BOTA Holdings Logo
Privacy Policy

The Privacy of Family Capital

Discretion is the foundation of our practice. This policy explains how BOTA Holdings, LLC handles personal data - what we collect, why we collect it, who we share it with, how long we keep it and the rights you can exercise at any time. It is written to be read, not to be filed.
I

The Firm & Privacy Officer

BOTA Holdings, LLC processes personal data with the care of a private bank. Every relationship is anchored to an accountable senior officer responsible for privacy.

This policy is issued by BOTA Holdings, LLC, a Delaware limited liability company with its registered office at 169 Madison Avenue, New York, NY 10016, United States. It applies to all personal data the firm collects and processes in connection with its investment advisory and family-office services, wherever the data subject is located.

The Firm
BOTA Holdings, LLC, acting through its New York principal office and its representative offices in Lugano, Milan and London.
Chief Privacy Officer
Reachable at [email protected]. The CPO operates independently of business lines and reports directly to the Group Audit & Risk Committee.
EU Representative
For data subjects located in the European Economic Area, our representative under Article 27 GDPR is appointed in Milan. Contact details are available on request.
UK Representative
For data subjects located in the United Kingdom, our representative under Article 27 UK GDPR is appointed in London. Contact details are available on request.
III

Personal Data We Collect

We collect only what is necessary to operate a regulated mandate and to discharge our duties to you. Wherever possible, we collect information directly from you, with your knowledge.

Identity
Full legal name, date of birth, citizenship, government-issued identifiers (passport, driving licence, SSN or ITIN for U.S. persons), and the documentation required by our internal Customer Identification Programme, modelled on the standards of the USA PATRIOT Act.
Contact
Residential and correspondence addresses, telephone numbers, email addresses and authorised channels of communication.
Financial
Source of wealth and source of funds, banking and custody references, transaction history, asset and liability position, and tax-status declarations (Form W-9 for U.S. persons, Form W-8BEN / W-8BEN-E for non-U.S. persons).
Family & Structure
Information regarding beneficial owners, controlling persons, trustees, protectors, settlors and named beneficiaries - collected only where necessary to onboard a structure.
Suitability
Investment objectives, risk tolerance, time horizon and capacity to bear loss, used to apply the federal fiduciary suitability standard.
Special Category
Limited categories of sensitive data - for example, biometric identifiers used during enhanced identity verification - only where unavoidable and only with explicit consent or another lawful basis.
IV

How We Use Your Information

  • To assess suitability before any advisory service is provided, in line with our federal fiduciary duty.
  • To execute, transmit and settle transactions on your behalf and to maintain consolidated reporting.
  • To carry out customer-identification and ongoing-monitoring procedures aligned with the USA PATRIOT Act, OFAC sanctions screening and industry best practice.
  • To provide U.S. tax reporting (1099 series, K-1 series) and, where applicable, FATCA / CRS reporting to non-U.S. tax authorities.
  • To manage credit, operational, cyber and reputational risk across the firm.
  • To provide secure access to the Family Portal, including authentication and session integrity.
  • To improve the quality of our services through internal analysis on a strictly need-to-know basis.

We do not engage in automated decision-making that produces legal or similarly significant effects on data subjects without meaningful human involvement.

V

When We Share Information

Under GLBA we are permitted to share non-public personal information only in narrowly defined circumstances. We never sell personal information.

Categories of recipient

  • Qualified custodians, prime brokers and counterparties - to execute and settle transactions on your behalf.
  • Auditors, legal advisers, tax preparers and other professional advisers - bound by duties of confidentiality.
  • Service providers and cloud-infrastructure vendors - operating under written agreements that restrict use of personal data to the services contracted.
  • Regulators, self-regulatory organisations, tax authorities, law-enforcement agencies and courts - where required by law or by a binding order.
  • Affiliates within the BOTA group - only to the extent necessary to provide consolidated reporting and group-wide risk management.

