ERAM · Legal · Investor Data & GDPR

Investor Data & GDPR.

A focused statement on how we handle the personal and financial data of investors who register and subscribe through the ERAM Investors Portal, aligned with EU GDPR principles and the Kosovo Law on Personal Data Protection.

Effective date: 1 May 2026

1. Controller and contact

ERAM Real Estate Sh.P.K., NUI 812052025, Rruga Agim Ramadani, Nr. 2, 10000 Prishtina, Kosovo. Contact for data-protection enquiries: [email protected].

2. Investor-specific data categories

  • KYC identification: government ID, proof of address, photograph for liveness check.
  • AML data: source-of-funds declaration, politically-exposed-person screening, sanctions screening.
  • Qualified-investor status: documentation supporting eligibility classification.
  • Subscription and holdings: shares held per project SPV, capital contributions, distributions.
  • Communication records: support tickets, document acknowledgements, e-signatures.

3. Legal bases

Legal obligation (AML/CFT), contractual necessity (subscription agreement), legitimate interest (investor reporting, fraud prevention), consent (marketing communications).

4. Sub-processors

We engage a limited number of sub-processors, including: KYC/AML provider, e-signature provider, document-vault provider, cloud hosting (EU/EEA primary), custodian/escrow bank, and statutory auditor. The current sub-processor list is available on request via the Investors Portal.

5. Retention

KYC and investor records are retained for the period required by Kosovo AML/CFT law (currently five years following the end of the investor relationship), after which they are securely deleted or anonymised.

6. Investor rights

Right of access, rectification, erasure (subject to legal-retention obligations), restriction, portability, and objection. Right to withdraw consent for any consent-based processing. Right to lodge a complaint with the Information and Privacy Agency of Kosovo or your local supervisory authority.

7. Security

The Investors Portal is hosted on infrastructure with encryption in transit and at rest, role-based access controls, multi-factor authentication for administrators, and regular security review.