3 years where the call relates to a specific dispute or compliance matter. | 3 years (90 days for non-dispute call recordings) |
| Product Compliance Certifications and Due Diligence Records | Duration of active vendor relationship + 5 years from account closure. | Product liability claims can arise years after the product was sold. EU Product Liability Directive: 10-year maximum. AqNova retains compliance documents for 5 years post-relationship as a proportionate standard. | Active account + 5 years |
| Dispute and Claims Records | 7 years from the date the dispute or claim is finally resolved. | Covers standard limitation periods for contract claims and tort claims in most jurisdictions (UK: 6 years; US: 3-7 years by state; Australia: 6 years; Nigeria: 6 years for contract; France: 5 years). AqNova adopts 7 years. | 7 years from resolution |
| Vendor Portal Technical Logs (login records; API call logs; security logs) | 2 years from the date the log was generated. | GDPR storage limitation; proportionate to security monitoring purpose; typically covered by 2-year rule in most jurisdictions. Extended to 5 years where a log is relevant to an active investigation or legal matter. | 2 years (5 years if relevant to active matter) |
| Marketing Consent Records | Until consent is withdrawn or the vendor account is closed; whichever is earlier. | GDPR Recital 42: proof of consent must be maintained for as long as consent is relied upon. ICO guidance: keep records of consent for as long as you need to send marketing. AqNova retains consent records for 3 years after the last marketing communication sent under that consent. | Until withdrawn or account closure; consent records 3 years |
| Beneficial Ownership Records (for AML purposes) | Same as KYC records: 5 years from end of business relationship. | EU AMLD5 beneficial ownership register requirements; UK MLR 2017; FATF Recommendation 10. | 5 years from end of relationship |
| SECTION 6 | YOUR PRIVACY RIGHTS — GLOBAL RIGHTS MATRIX |
|---|
| The privacy rights available to vendor personnel depend on the data protection law applicable in their jurisdiction of residence or location. AqNova respects and implements all rights described below to the extent they apply under the applicable law. AqNova generally applies the highest standard available — where GDPR rights apply, AqNova extends equivalent treatment to all vendor personnel globally as a matter of practice. |
|---|
| Right | EU/EEA GDPR | UK GDPR | US CCPA | Canada PIPEDA | Brazil LGPD | Nigeria NDPA | S.Africa POPIA | India DPDPA | Aus. APPs |
|---|---|---|---|---|---|---|---|---|---|
| Right to Access / Know — right to obtain confirmation of whether your personal data is processed and to receive a copy | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Right to Rectification / Correction — right to correct inaccurate or incomplete personal data | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Right to Erasure / Deletion — right to request deletion of personal data (subject to legal retention obligations) | Yes | Yes | Yes | Limited | Yes | Yes | Yes | Yes | Limited |
| Right to Restrict Processing — right to limit how personal data is used in certain circumstances | Yes | Yes | Limited | No | Yes | Yes | Yes | No | No |
| Right to Data Portability — right to receive personal data in a structured; machine-readable format | Yes | Yes | Limited | Limited | Yes | Yes | No | Yes | No |
| Right to Object — right to object to processing based on legitimate interests or for direct marketing | Yes | Yes | Limited | Yes | Yes | Yes | Yes | No | No |
| Right to Opt-Out of Sale / Sharing — right to opt out of sale or sharing for targeted advertising (CCPA-specific concept) | No | No | Yes | No | No | No | No | No | No |
| Right Not to Be Subject to Solely Automated Decisions — right to human review of significant automated decisions | Yes | Yes | Limited | No | Yes | Yes | No | No | No |
| Right to Withdraw Consent — right to withdraw consent for marketing or optional processing at any time | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Right to Lodge a Complaint — right to complain to a supervisory authority or data protection regulator | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Right to Non-Discrimination for Exercising Rights (CCPA-specific) | No | No | Yes | No | No | No | No | No | No |
| Right to Know About Automated Decision-Making — DPDPA right to explanation (India) | Yes | Yes | Limited | No | Yes | Limited | No | Yes | No |
| Yes = right exists and is fully applicable. Limited = right exists with significant exceptions or only in specific circumstances. No = right does not exist under this specific law (though AqNova may still provide the right as a matter of practice). |
