AqNova Marketplace Policies & Disclosures
Global Legal Footer Framework
Comprehensive Compliance & Platform Governance Reference
&
Global Transfer Safeguards, Mechanisms & Third-Party Sharing Obligations — Master Edition
Effective Date: April 7, 2026 | Version 1.0 | Arivon Holding Corporation
| Global Regulatory Frameworks — Data Transfers & Third-Party Disclosure EU: GDPR Arts. 44–49 — International Transfer Chapter; SCCs (Implementing Decision 2021/914/EU) EDPB Guidelines 05/2021 on SCCs; EDPB Recommendations 01/2020 (TIAs) UK: UK GDPR Art. 46; IDTA (ICO, March 2022); UK Adequacy Regulations ICO International Data Transfer Guidance (2022 update) United States: CCPA/CPRA — Cross-context behavioral advertising sharing disclosure US-EU Data Privacy Framework (DPF, effective July 17, 2023) US-UK Data Bridge (effective Oct 17, 2023) Canada: PIPEDA Principle 4.1.3 — Comparable protection for cross-border transfers Quebec Law 25 — Privacy Impact Assessment for extraterritorial transfers Brazil: LGPD Art. 33 — International transfer conditions; ANPD standard clauses Nigeria: NDPA 2023 Sections 40-43 — Cross-border transfer framework Kenya: DPA 2019 Sections 48-50 — Third-country transfer conditions South Africa: POPIA Section 72 — Third-country transfer conditions Ghana: DPA 2012 Part VII — Third-country transfer framework Egypt: PDPL 151/2020 — Restrictions on cross-border personal data transfers India: DPDPA 2023 Section 16 — Cross-border transfer restrictions Australia: APP 8 — Cross-border disclosure; Privacy Act s. 16C Singapore: PDPA Section 26 — Transfer obligation Japan: APPI Art. 24 — Third-country provision; PPC adequacy recognition South Korea: PIPA Art. 17 — Third-country provision conditions China: PIPL Arts. 38-43 — Security assessment; standard contract; certification Indonesia: PDP Law 2022 Art. 56 — Cross-border transfer conditions Colombia: Ley 1581/2012 Art. 26 — International transmission conditions Argentina: Ley 25,326 Art. 12 — Cross-border transfer to adequate countries Mexico: LFPDPPP Arts. 36-37 — International data transfer rules UAE: PDPL Decree-Law 45/2021 — Cross-border transfer framework |
|---|
| ⚠ IMPORTANT NOTICE THIS DOCUMENT COVERS TWO LINKED SECTIONS: SECTION 3.5: WHERE YOUR DATA GOES — INTERNATIONAL TRANSFER NOTICE SECTION 3.6: WHO RECEIVES YOUR DATA — THIRD-PARTY SHARING DISCLOSURE THESE DISCLOSURES ARE PROVIDED IN COMPLIANCE WITH GDPR ARTS. 13–14, CCPA, AND EQUIVALENT GLOBAL TRANSPARENCY OBLIGATIONS. YOUR DATA IS NEVER TRANSFERRED OR SHARED WITHOUT APPROPRIATE SAFEGUARDS. YOU RETAIN FULL RIGHTS OVER YOUR DATA. |
|---|
| Quick Reference — Sections 3.5 & 3.6 SECTION 3.5 — CROSS-BORDER DATA TRANSFER NOTICE: 3.5.1 Why Data Crosses Borders — The Nature of Global Marketplace Operations 3.5.2 Destination Countries — Where Your Data Is Transferred 3.5.3 Transfer Mechanism 1 — Standard Contractual Clauses (SCCs) 3.5.4 Transfer Mechanism 2 — UK International Data Transfer Agreements (IDTAs) 3.5.5 Transfer Mechanism 3 — Adequacy Decisions 3.5.6 Transfer Mechanism 4 — Binding Corporate Rules (BCRs) 3.5.7 Transfer Mechanism 5 — Equivalent Contractual Safeguards (Non-EU/UK Origins) 3.5.8 Transfer Impact Assessments (TIAs) 3.5.9 Jurisdiction-Origin Transfer Mechanism Matrix 3.5.10 Government Access & Law Enforcement Considerations 3.5.11 Your Rights in Connection with Transfers SECTION 3.6 — THIRD-PARTY DATA SHARING DISCLOSURE: 3.6.1 Categories of Third-Party Recipients 3.6.2 Payment Processors 3.6.3 Logistics & Fulfillment Partners 3.6.4 Analytics & Performance Providers 3.6.5 Marketing & Advertising Platforms 3.6.6 Fraud Prevention & Security Services 3.6.7 Identity Verification & KYC Providers 3.6.8 Cloud Infrastructure & Hosting 3.6.9 Customer Support Technology 3.6.10 Regulatory Authorities & Law Enforcement 3.6.11 Vendors — Buyer Data Sharing Framework 3.6.12 Referral Partners 3.6.13 Business Transfers (Mergers & Acquisitions) 3.6.14 Sub-Processor Register & Updates |
|---|
AqNova operates as a genuinely global e-commerce marketplace. By design, the Platform connects buyers and vendors located in different countries, routes transactions through international payment networks, deploys cloud infrastructure distributed across multiple geographic regions, and engages specialist service providers located around the world. The international transfer of personal data is therefore an operational necessity — not a choice — for AqNova to deliver its services to users across more than 25 countries.
AqNova is deeply aware that international data transfers carry regulatory and privacy implications for users in many jurisdictions — particularly those subject to GDPR, UK GDPR, LGPD, PIPL, DPDPA, and equivalent high-protection frameworks. This Notice provides full transparency about where your data goes, why it goes there, and what safeguards protect it in transit and at the destination.
