Version 15 October 2025 — This Privacy Policy sets out how Magnificentech Solution Ltd trading as TrustVerify (Company No.: 16321180) collects, uses, stores, shares, and protects personal data in accordance with the UK GDPR, the Data Protection Act 2018, and the EU GDPR where applicable.
Table Of Contents
This Privacy Policy sets out the principles and procedures adopted by Magnificentech Solution Ltd trading as TrustVerify (Company No.: 16321180) in relation to the collection, use, storage, sharing, and protection of personal data. TrustVerify is a fintech and cybersecurity SaaS provider, committed to the highest standards of data protection and privacy compliance in accordance with applicable laws and regulations in the United Kingdom, the European Economic Area, and internationally.
The purpose of this policy is to provide clear and transparent information to customers, clients, website visitors, employees, and third parties regarding how TrustVerify processes personal data, the rights of individuals, and the measures in place to safeguard such data.
TrustVerify recognises the importance of privacy and is dedicated to ensuring that all personal data is handled lawfully, fairly, and transparently. This policy is designed to support compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU GDPR (where applicable), and other relevant data protection laws.
This policy applies to all personal data processed by TrustVerify, whether collected directly from individuals, through automated technologies, or from third-party sources, and covers all categories of data subjects including customers, clients, website visitors, employees, and third parties.
TrustVerify processes a range of personal data, including but not limited to names, contact details, identification data, technical and usage data, financial data, employment data, and special category data, in accordance with lawful bases such as consent, contract, legal obligation, legitimate interests, public task, and vital interests.
The company is committed to robust data security, implementing appropriate technical and organisational measures such as encryption, access controls, staff training, regular security audits, multi-factor authentication, and physical security measures to protect personal data from unauthorised access, loss, or misuse.
TrustVerify ensures that personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory requirements, or until it is no longer required for business needs. Secure deletion, anonymisation, and destruction of physical records are employed for data disposal.
Individuals have a range of rights in relation to their personal data, including the right to access, rectify, erase, restrict processing, data portability, object, and withdraw consent. Procedures are in place to facilitate the exercise of these rights, including identity verification and response timeframes.
TrustVerify has appointed a Data Protection Officer (DPO) or designated contact for data protection matters. Contact details are provided in Section 15 of this policy.
Complaints or enquiries regarding data protection are handled through a dedicated email address, with an internal investigation process, escalation to the DPO or senior management, and information on referral to the Information Commissioner's Office (ICO) where appropriate.
This policy is reviewed annually by senior management to ensure ongoing compliance and effectiveness. Bi-annual internal monitoring and audits are conducted to assess data protection practices.
This Privacy Policy should be read in conjunction with other relevant policies and documents, including but not limited to the Data Protection Policy, Information Security Policy, and Employee Handbook.
2.1 This Privacy Policy applies to all personal data processed by Magnificentech Solution Ltd trading as TrustVerify (Company No.: 16321180) in connection with its fintech and cybersecurity SaaS activities, including fraud prevention and compliance tools.
The Policy covers the collection, use, storage, sharing, and disposal of personal data relating to the following categories of individuals:
This Policy applies to personal data processed in the United Kingdom, the European Economic Area (EEA), and internationally, subject to applicable data protection laws and regulations in each jurisdiction.
The Policy encompasses all types of personal data collected by TrustVerify, including names, contact details, identification data, technical and usage data, financial data, employment data, and special category data, regardless of the method of collection.
The Policy applies to personal data collected directly from individuals, through automated technologies such as cookies and tracking tools, and from third-party sources.
All TrustVerify employees, departments, and authorised personnel are required to comply with this Policy when processing personal data.
The Policy also applies to external parties who process personal data on behalf of TrustVerify, including data processors, contractors, and service providers, who must adhere to contractual obligations and data protection standards equivalent to those set out in this Policy.
This Policy is intended to ensure compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and other relevant international data protection laws.
The Policy is binding on all individuals and entities to whom it applies, and forms part of TrustVerify's wider governance and compliance framework.
