Policies
Information Disclosure Policy and Information Protection Policy. Read each document in full or use the contents to find a section.
Information Disclosure Policy
Annexure 4
Alpha Halal Fund
Version 1 · May, 2023
c/o Global Alpha Capital Limited
P O Box 70166, DAR ES SALAAM
1.0 Purpose and objectives
1.1 The Alpha Halal Collective Investment Scheme (Alpha Halal Fund) is committed to making information about its activities available to the public. Alpha Halal Fund considers public access to information a key component of effective engagement with all stakeholders, including Alpha Halal Fund’s current and prospective Unitholders, Regulators and the public generally, in the fulfilment of its mandate. Public access to the Fund’s information facilitates transparency and accountability and enhances trust in Alpha Halal Fund’s activities.
1.2 This Information Disclosure Policy (“This Policy” and “this Policy”) is intended to ensure that information concerning Alpha Halal Fund’s activities is made publicly available, subject to the limitations set out in this Policy. To that end, this Policy explains principles, practices and procedures; and defines clear categories of information according to their status with regards to public disclosure.
1.3 Information held by Alpha Halal Fund is made available primarily through the Alpha Halal Fund website, the Fund Manager’s websites and webpages of Alpha Halal Fund’s partners.
2.0 Scope of this Policy
2.1 This Policy applies to all Information in the custody of Alpha Halal Fund. For the purposes of this Policy, “Information” means any produced content, in any medium (paper, electronic or sound, visual or audiovisual recording) concerning a matter relating to Alpha Halal Fund’s activities.
2.2 This Policy does not apply to data collected by any of Alpha Halal Fund’s Partner or Service Provider that is governed by the Partner or Service Provider’s internal data sharing policies.
2.3 Information jointly owned with third parties, for example, memoranda of understanding, service agreements, and other contractual arrangements, will be made available on a case by case basis with the agreement of the parties concerned.
3.0 General principles of access to information
3.1 Information accessible to the public shall be made available, as far as reasonable and practical, through the Alpha Halal Fund website. An overview of information presently available to the public (or which is made available on an on-going basis) is listed in Annex 1.
3.2 This Policy is guided by the principles of openness and transparency, such that any information concerning Alpha Halal Fund is publicly accessible, or available upon request, unless one or more of the exceptions to the Policy, or another compelling reason, applies.
4.0 Categories of Information
4.1 Alpha Halal Fund is committed to open and transparent disclosure of information. Nevertheless, there are legal, operational and other practical considerations that are necessary to preserve the interests of the Fund and its Unitholders, as well as those of its staff and third parties with which Alpha Halal Fund collaborates. The application of these considerations has resulted in some exceptions to the principle of disclosure. As such, Alpha Halal Fund information is classified by reference to three broad categories: publicly available information, information available on request, and confidential information.
4.1.1 Category 1: Publicly available Information
Annex 1 sets out an overview of publicly available information (i.e. information which is available on the Alpha Halal Fund website).
4.1.2 Category 2: Information available on request
Alpha Halal Fund makes available certain types of information on request only. In some cases, limitations may apply with regard to the types of request or to Alpha Halal Fund information that will be made available. For example, Alpha Halal Fund’s internal audit reports addressed to senior management are made available to Unitholders, regulators or external auditors upon request. In addition, restrictions (e.g. redaction of content) or conditions may be applied to the use of such information when made available on request. Annex 2 sets out an overview of information available on request.
4.1.3 Category 3: Confidential information
Information identified as confidential by Alpha Halal Fund constitutes an exception to the principle of public disclosure. Annex 3 provides an overview of information considered by Alpha Halal Fund to be confidential. The exceptions to disclosure reflect what is necessary to preserve legitimate public or private (including personal privacy) interests.
Decisions and resolutions of the Regulators, Board of Directors or the Shari’ah Advisory Board, may contain information disclosure limitations. Nothing in or relating to this Policy will be deemed in any way to limit or modify the application of decisions or resolutions of these governing bodies.