| Principal Reasons Personal Data Is Transferred Internationally 1. ORDER FULFILLMENT ACROSS BORDERS When a Buyer in one country purchases from a Vendor in another country, order data (buyer name, address, items) must flow between jurisdictions. This is the most fundamental transfer and the reason AqNova exists. 2. CLOUD INFRASTRUCTURE AqNova's primary cloud infrastructure is hosted on AWS (Amazon Web Services) with primary region: [AWS US-East / EU-West — to be confirmed at go-live]. Data stored on cloud infrastructure may be replicated across geographic regions for redundancy and disaster recovery purposes. 3. PAYMENT PROCESSING Payment data flows through global payment network infrastructure (Visa, Mastercard, Stripe, PayPal) which process transactions through servers located in multiple countries. 4. SPECIALIST SERVICE PROVIDERS AqNova engages best-in-class specialist providers for analytics, fraud prevention, KYC verification, customer support, and security — many of which are headquartered in or process data in the United States or other third countries. 5. INTRA-GROUP OPERATIONS AqNova's parent company Arivon Holding Corporation and affiliated entities may process data across their respective jurisdictions in the course of corporate governance, legal compliance, and platform operations. |
|---|
AqNova transfers personal data to the following countries and regions in connection with its Platform operations. The legal basis for each transfer (the mechanism relied upon) is identified in the columns below:
| Destination Country / Region | Data Categories Transferred | Recipient Type(s) | Transfer Mechanism |
|---|---|---|---|
| United States | All categories — identity, contact, financial, transaction, technical, usage | Primary cloud infrastructure (AWS); Payment processors (Stripe, PayPal); Analytics (Google); Marketing platforms (Meta, Google Ads, TikTok); Fraud detection; KYC providers; Parent entity (Arivon Holding Corporation) | EU: SCCs (2021/914) + TIA; UK: IDTA; CA: SCCs or adequacy; Brazil: LGPD Art. 33 SCCs; India: DPDPA consent/adequacy; Other: Contractual safeguards |
| European Union / EEA | Identity, contact, transaction, usage data for EU-based Vendors and Buyers | EU-based Vendors; EU logistics partners; EU payment processors; GDPR-regulated service providers | Adequacy (EU member states are not 'third countries'); contractual safeguards for sub-processors |
| United Kingdom | Identity, contact, transaction data for UK-based users and Vendors | UK-based Vendors; UK logistics partners; UK service providers; ICO-regulated processors | EU: SCCs + UK Addendum (IDTA); US: US-UK Data Bridge; Other: IDTA or equivalent |
| Canada | Identity, contact, transaction, KYC data | Canadian Vendors; Canadian logistics partners; Analytics (where applicable); KYC providers | EU: Adequacy Decision (2001, reaffirmed); UK: UK-Canada adequacy; Brazil: ANPD adequacy assessment; Other: Contractual safeguards |
| Australia | Transaction, identity, usage data | Australian Vendors; Australian logistics; Analytics (where applicable) | EU: SCCs + TIA (Australia: no adequacy decision); UK: IDTA + TIA; Other: APP 8 contractual obligations |
| Singapore | Transaction, identity data | Singapore-based Vendors; APAC logistics partners; Regional technology providers | EU: SCCs + TIA; UK: IDTA; Brazil: LGPD Art. 33; Other: PDPA s. 26 contractual safeguards |
| Japan | Transaction, identity data | Japanese Vendors; APAC logistics; Analytics (Google Japan infrastructure) | EU: Adequacy Decision (2019); UK: UK-Japan adequacy (under assessment); Other: SCCs or contractual |
| India | Transaction data; KYC for India-based Vendors | Indian Vendors; KYC providers; Payment processors (UPI/Razorpay); Logistics (India delivery) | EU: SCCs + TIA; UK: IDTA; Brazil: LGPD Art. 33; DPDPA 2023: subject to restricted country list (pending) |
| Nigeria | Transaction, identity data for Nigeria-based Vendors and Buyers | Nigerian Vendors (Sahara Eagle Ltd entity); Local payment providers (M-Pesa, Flutterwave); NEPC-regulated logistics | EU: SCCs + TIA; UK: IDTA; Brazil: LGPD Art. 33; NDPA 2023: contractual safeguards (NDPC regulations pending) |
| South Africa | Transaction, identity data for South Africa-based users | South African Vendors; SA logistics; Local payment providers | EU: SCCs + TIA; UK: IDTA; Brazil: LGPD Art. 33; POPIA Section 72 binding agreement |
| Kenya | Transaction data for Kenya-based users | Kenyan Vendors; M-Pesa payment processing; Local logistics | EU: SCCs + TIA; UK: IDTA; DPA Kenya 2019 — contractual safeguards |
| Brazil | Transaction, identity data for Brazil-based users and Vendors | Brazilian Vendors; PIX payment infrastructure; Brazilian logistics; ANVISA-related compliance partners | EU: SCCs + TIA; UK: IDTA; LGPD Art. 33: ANPD adequacy or SCCs where applicable to onward transfers |
| Colombia / Chile / Argentina / Mexico | Transaction data for LatAm-based users | LatAm Vendors; Regional logistics; Local payment providers (SPEI/PSE/etc.) | EU: SCCs + TIA; UK: IDTA; National data protection law contractual safeguards |
| UAE / Middle East | Transaction, identity data for ME-based users (where applicable) | ME-based Vendors; Regional payment providers; Logistics | EU: SCCs + TIA; UK: IDTA; UAE PDPL contractual safeguards (Decree-Law 45/2021) |
| China (limited) | Minimal — where Chinese residents access the Platform | Subject to PIPL security assessment requirements for large-volume transfers. AqNova limits China-specific processing to the minimum required. | EU: SCCs; UK: IDTA; PIPL Art. 38: CAC standard contract or security assessment where thresholds met |
This table will be updated whenever AqNova adds a new destination country or changes a transfer mechanism. The current version and date are recorded in the document header. Users may request a point-in-time copy of the transfer destination list by contacting dpo@aqnova.co.
Standard Contractual Clauses (SCCs) are pre-approved contractual terms adopted by the European Commission that provide appropriate safeguards for international data transfers from the EEA to countries that do not benefit from an adequacy decision. SCCs create binding obligations between the exporting entity (AqNova as data exporter) and the receiving entity (the importer) to ensure that the importer processes the transferred data to an equivalent standard of protection as required under GDPR.
AqNova uses the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 of June 4, 2021 ('New SCCs'), which replaced the 2004 and 2010 SCCs. The 2021 SCCs comprise four modules:
Module 1 (Controller-to-Controller): used where AqNova transfers personal data to a third party acting as an independent data controller for its own purposes (e.g., payment processors where they act as independent controllers; logistics carriers).
Module 2 (Controller-to-Processor): used where AqNova transfers personal data to a service provider that processes data only on AqNova's instructions (e.g., cloud hosting providers, analytics tools, fraud detection services).
Module 3 (Processor-to-Processor): used where AqNova, acting as a processor on behalf of a Vendor, engages a sub-processor in a third country.
Module 4 (Processor-to-Controller): used in limited circumstances where AqNova processes data as a processor and transfers back to the controller located in a third country.
AqNova implements the following supplementary measures alongside SCCs, consistent with EDPB Recommendations 01/2020 on measures that supplement transfer tools:
Encryption: all personal data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256). Encryption keys are held by AqNova and not provided to the importing entity, except to the extent necessary for the importing entity to process the data for its authorized purpose.
Pseudonymization: where technically feasible without impairing the legitimate processing purpose, personal data transferred to analytics and marketing providers is pseudonymized (e.g., hashed email addresses, device IDs rather than full profiles).
Data minimization: only the minimum necessary data for the specific transfer purpose is included in each cross-border transfer.
Access controls: AqNova's DPAs with all importers include requirements that access to transferred data is restricted to personnel with a documented need-to-know and subject to appropriate authentication.
Contractual protections: all SCC-based transfers include provisions requiring the importer to: notify AqNova of any government access requests; challenge overreaching requests where legally permitted; notify AqNova of any breaches affecting the transferred data; and cooperate with AqNova's audit rights.
Copies of AqNova's executed SCCs, or the relevant modules, are available to EU/EEA data subjects and supervisory authorities upon lawful request. To request a copy, contact dpo@aqnova.co with the subject line 'SCC Documentation Request.' AqNova may redact commercially sensitive information that is not necessary to demonstrate the adequacy of the safeguards.