Any queries regarding the scope or applicability of this Policy should be directed to the Data Protection Officer or designated contact person, whose details are provided in Section 15.
3.1 For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:
4.1 In the course of its operations, Magnificentech Solution Ltd trading as TrustVerify collects and processes a range of personal data relating to individuals, including but not limited to customers, clients, website visitors, employees, and third parties. The categories of personal data collected are determined by the nature of the relationship with the individual and the specific services provided.
The types of personal data collected may include the following:
Personal data may be collected directly from individuals, through automated technologies (including cookies and tracking tools), or from third-party sources, depending on the context and purpose of processing.
TrustVerify is committed to collecting only the minimum personal data necessary for the specified purposes and to ensuring that all data is processed lawfully, fairly, and transparently in accordance with applicable data protection legislation.
5.1 TrustVerify collects personal data through a variety of methods to ensure the effective delivery of its fintech and cybersecurity SaaS services, compliance with legal obligations, and the protection of individuals' rights. The following outlines the principal methods by which data is collected.
5.2 Cookies and similar technologies are used not only for website functionality and analytics, but also for security and fraud detection purposes (e.g., identifying suspicious activity, preventing unauthorised access). Where required by law, consent is obtained for the use of non-essential cookies, and users are informed of the specific purposes for which cookies are used.
Direct Collection from Individuals: Personal data is collected directly from individuals when they interact with TrustVerify, including but not limited to completing online registration forms, account creation, or onboarding processes; submitting identification or verification documents as part of fraud prevention or compliance checks; communicating with TrustVerify via email, telephone, live chat, or other communication channels; and participating in surveys, feedback requests, or customer support interactions.
Automated Technologies and Interactions: Data is automatically collected through the use of cookies, web beacons, tracking pixels, and similar technologies when individuals visit TrustVerify's websites, use its applications, or interact with its digital platforms. This includes collecting technical data such as IP addresses, browser types, device identifiers, operating systems, and access times; monitoring usage data, including navigation patterns, page views, and interaction logs to enhance security, detect fraud, and improve user experience; and deploying analytics tools to gather statistical information for service optimisation and compliance monitoring.
Third-Party Sources: TrustVerify may obtain personal data from third-party sources, including business partners, financial institutions, or service providers involved in the delivery of TrustVerify's services; publicly available registers, databases, or social media platforms for verification and due diligence purposes; and regulatory authorities, law enforcement agencies, or other entities as required for legal compliance, fraud prevention, or risk management.
Where required by law, TrustVerify will notify individuals when data is collected from third-party sources and provide information regarding the categories of data obtained and the purposes of processing.
TrustVerify ensures that all methods of data collection are conducted in accordance with applicable data protection laws, including the UK GDPR, Data Protection Act 2018, and relevant international regulations. Appropriate safeguards are implemented to protect the integrity and confidentiality of personal data throughout the collection process.
Magnificentech Solution Ltd trading as TrustVerify processes personal data only where there is a valid legal basis under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where relevant, the EU General Data Protection Regulation (EU GDPR). The lawful bases relied upon are as follows:
We maintain records of our processing activities and the lawful bases relied upon for each category of personal data. Where the lawful basis for processing changes, we will notify affected individuals as required by law.
If you have any questions regarding the lawful bases for processing your personal data, or require further information, please contact our Data Protection Officer or designated contact person as set out in this policy.
7.1 Magnificentech Solution Ltd trading as TrustVerify recognises the heightened sensitivity and legal protections afforded to special category data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Special category data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, and data concerning a person's sex life or sexual orientation.
The company processes special category data only where strictly necessary and in accordance with one or more of the lawful bases set out in Article 9 of the UK GDPR, including explicit consent, employment and social security law obligations, vital interests, legal claims, substantial public interest, medical diagnosis or provision of care, public health, and archiving or research purposes.
Special category data is collected and processed for the following purposes:
Access to special category data is strictly limited to authorised personnel who require such access for legitimate business or legal purposes. All staff handling such data receive appropriate training on confidentiality and data protection obligations.
Special category data is subject to enhanced security measures, including encryption, access controls, and regular security audits, to ensure its confidentiality, integrity, and availability.