|---|
| Element | Detail |
|---|---|
| Submit a Rights Request | Email: dpo@aqnovamarketplace.com with subject line "Vendor Privacy Rights Request — [Right Type] — [Your Name]". Vendor Portal: use the Privacy Rights section under Account Settings (where available). Post: Data Protection Officer, AqNova Marketplace / Arivon Holding Corporation, Huntington Park, CA, USA. |
| Identity Verification | To protect vendor data from unauthorized access: AqNova will verify the identity of the person making a rights request before acting on it. Verification: typically by confirming email address; account details; and (for high-risk requests such as data erasure) one additional verification factor. AqNova will not use the identity verification process to delay or obstruct legitimate rights requests. |
| Response Timelines | GDPR: 1 month (extendable by 2 months for complex requests; with notification). CCPA: 45 days (extendable by 45 days). LGPD: 15 days. NDPA: 30 working days. POPIA: 30 days. PIPEDA: 30 days. DPDPA: as specified by DPBI regulations. AqNova targets 30-day response globally as a standard; and will confirm receipt within 5 business days of receiving any rights request. |
| Requests That Cannot Be Fulfilled | AqNova will tell you if we cannot fulfill a rights request and why. Common reasons: legal retention obligation overrides erasure; the data is not personal data (business registration data about a company is not personal data); the data belongs to another person. For each refused request: you have the right to complain to the applicable supervisory authority. |
| SECTION 7 | JURISDICTION-SPECIFIC SUPPLEMENTS — ADDITIONAL DISCLOSURES REQUIRED BY LOCAL LAW |
|---|
| For California residents: this section provides the specific disclosures required by the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), effective January 1, 2023. Enforced by the California Privacy Protection Agency (CPPA) and the California Attorney General (AG). |
|---|
| CCPA/CPRA Element | Disclosure |
|---|---|
| B2B / Commercial Context Note | The CCPA contains an exemption for personal information collected in the context of a business-to-business relationship (§1798.145(w)). The status of the B2B exemption under CPRA is subject to regulatory guidance from the CPPA. AqNova complies with all applicable CCPA/CPRA requirements for California-resident vendor personnel to the full extent they apply, and provides the disclosures below as a matter of best practice. |
| Categories of Personal Information Collected (CCPA §1798.100) | AqNova collects the following CCPA categories from vendor personnel: (A) Identifiers (name; email; account ID); (B) Customer Records Information (contact details; financial data); (C) Protected Classification Characteristics (nationality — for KYC only); (D) Commercial Information (transaction data; product listings); (F) Internet/Electronic Activity (Vendor Portal usage; technical logs); (G) Geolocation (country; work address); (H) Audio/Video (call recordings where applicable); (K) Professional Information (job title; role at vendor company); (L) Education Information (not typically collected). |
| Sensitive Personal Information (CCPA §1798.121) | AqNova collects the following sensitive personal information where required for compliance: (1) Government ID numbers (for KYC); (2) Financial account information (for payment processing); (3) Biometric data (facial verification for identity — where used). AqNova uses sensitive personal information only for the purposes disclosed in this Notice and does not use it to infer characteristics. "Limit the Use of My Sensitive Personal Information": contact dpo@aqnovamarketplace.com. |
| Sale or Sharing of Personal Information | AqNova does NOT sell vendor personal information as defined under CCPA. AqNova does NOT share vendor personal information for cross-context behavioral advertising. Vendor data shared with third parties (payment processors; KYC providers; tax authorities; logistics partners) is shared for operational purposes under service provider or contractor arrangements — not "sales" or "sharing" as defined under CCPA. |
| California-Specific Rights | California vendor personnel have: the right to know what personal information is collected and how it is used; the right to delete personal information (with exceptions); the right to correct inaccurate personal information; the right to opt-out of sale or sharing (not applicable here — AqNova does not sell or share as defined); the right to limit use of sensitive personal information; the right to non-discrimination for exercising CCPA rights. To exercise: dpo@aqnovamarketplace.com. |