Following the UK's departure from the European Union, the UK GDPR (retained in domestic law as the UK version of GDPR under the European Union (Withdrawal) Act 2018) requires its own transfer safeguards for transfers of personal data from the United Kingdom to countries outside the UK that do not benefit from a UK adequacy regulation. The UK International Data Transfer Agreement (IDTA) is the UK's equivalent of the EU SCCs.
The IDTA was issued by the UK Information Commissioner's Office (ICO) and came into force on 21 March 2022. AqNova uses the IDTA for all transfers of personal data from the United Kingdom to non-adequate third countries, including transfers to the United States (AqNova's principal operating jurisdiction).
The IDTA incorporates a mandatory Table of contents specifying: the parties; the transferred data; the transfer purpose; the applicable modules; and any supplementary measures. AqNova completes a separate IDTA (or addendum to EU SCCs using the UK Addendum to EU SCCs) for each material UK-to-third-country transfer relationship.
Where AqNova has already executed EU SCCs with an importer for EU-to-third-country transfers, AqNova adds the UK Addendum (approved by the ICO and laid before Parliament on 2 February 2022) to extend the SCC relationship to UK-origin personal data without requiring a separate IDTA. This reduces administrative duplication for importers that receive data from both EU and UK operations.
On October 17, 2023, the US-UK Data Bridge extension to the EU-US Data Privacy Framework (DPF) came into effect. UK companies may transfer personal data to US organizations that are certified under the DPF (including the UK Extension) without needing to use an IDTA or UK Addendum. AqNova evaluates DPF-certified US recipients to determine whether reliance on the Data Bridge is appropriate, alongside its standard IDTA-based arrangements.
An adequacy decision is a formal determination by a data protection authority or legislative body that a third country, territory, or sector provides an essentially equivalent level of data protection to the originating jurisdiction. Where an adequacy decision is in place, personal data may flow to the recognized country without the need for SCCs, IDTAs, or other safeguards.
The European Commission has issued adequacy decisions for the following countries, territories, and sectors relevant to AqNova's operations:
| Country / Territory / Sector | EU Adequacy Status & Notes |
|---|---|
| United States — EU-US Data Privacy Framework (DPF) | ADEQUATE (effective July 17, 2023) — Commission Implementing Decision (EU) 2023/1795. Applies only to US organizations certified under the DPF administered by the US Department of Commerce. AqNova verifies DPF certification for US recipients before relying on this mechanism. Note: subject to annual review and potential legal challenge. |
| United Kingdom | ADEQUATE (effective June 28, 2021) — Commission Implementing Decisions (EU) 2021/1772 & 2021/1773. Valid until June 27, 2025; subject to periodic review. Post-review status to be updated. Where UK adequacy is withdrawn, AqNova will implement SCCs within the required transition period. |
| Canada (PIPEDA commercial sector) | ADEQUATE (since 2001). Limited to data subject to PIPEDA; does not cover provincially regulated sectors. AqNova relies on this adequacy for transfers of commercial personal data to Canada. |
| Japan | ADEQUATE (since January 23, 2019) — following Japan's adoption of supplementary rules aligning APPI with GDPR. AqNova relies on this adequacy for EU-to-Japan transfers. |
| South Korea | ADEQUATE (since December 17, 2021). AqNova relies on this adequacy for EU-to-South Korea transfers. |
| New Zealand | ADEQUATE (since 2012, reaffirmed under new assessment framework). Relevant for any transfers to New Zealand-based service providers. |
| Israel | ADEQUATE (since 2011). Relevant for any transfers to Israel-based providers. |
| Switzerland | ADEQUATE (since 2000, currently under reassessment). AqNova monitors the reassessment status and will implement SCCs if adequacy lapses. |
| Argentina | ADEQUATE (since 2003). AqNova relies on this adequacy for EU-to-Argentina transfers. |
| Uruguay | ADEQUATE (since 2012). Relevant for any transfers to Uruguay-based providers. |
The UK has independently issued adequacy regulations covering the following countries (where transfers from the UK do not require IDTA or UK Addendum):
EU and EEA member states: recognized as adequate by UK adequacy regulations (SI 2021/1772).
Countries covered by UK adequacy: Andorra, Argentina, Canada (commercial sector), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Republic of Korea, Switzerland, Uruguay, and the US under the UK-US Data Bridge.
AqNova maintains a current list of UK-adequate countries and monitors UK adequacy updates through ICO notifications. Changes to UK adequacy status are incorporated into AqNova's transfer mechanism review cycle.
| Origin Jurisdiction | Adequacy / Equivalent Recognition Framework |
|---|---|
| Brazil (LGPD Art. 33(I)) | ANPD has authority to issue adequacy decisions for third countries. Where ANPD issues an adequacy finding for the destination country, AqNova may rely on it for Brazil-origin transfers. AqNova monitors ANPD adequacy decisions as they are issued. |
| Japan (APPI Art. 24 — PPC adequacy) | Japan's PPC issues adequacy-equivalent recognition for countries with substantially similar protection levels. Countries recognized: European Economic Area (EEA). AqNova monitors PPC adequacy updates for Japan-origin transfers. |
| South Korea (PIPA Art. 17) | PIPC has authority to recognize third countries. EEA and UK: recognized. AqNova monitors PIPC adequacy determinations. |
| India (DPDPA 2023 Section 16) | The Central Government may notify countries to which cross-border transfer of personal data is permitted. Until the restricted country list is published, AqNova applies consent-based transfers or contractual safeguards for India-origin transfers. |
| South Africa (POPIA Section 72) | No formal adequacy decision mechanism under POPIA. Transfers rely on binding agreements providing substantially equivalent protection. AqNova's DPAs include POPIA § 72 compliant binding conditions. |
Binding Corporate Rules (BCRs) are a set of legally binding data protection rules that a corporate group can adopt to facilitate intra-group international transfers of personal data from the EEA and UK. BCRs must be approved by a lead supervisory authority within the EU (with consistency mechanism review by all relevant SAs) or the ICO (for UK BCRs).
AqNova is in the process of developing and preparing BCRs for submission to the applicable lead supervisory authority. BCR submission is targeted for Q4 2026. Once approved, BCRs will serve as the primary transfer mechanism for intra-group transfers between Arivon Holding Corporation entities, replacing SCC-based intra-group arrangements.
During the period prior to BCR approval, all intra-group international transfers are governed by executed EU SCCs (Module 1, Controller-to-Controller) and, for UK-origin transfers, UK IDTAs or UK Addenda to EU SCCs, supplemented by AqNova's group-wide privacy and security policies which are contractually binding on all group entities.
AqNova's BCRs will, upon approval, provide binding protections including: application of GDPR-equivalent standards to all personal data processed within the group; legally enforceable rights for data subjects against any group entity; data subject complaint mechanisms; regular compliance audits; and an obligation to report any breaches affecting BCR-covered data to the lead supervisory authority.