5.0 Procedure for submitting requests for disclosure of information
5.1 Any individual or entity may request the disclosure of Alpha Halal Fund’s non-confidential information that is not otherwise available through Alpha Halal Fund public-access websites or web-pages of Alpha Halal Fund’s hosted partnerships. Requests for disclosure of information should be clearly formulated and as specific as possible, and should identify the individual or entity making the request, the information being requested (with the title of the document, if known) and the time period covered by the request, where relevant.
5.2 Where the request for information is by or on behalf of a Unitholder, the person making the request shall include such information in the request as would allow Alpha Halal Fund to identify and respond directly to the respective Unitholder.
5.3 This Policy does not apply to data existing only in raw form, either physically or electronically. Alpha Halal Fund is not able to respond to requests that require the selection and/or manipulation of data to produce content.
5.4 Requests for disclosure of information must be submitted to the Fund manager by any one of the following channels:
(a) Physically at office: 8th Floor, Millennium Towers-1, Makumbusho, Dar es Salaam;
(b) By post : P O Box 70166, 14107 Dar es Salaam;
(c) By email: info@alphacapital.co.tz
5.5 Alpha Halal Fund shall endeavour to process requests for disclosure of information as promptly as possible. Depending on the complexity of the request, Alpha Halal Fund will seek to respond to requests within 48hours of receipt of the request. Alpha Halal Fund may charge a fee for requests for information, based on the estimated costs of retrieving and supplying the information requested, which will be communicated to the requestor and must be paid in advance. Alpha Halal Fund will refund the fee if the information requested is not provided. Alpha Halal Fund reserves the right to charge an additional fee in complex cases.
5.6 If a requestor is not satisfied with Alpha Halal Fund’s response to a request for disclosure of information, they may request in writing for an internal review of Alpha Halal Fund’s response. Requests for internal Alpha Halal Fund review should be submitted to the email address mentioned above. Such internal review will be carried out by the first level supervisor of the Alpha Halal Fund staff member who signed the initial response. Subject to the complexity of the request, Alpha Halal Fund will aim to respond within seven (7) days of receipt of the request for internal review.
6.0 Conditions
6.1 Alpha Halal Fund may deny a request for disclosure of information, in whole or in part, if any of the following situations apply:
6.1.1. If one or more of the limitations set out or referred to in this Policy or its Annexes applies;
6.1.2. If the request is deemed by Alpha Halal Fund, in its sole discretion, to be an excessive demand upon Alpha Halal Fund’s resources, i.e. requiring a significant amount of full time staff time, provided that this limitation shall not apply to a request by a Unitholder;
6.1.3. If, in the judgment of Alpha Halal Fund, the request is unreasonable, repetitive, abusive or vexatious; or
6.1.4. If the request is related to one or more similar request(s) that have been denied by Alpha Halal Fund.
6.2 If only part of the information that is responsive to a particular request for disclosure is subject to one of the limitations set out in this Policy or its Annexes, Alpha Halal Fund may decide, at its sole discretion, that the remaining part of the information, responsive to that request, will be disclosed. In such cases, Alpha Halal Fund will take appropriate measures to preserve the confidentiality of the information that is not disclosed.
6.3 The implementation of this Policy is subject to the intellectual property and other proprietary rights of Alpha Halal Fund and third parties, including but not limited to patents, copyrights, and trademarks, or non-disclosure agreements which may, inter alia, limit the right to reproduce, share or otherwise exploit information.
6.4 No representation is made or warranty given, express or implied, as to the completeness or accuracy of third-party-owned information made available by Alpha Halal Fund. Moreover, Alpha Halal Fund does not warrant that the use of any such individual component contained in the requested information will not infringe on the rights of those third parties. The risk of claims resulting from such infringement rests solely with the requestor/user. It is the responsibility of the requestor/user to determine whether permission is needed for any use of the information and to obtain permission from the copyright holder. In no circumstances will Alpha Halal Fund be liable for any direct or indirect loss arising from use of the information.
6.5 Nothing contained in or relating to this Policy, or done pursuant to it, shall be construed as a waiver of any of the privileges and immunities enjoyed by Alpha Halal Fund under national or international law, and/or as submitting Alpha Halal Fund to any national court jurisdiction. Without limiting the generality of the previous sentence, the disclosure of information in response to a request for disclosure, will not constitute a waiver, express or implied, of any of the rights and privileges of Alpha Halal Fund.