| Authorized Agent | California residents may use an authorized agent to submit CCPA requests. AqNova requires: written authorization signed by the California resident; or proof that the agent holds a power of attorney. AqNova may verify the California resident's identity directly despite the use of an agent. |
| PIPEDA Element | Disclosure |
|---|---|
| Governing Principle | PIPEDA Schedule 1 (Ten Fair Information Principles) governs AqNova's collection; use; and disclosure of personal information about Canadian vendor personnel. AqNova has designated a Privacy Officer for PIPEDA purposes: dpo@aqnovamarketplace.com. |
| Consent Under PIPEDA | PIPEDA §6.1-6.3: where AqNova relies on implied consent (for processing necessary to provide the vendor service under the Vendor Agreement); this implied consent arises from the vendor entering the commercial relationship. For marketing communications: express consent is obtained separately. Vendors may withdraw consent at any time (subject to legal and contractual restrictions) by contacting dpo@aqnovamarketplace.com. |
| Breach Notification — PIPEDA §10.1 | AqNova will notify the OPC (Office of the Privacy Commissioner of Canada) and affected Canadian vendors of any breach of security safeguards that creates a real risk of significant harm, within a reasonable timeframe and in the prescribed form. |
| Quebec — Law 25 (Bill 64) | For Quebec-based vendor personnel: Quebec's Law Modernizing Privacy Protection Provisions (Law 25 / Bill 64 — amending Act Respecting the Protection of Personal Information in the Private Sector) applies additional requirements including: mandatory privacy impact assessments (PIAs); enhanced data breach notification; right to data portability; and the right to deindex information. |
| LGPD Element | Disclosure |
|---|---|
| ANPD Compliance | AqNova complies with the Lei Geral de Proteção de Dados (LGPD — Law 13.709/2018) for Brazilian vendor personnel. AqNova has appointed a Data Protection Officer (Encarregado de Proteção de Dados) accessible at dpo@aqnovamarketplace.com. |
| Lawful Bases Under LGPD | AqNova processes Brazilian vendor data under the following LGPD bases (Art. 7): Art. 7(II) — compliance with legal obligations; Art. 7(V) — contract performance; Art. 7(VI) — regular exercise of rights in judicial/administrative/arbitration proceedings; Art. 7(IX) — legitimate interests (for fraud prevention; security). Marketing communications: Art. 7(I) — consent. |
| LGPD Rights | Brazilian vendors have all rights under LGPD Art. 18: confirmation of processing; access; correction; anonymization/blocking/deletion; portability; sharing information; not providing consent; and revocation of consent. AqNova responds to LGPD requests within 15 days as required. |
| Breach Notification — LGPD Art. 48 | AqNova will notify the ANPD and affected Brazilian vendors of security incidents that may create risk or damage to vendors, within a reasonable timeframe. |
| NDPA Element | Disclosure |
|---|---|
| NDPA Compliance | AqNova complies with the Nigeria Data Protection Act 2023 (NDPA) for Nigerian vendor personnel. The NDPA supersedes the NDPR 2019. The Nigeria Data Protection Commission (NDPC) is the regulatory authority. AqNova has designated a Data Protection Officer accessible at dpo@aqnovamarketplace.com. |
| Lawful Bases Under NDPA | NDPA §25: AqNova processes Nigerian vendor data under: §25(1)(b) — contract performance; §25(1)(c) — legal obligation; §25(1)(f) — legitimate interests. Marketing: §25(1)(a) — consent. |
| Data Localization | NDPA §43: cross-border transfer of personal data is subject to NDPC oversight. Where AqNova transfers Nigerian vendor data outside Nigeria: appropriate safeguards are in place (contractual clauses meeting NDPA standards). |
| NDPA Rights | Nigerian vendor personnel have rights including: right to access; rectification; deletion; restriction; objection; and data portability under the NDPA. Requests: dpo@aqnovamarketplace.com. Response: 30 working days. |
| POPIA Element | Disclosure |
|---|---|
| Responsible Party | Under POPIA, AqNova (Arivon Holding Corporation) is the "responsible party" for personal information processed about South African vendor personnel. AqNova's Information Officer (equivalent to DPO) is registered with the Information Regulator of South Africa. Contact: dpo@aqnovamarketplace.com. |
| PAIA (Access to Information) | South African vendors may also request access to records under the Promotion of Access to Information Act (PAIA). AqNova has a PAIA Manual available on request. |