For personal data originating from jurisdictions other than the EU/EEA and UK, AqNova implements jurisdiction-specific contractual safeguards that meet the transfer requirements of the applicable local data protection law. The following matrix sets out the contractual safeguards used for principal non-EU/UK origin jurisdictions:
| Origin Jurisdiction | Transfer Safeguard Required | AqNova's Implementation |
|---|---|---|
| Brazil — LGPD Art. 33 | Transfer permitted if: (a) ANPD adequacy; (b) standard contractual clauses (ANPD-approved); (c) binding corporate rules; (d) specific consent; (e) regulatory cooperation; or (f) necessary for contract performance. | AqNova uses ANPD-equivalent contractual clauses for Brazil-origin transfers where adequacy does not apply. Where transfer is necessary for contract performance (e.g., cross-border order fulfillment), Art. 33(V) necessity exception applies. |
| Nigeria — NDPA 2023 s. 40–43 | Transfer permitted to countries with comparable data protection laws, or through binding contractual arrangements providing equivalent protection. | AqNova implements binding contractual arrangements (DPAs) with all Nigeria-origin transfer recipients incorporating NDPA-equivalent data protection obligations. NDPC registration maintained. |
| Kenya — DPA 2019 s. 48–50 | Transfer to third country permitted if: (a) authorized by ODPC; (b) adequate safeguards; or (c) necessary for contract performance with the data subject. | AqNova relies on contract performance necessity for order fulfillment transfers and implements DPA-based safeguards for all other Kenya-origin transfers. |
| South Africa — POPIA s. 72 | Transfer to a foreign country permitted only if: (a) the recipient is subject to substantially similar data protection conditions; or (b) the data subject consents; or (c) necessary for contract between data subject and responsible party. | AqNova implements binding agreements with all South Africa-origin transfer recipients incorporating POPIA-equivalent conditions. Where binding agreements are in place, s. 72(1)(d) exception applies. |
| Ghana — DPA 2012 Part VII | Transfer to third country permitted if: (a) adequate protection in recipient country; or (b) transfer is authorized by the DPC; or (c) subject to equivalent contractual protections. | AqNova implements contractual protections equivalent to Ghana DPA requirements in all agreements with Ghana-origin transfer recipients. |
| India — DPDPA 2023 s. 16 | Central Government may notify restricted countries; until list is published, transfers permitted with appropriate safeguards. Consent may serve as basis. | AqNova applies consent-based transfer basis where DPDPA consent was obtained for processing that requires cross-border transfer. Contractual safeguards applied in all cases. AqNova monitors Central Government notifications for restricted country list. |
| Australia — APP 8 / Privacy Act s. 16C | Before disclosing to overseas recipient, entity must take reasonable steps to ensure APP-equivalent protection; or obtain consent to disclosure with acknowledgment that APPs may not apply. | AqNova implements contractual obligations on all overseas recipients of Australia-origin personal data, requiring APP-equivalent handling. Australia-origin data transfers are accompanied by contractual protections in all DPAs. |
| Singapore — PDPA s. 26 | Transfer permitted if organization ensures receiving organization provides standard of protection comparable to PDPA, through: legally enforceable obligations; or applicable law; or binding corporate rules. | AqNova implements legally binding obligations on all recipients of Singapore-origin data, incorporating PDPA-comparable protection standards in all DPAs. |
| China — PIPL Arts. 38–43 | Transfer requires one of: (a) CAC security assessment (mandatory for CII operators and large-volume transfers); (b) standard contract filed with local CAC; (c) CAC-approved certification. AqNova monitors CAC thresholds. | AqNova implements CAC standard contracts for applicable China-origin transfers and files with the local CAC branch as required. Security assessment pathway applied where CAC thresholds are met for volume of Chinese residents' personal information processed. |
| Colombia — Ley 1581/2012 Art. 26 | International data transmission permitted if recipient country provides adequate levels of data protection. If not: requires authorization from SIC, or contractual guarantees. | AqNova obtains SIC authorization or implements contractual guarantees for Colombia-origin international transfers to non-adequate countries. |
| Argentina — Ley 25,326 Art. 12 | Transfer to third countries permitted if recipient country provides adequate protection. No transfer to countries without adequate protection without express exception (contract, international cooperation, vital interest, justice, etc.). | AqNova relies on ANPD/AAIP adequacy recognition where available; implements contractual safeguards for transfers to non-adequate countries from Argentina. |
| Mexico — LFPDPPP Arts. 36–37 | International data transfers permitted with consent, contract performance, or contractual arrangements providing equivalent protection. | AqNova implements contractual arrangements with all Mexico-origin transfer recipients incorporating LFPDPPP-equivalent protection. |
| UAE — PDPL Decree-Law 45/2021 | Cross-border transfers permitted to countries with adequate protection or through binding agreements with equivalent protection. | AqNova implements binding agreements for UAE-origin personal data transfers incorporating PDPL-equivalent protection standards. |
For all international data transfers that rely on SCCs, IDTAs, or equivalent contractual mechanisms (rather than an adequacy decision), AqNova conducts and maintains a Transfer Impact Assessment (TIA) for each material transfer relationship. TIAs are required under EDPB Recommendations 01/2020 on measures that supplement transfer tools, and represent the European standard of due diligence for cross-border data transfers.
AqNova's TIA methodology follows the six-step process recommended by the EDPB:
Step 1 — Map all transfers: identify all personal data flows leaving the EEA/UK, including onward transfers from processors.
Step 2 — Identify the transfer tool: determine which Art. 46 mechanism (SCCs, BCRs, etc.) applies to each transfer.
Step 3 — Assess the third country legal framework: evaluate whether the legal framework of the destination country impairs the effectiveness of the transfer tool. Key factors: government access powers; independent oversight; available data subject remedies; history of legal conflicts with EU standards.
Step 4 — Identify supplementary measures: where the third country framework could impair SCC protections, identify and implement supplementary technical, contractual, or organizational measures to address identified gaps.
Step 5 — Implement supplementary measures: integrate identified measures into the transfer arrangement; amend DPAs as necessary.
Step 6 — Re-evaluate periodically: TIAs are reviewed annually and immediately upon any material change to the destination country legal framework or the nature of the transfer.
The United States represents AqNova's most significant transfer destination (primary cloud infrastructure, payment processors, analytics, advertising measurement). Key TIA findings for US transfers:
Legal framework: US surveillance law — particularly FISA Section 702 and Executive Order 12333 — has historically raised concerns regarding government access to transferred data. The EU-US DPF (effective July 2023) was established specifically to address these concerns through binding commitments by the US government, including the establishment of the Data Protection Review Court (DPRC).
AqNova's supplementary measures for US transfers include: end-to-end encryption where applicable; pseudonymization; access minimization (each US service provider receives only the data elements necessary for its specific function); contractual notification obligations (processors must notify AqNova of any government access requests); and prohibition on 'back door' access.
AqNova monitors legal developments in the US-EU DPF — including any challenge proceedings before the CJEU — and will update its transfer mechanism if the DPF is invalidated.
AqNova conducts a heightened TIA for any transfers involving Chinese residents' personal data, in light of China's broad national security and intelligence laws (including National Security Law 2015, Cybersecurity Law 2017, National Intelligence Law 2017, and Data Security Law 2021). AqNova's current approach is to minimize China-origin personal data transfers to the maximum extent possible and, where transfers are necessary, to: implement CAC-standard contractual provisions; file with the local CAC branch; apply strict data minimization; and encrypt all transferred data.
