Home/Privacy Policy

Privacy Policy

Last updated: 2 August 2026

1. Who We Are

DAWN JON Inc. is an international project consultancy incorporated in the British Virgin Islands, providing advisory, coordination, and administrative services to institutional and corporate clients worldwide.

DAWN JON Inc. is the data controller for personal data collected through this website and in the course of service engagements.

Registered office: Geneva Place, Waterfront Drive, Road Town, Tortola, British Virgin Islands. Data enquiries: [email protected].

This policy explains how we collect, use, store and protect personal data, and describes the rights available to individuals under applicable data protection law.

2. Applicable Data Protection Law

DAWN JON Inc. is incorporated in the British Virgin Islands. The BVI Data Protection Act 2021 applies to our operations as the law of the jurisdiction in which we are incorporated.

Where we process personal data of individuals located in the European Economic Area or the United Kingdom, the EU General Data Protection Regulation (GDPR) and UK GDPR also apply.

Where the standards imposed by applicable laws differ, we apply whichever standard gives the individual the greater degree of protection.

3. Personal Data We Collect

3.1 Contact and enquiry form: When you submit an enquiry through our website we collect your name, email address, organisation name, job title, and the content of your message, including any service interests you indicate.

3.2 Project intake and assessment forms: When you submit a project intake form or 24-Hour Assessment request, we collect your name, email address, organisation name, project description, sector, funding requirements, billing country, and any supporting documentation you provide.

3.3 Institutional registration and Members' Lounge: During the registration process we collect organisational details, contact information, and the information required to issue your Application Reference Number. Login session data and referral codes are collected when you access the Members' Lounge.

3.4 Invoicing and payments: For billing purposes we collect your name, business name, billing address, billing country code, and email address. Payment card data is processed directly by Stripe, Inc. and is not stored on our systems. Bank routing details are held server-side only and are never included in the client-facing application.

3.5 Automatic technical data: When you visit our website, our hosting provider and analytics tools automatically collect your IP address, browser type and version, operating system, referring URL, pages visited, time and duration of visit, and device type. This data is collected through server logs and Google Analytics 4.

4. How We Use Personal Data and the Lawful Basis for Each Use

Responding to enquiries and project submissions — Legitimate interests: responding to a business enquiry you initiated.

Processing project intake forms and 24-Hour Assessment requests — Performance of a pre-contractual arrangement at your request.

Delivering advisory, coordination, and consultancy services under an engagement — Performance of a contract to which you are party.

Issuing invoices and processing payments — Performance of a contract; compliance with legal obligations.

Administering the Members' Lounge, including registration, login authentication, and referral programme management — Performance of a contract; legitimate interests.

Maintaining records of engagements — Legitimate interests: accurate business record-keeping.

Improving our website and understanding visitor behaviour — Legitimate interests: analysing aggregate usage to improve service quality.

Complying with applicable law or responding to lawful requests — Compliance with a legal obligation.

We do not use personal data for automated decision-making that produces legal or similarly significant effects, and we do not use it for direct marketing without your prior consent.

5. Third Parties We Share Data With

We share personal data only with the following third parties, and only to the extent necessary for the purposes described above.

GoDaddy Inc. (United States) — provides website hosting, email delivery infrastructure, and visitor analytics. GoDaddy processes data on servers located in the United States and other jurisdictions in which it operates.

Google LLC (United States) — provides Google Analytics 4, which collects anonymised visitor behaviour data. You may opt out by installing the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.

Stripe, Inc. (United States) — processes payment card transactions on our behalf. Stripe is PCI-DSS compliant. We do not receive or store full payment card numbers. Stripe's privacy policy is available at stripe.com/privacy.

Banking Circle S.A. (Luxembourg) — international payment processing and bank transfer routing for applicable transactions.

We do not sell personal data to any third party. We do not share personal data with any other third party except where required by law or with your explicit consent.

6. International Transfers

DAWN JON Inc. is incorporated in the British Virgin Islands and operates as an international practice. Personal data processed in the course of our work may be accessed by personnel and service providers located in different countries.

The third parties named in section 5 operate in the United States and other jurisdictions. Where personal data is transferred to these vendors, we rely on the contractual arrangements and data protection commitments of those vendors, which include standard contractual clauses or equivalent safeguards recognised under applicable law.

If you have questions about the safeguards applicable to a specific transfer, please contact us at [email protected].

7. Retention

We retain personal data for as long as is necessary for the purpose for which it was collected, subject to the following general principles.

Enquiry and contact data where no engagement follows: up to 12 months from the date of last contact.

Project intake, engagement, and contract records: for the duration of the engagement and for a period of not less than 7 years thereafter, to meet legal and professional obligations.

Members' Lounge registration and session data: for the duration of active membership, plus 2 years following account closure.

Invoicing and financial records: as required by applicable law, typically 5 to 7 years.

Website analytics data: in accordance with the retention settings configured in Google Analytics 4, which we set to a maximum of 14 months.

When data is no longer required we delete or anonymise it in a secure manner.

8. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration or destruction. These measures include encrypted data transmission (TLS/HTTPS) across all pages and API endpoints, IP-based rate limiting on authentication endpoints, server-side-only storage of bank routing details and payment credentials, and access controls restricting staff access to personal data on a need-to-know basis.

No method of transmission over the internet or electronic storage is completely secure. While we take reasonable precautions, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to individuals, we will take appropriate steps in accordance with applicable law.

9. Your Rights

Depending on the data protection law applicable to your situation, you may have some or all of the following rights in relation to personal data we hold about you.

Right of access — to request a copy of the personal data we hold about you.

Right to rectification — to request correction of inaccurate or incomplete data.

Right to erasure — to request deletion of your personal data where there is no longer a lawful basis for its retention.

Right to restriction — to request that we restrict processing of your data in certain circumstances.

Right to data portability — to receive your personal data in a structured, commonly used format where processing is based on consent or contract.

Right to object — to object to processing based on legitimate interests.

Right to withdraw consent — where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please submit a written request to [email protected]. We will respond within the timeframe required by applicable law. We may need to verify your identity before processing your request.

10. Complaints

If you believe we have not handled your personal data in accordance with this policy or applicable law, you may raise a complaint with us in the first instance by writing to [email protected]. We will acknowledge your complaint and respond within a reasonable period.

You also have the right to lodge a complaint with the supervisory authority responsible for data protection in the jurisdiction relevant to your situation. This includes the BVI Information Commissioner for BVI-related matters, and the relevant EU or UK supervisory authority where the EU or UK GDPR applies.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The date at the top of this page indicates when the policy was last revised. We encourage you to review this page periodically.

12. Contact

All data protection enquiries, access requests, and complaints should be directed to:

DAWN JON Inc., Geneva Place, Waterfront Drive, Road Town, Tortola, British Virgin Islands. Email: [email protected].