The company maintains detailed records of processing activities involving special category data, including the legal basis for processing, categories of data subjects, and retention periods, in accordance with accountability requirements.
Special category data is retained only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal or regulatory obligations, or to defend legal claims. Upon expiry of the retention period, data is securely deleted, anonymised, or destroyed in accordance with company procedures.
Individuals whose special category data is processed by the company are informed of their rights, including the right to access, rectify, erase, restrict processing, object, and withdraw consent, as set out in this policy.
Any queries or concerns regarding the processing of special category data should be directed to the Data Protection Officer or designated contact, whose details are provided in this policy.
8.1 TrustVerify processes personal data strictly for specified, explicit, and legitimate purposes in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where relevant, the EU GDPR.
The main purposes for which personal data is processed by TrustVerify include:
Personal data is only processed for the purposes for which it was collected, unless TrustVerify reasonably considers that it is necessary to process such data for another purpose that is compatible with the original purpose. Where processing for a new purpose is required, individuals will be notified in advance and, where necessary, additional consent will be obtained in accordance with applicable law.
Trust Scoring, Profiling, and Automated Decision-Making: TrustVerify uses personal data to generate trust scores and conduct profiling for the purposes of fraud detection, risk assessment, and service optimisation. This involves automated analysis of identity, transaction, and behavioural data to assess the likelihood of fraudulent activity or to determine eligibility for certain services.
Processing for trust scoring and profiling is based on our legitimate interests in fraud prevention and service security, compliance with legal obligations, and, where required, the performance of a contract.
You have the right to object to profiling and automated decision-making under Articles 21 and 22 of the UK/EU GDPR. You may request human intervention, express your point of view, and contest decisions made solely by automated means that produce legal or similarly significant effects. To exercise these rights, contact our Data Protection Officer (see Section 15). TrustVerify does not make decisions with legal or similarly significant effects solely based on automated processing without appropriate safeguards. Where such processing occurs, you will be informed and provided with meaningful information about the logic involved, as well as the significance and consequences of such processing.
We, Magnificentech Solution Ltd trading as TrustVerify, are committed to ensuring that personal data is only shared or disclosed in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where relevant, the EU GDPR.
Personal data may be shared internally within TrustVerify strictly on a need-to-know basis, limited to employees and departments whose roles require access for the purposes set out in this policy, such as service provision, compliance, fraud prevention, and employee administration.
External sharing of personal data is only undertaken where necessary and in accordance with legal requirements. This may include sharing with:
We do not sell or rent personal data to third parties for marketing or any other commercial purposes.
Where personal data is shared with third parties, we ensure that appropriate due diligence is conducted and that data sharing agreements or data processing contracts are in place to safeguard the data and ensure compliance with applicable laws.
All integrations with third-party services and API interactions are subject to data protection impact assessments and contractual safeguards. Legal grounds for such processing include legitimate interests, contract performance, and legal obligations. All data sharing is conducted under written agreements or legal obligations, with due diligence and safeguards in place. Regulatory interactions are documented and based on statutory requirements or legitimate interests.
Personal data is not transferred outside the UK or EEA. Should this position change, we will implement appropriate safeguards, such as Standard Contractual Clauses or other approved mechanisms, and update this policy accordingly.
All disclosures of personal data are logged and subject to regular review as part of our internal audit and compliance processes. Individuals will be notified, where required by law, if their personal data is to be shared with third parties, and will be informed of their rights in relation to such disclosures.
Any queries or concerns regarding data sharing and disclosure should be directed to the Data Protection Officer or designated contact, whose details are provided in this policy.
10.1 TrustVerify does not currently transfer personal data outside the United Kingdom (UK) or the European Economic Area (EEA). All personal data collected, processed, and stored by Magnificentech Solution Ltd trading as TrustVerify is maintained within the UK or EEA, in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Should it become necessary in the future to transfer personal data internationally, TrustVerify will ensure that such transfers are conducted in full compliance with all relevant legal requirements. This includes, but is not limited to, implementing appropriate safeguards to protect the rights and freedoms of data subjects.