AqNova's TIA for China-destination transfers (e.g., transfers to suppliers or logistics providers in China) similarly applies heightened scrutiny and supplementary measures given the broad scope of Chinese government access to data held by Chinese entities.
The following consolidated matrix maps each origin jurisdiction to the applicable transfer mechanisms used for outbound international data transfers:
| Data Origin Jurisdiction | Transfer Mechanism(s) Used | Key Legal Authority |
|---|---|---|
| European Union / EEA | EU SCCs (Implementing Decision 2021/914/EU) + TIA; Adequacy Decisions where available (US-DPF, UK, Canada, Japan, Korea, etc.); BCRs (in development) | GDPR Arts. 45–46 |
| United Kingdom | UK IDTA; UK Addendum to EU SCCs; UK Adequacy Regulations; US-UK Data Bridge (for DPF-certified US orgs) | UK GDPR Art. 46; ICO IDTA |
| United States (California & other states) | No general restriction on international transfers under US law. CPRA cross-context behavioral advertising opt-out applies to advertising sharing. AqNova implements DPAs as data security best practice. | No federal equivalent of GDPR Art. 44 |
| Canada (Federal — PIPEDA) | Contractual arrangements requiring comparable protection (PIPEDA Principle 4.1.3). No adequacy decisions issued by Canada. | PIPEDA Principle 4.1.3 |
| Canada — Quebec (Law 25) | Privacy Impact Assessment (PIA) required before extraterritorial transfer. Written agreements with recipients. Disclosure to CAI on request. | Quebec Law 25 ss. 70.1–70.2 |
| Brazil — LGPD | ANPD adequacy decisions; ANPD-approved SCCs; Binding corporate rules; Specific consent; Contract performance necessity | LGPD Art. 33 |
| Nigeria — NDPA 2023 | Comparable protection assessment; Binding contractual arrangements; NDPC approval where required | NDPA 2023 ss. 40–43 |
| Kenya — DPA 2019 | Adequate protection assessment; ODPC authorization; Contract performance necessity | DPA Kenya 2019 ss. 48–50 |
| South Africa — POPIA | Substantially similar conditions (binding agreement); Data subject consent; Contract performance necessity | POPIA s. 72 |
| Ghana — DPA 2012 | DPC authorization; Adequate protection assessment; Contractual protections | Ghana DPA 2012 Part VII |
| Egypt — PDPL 151/2020 | Adequate protection (PDPA Egypt determination); Contractual guarantees; Ministerial approval for sensitive data | PDPL 151/2020 Art. 15 |
| India — DPDPA 2023 | Consent basis; Contractual safeguards; Central Government restricted country list (pending publication) | DPDPA 2023 s. 16 |
| Australia — Privacy Act | APP 8 reasonable steps to ensure comparable protection; Privacy Act s. 16C contractual obligations; Data subject consent to disclosure | Privacy Act 1988 APP 8 |
| Singapore — PDPA | Legally enforceable obligations providing PDPA-comparable protection; Applicable law of recipient country; BCRs | PDPA 2012 s. 26 |
| Japan — APPI | PPC adequacy recognition (EEA); Standard clauses (PPC-approved); Information handling system approved by PPC; Consent | APPI Art. 24 (amended 2022) |
| South Korea — PIPA | PIPC adequacy recognition; Contract with adequate protection; Data subject consent; BCRs | PIPA Art. 17 |
| China — PIPL | CAC security assessment; CAC-filed standard contract; CAC-approved certification; BCRs within groups | PIPL Arts. 38–43 |
| Indonesia — PDP Law 2022 | Cooperation and coordination with BSSN; Recipient country provides equivalent protection; Contractual conditions | PDP Law 2022 Art. 56 |
| Colombia — Ley 1581/2012 | SIC authorization; Adequate country recognition; Contractual guarantees | Ley 1581/2012 Art. 26 |
| Argentina — Ley 25,326 | AAIP-recognized adequacy; Express consent; Contract performance necessity | Ley 25,326 Art. 12 |
| Mexico — LFPDPPP | Consent; Contract performance necessity; Binding transfer agreement with equivalent protection | LFPDPPP Arts. 36–37 |
| UAE — PDPL | Adequate protection recognition; Binding agreement with equivalent protection | PDPL Decree-Law 45/2021 Arts. 22–24 |
A material concern for cross-border data transfers — particularly as assessed in Transfer Impact Assessments — is the extent to which government authorities in the destination country may lawfully access personal data transferred from the originating jurisdiction. AqNova has assessed this risk for its primary transfer destinations and has implemented the following policy and contractual protections:
| AqNova's Government Access Protection Framework AqNova's contractual arrangements with all international data processors and recipients include the following government access protection provisions: 1. NOTIFICATION OBLIGATION: The processor/recipient must notify AqNova of any government order or request to access personal data, to the extent legally permitted. Where notification is prohibited by law, the processor must notify AqNova as soon as the prohibition ceases. 2. CHALLENGE OBLIGATION: The processor/recipient must challenge any government access request that lacks a clear and specific legal basis, to the extent available under applicable law, before complying. 3. MINIMIZATION OBLIGATION: The processor/recipient must disclose only the minimum amount of personal data required to comply with a lawful government request. 4. DISCLOSURE OBLIGATION: AqNova will notify affected data subjects of government access to their data as soon as legally permitted to do so, consistent with applicable transparency requirements. 5. AUDIT TRAIL: Processors must maintain records of all government access requests and disclose them to AqNova (or its designated auditor) upon request. 6. NO BACK-DOOR ACCESS: Processors must contractually warrant that they have not provided any government authority with a 'back door' or direct access to AqNova user data outside of a formal legal process. |
|---|
AqNova publishes an annual Government Data Request Transparency Report as part of its Privacy Transparency Report, disclosing the number of government requests received by country, the number of requests challenged, the number complied with, and the approximate number of users affected. The report is published at [aqnova.co/privacy/transparency].
In connection with AqNova's cross-border data transfers, you have the following specific rights:
Right to information: you are entitled to know the destination countries of your personal data and the safeguards in place — this Notice constitutes that disclosure. For more specific information about a particular transfer, contact dpo@aqnova.co.
Right to a copy of transfer safeguards: EU/EEA data subjects have the right to obtain a copy of the SCCs or other transfer mechanism documents under which their data is transferred. Contact dpo@aqnova.co [Subject: Transfer Mechanism Copy Request] to request these documents.
Right to object: EU/EEA data subjects may object to specific international transfers based on legitimate interests (GDPR Art. 21). AqNova will assess the objection and provide a substantive response within the applicable timeframe.
Right to lodge a complaint: if you believe AqNova has transferred your personal data internationally without appropriate safeguards, you have the right to lodge a complaint with the applicable supervisory authority in your jurisdiction (see the Supervisory Authority Directory in Section 3.4.13).