7.0 Entry into force and application of this Policy
7.1 This Policy shall enter into force on the date assigned by the Board of Directors of Global Alpha Capital Limited, the Fund Manager. It applies to information created or coming into Alpha Halal Fund’s possession after its entry into force. This policy will be implemented progressively, subject revision by the Board.
7.2 Heads of Alpha Halal Fund Departments are responsible for ensuring compliance with this Policy, and for defining and periodically reviewing the classification of information for which they are responsible, in accordance with this Policy.
7.3 This Policy will be reviewed (for amendment or reaffirmation) by the Board of Directors of Alpha Halal Fund’s Fund Manager at least once every three years.
ANNEX 1
Overview of Alpha Halal Fund information available on dedicated Alpha Halal Fund websites
(“Publicly Available Information”)
1. Institutional information
1.1 About Alpha Halal Fund
1.1.1 Constitutive documents
1.1.2 Form of Shari’ah contract
1.2 The work of Alpha Halal Fund
1.2.1 Investment Policy
1.2.2 NAV
1.2.3 Periodic Financial Results
1.2.4 Geographic spread
2. Governance and Oversight
2.1 Governing Bodies (Fund Manager, Custodian / Trustee)
2.2 Shari’ah Advisor
2.3 Sharia Advisory Board
2.4 Shari’ah Advisor, Composition of Shariah Advisory Board,
2.5 Fund Manager, Custodian/Trustee, Legal Counsel, Auditor
2.6 Selling agent(s)
2.7 Independent Oversight
2.7.1. Internal Compliance Officer
2.7.2. Shari’ah Auditor
ANNEX 2
Overview of types of ALPHA HALAL FUND information available on request
(“Information available on request”)
This comprises all remaining information which is not publicly available on the Alpha Halal Fund website (Annex 1), but is not classified as confidential information (Annex 3).
Access to some information in this category may be restricted to Unitholders only. This includes internal audit reports and reports of due diligence on other actors.
ANNEX 3
Overview of types of ALPHA HALAL FUND information considered to be confidential
(“Confidential information”)
Confidential information is not subject to disclosure.
The following categories of information are classified as “Confidential information”:
1. Personal information
Alpha Halal Fund does not provide access under this Policy to information and documentation pertaining to either staff members or non-staff members performing Alpha Halal Fund work or holding Units of Alpha Halal Fund, including:
(a) Private and employment-related information, including human resources records, medical records, salaries and benefits, personal communications;
(b) Personal information received from individuals performing work for Alpha Halal Fund including technical and financial experts;
(c) Information on staff appointment and selection processes;
(d) Information on claims and internal conflict resolution proceedings;
(e) Personal declaration of interest forms and related internal deliberations or similar issues submitted by Alpha Halal Fund staff members, as well as other individuals performing work for Alpha Halal Fund and experts participating in Alpha Halal Fund technical meetings;
(f) Information about investigations of allegations of misconduct (other than as reported to Alpha Halal Fund Governing Bodies).
2. Security and safety
(a) Information, the disclosure of which may endanger the life, health, safety or security of any individual, or
(b) Information, the disclosure of which may violate the rights of any individual or to invade his or her privacy;
(c) Information, the disclosure of which may endanger public security or prejudice the security or proper conduct of any operation or activity of Alpha Halal Fund;
(d) Information, the disclosure of which may compromise the security and safety or commercial interests of any Alpha Halal Fund collaborators; or
(e) Information, the disclosure of which may jeopardize Alpha Halal Fund property;
3. Information concerning Alpha Halal Fund Unitholders
Information, the disclosure of which may adversely affect Alpha Halal Fund’s relations with any Unitholder or agent(s) thereof.
4. Information obtained or shared in confidence
(a) Information received from or sent to a Unitholder, Investee or third parties under an expectation of confidentiality;
(b) Information obtained in confidence from a government, non-governmental organisation, international organisation or other entity or person that would or would be likely to, if disclosed, compromise the Fund’s relations with that party.
