01 — Identity & Contact
Data Controller
The entity responsible for the processing of personal data in connection with this website and all associated communications is Chalor Capital Allocation & Institutional Group (hereinafter referred to as "Chalor", "we", "us", or "the Company"). The Company is the data controller within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR) for all processing activities described in this Privacy Policy.
We take our obligations under applicable data protection law with the utmost seriousness. This Privacy Policy has been drafted to meet the high standard of transparency required by the GDPR and to give you, as a data subject, a thorough and honest account of how your personal data is treated when you interact with us — whether through this website, by email, or in the course of a professional engagement.
Controller Identity (Art. 13(1)(a) GDPR)
All data protection enquiries, requests to exercise your rights, complaints, or requests for further information regarding our data processing practices should be submitted to chalorgroup@outlook.fr. We will acknowledge receipt of your message within five (5) business days and aim to respond fully within one (1) calendar month from the date of receipt, as required by Article 12 GDPR.
02 — Scope
Scope of This Privacy Policy
This Privacy Policy applies to all personal data processed by Chalor Capital Allocation & Institutional Group in the following contexts:
- Visits to and use of our website at www.chalorgroup.com, including any subdomains or microsites operated by us;
- Submission of enquiries via the contact form embedded on our website;
- All incoming and outgoing email correspondence sent to or from any address associated with chalorgroup.com or the Company's official email accounts;
- Pre-engagement communications, including the assessment of potential mandates and initial client due diligence;
- The performance of advisory, capital allocation, and institutional services for established clients, to the extent personal data is involved;
- Any other interaction through which you voluntarily provide personal data to the Company.
This policy does not apply to the websites or services of third parties that may be accessible via hyperlinks on our website. We have no control over those external sites and encourage you to review their own privacy policies independently.
Where the Company acts as a data processor on behalf of a client entity — for example, where a corporate client provides us with personal data about their own employees or beneficiaries — a separate data processing agreement (DPA) governs that arrangement. This policy covers only the Company's activities as data controller.
03 — Legal Bases
Legal Bases for Processing Personal Data
Every processing activity carried out by Chalor Capital Allocation & Institutional Group rests on one or more legal bases set out in Article 6 of the GDPR. We do not process personal data without a valid legal basis. The following legal bases are applicable to our processing activities:
Consent (Art. 6(1)(a) GDPR)
Where you have freely, specifically, and unambiguously indicated your agreement to the processing of your personal data for a defined purpose — for example, by accepting non-essential cookies or agreeing to receive communications from us — we rely on your consent as the legal basis. You have the right to withdraw consent at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of consent does not affect any other legal basis on which we may simultaneously rely.
Performance of a Contract (Art. 6(1)(b) GDPR)
Where we are in a contractual relationship with you, or where you have taken steps to enter into such a relationship with us, we process personal data to the extent necessary to perform the agreement or to respond to your pre-contractual enquiries. This applies, for example, when preparing a mandate proposal, conducting client onboarding, or delivering agreed advisory services.
Compliance with a Legal Obligation (Art. 6(1)(c) GDPR)
Certain processing activities are required of us by law. These include, but are not limited to, obligations arising under applicable anti-money laundering legislation, tax law, accounting obligations, and data retention rules imposed by statute. We process personal data to the minimum extent necessary to satisfy these obligations.
Legitimate Interests (Art. 6(1)(f) GDPR)
In a number of circumstances, we process personal data where it is necessary for the purposes of our legitimate interests, provided those interests are not overridden by your own interests, rights, or freedoms. Legitimate interests we pursue include: operating a secure and functional website; responding to enquiries received from individuals or organisations; maintaining accurate business records; detecting and preventing fraud and abuse; and communicating with prospective clients who have voluntarily reached out to us. Where we rely on this basis, we have conducted a balancing assessment and are satisfied that our legitimate interests are proportionate and do not unduly prejudice data subjects.
04 — Website Data
Data Collected Through the Website
Server Log Files
When you access and browse our website, our web server automatically records certain technical information in log files. This data is collected solely for the purpose of maintaining the secure and stable operation of the website and cannot be used to identify you by name. The following categories of data are logged automatically upon each page request:
- The IP address of the device from which the request originates (stored in a form that may or may not be anonymised depending on server configuration);
- The date and time of the request, recorded to the second;
- The specific URL (web address) of the page requested;
- The HTTP response status code returned by the server (e.g. 200, 404);
- The volume of data transferred in connection with the request;
- The referring URL, where a request originates from a link on another website;
- The browser type, browser version, operating system, and device category of the requesting client.