AqNova shares personal data with third parties in the following 13 categories. In each case, AqNova shares only the minimum data necessary for the specific purpose of the sharing, on the basis of a valid legal ground, and subject to appropriate contractual safeguards. AqNova does not sell personal data to any third party. The following sections provide full disclosure of each category, consistent with GDPR Articles 13–14, CCPA § 1798.115, and equivalent transparency obligations worldwide.
| Principles Governing All Third-Party Data Sharing 1. MINIMUM NECESSARY DATA: Only the data elements genuinely required for the specific sharing purpose are disclosed to each third party. 2. LAWFUL BASIS: Every sharing has a documented legal basis — contract performance, legitimate interests, legal obligation, or consent (where required). 3. CONTRACTUAL PROTECTION: All third parties that process data on AqNova's behalf (data processors) are bound by written Data Processing Agreements (DPAs) that restrict processing to authorized purposes and require appropriate security. 4. NO SECONDARY USE: Third-party processors may not use AqNova user data for their own commercial purposes beyond what is authorized in the DPA. 5. AUDIT RIGHTS: AqNova retains audit rights over all data processors and conducts or commissions periodic assessments of processor compliance. 6. SUB-PROCESSOR CONTROL: Processors may not engage sub-processors without AqNova's prior written authorization. Authorized sub-processors are listed at [aqnova.co/privacy/sub-processors]. |
|---|
AqNova shares payment-related personal data with payment processing partners to authorize, settle, and manage transactions on the Platform. Payment processors receive only the data necessary to process the specific payment method used by the Buyer.
| Payment Processor | Data Shared & Purpose | Processor Role & Safeguards |
|---|---|---|
| Stripe, Inc. (US) | Transaction amount, payment method token, billing postal code, email address (for fraud screening), IP address (for fraud detection). Purpose: card payment authorization, settlement, fraud detection, chargeback management. | PCI-DSS Level 1 certified. Independent data controller for own compliance purposes. DPA executed with AqNova (Stripe DPA). EU SCCs / UK IDTA for EEA/UK transfers. Privacy Policy: stripe.com/privacy. |
| PayPal Holdings, Inc. (US) | Payment amount, PayPal account identifier (not personal details), transaction reference. Purpose: PayPal payment processing for Buyers who select PayPal at checkout. | PayPal is an independent data controller for its own compliance. DPA executed. EU SCCs for EEA transfers. Privacy Statement: paypal.com/privacy. |
| Adyen N.V. (Netherlands/Global) | Transaction data, payment method token, device fingerprint (fraud detection). Purpose: alternative payment method processing (where applicable); global payment infrastructure. | PCI-DSS Level 1. EU data controller within EEA; DPA for non-EEA transfers. Privacy: adyen.com/legal/privacy-policy. |
| Flutterwave (Nigeria/Africa) | Transaction amount, payment reference, partial account details. Purpose: African regional payment processing (M-Pesa, bank transfer, mobile money). Purpose limited to payment settlement. | Data processor under AqNova DPA. NDPA 2023 compliance. Binding agreement for any cross-border transfer of Nigeria-origin data. |
| Razorpay Software Pvt. Ltd. (India) | Transaction amount, UPI ID (masked), payment reference. Purpose: UPI and net banking payments for India-based Buyers. | RBI-regulated payment aggregator. DPDPA 2023 compliance. Data processor under AqNova DPA. |
| Local Payment Providers (PIX-Brazil, SPEI-Mexico, others) | Transaction amount, payment reference, local account identifiers. Purpose: local payment rails for respective countries. | Subject to local payment regulation (Banco Central do Brasil; Banxico; etc.). DPA executed for each provider. Cross-border transfer safeguards applied as appropriate. |
AqNova does not store full payment card numbers, CVV/CVC codes, or full bank account numbers in its own systems. All sensitive payment data is tokenized and held by PCI-DSS certified payment processors. AqNova stores only payment method type (e.g., Visa), last four digits for display, and the processor's payment token reference.
When an order is dispatched by a Vendor, AqNova (or the Vendor directly) shares shipment-related personal data with logistics and delivery partners to arrange collection, transit, and delivery of the order.
Data shared: Buyer's full name; delivery address (street, city, postal code, country); contact telephone number (for delivery notifications and missed delivery callbacks); order reference number; declared package contents description (for customs purposes on cross-border shipments); package weight and dimensions.
Legal basis: contract performance — sharing this data is necessary to fulfill the purchase contract between the Buyer and Vendor.
Logistics partners: global carriers (DHL, FedEx, UPS, DPD, and equivalents); national postal services (USPS, Royal Mail, Canada Post, Australia Post, NIPOST, and equivalents); last-mile regional carriers in Africa, Asia, and Latin America.
Data processing restrictions: logistics carriers process the provided data solely for the purpose of delivering the specific shipment. They may not use delivery address data for marketing or profiling purposes.
Retention: logistics providers typically retain delivery records for 6–12 months for tracking and dispute purposes. AqNova retains logistics data for 7 years for tax and regulatory compliance.
AqNova uses analytics tools to understand how users interact with the Platform and to improve Platform performance, usability, and features.
| Provider | Data Shared, Purpose & Safeguards |
|---|---|
| Google Analytics 4 (Alphabet Inc., US) | DATA: Pseudonymized session data — anonymized IP address, page views, click paths, conversion events, session duration, device type. No names, email addresses, or other directly identifying data are sent to Google Analytics. IP anonymization is enabled. PURPOSE: Understanding aggregate Platform usage; measuring feature effectiveness; identifying technical issues. SAFEGUARDS: Data processing amendment (DPA) executed under Google's DPA framework. EU SCCs for EEA transfers. Only activated with consent (Category 3 cookies). Data processing location: US (with EU processing option under Google Analytics for EU customers). Google Analytics for Firebase DPA governs mobile app analytics. |
| AqNova Internal Analytics Platform | DATA: Full session data (pseudonymized user identifier, page views, navigation paths, conversion funnels, feature usage). No external sharing — this data remains within AqNova's infrastructure. PURPOSE: Granular internal performance analysis; A/B test measurement; product improvement decisions. SAFEGUARDS: Data processed within AqNova-controlled systems; access restricted to authorized analytics and product team members; raw session data deleted after 30 days; aggregated data retained indefinitely in anonymized form. |
| Hotjar / Equivalent UX Tool (where implemented) | DATA: Anonymized scroll maps, click heatmaps, session recordings (faces and sensitive form fields masked). No personally identifying information is captured. PURPOSE: Understanding user experience and identifying usability issues at aggregate level. SAFEGUARDS: DPA executed. EU SCCs for EEA transfers. Only activated with consent. PII masking enforced at collection layer. No individual identification from recordings. |
| Crashlytics / Firebase Crash Reporting (Google, US) | DATA: Device model, OS version, app version, stack trace at time of crash, session ID. No user-identifiable information captured in crash reports. PURPOSE: Identifying and fixing technical errors in the AqNova mobile application. SAFEGUARDS: Firebase DPA / Google Cloud DPA executed. EU SCCs for EEA transfers. No advertising use of crash data. |
AqNova shares limited pseudonymous data with advertising and marketing platforms for the sole purpose of measuring the effectiveness of AqNova's own marketing campaigns. This sharing is conducted only where users have given valid consent (through the Cookie Consent Manager for web users; through ATT opt-in for iOS users; through GAID settings for Android users). AqNova does not share personal data with advertising platforms for third-party behavioral advertising.
