The Firm & Privacy Officer
BOTA Holdings, LLC processes personal data with the care of a private bank. Every relationship is anchored to an accountable senior officer responsible for privacy.
This policy is issued by BOTA Holdings, LLC, a Delaware limited liability company with its registered office at 169 Madison Avenue, New York, NY 10016, United States. It applies to all personal data the firm collects and processes in connection with its investment advisory and family-office services, wherever the data subject is located.
- The Firm
- BOTA Holdings, LLC, acting through its New York principal office and its representative offices in Lugano, Milan and London.
- Chief Privacy Officer
- Reachable at [email protected]. The CPO operates independently of business lines and reports directly to the Group Audit & Risk Committee.
- EU Representative
- For data subjects located in the European Economic Area, our representative under Article 27 GDPR is appointed in Milan. Contact details are available on request.
- UK Representative
- For data subjects located in the United Kingdom, our representative under Article 27 UK GDPR is appointed in London. Contact details are available on request.
Legal Framework
BOTA's privacy programme is built on overlapping U.S. federal, state and international rules. The policy below explains which framework applies to your information and, where multiple frameworks overlap, we apply the most protective standard available.
- Gramm-Leach-Bliley Act (GLBA) - federal financial-privacy framework for non-public personal information.
- FTC Safeguards Rule (16 C.F.R. Part 314) - implementing GLBA for non-bank financial institutions; sets the baseline standard for information-security programmes at firms of our type.
- FTC Privacy Rule (16 C.F.R. Part 313) - initial and annual privacy notices and limitations on sharing non-public personal information with non-affiliated third parties.
- New York SHIELD Act and 23 NYCRR Part 500 - reasonable safeguards and cybersecurity requirements for financial services conducted from New York.
- California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA) - for California residents.
- Other comparable state laws - including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA) and others as they enter into force.
- EU General Data Protection Regulation and UK GDPR - for data subjects located in the EEA or the United Kingdom, even where BOTA is the sole controller.
Personal Data We Collect
We collect only what is necessary to operate a regulated mandate and to discharge our duties to you. Wherever possible, we collect information directly from you, with your knowledge.
- Identity
- Full legal name, date of birth, citizenship, government-issued identifiers (passport, driving licence, SSN or ITIN for U.S. persons), and the documentation required by our internal Customer Identification Programme, modelled on the standards of the USA PATRIOT Act.
- Contact
- Residential and correspondence addresses, telephone numbers, email addresses and authorised channels of communication.
- Financial
- Source of wealth and source of funds, banking and custody references, transaction history, asset and liability position, and tax-status declarations (Form W-9 for U.S. persons, Form W-8BEN / W-8BEN-E for non-U.S. persons).
- Family & Structure
- Information regarding beneficial owners, controlling persons, trustees, protectors, settlors and named beneficiaries - collected only where necessary to onboard a structure.
- Suitability
- Investment objectives, risk tolerance, time horizon and capacity to bear loss, used to apply the federal fiduciary suitability standard.
- Special Category
- Limited categories of sensitive data - for example, biometric identifiers used during enhanced identity verification - only where unavoidable and only with explicit consent or another lawful basis.
How We Use Your Information
- To assess suitability before any advisory service is provided, in line with our federal fiduciary duty.
- To execute, transmit and settle transactions on your behalf and to maintain consolidated reporting.
- To carry out customer-identification and ongoing-monitoring procedures aligned with the USA PATRIOT Act, OFAC sanctions screening and industry best practice.
- To provide U.S. tax reporting (1099 series, K-1 series) and, where applicable, FATCA / CRS reporting to non-U.S. tax authorities.
- To manage credit, operational, cyber and reputational risk across the firm.
- To provide secure access to the Family Portal, including authentication and session integrity.
- To improve the quality of our services through internal analysis on a strictly need-to-know basis.
We do not engage in automated decision-making that produces legal or similarly significant effects on data subjects without meaningful human involvement.
Retention Periods
We keep personal data only for as long as we need it, and never longer than the law allows.
- Active Mandate
- For the duration of the relationship, plus the retention periods required by the Investment Advisers Act.
- Mandate Records
- Books and records relating to advice given, transactions executed and communications with the client are retained for at least five years from the end of the fiscal year in which the entry was made, in line with the standard applied by professional fiduciaries.
- AML Records
- Customer identification and due-diligence records are retained for at least five years after the end of the relationship, consistent with the USA PATRIOT Act standard.
- Tax Records
- Generally retained for at least seven years after the relevant tax year, consistent with IRS and state limitation periods.
- Prospective Clients
- Information about prospective clients who do not proceed is deleted within twelve months unless they ask us to keep them informed.
Your Rights
Your rights depend on where you live and on the data we hold. Where multiple frameworks overlap, we apply the most protective standard available. To exercise any of the rights below, write to [email protected]. We respond within thirty days for U.S. requests and within one calendar month for GDPR / UK GDPR requests.
Across all jurisdictions
- Annual GLBA privacy notice - provided automatically to every client of the firm.
- Right to opt out of sharing non-public personal information with non-affiliated third parties beyond the GLBA Section 502(e) exceptions.
U.S. state residents
- Right to know what categories of personal information are collected and for what purposes (CCPA/CPRA and comparable state laws).
- Right to access, correct and delete personal information, subject to the exceptions provided for financial institutions.
- Right to opt out of the sale or sharing of personal information for cross-context behavioural advertising - BOTA does not engage in such sale or sharing.
- Right to limit the use of sensitive personal information.
- Right to non-discrimination for exercising any of the rights above.
EEA and United Kingdom residents
- Right of access, rectification, erasure, restriction, portability and objection under GDPR / UK GDPR.
- Right to withdraw consent at any time, without prejudice to processing already carried out.
- Right to lodge a complaint with the Garante (Italy), the FDPIC (Switzerland), the ICO (United Kingdom) or any other competent supervisory authority in the data subject's place of residence.
Security & Confidentiality
We treat client information with the same discretion we apply to investment decisions. Our information-security programme is designed to meet the FTC Safeguards Rule under GLBA, the New York SHIELD Act and the cybersecurity requirements of 23 NYCRR Part 500.
- Encryption in transit (TLS 1.2 or higher) and at rest for all client records.
- Multi-factor authentication for all staff and for Family Portal access.
- Annual independent penetration testing and continuous monitoring of production systems.
- Segregation of duties between front-office, operations, risk and compliance functions.
- A written incident-response plan with notification timelines aligned to the FTC Safeguards Rule, applicable state breach-notification laws (including New York SHIELD), and Article 33 GDPR for affected EEA / UK data subjects.