In the event of any future international data transfers, TrustVerify will assess the adequacy of the destination country's data protection laws and, where required, implement one or more of the following safeguards:
TrustVerify will provide clear and transparent information to data subjects regarding any international data transfers, including the legal basis for such transfers and the safeguards in place to protect their personal data. If personal data is transferred outside the UK/EEA, TrustVerify will implement safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or binding corporate rules. Additional technical measures (e.g., encryption, pseudonymisation) are applied to protect data during transfer. Data subjects will be informed of the legal basis and safeguards for any such transfers.
All international data transfers, if undertaken, will be subject to regular review and risk assessment to ensure ongoing compliance with applicable data protection laws and to address any changes in legal requirements or business operations.
Data subjects may contact TrustVerify's Data Protection Officer (DPO) for further information regarding international data transfers, including details of the safeguards implemented and their rights in relation to such transfers.
11.1 Magnificentech Solution Ltd trading as TrustVerify is committed to ensuring that all personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, to comply with legal and regulatory obligations, and to meet legitimate business needs.
Personal data will be retained in accordance with applicable laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and any other relevant statutory or regulatory requirements.
The retention period for each category of personal data is determined based on the following criteria:
Once the applicable retention period has expired, or when personal data is no longer required for the purposes for which it was collected, the Company will ensure secure and irreversible disposal of such data. Methods of data disposal include secure deletion of electronic records using industry-standard data erasure tools, anonymisation of data where continued use is required for statistical, research, or analytical purposes, and physical destruction of paper records and other tangible media containing personal data.
The Company maintains a Data Retention Schedule, which specifies retention periods for all categories of personal data processed. This schedule is reviewed and updated regularly to ensure ongoing compliance with legal and business requirements:
Data Retention Schedule
| Data Category | Retention Period |
|---|---|
| Trust scoring / profiling data | 5 years from last activity |
| API credentials | 12 months after account closure |
| Fraud detection logs | 7 years |
| Customer account data | 6 years after closure |
| Regulatory correspondence | As required by law |
Where personal data is subject to a legal hold or is required for the establishment, exercise, or defence of legal claims, such data will be retained until the hold is lifted or the claim is resolved, notwithstanding any other retention periods.
Employees and relevant third parties are provided with training and guidance on data retention and disposal obligations as part of the Company's data protection compliance programme. Any queries or concerns regarding data retention and disposal should be directed to the Data Protection Officer or designated contact person, whose details are set out in this Policy.
12.1 Magnificentech Solution Ltd trading as TrustVerify is committed to maintaining the highest standards of data security to protect all personal data processed in connection with its fintech and cybersecurity SaaS operations. The following measures are implemented to ensure the confidentiality, integrity, and availability of personal data at all times.
12.13 TrustVerify collects and processes data from developers and API users, including registration details, usage logs, and access credentials. Credentials (such as API keys and tokens) are generated, stored, and transmitted using strong encryption and are accessible only to authorised personnel.
12.14 API usage is monitored for security, compliance, and fraud prevention. Data exchanged via APIs is subject to the same security and privacy standards as other personal data.
12.15 Developer and API user data, including credentials, are retained for the duration of the user relationship and for a period of 12 months after account closure, unless a longer period is required by law or for the establishment, exercise, or defence of legal claims. Credentials are securely deleted or anonymised upon expiry of the retention period.
13.1 Individuals whose personal data is processed by Magnificentech Solution Ltd trading as TrustVerify are entitled to exercise a range of rights under applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where relevant, the EU GDPR. The following rights are available to individuals, subject to certain legal limitations and conditions:
You have the right to object to processing, including profiling, under Article 21 GDPR, and the right not to be subject to a decision based solely on automated processing, including profiling, under Article 22 GDPR. For more information or to exercise these rights, contact our Data Protection Officer.
To exercise any of these rights, individuals should submit a written request via email to the designated data protection contact. TrustVerify may require verification of identity before processing any request to ensure the security of personal data.