| Platform | Data Shared, Purpose & Restrictions |
|---|---|
| Meta Platforms, Inc. (US) — Meta Pixel & Conversions API | DATA SHARED: Hashed (SHA-256) email address; hashed phone number (where provided); pseudonymous pixel identifier (_fbp); conversion event type (e.g., 'Purchase,' 'Add to Cart'); event timestamp; currency and value (for purchase events); URL of event page. Raw personal data (name, address) is NOT shared. PURPOSE: Measure whether users who saw AqNova's Meta/Instagram ads subsequently completed a purchase. Campaign attribution and optimization. RESTRICTIONS: Data shared for attribution measurement only; Meta may not use this data to build profiles for targeting by other advertisers. Meta Business Tools Terms govern usage. Only activated with consent. EU SCCs in place. Meta is an independent data controller for its own purposes. |
| Google LLC (US) — Google Ads Conversion Tracking & Enhanced Conversions | DATA SHARED: Hashed (SHA-256) email address (via Enhanced Conversions); Google click identifier (gclid — pseudonymous); conversion event type and value. Raw personal data is NOT shared. PURPOSE: Measure the effectiveness of AqNova's Google Ads campaigns; attribute purchases to specific ad interactions. RESTRICTIONS: Google's Customer Match and Enhanced Conversions terms restrict use to measurement purposes. Google Ads DPA executed. EU SCCs in place. Only activated with consent. |
| TikTok (ByteDance Ltd., Cayman Islands) | DATA SHARED: Hashed email; pseudonymous TikTok Pixel identifier (_ttp); conversion event type and value. PURPOSE: Campaign effectiveness measurement for any TikTok advertising. RESTRICTIONS: TikTok Events API Terms govern usage. Particular attention given to data security given TikTok's corporate structure. AqNova conducts enhanced TIA for TikTok data transfers. EU SCCs in place. Only activated with consent. |
| Pinterest, Inc. (US) | DATA SHARED: Pseudonymous Pinterest Pixel identifier (_pin_unauth); conversion event type. PURPOSE: Campaign measurement for any Pinterest advertising. RESTRICTIONS: Pinterest Ads Terms govern usage. Only activated with consent. EU SCCs in place. |
AqNova shares behavioral and technical signals with specialist fraud detection and platform security services to protect all users from financial fraud, account takeover, and bot activity.
Data shared: device fingerprint (non-personal technical signals); IP address (truncated for anonymization in analytics but full for fraud detection); browser/OS combination; transaction velocity patterns; account behavior signals; email address (hashed, for cross-network fraud signal matching).
Legal basis: legitimate interests — protecting all Platform users from fraud; preventing financial losses to Buyers, Vendors, and AqNova; maintaining Platform integrity. AqNova has conducted a LIA for this processing.
Providers: Sift Science (Sift, Inc., US); Kount (Equifax, US); equivalent fraud prevention network (to be finalized at go-live); Cloudflare Bot Management (Cloudflare, Inc., US).
Restrictions: fraud prevention providers may not use AqNova user signals to build advertising profiles, score users for purposes other than fraud detection, or share signals with third parties other than their own sub-processors under DPA.
Safeguards: DPA executed with each provider; EU SCCs for EEA transfers; strict data minimization (only fraud-relevant signals shared, not general profile data); data retained by fraud providers for a maximum of 13 months for fraud pattern analysis.
AqNova shares identity and business registration data with specialist identity verification and Know Your Customer (KYC) providers for the purpose of onboarding Vendor accounts and complying with applicable anti-money laundering (AML) and counter-terrorist financing (CTF) obligations.
Data shared: Vendor name; date of birth; government-issued ID type and reference number (not the full document image, unless required by the provider's verification process); business registration number; beneficial ownership declarations; liveness check data (where biometric verification is required).
Legal basis: legal obligation (AML Directives; BSA/FinCEN; PCMLTFA; FMPA Nigeria; applicable national AML laws); contract performance (Vendor Agreement requires identity verification).
Providers: Jumio (Jumio Corporation, US); Onfido (Onfido Ltd., UK); ComplyAdvantage (ComplyAdvantage Ltd., UK) — for sanctions screening; or equivalent providers selected at go-live.
Restrictions: KYC providers act exclusively as data processors; they process Vendor identity data solely for the purpose of AqNova's identity verification and sanctions screening; they may not use the data for their own commercial purposes or share it beyond their authorized sub-processors.
Retention: KYC documents and verification records are retained for 5 years from the end of the business relationship, consistent with AML record-keeping requirements. AqNova does not retain copies of full government-issued ID documents beyond the verification period unless specifically required by applicable AML law.
All personal data collected and processed by AqNova is stored and processed on cloud infrastructure provided by leading cloud service providers. These providers do not process personal data for their own purposes — they provide the technical infrastructure on which AqNova's systems run.
Primary cloud provider: Amazon Web Services, Inc. (AWS), a subsidiary of Amazon.com, Inc. (US). Primary region: [US-East-1 / EU-West-1 — to be confirmed at go-live]. Backup regions for disaster recovery: [secondary regions to be disclosed]. AqNova uses AWS's EU-based infrastructure options (EU-West-1 Frankfurt or Ireland) for EU/UK data residency where required by applicable law or commercial arrangements.
Content Delivery Network (CDN) & DDoS Protection: Cloudflare, Inc. (US). Cloudflare processes network traffic metadata (IP addresses, request logs) to provide DDoS protection, WAF, and CDN services. AqNova has executed the Cloudflare DPA. EU SCCs in place for EEA traffic.
Email Infrastructure: Amazon SES (AWS) or equivalent email service provider for transactional email delivery. Email content (transactional notifications) may transit through AWS servers. AqNova's DPA with AWS covers this processing.
Data Processing Agreements: AqNova has executed DPAs with all cloud infrastructure providers that comply with the GDPR Art. 28 requirements, including GDPR-compliant sub-processor lists, audit rights, security measures, and data deletion obligations.
AqNova uses customer support technology platforms to manage user inquiries, disputes, and platform communications. These platforms may process personal data in the course of providing their services.
Platform: Intercom, Inc. (US) — for live chat support and customer messaging. Intercom processes: user name; email address; conversation content; Platform usage context (page visited when support initiated); account status. Intercom acts as a data processor under AqNova's DPA. EU SCCs in place. Intercom data is retained for the duration of the support relationship plus 90 days.
Ticketing system: Zendesk, Inc. (US) or equivalent (to be confirmed at go-live) — for structured support ticket management. Processes: user contact details; issue description; resolution history. DPA executed; EU SCCs in place.
Vendor restrictions: customer support providers may only access user data as necessary to support AqNova's customer service function; they may not use this data for their own marketing or advertising; access controls limit support provider access to data directly related to active support interactions.
When a Buyer places an order, AqNova shares the Buyer's personal data with the applicable Vendor to the extent necessary for order fulfillment. This is the most fundamental data sharing on the Platform. The scope of Buyer data shared with Vendors and the obligations on Vendors in connection with that data are defined in the Vendor Agreement (Section 2.2) and are summarized here.