5. Confidential Internal documents
(a) Internal email correspondence;
(b) Internal reports, analyses, reviews, notes for the record of internal meetings or meetings with third parties, statistics prepared solely to inform Alpha Halal Fund’s internal decision-making processes;
(c) Internal policy, guidelines, standard operating procedures, unless otherwise decided;
(d) Internal telephone directories;
(e) Information pertaining to corporate administrative matters.
6. Deliberative information
(a) Information concerning Alpha Halal Fund’s own internal deliberations, communications (including internal interoffice or intra-office documents such as emails, memos, and draft documents);
(b) Documents relating to the communications, deliberations and decisions of Alpha Halal Fund internal bodies and internal advisory committees;
(c) Contributions to and deliberations of Alpha Halal Fund expert panels and committees, technical advisory groups, including communicators between Alpha Halal Fund and its experts or service providers;
(d) Internal management documents produced by Alpha Halal Fund for the information of senior management including without being limited to internal briefings, reports, self-assessments, corporate risk register;
(e) Communications of Member States’ representatives and/or their offices;
(f) Alpha Halal Fund’s communications and deliberations with third parties and other entities with which the Fund collaborates, except where such collaboration is deemed to have an impact on the Fund’s compliance with the Constitutive Document or Offer Document.
7. Privileged information
(a) Information covered by legal privilege, or the disclosure of which may expose Alpha Halal Fund to legal risk;
(b) Legal advice and requests for legal advice;
(c) Information related to due process rights of individuals involved in internal audits and investigations;
(d) Requests for ethics advice addressed to, and ethics advice provided by, any third party.
8. Financial information
(a) Documents, analyses, correspondence or other information prepared for financial and budgetary transactions, or for the development of internal or external financial reports;
(b) Banking or billing information of Alpha Halal Fund offices, Alpha Halal Fund’s contractors and vendors (companies or individuals), including consultants.
9. Commercial information
(a) Commercial information which, if disclosed, may harm either the financial interests of Alpha Halal Fund or those of third parties;
(b) Information relating to Alpha Halal Fund’s procurement processes, except that covered in Annex 1, paragraph 5, such as information submitted by prospective bidders, tenders, proposals or price quotations;
(c) Information relating to the Alpha Halal Fund Pre-Qualification of Vendors (PQV), including but not limited to information and data submitted by such bidders;
(d) Information that is subject to obligations of confidentiality or non-disclosure pursuant to confidentiality agreements or other contractual or legal obligations of the Fund or which could, if disclosed, expose the Fund to legal risk or violate applicable internal regulations, rules and procedures.
10. Other
(a) Other kinds of information, which because of its nature, content or the circumstances surrounding its creation, use or communication is deemed confidential in the interests of Alpha Halal Fund or third parties;
(b) Passwords, pins and other access codes for Alpha Halal Fund systems.
Disclaimer:
This list is not exhaustive, and other types of information may need to be added to the category of Alpha Halal Fund Confidential Information.
Information Protection Policy
Global Alpha Capital Limited
Dar es Salaam · August 2025
Protecting Client Information, Market Data, Corporate Information and Information Systems
1.0 Purpose
This Policy establishes the principles, responsibilities and minimum controls that Global Alpha Capital Limited (“Alpha Capital” or the “Company”) shall apply to protect information against unauthorised access, disclosure, use, alteration, destruction, loss or disruption. It is intended to preserve confidentiality, integrity and availability of information while supporting the Company’s stock brokerage, investment advisory, fund management, portfolio/wealth management, transaction execution and digital-client services.
The Policy recognises that information is a critical corporate asset and, in a regulated securities business, may also represent client property, confidential market information, personal data, commercially sensitive information or information subject to statutory, contractual and fiduciary obligations.
2.0 Regulatory and Governance Context
This Policy shall be implemented in conjunction with applicable laws, regulations, regulatory directives, licence conditions and contractual obligations. In particular, Alpha Capital shall take account of the Capital Markets and Securities Act and applicable CMSA regulations and guidelines, the Personal Data Protection Act, 2022 and applicable regulations, electronic-transactions and communications requirements, AML/CFT obligations, and any applicable requirements of the Dar es Salaam Stock Exchange (DSE), Central Depository and other market infrastructure providers.
