Privacy Policy

CitizenshipByInvestmentPro.com is committed to protecting your privacy and handling your personal information with the highest standards of confidentiality and security.

Last Updated
June 2026
Compliance
GDPR · CCPA · International
Data Controller
CitizenshipByInvestmentPro.com
1

# PRIVACY POLICY

**Last Updated: January 2025**
2

Introduction and Overview

CitizenshipByInvestmentPro.com ("we," "us," "our," or "the Company") is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our citizenship by investment advisory services. We recognize that high net worth individuals entrust us with highly sensitive personal and financial information, and we take this responsibility with the utmost seriousness. This policy applies to all users of our platform, regardless of geographic location, and has been designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws worldwide. By accessing or using our services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with any part of this policy, please do not use our website or services.
3

Information We Collect

We collect various types of information to provide and improve our citizenship by investment advisory services. Personal data we collect includes your full name, date of birth, nationality, passport information, contact details (email address, phone number, physical address), professional background, and family information relevant to citizenship applications. Financial information collected includes details about your net worth, sources of wealth, bank references, investment capacity, tax residency status, and financial documentation necessary for due diligence and citizenship application processes. We automatically collect usage data when you interact with our website, including your IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, and information about your visit including the URL clickstream, products you viewed or searched for, page response times, download errors, and length of visits to certain pages. We also collect information through cookies and similar tracking technologies to enhance your user experience, analyze trends, administer the website, track users' movements around the site, and gather demographic information about our user base as a whole. Additionally, we may collect information you provide when you subscribe to our newsletter, request a consultation, complete forms on our website, participate in surveys, or correspond with us via email, phone, or other communication channels.
4

Legal Basis for Processing

Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, we process your personal data only when we have a lawful basis to do so. Our primary legal basis for processing your personal information is the performance of a contract, specifically when you engage us for citizenship by investment advisory services and we need to process your data to fulfill our contractual obligations to you. We also process certain personal data based on our legitimate interests in operating our business, providing high-quality advisory services, improving our platform, conducting due diligence, preventing fraud, and ensuring the security of our systems and your information, provided these interests are not overridden by your fundamental rights and freedoms. Where required by law, we obtain your explicit consent before processing certain categories of personal data, particularly for marketing communications, the use of certain cookies, and the processing of sensitive personal data such as criminal background information that may be relevant to citizenship applications. In some cases, we process your personal data to comply with legal obligations to which we are subject, including anti-money laundering regulations, tax reporting requirements, know-your-client (KYC) obligations, and other regulatory compliance requirements in the financial advisory and immigration sectors. You have the right to withdraw your consent at any time where we rely on consent as the legal basis for processing, though this will not affect the lawfulness of processing based on consent before its withdrawal.
5

How We Use Your Information

We use the information we collect for several essential purposes related to our citizenship by investment advisory services. Primarily, we use your personal and financial information to assess your eligibility for various citizenship by investment programs, prepare and submit applications on your behalf, conduct necessary due diligence, liaise with government authorities and program operators, and provide comprehensive advisory services throughout the citizenship acquisition process. We utilize your contact information to communicate with you about your application status, respond to your inquiries, provide customer support, send important notices about our services, and keep you informed of developments that may affect your citizenship application. Your data enables us to personalize and improve your experience on our platform by understanding how you use our services, identifying areas for enhancement, developing new features and services, and tailoring our recommendations to your specific circumstances and goals. We process your information to comply with legal and regulatory obligations, including anti-money laundering (AML) checks, know-your-client (KYC) verification, tax reporting requirements, and responses to lawful requests from government authorities and regulatory bodies. Additionally, we use aggregated and anonymized data for research and analytics purposes to better understand market trends, improve our service offerings, and produce industry insights, ensuring that individual users cannot be identified from this aggregated data. We may also use your information to protect our legal rights, prevent fraud, enhance security, enforce our terms and conditions, and protect the safety and security of our users and third parties.
6