| Breach Notification — POPIA §22 | AqNova will notify the Information Regulator and affected South African vendors of security compromises of personal information without unreasonable delay. |
| Eight Conditions for Lawful Processing | AqNova's processing of South African vendor data complies with all eight POPIA Conditions for Lawful Processing: (1) Accountability; (2) Processing Limitation; (3) Purpose Specification; (4) Further Processing Limitation; (5) Information Quality; (6) Openness; (7) Security Safeguards; (8) Data Subject Participation. |
| DPDPA Element | Disclosure |
|---|---|
| DPDPA Compliance | AqNova complies with the Digital Personal Data Protection Act 2023 (DPDPA) for Indian vendor personnel. The DPDPA is being implemented in phases; AqNova monitors DPBI (Data Protection Board of India) notifications for operational implementation dates and requirements. |
| Data Fiduciary and Data Principal | Under the DPDPA: AqNova is a "Data Fiduciary" and Indian vendor personnel are "Data Principals." AqNova's obligations include: notice and consent where required; accuracy; security; and cooperation with Data Principal rights requests. |
| DPDPA Rights | Indian vendor personnel have the right to: access information about processing; correction and erasure; grievance redressal (through AqNova's internal mechanism and through the DPBI); and nomination of another person to exercise rights in case of death or incapacity. |
| Significant Data Fiduciary | AqNova monitors whether it meets the criteria for designation as a "Significant Data Fiduciary" (SDF) under the DPDPA, which triggers additional obligations including a Data Protection Officer and Data Protection Impact Assessments. |
| Middle East Element | Disclosure |
|---|---|
| UAE PDPL (Federal) | AqNova complies with UAE Federal Decree-Law No. 45/2021 (PDPL) for UAE-based vendor personnel. Cross-border transfers: UAE PDPL Art. 26 — AqNova ensures adequate protection through contractual clauses. DPO: dpo@aqnovamarketplace.com. UAE TRA is the regulatory authority. |
| DIFC Data Protection Law | For vendor personnel at businesses incorporated in the DIFC: DIFC Law No. 5 of 2018 (as amended) applies. DIFC Commissioner of Data Protection. AqNova's DIFC-engaged activities comply with the DIFC DPL standard. |
| Saudi Arabia PDPL | AqNova complies with the Saudi Arabia Personal Data Protection Law (PDPL) effective September 2023, for Saudi-based vendor personnel. SDAIA (Saudi Data and AI Authority) and the NCA (National Cybersecurity Authority) govern. Cross-border transfer: SDAIA authorization or equivalent contractual safeguards. |
| GCC (Qatar; Kuwait; Bahrain) | AqNova monitors and complies with applicable data protection laws in Qatar (Law No. 13/2016 on Personal Data Privacy); Kuwait (in development); and Bahrain (Personal Data Protection Law 2018 — Law No. 30/2018). Local counsel advises on jurisdiction-specific requirements. |
| APAC Element | Disclosure |
|---|---|
| Australia (Privacy Act / APPs) | AqNova complies with the Privacy Act 1988 (Cth) and Australian Privacy Principles for Australian vendor personnel. AqNova's Privacy Policy (covering Australian obligations) is available at aqnovamarketplace.com/privacy. Notifiable Data Breaches (NDB) Scheme: AqNova will notify the OAIC and affected Australian vendors of eligible data breaches. Complaints: OAIC website at oaic.gov.au. |
| Singapore (PDPA) | AqNova complies with the Personal Data Protection Act 2012 (revised 2021) for Singapore vendor personnel. AqNova has appointed a Data Protection Officer. Mandatory breach notification: within 3 calendar days of AqNova becoming aware of a notifiable data breach. PDPC is the regulatory authority. |
| Japan (APPI) | AqNova complies with the Act on the Protection of Personal Information for Japanese vendor personnel. Cross-border transfer: AqNova uses standard contracts compliant with PPC guidance. Japanese vendor personnel may request disclosure; correction; or deletion of their personal information. Complaints: PPC Japan. |
| South Korea (PIPA) | AqNova complies with the Personal Information Protection Act for South Korean vendor personnel. PIPA has one of the most stringent global regimes. Minimum collection; purpose limitation; breach notification within 72 hours to PIPC; and mandatory appointment of a Chief Privacy Officer (CPO). Cross-border transfer: PIPA Chapter 3 conditions or data subject consent. |
| China (PIPL) | AqNova complies with the Personal Information Protection Law (PIPL — effective November 1, 2021) for Chinese vendor personnel and for processing of data originally collected in China. PIPL imposes: purpose limitation; data minimization; extraterritorial provisions; mandatory security assessment or standard contract for cross-border transfers. Complaints: Cyberspace Administration of China (CAC). |