The Personal Data Protection Act establishes the framework for collection and processing of personal data and the protection of data subjects, while the CMSA Electronic Trading Guidelines require confidentiality, integrity and availability controls for electronic securities services. Alpha Capital shall therefore treat information protection as both a governance responsibility and a regulatory-control obligation.
3.0 Scope
This Policy applies to:
(a) All directors, officers, employees, consultants, temporary staff, interns, contractors and other persons authorised to access Alpha Capital information.
(b) All business units and functions, including Brokerage, Investment Advisory, Fund Management, PMS/Wealth Management, Finance, Operations, Compliance, Risk, ICT, HR and Corporate Services.
(c) All information created, received, processed, stored, transmitted or disposed of by or on behalf of Alpha Capital, whether electronic, physical, verbal or recorded in another medium.
(d) All information systems, applications and platforms, including the Broker Back Office (BBO), online Client Portal, corporate website, email, cloud services, endpoint devices, network infrastructure and interfaces with banks, mobile-money operators, DSE/CSDR and other service providers.
(e) Third parties processing Alpha Capital or client information under contract or otherwise on the Company’s behalf.
4.0 Policy Objectives
(a) Protect client, investor, employee, counterparty and corporate information from unauthorised access or misuse.
(b) Protect the confidentiality of orders, transactions, portfolios, client identities, account information, research, mandates and commercially sensitive information.
(c) Maintain the accuracy and integrity of records, market information and transaction data.
(d) Maintain availability and recoverability of critical systems and information.
(e) Meet applicable legal, regulatory and contractual obligations.
(f) Reduce the likelihood and impact of cyber incidents, fraud, data leakage, operational errors and insider threats.
(g) Establish clear accountability for information ownership, access and handling.
(h) Support secure digital service delivery without unnecessarily restricting legitimate business activity.
5.0 Information Protection Principles
5.1 Need-to-Know and Least Privilege
Access shall be granted only where required for legitimate business purposes and shall be limited to the minimum information and system privileges necessary to perform an authorised role.
5.2 Confidentiality
Confidential information shall not be disclosed to any person unless the recipient is authorised and the disclosure is lawful, necessary and appropriately controlled.
5.3 Integrity
Information and records shall be protected against unauthorised alteration, deletion, manipulation or corruption. Critical transactions and changes shall be traceable through appropriate logs and approvals.
5.4 Availability
Critical information and systems shall be maintained in a manner that supports continuity of client service, trading, settlement, fund administration, regulatory reporting and other essential operations.
5.5 Data Minimisation and Purpose Limitation
Alpha Capital shall collect and process only information reasonably required for a legitimate business, legal, regulatory or contractual purpose and shall avoid retaining information longer than necessary, subject to applicable record-retention requirements.
5.6 Accountability
Information owners, users, system administrators, vendors and management shall be accountable for the protection of information within their respective responsibilities.
6.0 Information Classification
Information shall be classified according to sensitivity and potential impact of unauthorised disclosure, alteration or loss.
| Classification | Typical Examples | Minimum Handling | Disclosure |
|---|---|---|---|
| Public | Approved public reports, published research, public website content, approved marketing material. | May be shared externally after appropriate approval. | Openly releasable. |
| Internal | Routine internal procedures, operational information, non-public management material. | Access limited to Alpha personnel/approved parties with business need. | Internal or authorised recipients. |
| Confidential | Client files, account information, portfolio information, contracts, internal financial information, non-public research, staff records. | Need-to-know access; secure transmission/storage ; controlled disclosure. | Authorised recipients only. |
| Restricted / Highly Confidential | Trading orders, credentials, security keys, privileged access information, sensitive personal data, material non-public information, security incidents, critical system configurations. | Strong access controls, encryption where appropriate, enhanced monitoring and senior/owner approval for disclosure. | Strictly limited and documented. |
7.0 Roles and Responsibilities
7.1 Board of Directors
The Board shall:
(a) Approve this Policy and provide oversight of information and cyber-risk.
(b) Ensure management maintains appropriate resources and governance arrangements.
(c) Receive material information-security, data-protection and incident reports as appropriate.