Data Sharing and Third Parties

We share your personal information with carefully selected third parties only when necessary to provide our services or as required by law. We utilize Supabase as our backend database and authentication provider, which means your account information and certain personal data are stored and processed through their secure infrastructure in accordance with their privacy practices and our data processing agreement with them. Google Analytics is employed on our website to collect and analyze usage data, helping us understand how visitors interact with our platform; while this service collects certain information about your browsing behavior, we have configured it to anonymize IP addresses and respect user privacy preferences to the extent possible. We share relevant personal and financial information with citizenship by investment program operators, government authorities, and immigration departments in the jurisdictions where you are seeking citizenship, as this is essential to processing your application and complying with program requirements. Professional service providers who assist us in delivering our services have access to your information on a need-to-know basis, including legal advisors, accountants, due diligence firms, background check providers, translation services, document verification services, and IT support providers, all of whom are bound by strict confidentiality obligations and data processing agreements. Financial institutions, payment processors, and banking partners may receive limited information necessary to process payments, conduct financial verifications, and fulfill banking requirements associated with citizenship by investment programs. We may disclose your information to comply with legal obligations, respond to lawful requests from public authorities, enforce our terms and conditions, protect our rights and property, investigate fraud or security issues, and protect the safety of our users and the public. In the event of a business transition such as a merger, acquisition, sale of assets, or bankruptcy, your personal information may be transferred to the successor organization, and we will notify you of any such change in ownership or control of your personal information. We do not sell, rent, or trade your personal information to third parties for their marketing purposes without your explicit consent.
7

International Data Transfers

Given the global nature of citizenship by investment programs and our international client base, your personal information may be transferred to, stored in, and processed in countries other than your country of residence. These international transfers are necessary to provide our services, as citizenship applications inherently involve transferring your information to the countries whose citizenship you are seeking, many of which may be outside the European Economic Area (EEA) or may not provide the same level of data protection as your home jurisdiction. When we transfer personal data from the EEA, United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection by the European Commission, we implement appropriate safeguards to protect your information, including the use of Standard Contractual Clauses approved by the European Commission, binding corporate rules, or reliance on adequacy decisions where applicable. For transfers to the United States and other jurisdictions, we ensure that our service providers and partners either participate in recognized privacy frameworks, implement appropriate technical and organizational measures, or enter into data processing agreements that include standard data protection clauses. We conduct due diligence on all third parties who receive your personal data to ensure they provide an adequate level of protection and comply with applicable data protection laws, and we continuously monitor the evolving legal landscape surrounding international data transfers to maintain compliance with the latest requirements. You have the right to request information about the safeguards we have implemented for international data transfers, and we will provide you with relevant details about the mechanisms we use to protect your data when it crosses borders. Where legally required or appropriate, we will seek your consent before transferring your personal data internationally, particularly when such transfers involve sensitive personal information or countries without adequate data protection frameworks.
8

Data Security and Protection

We implement comprehensive technical and organizational security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Our security infrastructure includes industry-standard encryption for data in transit using TLS/SSL protocols, encryption for sensitive data at rest, secure authentication mechanisms, regular security audits, penetration testing, and vulnerability assessments to identify and address potential security weaknesses. Access to personal information is restricted to employees, contractors, and agents who need to know that information to process it on our behalf and who are subject to strict contractual confidentiality obligations; we employ role-based access controls, multi-factor authentication for administrative access, and maintain detailed access logs to monitor who accesses personal data and when. Our physical and digital infrastructure includes firewalls, intrusion detection systems, malware protection, regular security patches and updates, secure backup systems, and disaster recovery procedures to ensure business continuity and data integrity in the event of a security incident or system failure. We maintain a comprehensive information security policy that covers data classification, acceptable use, password management, incident response, and employee training, ensuring that all personnel who handle personal data understand their responsibilities and follow security best practices. Despite our security measures, no method of transmission over the Internet or electronic storage is completely secure, and while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security; you are responsible for maintaining the confidentiality of your account credentials and for notifying us immediately of any unauthorized access to your account. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant supervisory authorities without undue delay and in accordance with applicable legal requirements, providing information about the nature of the breach, the likely consequences, and the measures we have taken or propose to take to address it.
9

Data Retention Periods

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. For active clients with ongoing citizenship applications or advisory relationships, we retain your personal and financial information throughout the duration of our engagement and for a period following completion of services as required by professional standards and regulatory requirements in the citizenship by investment industry. Following the completion or termination of our advisory services, we typically retain your personal data for a period of seven (7) years from the conclusion of our relationship, which allows us to comply with financial record-keeping requirements, tax obligations, anti-money laundering regulations, and professional indemnity insurance requirements. Certain categories of information may be retained for longer periods when required by specific legal obligations, such as documentation related to financial transactions, regulatory compliance, or citizenship applications that may be subject to ongoing government oversight or potential review. We retain marketing communication preferences and opt-out requests indefinitely to ensure we continue to respect your choices and do not inadvertently contact you after you have opted out of receiving marketing materials. Usage data and analytics information collected through cookies and similar technologies are typically retained for shorter periods, generally between 12 to 26 months, unless we have obtained your consent for longer retention or have a legitimate interest in retaining this information for a longer period. When personal information is no longer required for the purposes described in this Privacy Policy and no legal obligation mandates its continued retention, we will either delete it securely or anonymize it so that it can no longer be associated with you; our secure deletion procedures include overwriting data, degaussing storage media, and physical destruction of hardware when appropriate. You may request information about our retention practices for your specific data and may request deletion of your personal information subject to any legal obligations we have to retain certain records; we will honor such requests unless we have a legitimate legal basis to continue processing your information.
10