All Vendors who receive Buyer personal data through the Platform are subject to the following binding data protection obligations under the Vendor Agreement (Section 2.2), which incorporate GDPR Article 28-equivalent terms for EU/UK Vendors and equivalent protections for all other jurisdictions:
Purpose limitation: Vendor may use Buyer data only for fulfilling the specific order and providing order-related customer service. Buyer data may not be used for the Vendor's own marketing, profiling, or commercial purposes.
No resale or onward transfer: Vendor may not sell, license, or transfer Buyer personal data to any third party, including the Vendor's own suppliers or logistics partners, without AqNova's prior written authorization.
Security: Vendor must implement appropriate technical and organizational measures to protect Buyer data against unauthorized access, disclosure, or loss, consistent with the sensitivity of the data and the applicable law.
Retention: Vendor must delete or destroy Buyer personal data within 30 days of order completion (or longer if required for a returns, dispute, or regulatory purpose) and must not retain it for any other purpose.
GDPR processor status: for EU/UK Vendors, the relationship between AqNova (as a controller of Buyer data) and the Vendor (as a processor of that data for order fulfillment) is governed by a controller-processor DPA (Article 28 agreement) embedded in the Vendor Agreement.
Breach notification: Vendor must notify AqNova at security@aqnova.co within 24 hours of discovering any actual or suspected breach affecting Buyer data received through the Platform.
Audit: Vendor must cooperate with AqNova's reasonable audit requests regarding data protection compliance, and must provide documentation of their data protection practices upon request.
AqNova shares limited data with Vendor Referral Partners (VRPs) who participate in the Vendor Referral Partner Program (VRPP) for the purpose of calculating and attributing referral commissions.
Data shared with referring VRPs: confirmation that a referred Vendor has completed registration and activated their account (binary — yes/no, no Vendor personal details beyond this confirmation); referral commission amount attributable to the referring VRP.
Data not shared: the referred Vendor's personal details, KYC information, sales volumes, payout amounts, or any Buyer data are not shared with referring VRPs.
Legal basis: contract performance (VRPP Agreement); legitimate interests (commission calculation and fraud prevention).
Safeguards: VRPs must comply with AqNova's data protection requirements under the VRPP Agreement, including restrictions on the use of any referral-related data for purposes other than their own commission records.
In the event that Arivon Holding Corporation or AqNova undergoes a merger, acquisition, sale of all or substantially all of its assets, corporate restructuring, or similar business transaction, personal data held by AqNova may be transferred to the successor entity or acquiring party as part of the transaction.
If such a transaction occurs, AqNova will:
Provide advance notice to registered users via email and in-Platform notification as soon as practicable, subject to any confidentiality constraints associated with the transaction.
Disclose the nature of the transaction, the identity of the successor entity (or its country of incorporation if the specific identity cannot yet be disclosed), and the implications for users' personal data.
Ensure that the successor entity agrees, as a condition of the transfer, to honor the privacy commitments made in this Privacy Policy with respect to personal data transferred as part of the transaction. Where the successor entity's privacy practices differ materially from AqNova's, users will be notified and given the opportunity to delete their accounts before the transfer takes effect.
Provide users with the right to opt out of the transfer to the successor entity where applicable law permits and where the successor entity's practices differ materially from AqNova's.
AqNova maintains a public Sub-Processor Register listing all third-party data processors that process personal data on AqNova's behalf. The register is accessible at [aqnova.co/privacy/sub-processors] and is updated whenever AqNova adds, changes, or removes a sub-processor.
| Sub-Processor Register — Information Published For each sub-processor, the register discloses: — Sub-Processor Name and Legal Entity — Country of Establishment / Primary Data Processing Location — Processing Category (payment, analytics, KYC, logistics, infrastructure, etc.) — Data Categories Processed — Transfer Mechanism (for non-EEA/UK processors from EEA/UK origin data) — DPA Status (executed) — Date Added or Last Updated The register is maintained in English and is updated in real time. Users may subscribe to email notifications of sub-processor changes at [aqnova.co/privacy/sub-processors/subscribe]. |
|---|
In compliance with GDPR Article 28(2) and equivalent provisions, AqNova provides advance notice of material sub-processor changes — specifically, the addition of a new sub-processor or substitution of an existing sub-processor — through the following process:
For EU/UK users: 30 days' advance notice via email and sub-processor register update, during which period EU/UK users may object to the specific sub-processor change. AqNova will assess all objections in good faith; where AqNova cannot address a legitimate objection without disproportionate operational impact, it will notify the objecting user and, where the user's objection relates to a material change in data protection standards, offer the user the option to terminate their account without penalty.
For all other users: sub-processor register updated with 14 days' advance notice. Opt-out of the relevant processing category available through account settings or privacy@aqnova.co.
| Category | Principal Sub-Processors (Full List at [aqnova.co/privacy/sub-processors]) |
|---|---|
| Cloud Infrastructure & Hosting | Amazon Web Services (AWS); Cloudflare |
| Payment Processing | Stripe; PayPal; Adyen; Flutterwave; Razorpay; local payment providers |
| Analytics | Google Analytics 4; Firebase (Google); internal AqNova analytics platform |
| Marketing Measurement | Meta (Facebook/Instagram Conversions API); Google Ads; TikTok Events API; Pinterest Tag |
| Fraud Detection & Security | Sift Science; Kount (Equifax); Cloudflare Bot Management |
| Identity Verification / KYC | Jumio; Onfido; ComplyAdvantage (sanctions screening) |
| Customer Support | Intercom; Zendesk (or equivalent) |
| Email Delivery | Amazon SES (AWS) |
| Mobile App Analytics | Firebase Crashlytics (Google) |
| AqNova — Transfer & Sharing Contacts Data Protection Officer: dpo@aqnova.co General Privacy Inquiries: privacy@aqnova.co SCC / Transfer Mechanism Copies: dpo@aqnova.co [Subject: Transfer Mechanism Copy] Sub-Processor Register: [aqnova.co/privacy/sub-processors] Sub-Processor Change Notifications: [aqnova.co/privacy/sub-processors/subscribe] EU/UK GDPR Representative: gdpr@aqnova.co Government Data Request Portal: legal@aqnova.com (law enforcement requests) Brazil LGPD Encarregado: privacy@aqnova.co [Subject: LGPD — Brazil DPO] India Grievance Officer: grievance-india@aqnova.co Data Breach Reports: security@aqnova.co Legal Notices: legal@aqnova.com Registered Office: Arivon Holding Corporation C/O Arivon Holding Corporation, 2571 Saturn Avenue, Unit #265 Huntington Park, CA 90255, USA California File Number: B20250418195 | EIN: 41-3210066 | D-U-N-S: 142957477 GB EORI: GB511467217000 Nigeria (Sahara Eagle Ltd) — Reg: 1957145 | Tax ID: 31052811-0001 | NEPC: 0030281 |
|---|
AqNova Marketplace | Global Legal Footer Framework | Sections 3.5 & 3.6: Cross-Border Transfers & Third-Party Sharing
© 2026 Arivon Holding Corporation. All rights reserved. Effective April 7, 2026. Version 1.0.