7.2 Chief Executive Officer
It is the responsibility of the Chief Executive to:
(a) Ensure implementation of the Policy across the Company.
(b) Allocate appropriate resources and establish management accountability.
(c) Ensure material information-security incidents are escalated to the Board and regulators where required.
7.3 Compliance / Risk Function
(a) Monitor compliance with this Policy and applicable regulatory requirements.
(b) Coordinate risk assessments, control reviews and regulatory reporting.
(c) Maintain oversight of information-security and data-protection incidents and remediation.
7.4 ICT / System Administration
(a) Implement technical safeguards, access controls, backups, logging, patching and system hardening.
(b) Maintain secure configuration and change-management processes.
(c) Support incident detection, containment, recovery and forensic preservation.
7.5 Information Owners
(a) Determine classification, access requirements, retention and acceptable use for information under their control.
(b) Approve access requests and periodic access reviews.
(c) Ensure information is accurate and appropriately protected.
7.6 All Users
(a) Protect credentials and devices and follow approved security procedures.
(b) Use Company information only for authorised purposes.
(c) Immediately report suspected loss, unauthorised access, phishing, malware, misdirected communications or other security incidents.
8.0 Access Control
8.1 User access shall be based on approved roles and business need.
8.2 Privileged and administrative access shall be restricted to authorised personnel and separately controlled.
8.3 Strong authentication shall be required for critical systems and remote access; multi-factor authentication should be used wherever technically available and proportionate to risk.
8.4 User accounts shall be unique and shared accounts shall be prohibited except where technically unavoidable and specifically authorised.
8.5 Access shall be reviewed periodically and immediately upon termination, transfer or material change of responsibilities.
8.6 Dormant, unnecessary and former-employee accounts shall be disabled promptly.
8.7 Access to client wallets, holdings, orders, portfolio information and transaction records shall be subject to enhanced controls and audit trails.
9.0 Passwords, Credentials and Secrets
9.1 Passwords shall be unique, sufficiently strong and never shared.
9.2 Passwords, API keys, tokens, private keys and similar secrets shall not be stored in plain text or communicated through unsecured channels.
9.3 Default credentials shall be changed before production use.
9.4 Where supported, MFA and secure credential-management mechanisms shall be used for privileged and critical services.
9.5 Suspected credential compromise shall be reported immediately and credentials shall be reset or revoked without undue delay.
10.0 Personal Data Protection
10.1 Alpha Capital shall process personal data lawfully, fairly and transparently and shall maintain appropriate technical and organisational measures to protect personal data. The Company shall maintain appropriate arrangements for data-subject rights, lawful processing, retention, secure disposal, third-party processing and personal-data breach management.
10.2 Personal data shall be collected for defined and legitimate purposes and limited to what is reasonably necessary.
10.3 Access to personal data shall be restricted to authorised personnel with a legitimate business need.
10.4 Personal data shall be protected during transmission and storage using appropriate safeguards based on risk and sensitivity.
10.5 Third-party processors shall be subject to appropriate contractual and security requirements.
10.6 Cross-border transfers shall be undertaken only where lawful and after the relevant legal, regulatory and security requirements have been assessed.
10.7 A Data Protection Officer or other designated responsible officer shall perform the duties required by applicable law and Company governance arrangements.
11.0 Client, Trading and Investment Information
11.1 Because Alpha Capital is a regulated capital-markets intermediary, the following information requires heightened protection:
11.2 Client identification, KYC and account-opening information.
11.3 Orders, instructions, execution details, transaction histories and settlement information.
11.4 Client wallets, holdings, portfolio valuations and statements.
11.5 Investment-advisory records, mandates, investment recommendations and research.
11.6 Fund records, investor information, NAV-related information, portfolio holdings and fund transactions.
11.7 PMS/wealth-management portfolio information and client-specific strategies.
11.8 Non-public issuer, transaction, fundraising, listing and corporate-finance information.
11.9 Material non-public information and information subject to confidentiality, fiduciary or contractual restrictions.
11.10 Such information shall not be used for personal benefit, unauthorised trading, unauthorised solicitation, market abuse or any purpose outside the user’s authorised responsibilities.