| Philippines (DPA 2012) | AqNova complies with the Data Privacy Act 2012 and implementing rules for Philippine vendor personnel. National Privacy Commission (NPC). Personal data subject rights under the DPA 2012 are equivalent to GDPR. |
| Thailand (PDPA) | AqNova complies with the Personal Data Protection Act B.E. 2562 (2019) for Thai vendor personnel. PDPA became fully effective June 1, 2022. PDPC Thailand. Breach notification: 72 hours of becoming aware. |
| LATAM Element | Disclosure |
|---|---|
| Mexico (LFPDPPP) | AqNova complies with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP 2010) and its Reglamento for Mexican vendor personnel. Aviso de Privacidad: this Notice constitutes AqNova's Aviso de Privacidad as required by LFPDPPP Art. 15-17. INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales) is the regulatory authority. |
| Colombia (Ley 1581/2012) | AqNova complies with the Colombian Personal Data Protection Law (Ley 1581/2012 and Decree 1377/2013) for Colombian vendor personnel. SIC (Superintendencia de Industria y Comercio) is the regulatory authority. |
| Argentina (Ley 25.326) | AqNova complies with the Personal Data Protection Law 25.326 for Argentine vendor personnel. AAIP (Agencia de Acceso a la Información Pública) is the regulatory authority. Argentina has EU adequacy. |
| Chile (Ley 19.628 — reform pending) | AqNova complies with Chile's existing Law 19.628 on Personal Data Protection and monitors the reform legislation (PDL 11.144 — Proyecto de Ley Protección de Datos) for when it becomes effective. Consejo para la Transparencia governs existing law; a new authority will govern the reform. |
| Peru (Ley 29.733) | AqNova complies with Peru's Personal Data Protection Law 29.733 and Regulation (DS 003-2013-JUS) for Peruvian vendor personnel. ANPD (Autoridad Nacional de Protección de Datos) is the regulatory authority. |
| SECTION 8 | SECURITY, COOKIES, SUPERVISORY AUTHORITIES & HOW TO CONTACT US |
|---|
| Security Element | Detail |
|---|---|
| Technical Measures | Encryption: all vendor data transmitted to and from the AqNova Vendor Portal is encrypted using TLS 1.3 or higher. Data at rest: AES-256 encryption for stored personal data. Access controls: role-based access control (RBAC) — only AqNova personnel with a legitimate need to access vendor data are authorized. Two-factor authentication (2FA): required for all Vendor Portal accounts. Penetration testing: conducted at least annually by an independent security firm. Vulnerability management: continuous monitoring and patching program. |
| Organizational Measures | Data protection training: all AqNova employees and contractors with access to vendor data complete mandatory data protection training (connected to HR4.3 LEARN Framework mandatory training matrix). Information Security Policy: maintained; reviewed annually; enforced by CCRO. Vendor security assessments: all data processors are assessed for security standards before engagement. Incident response plan: documented; tested annually; with defined notification timelines for regulatory and data subject notification. |
| Incident Notification Timelines | GDPR / UK GDPR: supervisory authority notification within 72 hours of becoming aware of a breach. Affected data subjects: without undue delay where high risk. CCPA / CPRA: notification to affected California residents in "expedient time" and without "unreasonable delay." LGPD: ANPD notification within "reasonable timeframe." NDPA / POPIA / DPDPA: notification within the applicable regulatory timeframe. Australia NDB: notification to OAIC and affected individuals without unreasonable delay. Singapore PDPA: notification within 3 calendar days for notifiable breaches. |
AqNova uses automated systems to assess vendor applications, flag potential fraud, screen against sanctions lists, and calculate performance metrics. These automated processes may produce outcomes that affect vendor status (for example, temporary account suspension pending manual review if a sanctions screen returns a potential match). Where an automated decision has a significant effect on a vendor or vendor personnel, AqNova will: (a) notify the affected vendor of the automated decision; (b) provide an explanation of the basis for the decision; and (c) offer the opportunity to request human review. Human review: available to all EU/UK vendors as a GDPR Art. 22 right; AqNova extends human review as a matter of practice to all vendors globally.