Your Rights Under GDPR and CCPA

Under the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other applicable privacy laws, you have significant rights regarding your personal information. You have the right to access your personal data and obtain confirmation of whether we are processing your information, along with details about the purposes of processing, categories of data involved, recipients of the data, retention periods, and the source of the information if we did not collect it directly from you. You have the right to rectification of inaccurate personal data and the right to have incomplete personal data completed, ensuring that the information we hold about you is accurate, current, and complete for the purposes for which it is being processed. You may exercise your right to erasure (the "right to be forgotten") under certain circumstances, including when the personal data is no longer necessary for the purposes for which it was collected, you withdraw consent on which processing is based, you object to processing and there are no overriding legitimate grounds for processing, or the data has been unlawfully processed. You have the right to restrict processing of your personal data in specific situations, such as when you contest the accuracy of the data, the processing is unlawful but you oppose erasure, we no longer need the data but you require it for legal claims, or you have objected to processing pending verification of whether our legitimate grounds override your interests. The right to data portability allows you to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible, which applies when processing is based on consent or contract performance and is carried out by automated means. You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes, and we must cease such processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims. Where we rely on consent as the legal basis for processing, you have the right to withdraw that consent at any time, though this will not affect the lawfulness of processing based on consent before its withdrawal. You have the right not to be subject to automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for contract performance, authorized by law, or based on your explicit consent with appropriate safeguards. To exercise any of these rights, please contact us using the details provided in the Contact Information section; we will respond to your request within one month, though this period may be extended by two additional months when necessary, taking into account the complexity and number of requests, and you will be informed of any such extension. We will verify your identity before processing rights requests to ensure that personal data is not disclosed to unauthorized individuals, which may require you to provide additional information or documentation to confirm your identity.
11

Cookie Policy

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors are coming from. Cookies are small text files placed on your device when you visit our website; they enable the website to recognize your device and store certain information about your preferences or past actions, improving functionality and allowing us to provide a more personalized experience. We use several categories of cookies: strictly necessary cookies that are essential for the website to function properly and cannot be disabled in our systems, including cookies that enable core functionality such as security, network management, and accessibility; performance cookies that collect information about how visitors use our website, including which pages are visited most often and whether users receive error messages, helping us improve the website's performance and user experience; functionality cookies that allow the website to remember choices you make and provide enhanced, personalized features, such as remembering your login details, language preferences, or region; and targeting or advertising cookies that may be set through our site by our advertising partners to build a profile of your interests and show you relevant advertisements on other sites. We use Google Analytics, a web analytics service provided by Google, Inc., which uses cookies to help us analyze how users interact with our website; the information generated by the cookie about your use of the website (including your IP address) is transmitted to and stored by Google on servers in accordance with their privacy practices, and we have configured Google Analytics to anonymize IP addresses where possible. Most web browsers allow you to control cookies through their settings preferences, and you can choose to block or delete cookies; however, if you disable cookies, some features of our website may not function properly, and you may not be able to access all areas or take full advantage of our services. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout, which prevents your data from being used by Google Analytics. We also honor Do Not Track (DNT) signals and other mechanisms that provide you with the ability to exercise choice regarding the collection of personally identifiable information about your online activities over time and across third-party websites or online services. Our cookie banner provides you with information about the cookies we use and allows you to accept or customize your cookie preferences; we recommend reviewing and adjusting these settings according to your privacy preferences. We may update our use of cookies from time to time, and this Cookie Policy will reflect any such changes; we encourage you to review this section periodically to stay informed about how we use cookies and how you can manage your cookie preferences.
12

Marketing Communications

We may send you marketing communications about our citizenship by investment services, educational content about various programs, industry updates, newsletters, special offers, and other information that may be of interest to you based on your relationship with us and your expressed interests. These marketing communications may be sent via email, postal mail, telephone, SMS, or other communication channels, depending on the contact information you have provided and your communication preferences. We will only send you marketing communications where we have a lawful basis to do so, which may include: your explicit consent, which we obtain when you opt in to receive marketing materials; our legitimate interest in promoting our services to existing and prospective clients, provided your interests and fundamental rights do not override this interest; or where permitted by applicable

Privacy Questions?

Contact our privacy team for any questions about how we handle your data.

support@citizenshipbyinvestmentpro.comContact Us