Server log files are retained for a maximum of fourteen (14) days from the date of generation, after which they are automatically purged. They are used exclusively for the detection and investigation of security incidents, technical diagnostics, and server performance monitoring. They are not shared with any third party except where legally required. The legal basis is our legitimate interest in operating a secure and reliable online presence (Art. 6(1)(f) GDPR).
Cookies and Local Storage
Our website uses cookies and browser local storage to support certain site functions and to record your preferences. A cookie is a small text file placed on your device by your browser when you visit a site. We use a minimal number of cookies, classified as follows:
- Strictly necessary cookies: These are essential for the basic operation of the website. They include the record of your cookie consent choice (
chalor_cookie_choice), stored in your browser's local storage. These do not require your prior consent and are placed automatically to ensure the website functions correctly. They expire when you clear your browser data or local storage. - Analytics and performance cookies (optional): Where enabled by your consent, we may use analytics tools to understand aggregate patterns of user behaviour on our website, such as which pages are visited most frequently. These tools are configured to minimise the collection of personally identifiable information wherever possible. If you do not consent, these cookies will not be placed.
You may withdraw consent to optional cookies at any time by clearing your browser's local storage or adjusting your browser settings. Please refer to our separate Cookie Policy for a complete list of cookies in use, their providers, and their individual retention periods.
Third-Party Resources Embedded in the Website
For technical and design reasons, our website loads certain resources from third-party content delivery networks. This may result in your IP address and browser information being transmitted to those providers when you load a page on our site. The third-party services currently in use are:
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com): Typefaces loaded from Google's servers. Google may receive your IP address as part of the resource request.
- Tabler Icons (cdn.jsdelivr.net): Icon font loaded from the jsDelivr CDN network.
- AOS Animation Library (cdnjs.cloudflare.com): Scroll animation library served via Cloudflare's CDN infrastructure.
We do not control the data processing practices of these third-party providers and encourage you to review their respective privacy policies. The legal basis for the use of these resources is our legitimate interest in providing a performant and visually consistent website experience (Art. 6(1)(f) GDPR).
No Automated Profiling
We do not engage in automated decision-making or profiling based on data collected through the website that produces legal or similarly significant effects in respect of any individual, as defined in Article 22 of the GDPR.
05 — Contact Form
Enquiries Submitted via the Contact Form
Our website offers a contact form through which you may submit a business enquiry to the Company. When you use this form, we collect the personal data you choose to provide. Depending on which fields you complete, this may include:
- Your full name;
- The name of your company or organisation;
- Your email address;
- The category of your enquiry, selected from a drop-down menu (Private Mandate, Corporate Treasury, Brand Architecture, Institutional Mandate, or General Enquiry);
- The free-text content of your message.
This data is collected and processed for the purpose of handling and responding to your enquiry, assessing whether a service relationship would be appropriate, and maintaining a record of correspondence for business continuity purposes. We do not use contact form data for any marketing purpose without your express, specific consent.
The legal basis for processing contact form submissions is our legitimate interest in receiving and responding to business communications (Art. 6(1)(f) GDPR) and, where the enquiry relates to a potential service engagement, the taking of pre-contractual steps at your request (Art. 6(1)(b) GDPR).
Data submitted via the contact form is retained for a period of thirty-six (36) months from the date of your last communication with us, after which it is securely and permanently deleted unless a legal obligation requires us to retain it for a longer period or unless a client relationship has been established (in which case the data becomes part of the client record and is subject to the retention periods applicable to that record).
06 — Email Correspondence
Processing of Personal Data in Email Correspondence
A significant portion of the communications we receive and send takes place via email. Because email correspondence involves the transmission and storage of personal data, we are committed to explaining precisely how we handle this data — what we collect, why, on what legal basis, how long we keep it, who can access it, and how we keep it secure.