AqNova reviews and updates this Notice at least annually and whenever there is a material change to our data processing activities or to the applicable law. Material changes: notified to vendors via: email to the vendor contact address on record; a notice on the Vendor Portal homepage; or both. The effective date of each version is shown on the cover of this Notice. Continued use of the AqNova Marketplace after the effective date of a new version constitutes acknowledgment of the updated Notice (where acknowledgment is the applicable requirement; where consent is required for a new processing activity under applicable law: AqNova will obtain consent separately).
| AqNova Data Protection Officer — Contact Details Email (preferred): dpo@aqnovamarketplace.com EU / UK Representative: eurep@aqnovamarketplace.com Postal Address: Data Protection Officer, AqNova Marketplace / Arivon Holding Corporation, Huntington Park, California, USA Vendor Portal Rights Request: vendor.aqnovamarketplace.com/privacy-rights Response commitment: Acknowledgment within 5 business days; substantive response within 30 days (or the applicable statutory period if shorter). |
|---|
| APPENDIX | VERSION HISTORY, DEFINITIONS & APPROVAL LOG |
|---|
| Term | Definition | Legal Reference |
|---|---|---|
| Personal Data / Personal Information | Any information that directly or indirectly identifies a natural person (an individual human being). Does not include anonymized data that cannot reasonably be used to identify an individual. Equivalent terms: "personal information" (CCPA; PIPEDA; Australia; NZ; India); "dados pessoais" (LGPD); "données personnelles" (French law); "Personenbezogene Daten" (German law). | GDPR Art. 4(1); CCPA §1798.140 |
| Processing | Any operation performed on personal data — including collection; recording; organization; structuring; storage; adaptation; retrieval; use; disclosure; erasure; destruction. | GDPR Art. 4(2) |
| Data Controller / Data Fiduciary / Responsible Party / Business | The entity that determines the purposes and means of processing personal data. AqNova (Arivon Holding Corporation) in the context of this Notice. | GDPR Art. 4(7); DPDPA (India); POPIA; CCPA |
| Data Processor / Service Provider / Operator | A third party that processes personal data on behalf of the Data Controller, under the Controller's instructions, pursuant to a data processing agreement. | GDPR Art. 4(8); CCPA §1798.140(ag); LGPD |
| Data Subject / Data Principal | The natural person (individual human being) to whom personal data relates. In the context of this Notice: vendor personnel whose personal data AqNova processes. | GDPR Art. 4(1); DPDPA Art. 2(j) |
| Vendor / Seller | A business entity registered or applying to register as a seller on the AqNova Marketplace platform. The vendor is typically a legal entity; this Notice applies to the personal data of the individual representatives of the vendor. | AqNova Vendor Agreement |
| Vendor Personnel | Individuals associated with vendor businesses whose personal data AqNova processes — including company directors; employees; beneficial owners; and contact persons. | Defined for this Notice |
| Standard Contractual Clauses (SCCs) | Contractual clauses approved by the European Commission for the international transfer of personal data from the EU/EEA to non-adequate third countries. Also used as a model for equivalent transfer mechanisms globally. | GDPR Art. 46(2)(c); Commission Decision 2021/914 |
| KYC (Know Your Customer) | A set of identity verification and due diligence procedures required by AML laws globally — including verification of the identity of the vendor's beneficial owners and screening against sanctions lists. | AMLD5/6 (EU); MLR 2017 (UK); BSA (US); CBN AML (Nigeria) |