TrustVerify will acknowledge receipt of all valid requests and provide a substantive response within one month, or within any extended period permitted by law where requests are complex or numerous. Individuals will be informed of any such extension and the reasons for delay.
Where requests are manifestly unfounded or excessive, TrustVerify reserves the right to charge a reasonable fee or refuse to act on the request, in accordance with applicable law. If an individual is dissatisfied with TrustVerify's response or handling of their request, they may escalate the matter to the Data Protection Officer or designated contact identified in Section 15.
Individuals also have the right to lodge a complaint with the Information Commissioner's Office (ICO) or the relevant supervisory authority in their jurisdiction if they believe their data protection rights have been infringed. TrustVerify is committed to upholding the rights of individuals and will ensure that all requests are handled promptly, transparently, and in accordance with applicable data protection legislation.
14.1 Individuals whose personal data is processed by Magnificentech Solution Ltd trading as TrustVerify are entitled to exercise their data protection rights in accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where relevant, the EU General Data Protection Regulation (EU GDPR).
The rights available to individuals include the right to access their personal data, the right to rectification of inaccurate or incomplete data, the right to erasure (right to be forgotten), the right to restrict processing, the right to data portability, the right to object to processing, and the right to withdraw consent at any time where processing is based on consent.
Requests to exercise any of these rights must be submitted in writing via the designated email address provided in this policy. Individuals may be required to provide sufficient information to verify their identity before any action is taken in response to their request.
Upon receipt of a valid request, TrustVerify will acknowledge the request and respond within one month, in accordance with statutory timeframes. Where requests are complex or numerous, this period may be extended by a further two months, and the individual will be informed of any such extension and the reasons for it.
TrustVerify will provide information or take the requested action free of charge. However, where requests are manifestly unfounded or excessive, particularly if repetitive, TrustVerify reserves the right to charge a reasonable fee or refuse to act on the request, in accordance with applicable law.
In certain circumstances, TrustVerify may be required to retain or restrict access to personal data in order to comply with legal obligations or to establish, exercise, or defend legal claims. Where this applies, individuals will be informed of the reasons for any refusal or restriction, unless prohibited by law.
Individuals who are dissatisfied with the handling of their request or the outcome may raise a complaint using the dedicated email address for complaints set out in this policy. All complaints will be investigated internally and may be escalated to the Data Protection Officer or senior management as appropriate.
If an individual remains dissatisfied after internal review, they have the right to lodge a complaint with the Information Commissioner's Office (ICO) or, where applicable, with a supervisory authority in the EEA.
Further information on how to exercise data protection rights, including contact details for the Data Protection Officer, can be found in Section 15 of this policy. Individuals are encouraged to contact TrustVerify with any queries or concerns regarding their data protection rights.
15.1 In accordance with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, Magnificentech Solution Ltd trading as TrustVerify has appointed a Data Protection Officer (DPO) to oversee the company's data protection strategy and ensure ongoing compliance with statutory obligations.
The DPO is responsible for:
Data subjects, including customers, employees, website visitors, and third parties, may contact the DPO to submit data protection requests or exercise their statutory rights; raise concerns or complaints regarding the handling of their personal data; and request further information about TrustVerify's data protection practices.
15.4 The contact details for the DPO are as follows:
All data protection enquiries and complaints should be directed to the DPO using the contact details above. The DPO will acknowledge receipt of all requests within the statutory timeframe and provide a substantive response in accordance with legal requirements.
If you are dissatisfied with the response received from the DPO, you have the right to escalate your complaint to the Information Commissioner's Office (ICO) or the relevant supervisory authority in your jurisdiction. TrustVerify is committed to ensuring that the DPO is registered with the ICO and that their contact details are kept up to date in all relevant documentation and communications.
16.1 Magnificentech Solution Ltd trading as TrustVerify is committed to upholding the highest standards of data protection and privacy. We recognise the importance of addressing any concerns, complaints, or enquiries regarding the processing of personal data in a timely, transparent, and effective manner.
Individuals may submit complaints or enquiries relating to data protection, privacy practices, or the handling of their personal data by contacting our dedicated email address: michael.omotayo@magnificentechsolution.co.uk. All submissions must include sufficient information to enable us to identify the individual and the nature of the concern.