What Personal Data Is Contained in Emails
When you send an email to any address associated with Chalor Capital Allocation & Institutional Group, or when we conduct business correspondence with you by email, the following categories of personal data may be present in that communication:
- Sender metadata: Your email address, your display name as configured in your email client, and any other contact details your email application automatically appends to messages;
- Email signature data: Job title, company name, telephone number, physical address, or any other personal information you include in your email signature;
- Message content: The subject line and the body of the message, including any opinions, instructions, or personal information you choose to include;
- Attachments: Any files attached to the email, which may themselves contain personal data (e.g. CVs, contracts, identity documents, financial statements);
- Technical transmission metadata: Information automatically generated by email protocols (SMTP, IMAP, DKIM, SPF), including the IP addresses of sending and receiving mail servers, message identifiers (Message-ID), timestamps, and routing headers. This data is embedded in the email header and is transmitted as part of every email regardless of the sender's actions;
- Reply-chain content: Where you reply to one of our messages, or we reply to yours, earlier messages in the thread are typically included in the reply and thus form part of the email record.
Purposes of Processing and Applicable Legal Bases
We process personal data contained in email correspondence for the following specific purposes, each underpinned by a defined legal basis:
| Purpose of Processing | Legal Basis (GDPR Art. 6) |
|---|---|
| Reading and responding to your message | Art. 6(1)(f) — Legitimate interest in responding to business communications |
| Assessing a potential advisory engagement or mandate | Art. 6(1)(b) — Pre-contractual steps at your request |
| Performing services under an existing client agreement | Art. 6(1)(b) — Performance of a contract |
| Maintaining accurate and complete records of business correspondence | Art. 6(1)(f) — Legitimate interest in reliable business administration |
| Compliance with legal recordkeeping obligations | Art. 6(1)(c) — Legal obligation |
| Detecting and preventing fraudulent, malicious, or abusive communications | Art. 6(1)(f) — Legitimate interest in security and fraud prevention |
| Resolving disputes or enforcing contractual rights | Art. 6(1)(f) — Legitimate interest in the protection of legal rights |
Email Infrastructure and Storage
The Company's email communications are managed via Microsoft Outlook (Office 365 / Microsoft 365) infrastructure. Email data associated with the address chalorgroup@outlook.fr is hosted on Microsoft's servers. Microsoft acts as a data processor on our behalf in this context, subject to Microsoft's data processing terms and the European Commission's standard contractual clauses where applicable.
Microsoft's data centres serving European accounts are primarily located within the European Economic Area (EEA). However, Microsoft is a global organisation and some processing may take place in countries outside the EEA. Where this occurs, Microsoft has committed to applying appropriate transfer safeguards, including standard contractual clauses and adherence to applicable frameworks. Further details can be found in Microsoft's Privacy Statement at privacy.microsoft.com.
Access Controls and Confidentiality
Access to the Company's email accounts is restricted exclusively to authorised personnel of Chalor Capital Allocation & Institutional Group who require access in the course of their professional duties. All personnel with access to email systems containing personal data are bound by strict confidentiality obligations, which apply both during and after their engagement with the Company. We employ multi-factor authentication and other appropriate technical controls to prevent unauthorised access to email accounts and stored correspondence.
Email correspondence received by the Company is treated as strictly confidential business communication. Its contents will not be disclosed to any third party except as described in Section 9 (Disclosure and Recipients) of this Privacy Policy.
Security of Email Transmission
Emails transmitted over the internet are not inherently secure. While we configure our mail infrastructure to support encrypted transmission (TLS — Transport Layer Security) for email in transit, we cannot guarantee end-to-end encryption for all messages, as this depends also on the configuration of your own email provider. Accordingly, we recommend that particularly sensitive information — such as copies of identity documents, financial account details, or confidential mandate instructions — not be sent by standard email. If you need to share sensitive materials with us, please contact us at chalorgroup@outlook.fr to discuss available secure alternatives.
Retention of Email Correspondence
We retain email correspondence for as long as is necessary for the purposes for which it was received or sent, subject to the following guidelines:
- General enquiries and non-client communications: Retained for a maximum of thirty-six (36) months from the date of the last substantive communication in a given thread. After this period, email correspondence is permanently deleted unless there is an ongoing legal or contractual reason to retain it.
