P
PsilocybinLabs · Northward Capital
Private Placement Subscription Portal
HomeData Privacy Policy

Data Privacy Policy

Effective Date: January 1, 2025 · Last Updated: June 1, 2025

Northward Capital Partners Ltd. ("Northward Capital," "we," "us," or "our") is committed to protecting the privacy and security of personal information entrusted to us in connection with our private placement subscription portal.


1. Information We Collect

We collect personal information that you provide directly and information generated through your use of our platform.

1.1 Information You Provide

  • Identity Data — Full legal name, date of birth, government-issued ID numbers
  • Contact Data — Email address, mailing address, telephone number
  • Financial Data — Net worth declarations, income attestations, banking details for wire instructions
  • Corporate Data — Entity name, jurisdiction of incorporation, beneficial ownership information

1.2 Automatically Collected Information

When you access the portal, our systems automatically record:

Data TypePurposeRetention
IP AddressFraud detection90 days
Session tokensAuthentication24 hours
Browser fingerprintSecurity auditing30 days
Access timestampsCompliance logging7 years

1.3 Third-Party Sources

We may supplement your information with data from:

  1. Credit reference agencies for accredited investor verification
  2. Regulatory watchlists (OFAC, FINTRAC, Interpol)
  3. Corporate registry databases for entity verification

2. How We Use Your Information

Important: We do not sell, rent, or trade your personal information to third parties for marketing purposes. Your data is used exclusively to facilitate and administer your investment subscription.

We process your personal information for the following purposes:

  • Subscription Processing — To complete your private placement subscription agreement and associated regulatory filings
  • KYC/AML Compliance — To fulfill our obligations under FINTRAC, PCMLTFA, and applicable securities legislation
  • Communication — To send deal updates, funding confirmations, and regulatory notices
  • Fraud Prevention — To detect and prevent unauthorized access or fraudulent activity

3. Legal Basis for Processing

All processing of your personal data is grounded in one or more of the following legal bases:

  1. Contractual Necessity — Processing required to enter into or perform a subscription agreement
  2. Legal Obligation — Compliance with securities regulations, anti-money-laundering laws, and tax reporting requirements
  3. Legitimate Interests — Fraud prevention, platform security, and business operations
  4. Consent — Where you have explicitly provided consent for optional processing activities

4. Data Sharing

4.1 Service Providers

We share your information with carefully selected service providers under strict contractual obligations:

  • DocuSign Inc. — Electronic signature execution
  • ImageKit Technologies — Secure document storage
  • Google LLC — Spreadsheet-based compliance ledger

4.2 Regulatory Disclosure

We are required by law to disclose certain information to:

  • Financial Transactions and Reports Analysis Centre of Canada (FINTRAC)
  • Securities regulators in applicable jurisdictions
  • Law enforcement agencies pursuant to valid legal process

5. Data Security

We employ AES-256 encryption for data at rest and TLS 1.3 for data in transit. Access to personal information is restricted to authorized personnel on a strict need-to-know basis.

Our security measures include:

  • Multi-factor authentication for all administrative access
  • Quarterly third-party penetration testing
  • Automated intrusion detection and alerting
  • Encrypted off-site backup with geo-redundant storage

6. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal information:

RightDescription
AccessObtain a copy of personal data we hold about you
RectificationCorrect inaccurate or incomplete data
ErasureRequest deletion of your data, subject to legal retention obligations
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to certain types of processing

To exercise any of the above rights, submit a written request to our Privacy Officer. We will respond within 30 calendar days.


7. Retention

We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, and in any event for a minimum of seven (7) years following the close of the offering, as required by applicable securities and tax law.


8. Contact

To exercise your privacy rights or for any questions regarding this policy, please contact our Privacy Officer:

Northward Capital Partners Ltd. Privacy Office · privacy@northwardcap.com

This policy is subject to change. Material changes will be communicated via email to registered subscribers.