All briefings Platform

Our Commitment to Data Privacy

Data room access logs often outlive the transaction they were meant to support when no written policy tells operators what to retain, redact, or destroy after a pass. Principals allocating across New York, Israel, and…

Data room access logs often outlive the transaction they were meant to support when no written policy tells operators what to retain, redact, or destroy after a pass. Principals allocating across New York, Israel, and Ukraine need clarity on how Foundation handles identity records, financial suitability files, operator rosters, and human capital data when bilateral mandates run for years rather than quarters. This article explains our investor data privacy standards: what we collect, who may see it, how long it persists, and when confidentiality must yield to conflicts notice without eroding allocator trust.

Start with Sovereign Wealth Allocation to Real Assets: City Pair Analysis for Allocators for pillar sequencing, then Poland Ukraine Logistics Integration: Implementation Standards in Practice for adjacent topic framing. What follows concentrates on investor data privacy, not introductory platform mechanics.

Scope: which records privacy policy covers

Foundation privacy standards apply to allocator onboarding files, operator and contractor rosters, seller introduction attribution, pass and refusal logs, mentor correspondence, and incubator relationship data that intersects investment authority. Policy scope excludes public marketing materials but includes any record that could identify principals, financial capacity, or transaction intent. Scope tables dated in policy files give successors evidence that classification preceded execution rather than followed dispute.

Platform purpose and committee architecture appear in What Is Foundation and Why It Exists, which allocators should read when comparing whether privacy handling matches the cross corridor model onboarding describes.

Privacy guidance from the U.S. Federal Trade Commission privacy resources helps family offices explain why written classification should precede bilateral expansion when co investors import informal data sharing habits from vintage programs.

Collection limits and purpose binding

Data collection follows purpose binding: each field requested in onboarding or diligence must map to a stated mandate function such as suitability review, conflicts screening, operator vetting, or reporting compliance. Forms that collect optional biography or social graph data without purpose binding fail privacy review. Committees should reject sponsor packets that add personal data fields without allocator consent or documented need.

Allocator orientation material appears in Frequently Asked Questions About Foundation, which privacy onboarding should reference when explaining mandatory versus optional data categories.

Cross corridor transfers and consent triggers

Moving allocator files between New York, Israel, and Ukraine teams requires documented consent or contractual authority, not informal email forwards. Transfer logs should name sender, recipient role, data category, and legal basis before files cross jurisdictions with different regulatory expectations. Ad hoc transfers treated as operational convenience usually surface during disputes when retention and deletion schedules were never aligned.

Cross border governance research from the OECD corporate governance research supports memos that explain why transfer logs belong in minutes before multi corridor sleeves expand.

Access control, logging, and minimum necessary visibility

Role based access limits counsel, operators, and introducers to categories their function requires. Access events should log user, timestamp, and record category so post incident review can reconstruct who saw what before a pass or commitment vote. Shared drives without logging fail institutional privacy standards even when participants trust one another informally.

Conflicts policy intersects with access control in Our Conflicts of Interest Policy, which allocators should read when comparing how confidentiality tiers coexist with disclosure duties.

Information security frameworks from ISO information security standards help privacy committees benchmark access design when regulatory regimes differ across corridors.

Retention schedules and deletion authority

Retention schedules name minimum and maximum hold periods for allocator files, operator rosters, pass logs, and human capital records. Deletion or anonymization triggers when relationships end, mandates refuse, or statutory periods expire. Successor handoff packets must state which records transfer with consent, which remain archived under schedule, and which destroy on date certain rather than on staff convenience.

Long horizon mandate framing in What Is Foundation and Why It Exists connects retention design to thesis duration rather than to quarterly reporting pressure alone.

Adviser recordkeeping guidance from the SEC Investment Advisers Act resources helps family offices benchmark retention against stated privacy commitments before co investment scales.

Technology exploration files use separate retention rules

Incubator exploration generates prototype repositories, mentor challenge notes, and collaborator references that differ from rent rolls or appraisal drafts in sensitivity and retention needs. Foundation Incubator programs store those records under classification rules explained at onboarding, with access limited to mentors and allocators whose mandate includes human capital review. Collateral committees should not request incubator correspondence without documented authority, even when the same family office funds both sleeves.

Founders receive written notice describing which artifacts enter allocator packets, which remain confidential during exploration, and which destroy on schedule after a pass.

Incident response and allocator notification

Privacy incidents trigger documented response: containment, impact assessment, allocator notice where material, regulatory consultation where required, and control updates logged for successor review. Reporting that lists transaction counts without privacy outcomes misleads co investors who assumed onboarding summaries remained accurate. Incident memos should enter allocator updates when material exposure or unauthorized access occurred during the reporting period.

Financial stability research from the Federal Reserve commercial real estate notes supports conversations when committees explain that privacy discipline reflects stewardship rather than quarterly liquidity optics alone.

Vendor and operator processors under contract

Third party counsel, registry agents, contractors, and technology vendors that touch allocator data must operate under written processor terms specifying purpose limits, deletion duties, and breach notice windows. Operator benches that share diligence folders through consumer cloud tools without processor review fail privacy gates even when participants mean well. Vendor tables dated in minutes show successors which processors held data during each mandate phase.

Commercial real estate operators often underestimate how long registry scans, appraisal drafts, and insurance binders remain in vendor systems after a pass. Privacy review should require vendor deletion confirmations when mandates end, not assume files vanish when local copies delete.

Apply privacy standards before the next bilateral vote

Foundation investor data privacy succeeds when committees treat data handling as capital infrastructure: purpose bound collection, role based access with logs, corridor transfer consent, retention and deletion schedules, incubator separation from collateral files, incident response with allocator notice, and vendor processor discipline. Subscription footnotes cannot substitute for operational privacy files principals can audit after advisor transitions.

Maintain dated access logs, retention schedules, transfer records, and incident memos so each bilateral vote shows privacy was policy rather than preference.

Additional governance and privacy essays live in the General archive. Principals may submit confidentiality questions through the FAQ portal or review leadership responsibilities on About Us before onboarding data fields expand.

Review data classification tables and vendor processor lists in the next investment committee packet before bilateral files expand across corridors that share operators but must not share records without consent.

Privacy training for field operators should occur at mandate start, not after a data incident. Training logs belong in allocator onboarding packets so successors verify that access rules were understood before registry scans, appraisal drafts, or mentor correspondence entered shared systems.

Annual privacy review should version policy files when corridors expand, vendor rosters rotate, or incubator programs add data categories that collateral committees never previously stored.

Allocator requests to export diligence folders should trigger privacy review even when the requesting principal sits on both technology and real estate committees. Export logs preserve evidence that data left the platform only with appropriate classification and recipient role validation.

Programs hosted through Foundation Incubator publish privacy addenda describing exploration record handling for founders who also appear as co investors in collateral files elsewhere on the platform.

Related Foundation reading: Foundation Incubator.

Timeless Value. Perpetual Legacy.

Quiet intelligence. Serious capital.

Contact Foundation All briefings