12.0 Electronic Trading, BBO and Online Client Portal
12.1 Systems supporting client access and securities transactions shall be designed and operated with controls appropriate to their risk. At minimum:
12.2 Client authentication and authorisation shall be controlled and auditable.
12.3 Order submission, amendments, cancellations and other material client actions shall be logged.
12.4 System interfaces and APIs shall use secure authentication, authorisation, encryption and appropriate rate-limiting or equivalent controls.
12.5 Data received from DSE, CSDR, banks, MNOs or other third parties shall be clearly distinguished from Alpha Capital-generated records where necessary, and reconciliation controls shall be maintained.
12.6 Market prices, holdings, balances and portfolio values displayed to clients shall be subject to reasonable integrity and reconciliation controls; third-party data limitations shall be appropriately disclosed.
12.7 Production changes affecting trading, client accounts, transaction processing or security controls shall be subject to documented change management and testing.
12.8 Critical systems shall have recovery arrangements and tested backups appropriate to their operational importance.
13.0 Encryption and Secure Transmission
13.1 Sensitive information shall be encrypted in transit over untrusted networks using industry-accepted secure protocols.
13.2 Sensitive information stored on portable devices or removable media shall be encrypted where risk warrants.
13.3 Cryptographic keys and certificates shall be protected, access-controlled and periodically reviewed.
13.4 Confidential information shall not be transmitted through personal email accounts, unapproved messaging applications or other unauthorised channels.
14.0 Email, Messaging and Social Engineering
14.1 Users shall exercise caution with unexpected links, attachments, payment instructions, password-reset requests and requests for confidential information.
14.2 Changes to client or counterparty bank details or other high-risk instructions shall be verified through an approved independent channel where required by procedure.
14.3 Confidential information shall not be disclosed merely because a request appears to originate from a senior employee, client, bank, regulator or supplier.
14.4 Suspected phishing, impersonation or business-email compromise shall be reported immediately.
15.0 Endpoint, Mobile and Remote Working Security
15.1 Company devices shall use supported operating systems, security updates and appropriate endpoint protection.
15.2 Devices used to access Company information shall be protected against unauthorised physical access.
15.3 Lost or stolen devices shall be reported immediately so that access can be revoked or remote protective measures activated where available.
15.4 Remote access shall use approved secure mechanisms.
15.5 Company information shall not be copied to personal devices or personal cloud storage unless specifically authorised and adequately protected.
16.0 Backup, Business Continuity and Disaster Recovery
16.1 Critical information shall be backed up according to documented recovery requirements.
16.2 Backups shall be protected from unauthorised access, corruption and ransomware, including through appropriate segregation or immutability where feasible.
16.3 Recovery procedures shall be documented and tested periodically.
16.4 Business continuity and disaster-recovery arrangements shall identify critical systems, recovery priorities, responsible persons and communication channels.
17.0 Incident Management and Data Breaches
17.1 All actual or suspected information-security incidents shall be reported immediately to the designated ICT, Compliance/Risk or management contact. Incidents include, without limitation, suspected unauthorised access, malware, ransomware, lost devices, accidental disclosure, phishing, compromised credentials, data leakage, fraudulent transactions and material system disruption.
17.2 Incidents shall be recorded, assessed, contained and investigated according to severity.
17.3 Evidence and relevant logs shall be preserved where appropriate.
17.4 Access credentials and compromised systems shall be contained or isolated where necessary.
17.5 Clients, CMSA, PDPC, law-enforcement authorities, market infrastructure providers or other stakeholders shall be notified where required by law, regulation, contract or materiality.
17.6 Post-incident reviews shall identify root causes, control weaknesses and corrective actions.
18.0 Third-Party and Outsourced Service Providers
18.1 Vendors with access to Alpha Capital or client information shall undergo risk-based due diligence before engagement.
18.2 Contracts shall address confidentiality, information security, data protection, permitted use, access controls, incident notification, subcontracting, audit/cooperation rights, data return/deletion and termination arrangements as appropriate.
18.3 Critical service providers shall be monitored periodically based on risk.
18.4 Cloud, API, hosting, software, payment, market-data and other technology providers shall be subject to appropriate security and business-continuity assessment.
