Global Data Protection & Information Security Policy

Protecting Information. Respecting Privacy. Preserving Trust.

CompanyCMR Global Mobility Services Inc.

LocationGeorgetown, Guyana

Policy ReferenceDP-001

Version2.0

Effective Date1 January 2026

ClassificationPublic

Policy OwnerManagement, CMR Global Mobility Services Inc.

Contactinfo@cmrmobility.gy

1. Our Commitment

At CMR Global Mobility Services Inc., protecting personal information is an integral part of our commitment to the individuals, families, employees, and organizations we serve.

As a provider of international relocation, destination services, and housing management solutions, we recognize that our responsibilities extend beyond coordinating services. We are entrusted with personal identities, immigration documentation, family information, financial records, residential details, and confidential corporate information.

We understand that protecting this information is fundamental to maintaining trust, respecting individual privacy, and delivering professional services.

CMR Global Mobility Services Inc. is committed to processing information lawfully, fairly, transparently, and securely, applying appropriate safeguards throughout the information lifecycle.

Our approach combines internationally recognized data protection principles with practical operational controls designed to support responsible information management across our international activities.

2. International Data Protection Framework

Our data protection and information security framework incorporates principles established by the following regulatory systems:

Guyana — Data Protection Act No. 18 of 2023
The company’s framework considers Guyana’s data protection legislation, subject to its applicable commencement provisions, implementing requirements, and legally operative obligations.

Brazil — Lei Geral de Proteção de Dados Pessoais (LGPD)
Law No. 13,709/2018 establishes requirements concerning lawful processing, transparency, individual rights, data security, accountability, and international transfers of personal information.

European Union — General Data Protection Regulation (GDPR)
Regulation (EU) 2016/679 provides requirements concerning the lawful processing of personal data, privacy by design and by default, individual rights, controller and processor responsibilities, security, incident notification, and international data transfers.

United States — Federal and State Privacy Legislation
The company considers applicable U.S. privacy and information security requirements, including relevant provisions of the Federal Trade Commission Act, the California Consumer Privacy Act as amended, the Florida Information Protection Act, and other applicable federal and state legislation.

These regulatory frameworks inform our corporate standards. Specific legal obligations are evaluated according to the nature of the processing activity, the location of the individuals concerned, the jurisdictions involved, and the applicable territorial and contractual requirements.

3. Scope and Applicability

This policy applies to the collection, processing, storage, access, transfer, retention, and disposal of personal and confidential information handled by CMR Global Mobility Services Inc.

It covers management, employees, authorized representatives, and third parties processing information on behalf of the company.

The policy applies to the following activities:

The policy applies to both electronic and physical information.

4. Personal Information We Process

Depending on the nature of the services requested, CMR Global Mobility Services Inc. may collect and process:

Identification and immigration information
Names, nationality, passport information, visa documentation, identification numbers, and other records necessary for authorized relocation or immigration activities.

Personal and family information
Contact details, residential addresses, family composition, dependent information, and relocation preferences.

Housing and property information
Property preferences, lease agreements, inspection reports, property photographs, inventories, maintenance records, and relevant occupancy information.

Financial information
Bank details, rental payments, deposits, invoices, receipts, and other authorized financial or contractual records.

Employment and assignment information
Employer information, assignment details, relevant corporate contacts, and documentation necessary for relocation coordination.

Sensitive personal information
Where genuinely necessary and legally permitted, limited health-related information or other sensitive personal information may be processed with appropriate additional safeguards.

We seek to collect only information necessary for defined, legitimate business purposes.

5. Principles of Personal Data Processing

CMR Global Mobility Services Inc. follows these principles:

Lawfulness, fairness, and transparency
Personal information must be collected and processed for legitimate purposes supported by an applicable legal basis.

Purpose limitation
Information must be used only for specified and legitimate purposes, unless further processing is otherwise permitted by law.

Data minimization
Only information reasonably necessary for the relevant service or business activity should be collected, accessed, or disclosed.

Accuracy
Reasonable steps must be taken to maintain accurate and up-to-date records and address identified inaccuracies.

Storage limitation
Personal information must not be retained longer than necessary, except where continued retention is supported by applicable legal, contractual, or legitimate business requirements.

Integrity and confidentiality
Information must be protected against unauthorized access, alteration, disclosure, loss, or destruction through appropriate organizational and technical measures.

Accountability
Data protection responsibilities must be appropriately allocated, and relevant decisions, processes, and safeguards must be documented where necessary.

Personal information is processed on the basis of one or more legally recognized grounds, depending on the applicable jurisdiction and circumstances.

These may include:

Consent is not treated as a universal or automatic authorization for processing.

Where consent is relied upon, applicable requirements regarding its validity, documentation, and withdrawal must be respected.

Special categories of personal information are subject to additional legal conditions and safeguards.

7. Information Storage and Digital Security

CMR Global Mobility Services Inc. utilizes business-managed cloud environments, including Microsoft 365, OneDrive, SharePoint, Google Workspace, and Google Drive, for authorized document storage, collaboration, and information management.

Employees have individual system accounts, and access to confidential information is assigned according to professional responsibilities.

The company does not use personal email accounts or personal WhatsApp communications for the routine exchange of client documents.

Our information security standards require appropriate consideration of:

Security controls are subject to review and improvement in accordance with operational needs and identified risks.