- Pre-contractual correspondence: Where an enquiry or negotiation does not result in a formal engagement, correspondence is retained for thirty-six (36) months, after which it is deleted unless a dispute or legal claim is pending or reasonably foreseeable.
- Client engagement correspondence: Where a mandate or service agreement is established, email correspondence forming part of that client record is retained for the duration of the engagement and for a period of five (5) to ten (10) years thereafter, in accordance with applicable legal obligations and the Company's internal data retention policy.
- Legal and compliance correspondence: Where correspondence relates to a legal obligation, regulatory matter, or active or potential dispute, it will be retained for as long as that matter remains open and for a reasonable period thereafter, regardless of the above standard periods.
Upon the expiry of the applicable retention period, email data is permanently deleted from all active mailboxes and backup systems in a manner that prevents reconstruction of the original content.
Your Rights Regarding Email Correspondence
You have the right to request access to personal data contained in email correspondence in which you are identifiable as a data subject, subject to any limitations imposed by applicable law (for example, where disclosure would reveal confidential information about other individuals, or where a legal exemption applies). You also have the right to request rectification of inaccurate personal data and, in certain circumstances, erasure or restriction of processing. Please see Section 11 (Your Rights) for the full list of your rights and how to exercise them.
07 — Client Data
Personal Data Processed in the Context of Client Engagements
Where we enter into a formal advisory or capital allocation engagement with a client — whether a natural person, a family office, or a corporate entity — we process personal data to the extent strictly necessary to deliver the agreed services and to satisfy our obligations under applicable law. The categories of data we process in this context include:
- Identity information: full legal name, date of birth, nationality, country of residence;
- Contact details: correspondence address, telephone numbers, email addresses;
- Professional and business information: employer or business name, sector, role, business address;
- Financial information provided voluntarily by the client in connection with a mandate, including investment objectives, financial situation, and relevant transaction history;
- Source of wealth or source of funds information where reasonably necessary for due diligence purposes and where collected with the client's knowledge;
- Correspondence and meeting records generated in the course of providing advisory services.
The legal bases for processing client data are the performance of a contractual agreement (Art. 6(1)(b) GDPR), compliance with applicable legal obligations (Art. 6(1)(c) GDPR), and our legitimate interests in providing professional advisory services and maintaining accurate records (Art. 6(1)(f) GDPR). Where a client is a natural person, a tailored client-level privacy notice will be provided at the point of onboarding, supplementing and, where relevant, superseding this general policy.
08 — Retention
Retention Periods
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by applicable statutory obligations. At the end of each applicable retention period, data is securely and permanently deleted or irreversibly anonymised. The following table sets out our standard retention periods by category of data:
| Data Category | Standard Retention Period | Primary Basis |
|---|---|---|
| Website server log files | 14 days | Legitimate interest (security) |
| Cookie consent records | Until cleared by user; max. 24 months | Legal obligation (demonstrating consent) |
| Contact form enquiries (no engagement) | 36 months from last interaction | Legitimate interest (business records) |
| General email correspondence (no engagement) | 36 months from last substantive message | Legitimate interest (business records) |
| Pre-contractual email correspondence | 36 months from last contact | Legitimate interest / legal protection |
| Client engagement correspondence & records | 5–10 years after end of engagement | Legal obligation / legitimate interest |
| Accounting and financial records | As required by applicable law (typically 10 years) | Legal obligation |
| Correspondence relating to disputes | Duration of dispute plus applicable limitation period | Legitimate interest (legal protection) |
Where a legal obligation requires data to be retained for a period longer than the above standard periods, we will comply with that obligation. Where you request deletion of your data and we are unable to comply immediately due to a legal retention obligation, we will restrict processing of that data to the minimum necessary until deletion is lawfully possible.
09 — Disclosure
Disclosure of Personal Data to Third Parties
Chalor Capital Allocation & Institutional Group does not sell, rent, or trade personal data to or with third parties under any circumstances. We disclose personal data to third parties only in the specific situations described below.
Service Providers Acting as Data Processors
We engage a limited number of carefully selected third-party service providers who process personal data on our behalf in order to support our operations. These providers act as data processors pursuant to written agreements that contractually restrict their use of personal data to the purpose for which it was disclosed and require them to implement appropriate technical and organisational security measures. Categories of service providers include:
- Email and cloud computing infrastructure providers (including Microsoft, as described in Section 6);
- Cybersecurity and IT support services;
- Professional advisors such as lawyers and accountants, who are bound by statutory or professional confidentiality obligations in their own right.