Upon receipt of a complaint or enquiry, we will:
If the individual is dissatisfied with the outcome or handling of their complaint, the matter may be escalated to the Data Protection Officer (DPO) or a member of senior management for further review. Contact details for the DPO or designated contact person are provided in Section 15 of this policy.
16.5 Where a complaint remains unresolved, individuals have the right to refer their complaint to the Information Commissioner's Office (ICO) or the relevant supervisory authority in their jurisdiction. Details for contacting the ICO are available at www.ico.org.uk.
All complaints and enquiries, as well as the actions taken in response, will be documented and retained in accordance with our data retention policy. This ensures accountability and enables ongoing improvement of our privacy practices. We are committed to continuous improvement and will regularly review the effectiveness of our complaints and enquiries procedure as part of our annual policy review process.
17.1 This Privacy Policy is subject to regular review to ensure ongoing compliance with applicable data protection laws, regulatory requirements, and industry best practices relevant to the operations of Magnificentech Solution Ltd trading as TrustVerify.
The policy shall be reviewed at least annually by Senior Management, or more frequently if required by changes in law, regulatory guidance, business operations, or identified risks.
The review process will include:
Any amendments to this Privacy Policy will be approved by Senior Management and communicated promptly to all relevant parties, including employees, clients, and third parties as appropriate. Updated versions of the Privacy Policy will be published on the TrustVerify website and made available upon request.
All employees and relevant stakeholders are required to familiarise themselves with the most current version of this policy and adhere to its provisions. TrustVerify will maintain records of all policy reviews, updates, and approvals in accordance with its record-keeping obligations.
Where significant changes are made to the policy, TrustVerify will provide appropriate training or guidance to ensure continued understanding and compliance. This section should be read in conjunction with related policies, including but not limited to the Data Protection Policy, Information Security Policy, and Records Retention Policy.
18.1 TrustVerify is committed to maintaining the highest standards of data protection and privacy compliance. To ensure ongoing adherence to applicable data protection laws, regulatory requirements, and internal policies, we implement a robust programme of internal monitoring and audits. Internal monitoring and audits are conducted bi-annually and may be supplemented by ad hoc reviews in response to significant changes in law, business operations, or identified risks.
The objectives of internal monitoring and audits include:
Internal audits are led by senior management or designated compliance personnel, with findings documented in formal audit reports. These reports include identified issues, recommended corrective actions, and timelines for remediation. Where necessary, audit findings are escalated to the Data Protection Officer (DPO) or senior management for further review and action.
All employees and relevant third parties are required to cooperate fully with internal monitoring and audit activities, providing access to records, systems, and information as reasonably required. The results of internal monitoring and audits are used to inform continuous improvement of data protection practices, policy updates, and staff training programmes.
TrustVerify maintains records of all monitoring and audit activities, including actions taken in response to findings, for a minimum of six years or as required by law. Failure to comply with internal monitoring and audit requirements may result in disciplinary action, up to and including termination of employment or contract.
19.1 This Privacy Policy forms part of the wider data protection and information governance framework of Magnificentech Solution Ltd trading as TrustVerify. To ensure comprehensive compliance and robust data management, the following related policies and documents should be read in conjunction with this Privacy Policy:
References to external standards, guidance, and regulatory requirements include the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018; Information Commissioner's Office (ICO) guidance and codes of practice; and relevant industry standards for fintech and cybersecurity, such as ISO/IEC 27001 and FCA guidance.
19.3 All employees, contractors, and relevant third parties are required to familiarise themselves with these related policies and references to ensure full compliance with TrustVerify's data protection obligations. These documents are available upon request from the Data Protection Officer or the Senior Management Team.
20.1 This section sets out supplementary terms and conditions that apply to the processing of personal data by Magnificentech Solution Ltd trading as TrustVerify, in addition to the main provisions of this Privacy Policy. These provisions are intended to ensure comprehensive compliance with applicable data protection laws and to address specific operational, legal, and regulatory requirements relevant to the business activities of TrustVerify.