19.0 Records Retention and Secure Disposal
Information shall be retained in accordance with applicable legal, regulatory, contractual and business requirements. When the retention period expires and no legal hold or other legitimate reason for continued retention exists, information shall be securely deleted, destroyed or anonymised using a method appropriate to its sensitivity and medium.
20.0 Monitoring, Logging and Audit
20.1 Critical systems shall maintain logs sufficient to support security monitoring, investigation, reconciliation and accountability.
20.2 Logs and monitoring information shall themselves be protected from unauthorised alteration or deletion.
20.3 Access to sensitive systems and records shall be subject to periodic review.
20.4 The Company may conduct audits, vulnerability assessments, access reviews and security testing proportionate to risk.
20.5 Any security testing involving production systems shall be authorised and controlled to avoid disruption to client services or markets.
21.0 Security Awareness and Training
All personnel shall receive information-security and data-protection awareness appropriate to their role. Training shall cover confidentiality, phishing and social engineering, password security, personal-data handling, incident reporting, acceptable use and the specific risks associated with securities transactions and client information.
22.0 Information Sharing and Disclosure
22.1 External disclosure of Confidential or Restricted information requires a legitimate business, legal, regulatory or contractual basis and appropriate approval.
22.2 Regulatory and statutory disclosures shall be made through authorised channels.
22.3 Confidential information shall be shared with clients, counterparties, advisers, auditors and service providers only to the extent necessary and subject to applicable confidentiality arrangements.
22.4 Employees shall not make public statements on behalf of Alpha Capital unless authorised.
23.0 Prohibited Activities
23.1 Unauthorised access to systems, accounts or information.
23.2 Sharing passwords, tokens or access credentials.
23.3 Using client or Company information for personal benefit or unauthorised trading.
23.4 Copying confidential information to unauthorised personal storage or devices.
23.5 Installing unauthorised software or bypassing security controls.
23.6 Disabling or interfering with logging, security monitoring or protective measures.
23.7 Deliberately introducing malware, malicious code or unauthorised system changes.
23.8 Disclosing confidential information to unauthorised persons, including through social media or messaging platforms.
24.0 Information Security Risk Management
Information-security risks shall be identified, assessed, documented and treated in accordance with the Company’s enterprise risk-management framework. Critical assets and processes shall receive enhanced controls based on business impact, regulatory significance, threat exposure and sensitivity of information.
25.0 Exceptions
Any exception to this Policy shall be documented, risk-assessed, approved by the appropriate authority and time-bound. Exceptions affecting regulatory obligations, client information, trading systems or material security controls shall be escalated to Compliance/Risk and senior management and, where appropriate, the Board.
26.0 Enforcement
Failure to comply with this Policy may expose Alpha Capital and its clients to financial, operational, regulatory and reputational risk. A breach may result in disciplinary action, withdrawal of access, contractual remedies, regulatory reporting or legal action, as appropriate.
27.0 Policy Review and Maintenance
This Policy shall be reviewed at least annually and whenever there is a material change in law, regulation, business activities, technology, information systems, cyber-risk profile or organisational structure. The Policy owner shall ensure that changes are documented and submitted for approval in accordance with the Company’s governance arrangements.
28.0 Minimum Control Baseline
| Control Area | Minimum Requirement | Frequency / Trigger |
|---|---|---|
| User access | Role-based access; approval; periodic review; prompt termination of leavers | At onboarding/change; periodic review |
| MFA | Required for critical/privileged access where technically available | Continuous |
| Patch management | Supported systems and timely security updates | Ongoing |
| Backups | Protected backups for critical systems | Per documented schedule |
| Incident response | Defined reporting, escalation and investigation process | Immediate upon incident |
| Vendor security | Risk-based due diligence and contractual controls | Pre-engagement and periodic |
| Security awareness | Mandatory awareness training | At onboarding and periodically |
| Access logs | Logging for critical systems and sensitive activities | Continuous |
| Data protection | Lawful processing, minimisation, security and retention controls | Continuous |
| Recovery testing | Test critical recovery arrangements | Periodically |
29.0 Approval
This Information Protection Policy is submitted for approval by the Board of Directors of Global Alpha Capital Limited and shall become effective upon approval.