Data Processing

Data processing policy

Data Processing

This document describes the technical and organizational measures Nefesh Investigations takes to protect and process personal data in the context of its investigative and advisory services, in line with the GDPR.

1Purposes of Processing

Personal data is processed by us exclusively for the following specified and explicitly described purposes:

  • Conducting factual research, observations, and interviews for civil, criminal, or internal proceedings.
  • Performing background checks (pre-employment and in-employment screenings).
  • Complying with legal obligations, including administration and identity verification requirements.

2Categories of Data Collected

Depending on the nature of the investigation, we may process the following categories of data: name, address, contact details, date and place of birth, financial details, business interests, visual recordings (photos/videos obtained via lawful observation), public digital footprints (OSINT), and witness statements. We process special categories of personal data (such as criminal record data) only if and to the extent legally permitted and strictly necessary.

3Technical and Organizational Security

We implement appropriate technical and organizational measures to secure personal data against loss or any form of unlawful processing:

  • All digital files and communication channels are protected with strong end-to-end encryption.
  • Physical documents and items of evidence are stored in certified safes in a secure and monitored environment.
  • Access to investigative data is strictly restricted to designated investigators on a 'need-to-know' basis.

4Retention Periods

Investigative data is kept no longer than necessary for the purpose of the investigation, unless a legal retention period applies. As a rule, we maintain a retention period of up to 5 years after the completion of the file for the purpose of potential legal proceedings and accountability to the supervisory authority, after which all personal data is permanently and securely destroyed.

5Exercise of GDPR Rights

If you wish to exercise your rights under the GDPR (such as access, correction, or erasure), you can submit a written request via our contact page. To prevent misuse, we ask you to adequately identify yourself. We will respond to your request within the statutory period of four weeks.