| Lawful Basis / Legal Basis | The legal justification for processing personal data. Under GDPR: contract; legal obligation; vital interests; public task; legitimate interests; or consent. Equivalent provisions apply under LGPD; NDPA; POPIA; and other laws. | GDPR Art. 6 |
| Version | Date | Summary | Approved By |
|---|---|---|---|
| 1.0 | June 2026 | Initial release — AqNova Vendor Data Privacy Notice. CLEAR Framework (5 principles: Compliant Globally; Lawful Basis for All; Explicit Transparency; Accountable Processing; Rights-Ready). Section 1: Controller identity (Arivon Holding Corporation; EIN 41-3210066; DPO at dpo@aqnovamarketplace.com; EU Rep eurep@aqnovamarketplace.com); 17-law compliance framework table (GDPR; UK GDPR; Swiss nFADP; CCPA/CPRA; PIPEDA; LGPD; NDPA 2023; POPIA; DPDPA 2023; PDPA Singapore; APPI Japan; PIPA South Korea; PIPL China; PDPL UAE; PDPL Saudi Arabia; Australia Privacy Act APPs; NZ Privacy Act 2020; PDPA Thailand). Section 2: Personal data categories (10 types including Identity; Contact; Account; KYC; Financial; Communications; Compliance/DD; Performance/Transaction; Technical; Beneficial Ownership); Sensitive data (biometric; criminal; nationality); Business data (5 categories). Section 3: Purposes and lawful bases table (8 purposes × 6 columns: purpose; GDPR basis; UK/Swiss equivalent; LGPD; other law; data categories); LIA summary for legitimate interests processing. Section 4: Data sharing (9 recipient categories with lawful basis); International transfers table (14 transfer routes: EU→US DPF+SCCs; EU→UK adequacy; UK IDTAs; Nigeria NDPA §43; South Africa POPIA §72; India DPDPA §16; China PIPL SCC; South Korea adequacy; Japan adequacy; UAE/Saudi contractual; Australia APPs; Brazil LGPD Art.33; Canada adequacy+PIPEDA); DPA obligations (GDPR Art.28). Section 5: Retention schedule (10 data categories with period; justification; summary — KYC: 5yr; financial: 7yr/8yr India/10yr Saudi; account: 7yr post-closure; AML: 5yr; transaction: 7yr/10yr France; communications: 3yr; product compliance: 5yr post-closure; disputes: 7yr; logs: 2yr; consent records: 3yr). Section 6: Rights matrix (12 rights × 9 jurisdictions: EU GDPR; UK GDPR; US CCPA; Canada PIPEDA; Brazil LGPD; Nigeria NDPA; South Africa POPIA; India DPDPA; Australia APPs — Yes/Limited/No with color coding); rights exercise process (email; portal; post; 5-day acknowledgment; 30-day response). Section 7: Jurisdiction supplements (9 supplements: California CCPA/CPRA — B2B note; categories; sensitive PI; no sale/share; authorized agent; Canada PIPEDA+Quebec Law 25; Brazil LGPD+ANPD; Nigeria NDPA 2023+NDPC; South Africa POPIA+PAIA+8 conditions; India DPDPA+DPBI+SDF; Middle East UAE PDPL+DIFC DPL+Saudi PDPL+GCC; APAC Australia NDB+Singapore 3-day+Japan SCCs+South Korea PIPA+China PIPL+Philippines DPA+Thailand PDPA; LATAM Mexico LFPDPPP+Colombia Ley 1581+Argentina Ley 25.326 adequacy+Chile+Peru). Section 8: Security measures (TLS 1.3; AES-256; RBAC; 2FA; annual pen testing; NDB timelines by jurisdiction: GDPR 72h; LGPD reasonable; NDPA/POPIA/DPDPA applicable; Australia NDB reasonable; Singapore 3 cal. days); Cookie table (essential/analytics; consent management); Automated decision-making (sanctions screening; human review right for all vendors); Notice changes protocol; Supervisory authority directory (24 authorities with website and email); DPO contact block. | CCRO (Ronke Olatoye) + DPO + CEO (Ubon Isang) |
AqNova Marketplace | Arivon Holding Corporation | EIN: 41-3210066
Vendor Data Privacy Notice | CLEAR Framework | Version 1.0 | Effective June 2026
DPO: dpo@aqnovamarketplace.com | EU Rep: eurep@aqnovamarketplace.com
Required under GDPR Art.13/14 · CCPA/CPRA · PIPEDA · LGPD · NDPA · POPIA · DPDPA · 17+ Equivalent Laws