Disclosure Required by Law
We may be required to disclose personal data to courts, law enforcement authorities, or other competent public bodies where we are under a legal obligation to do so. We will disclose only the minimum necessary personal data in response to any such lawful demand, and where legally permissible, we will endeavour to inform the data subject concerned of the disclosure request before complying.
Business Succession
In the event of a merger, acquisition, reorganisation, or sale of the Company or its assets, personal data held by us may be transferred to the successor entity as part of that transaction. We would notify affected data subjects of any such transfer and the new controller's identity as soon as reasonably practicable.
With Your Explicit Consent
In any situation not covered above, we will only disclose your personal data to a third party where you have given us your explicit, informed, and freely given consent to do so. You may withdraw such consent at any time, and withdrawal will not affect the lawfulness of any disclosure made prior to withdrawal.
10 — International Transfers
Transfers of Personal Data Outside the EEA
Chalor Capital Allocation & Institutional Group primarily processes personal data within the European Economic Area (EEA). However, as described in Section 6, our email infrastructure relies on Microsoft's global services, and some processing may take place in countries outside the EEA, including the United States.
All international transfers of personal data are conducted in compliance with Chapter V of the GDPR. Transfers occur only where one of the following safeguards is in place:
- Adequacy decision: The European Commission has formally recognised the destination country as providing a level of data protection essentially equivalent to that within the EEA;
- Standard Contractual Clauses (SCCs): We or our data processors have implemented the European Commission's approved standard contractual clauses (Commission Implementing Decision (EU) 2021/914) with the relevant recipient, which contractually bind the recipient to GDPR-equivalent standards of data protection;
- Other appropriate safeguards: As recognised under Article 46 GDPR, including binding corporate rules or approved codes of conduct where applicable.
You may request further information about the specific safeguards applicable to any particular international transfer by contacting us at chalorgroup@outlook.fr.
11 — Your Rights
Your Rights as a Data Subject
Under the GDPR and applicable national data protection law, you have the following rights in respect of the personal data we hold about you. We are committed to facilitating the exercise of these rights promptly, free of charge (unless a request is manifestly unfounded or excessive), and within the timescales prescribed by law.
Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data relating to you, and if so, to receive a copy of that data together with supplementary information about how it is processed, including the purposes of processing, the categories of data, the recipients to whom it has been disclosed, the retention period, and the existence of your other rights. We will provide this information in a clear and intelligible format.
Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data we hold about you and the completion of incomplete personal data. We will act on such a request without undue delay and, where we have disclosed the inaccurate data to third parties, we will inform them of the rectification unless doing so is impossible or would involve disproportionate effort.
Right to Erasure / Right to Be Forgotten (Article 17 GDPR)
You have the right to request that we delete personal data relating to you where: (i) it is no longer necessary for the purposes for which it was collected; (ii) you withdraw consent and there is no other legal basis for processing; (iii) you object to processing under Art. 21 and no overriding legitimate grounds exist; (iv) the data has been unlawfully processed; or (v) erasure is required by applicable law. We will comply with a valid erasure request without undue delay, subject to any legal retention obligations that may require us to retain the data for a specified period.
Right to Restriction of Processing (Article 18 GDPR)
You have the right to request that we restrict processing of your personal data in the following circumstances: (i) you contest the accuracy of the data, pending verification; (ii) processing is unlawful but you oppose erasure; (iii) we no longer need the data but you require it for the establishment, exercise, or defence of legal claims; or (iv) you have objected to processing pending verification of whether our legitimate grounds override yours. Where processing is restricted, we will store your data but not process it further without your consent or for the establishment, exercise, or defence of legal claims.
Right to Data Portability (Article 20 GDPR)
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us. This right applies to the extent technically feasible.
Right to Object (Article 21 GDPR)
Where we process personal data on the basis of legitimate interests (Art. 6(1)(f)), you have the right to object to that processing at any time on grounds relating to your particular situation. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims. Where personal data is processed for direct marketing purposes — which we do not currently conduct — you have an absolute right to object at any time.