International transfers

Personal data transferred from the European Economic Area or the United Kingdom to the United States is protected by the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable), supplemented by a transfer-risk assessment and, where necessary, additional technical measures such as encryption in transit and at rest. Where available, we may also rely on the EU-U.S. Data Privacy Framework adequacy decision for transfers between participating organisations.

VI

Retention Periods

We keep personal data only for as long as we need it, and never longer than the law allows.

Active Mandate
For the duration of the relationship, plus the retention periods required by the Investment Advisers Act.
Mandate Records
Books and records relating to advice given, transactions executed and communications with the client are retained for at least five years from the end of the fiscal year in which the entry was made, in line with the standard applied by professional fiduciaries.
AML Records
Customer identification and due-diligence records are retained for at least five years after the end of the relationship, consistent with the USA PATRIOT Act standard.
Tax Records
Generally retained for at least seven years after the relevant tax year, consistent with IRS and state limitation periods.
Prospective Clients
Information about prospective clients who do not proceed is deleted within twelve months unless they ask us to keep them informed.
VII

Your Rights

Your rights depend on where you live and on the data we hold. Where multiple frameworks overlap, we apply the most protective standard available. To exercise any of the rights below, write to [email protected]. We respond within thirty days for U.S. requests and within one calendar month for GDPR / UK GDPR requests.

Across all jurisdictions

  • Annual GLBA privacy notice - provided automatically to every client of the firm.
  • Right to opt out of sharing non-public personal information with non-affiliated third parties beyond the GLBA Section 502(e) exceptions.

U.S. state residents

  • Right to know what categories of personal information are collected and for what purposes (CCPA/CPRA and comparable state laws).
  • Right to access, correct and delete personal information, subject to the exceptions provided for financial institutions.
  • Right to opt out of the sale or sharing of personal information for cross-context behavioural advertising - BOTA does not engage in such sale or sharing.
  • Right to limit the use of sensitive personal information.
  • Right to non-discrimination for exercising any of the rights above.

EEA and United Kingdom residents

  • Right of access, rectification, erasure, restriction, portability and objection under GDPR / UK GDPR.
  • Right to withdraw consent at any time, without prejudice to processing already carried out.
  • Right to lodge a complaint with the Garante (Italy), the FDPIC (Switzerland), the ICO (United Kingdom) or any other competent supervisory authority in the data subject's place of residence.
VIII

Security & Confidentiality

We treat client information with the same discretion we apply to investment decisions. Our information-security programme is designed to meet the FTC Safeguards Rule under GLBA, the New York SHIELD Act and the cybersecurity requirements of 23 NYCRR Part 500.

  • Encryption in transit (TLS 1.2 or higher) and at rest for all client records.
  • Multi-factor authentication for all staff and for Family Portal access.
  • Annual independent penetration testing and continuous monitoring of production systems.
  • Segregation of duties between front-office, operations, risk and compliance functions.
  • A written incident-response plan with notification timelines aligned to the FTC Safeguards Rule, applicable state breach-notification laws (including New York SHIELD), and Article 33 GDPR for affected EEA / UK data subjects.
IX

Cookies & Site Analytics

Our public website uses a minimal set of strictly necessary cookies to support session continuity and security. We do not deploy advertising, retargeting or cross-site tracking technologies and we do not sell or share personal information for cross-context behavioural advertising within the meaning of the CPRA.

  • Strictly necessary - session and security cookies. No consent required.
  • Preferences - language and accessibility settings, only when set by you. Removed on logout or after twelve months.
  • Analytics - privacy-preserving, aggregated server-side measurement; no individual user profiles are built.

The Family Portal uses additional authentication cookies and security tokens, all of which are documented in the Portal Terms of Use available within the portal itself.

Direct Access

Compliance & Regulatory

The Chief Privacy Officer is the dedicated point of contact for all privacy matters. Every request is acknowledged within two business days.

[email protected]
Document version 2026.01 · Effective 01 January 2026BOTA Holdings, LLC · 169 Madison Avenue, New York, NY 10016, United States