Right to Withdraw Consent (Article 7(3) GDPR)
Where we process your personal data based on your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing that took place prior to withdrawal. To withdraw consent for cookie-based processing, you may clear your browser's local storage. For any other consent-based processing, please contact us at chalorgroup@outlook.fr.
Right Not to Be Subject to Solely Automated Decisions (Article 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects or similarly significantly affects you. We do not currently engage in any such automated decision-making.
Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR or applicable national data protection law, you have the right to lodge a complaint with the competent supervisory authority in the EU member state in which you reside, work, or where the alleged infringement occurred. In Germany, you may contact the competent data protection authority for the relevant federal state, or the Federal Commissioner for Data Protection and Freedom of Information (BfDI) at www.bfdi.bund.de. We would, however, appreciate the opportunity to address your concern directly before you contact a supervisory authority, and encourage you to reach out to us first.
How to Exercise Your Rights
To exercise any of the rights set out above, please submit a written request to chalorgroup@outlook.fr. Please include sufficient information to enable us to identify you as a data subject and to locate the relevant personal data. We may request a reasonable form of identification before processing your request, in order to protect your data from unauthorised access. We will respond within one (1) calendar month of receipt of a valid request, and will notify you if we require an extension of up to two (2) further months in cases of complexity or volume.
12 — Security
Technical and Organisational Security Measures
Chalor Capital Allocation & Institutional Group implements a comprehensive set of technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Article 32 of the GDPR. Our security measures include, but are not limited to, the following:
- Encrypted transmission of data via TLS/SSL for all website traffic, ensuring that data exchanged between your browser and our servers is protected in transit;
- Multi-factor authentication (MFA) required for access to all systems that store or process personal data, including email accounts and cloud storage;
- Role-based access control (RBAC) to restrict access to personal data to only those personnel who have a demonstrable need to access it in the course of their duties;
- Regular review and update of software, systems, and security configurations to address emerging vulnerabilities;
- Regular backup of data to protected storage, enabling recovery in the event of data loss or corruption;
- Strict confidentiality obligations imposed on all personnel with access to personal data, applicable both during and after their engagement with the Company;
- Internal procedures for the detection, recording, and timely reporting of personal data breaches, in accordance with Articles 33 and 34 GDPR.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within seventy-two (72) hours of becoming aware of the breach. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly, without undue delay, providing clear information about the nature of the breach and the steps you may take to protect yourself.
Notwithstanding the above, no method of data transmission or storage is completely secure. While we take every reasonable precaution to protect your personal data, we cannot guarantee absolute security, and we encourage you to exercise caution about the type of information you transmit to us electronically.
13 — Minors
Data Relating to Minors
This website and all services offered by Chalor Capital Allocation & Institutional Group are directed exclusively at adults. We do not knowingly collect or process personal data relating to individuals under the age of eighteen (18). If you believe that we have inadvertently received personal data relating to a minor, please notify us immediately at chalorgroup@outlook.fr and we will take prompt steps to delete such data from our systems.
14 — Changes
Amendments to This Privacy Policy
We reserve the right to update, amend, or supplement this Privacy Policy at any time in order to reflect changes in our data processing practices, changes in applicable law or regulatory guidance, or changes in the services we offer. Any amendments will be published on this page with an updated revision date clearly indicated in the metadata bar at the top of the document.
Where we make material changes to this Privacy Policy — that is, changes that meaningfully affect your rights or our obligations — we will take reasonable steps to draw these changes to your attention, which may include a notice on our website or, where we hold your contact details, direct communication by email.
We encourage you to review this Privacy Policy periodically to remain informed of how we handle your personal data. Your continued use of our website or services following the publication of an amended Privacy Policy constitutes your acknowledgment of the updated version, without prejudice to any rights you hold under applicable data protection law.
Previous versions of this Privacy Policy are available on request by contacting us at chalorgroup@outlook.fr.
15 — Contact
Contact for Data Protection Matters
If you have any questions about this Privacy Policy, wish to exercise your rights as a data subject, have a concern about our data processing practices, or wish to report a suspected data security incident, please contact us using the details below. We are committed to responding to all data protection enquiries promptly, respectfully, and in full compliance with our obligations under applicable law.
Data Protection Contact
Berlin, Germany