8. Confidentiality and Employee Responsibilities

Every employee of CMR Global Mobility Services Inc. is required to respect the confidentiality of information accessed through their professional duties.

Employees sign confidentiality commitments and receive periodic privacy and information security awareness training.

Confidential information must be accessed only for legitimate business purposes.

Employees must not disclose personal, financial, contractual, or corporate information to unauthorized individuals.

Access permissions are determined by role and operational necessity.

Confidentiality obligations continue to apply after an employee’s professional relationship with the company ends, subject to applicable law.

9. Protection of Sensitive and Financial Information

Certain records require heightened protection because of their sensitivity or the potential consequences of unauthorized disclosure.

These include:

Access must be restricted to authorized personnel with a legitimate operational need.

Information must not be distributed beyond what is reasonably necessary for an authorized service.

Additional technical, contractual, or organizational safeguards may be required according to the associated risks.

10. Corporate Client Information Sharing

CMR Global Mobility Services Inc. works with corporate Human Resources and Global Mobility departments to coordinate international assignments.

Relevant personal information may be shared with authorized corporate representatives where justified by contractual responsibilities, lawful processing purposes, or other applicable legal grounds.

Information sharing must remain proportionate to the intended purpose.

Corporate sponsorship of an international assignment does not automatically authorize unrestricted access to all personal information concerning an expatriate or their family.

The company seeks to balance legitimate corporate reporting requirements with applicable individual privacy rights and confidentiality obligations.

11. Third-Party Service Providers

Personal information may be shared with authorized third parties where necessary to provide contracted services.

These may include immigration lawyers, professional consultants, technology providers, and other parties engaged for legitimate operational purposes.

Any sharing must have an appropriate legal and operational basis.

CMR Global Mobility Services Inc. requires third parties to respect confidentiality and applicable data protection obligations.

Where legally required or otherwise appropriate, contractual safeguards must address:

Third parties must not use personal information for unrelated commercial purposes without an appropriate legal basis.

12. International Data Transfers

International relocation services may require personal information to be accessed, processed, or transferred across national borders.

CMR Global Mobility Services Inc. recognizes the importance of assessing cross-border transfers according to applicable data protection laws.

Where the GDPR applies, international transfers must rely on an appropriate mechanism, such as an applicable adequacy decision, Standard Contractual Clauses, or another legally permitted mechanism, together with supplementary safeguards where necessary.

Where the LGPD applies, relevant international transfers must comply with Brazilian legal requirements and applicable regulations issued by the ANPD.

Transfers subject to applicable Guyanese or U.S. legal requirements must also be assessed accordingly.

The use of international cloud service providers does not eliminate responsibilities relating to confidentiality, data security, international access, or lawful transfers.

13. Privacy by Design and by Default

Privacy and information security considerations are incorporated into the company’s standards for operational processes and the development of digital solutions.

New relocation, housing management, and information management systems should be designed to consider:

Where legally required, processing activities likely to present a high risk to individuals must undergo an appropriate Data Protection Impact Assessment before implementation.

14. Data Retention and Disposal

CMR Global Mobility Services Inc. generally retains completed relocation and administrative records for periods ranging from two to five years, depending on the type of information and applicable business, legal, and contractual requirements.

This general range does not override any specific statutory retention period or obligation to retain or delete records.

Longer retention may be justified where required for legal compliance, contractual responsibilities, disputes, investigations, or legitimate legal claims.

Information that is no longer required must be securely deleted, anonymized, or disposed of using appropriate methods.

Retention arrangements are subject to ongoing review and further procedural standardization.

15. Individual Data Protection Rights

Individuals may have certain rights concerning their personal information under applicable law.

Depending on the jurisdiction, these may include rights to:

Requests are reviewed individually and handled according to applicable legal requirements.

Before disclosing or modifying personal information, the company may request appropriate verification of identity and authority.

Certain requests may be subject to lawful exceptions, including statutory retention requirements.

Privacy requests may be directed to info@cmrmobility.gy.

16. Information Security Incidents and Data Breaches

CMR Global Mobility Services Inc. recognizes the importance of responding promptly and responsibly to suspected or confirmed information security incidents.

Employees and authorized representatives must promptly report suspected unauthorized access, disclosure, alteration, destruction, or loss of personal or confidential information to management.

Management is responsible for coordinating the initial assessment and determining appropriate escalation.

Incident handling must address, as appropriate:

  1. Identification and initial assessment.
  2. Immediate containment and mitigation.
  3. Identification of potentially affected information and individuals.
  4. Evaluation of legal, operational, and contractual risks.
  5. Relevant internal and external escalation.
  6. Notification to clients, individuals, regulators, or authorities where legally required.
  7. Documentation, remediation, and preventive improvements.

The company is formalizing its written incident response procedures to support consistent incident management and compliance with applicable notification obligations.

Reporting requirements and deadlines must be assessed under the laws and contractual commitments applicable to the specific incident.

17. Backup, Recovery and Business Continuity

CMR Global Mobility Services Inc. maintains backup arrangements to support business information availability.

The company recognizes that effective recovery also requires documented procedures, assigned responsibilities, and appropriate testing.

Backup and restoration procedures are being formalized to strengthen operational continuity, recovery preparedness, and information integrity.

The objective is to reduce the potential impact of information loss, unauthorized alteration, or system disruption on business operations and client services.

18. Employee Training and Awareness

Information security and confidentiality are shared responsibilities throughout the organization.

CMR Global Mobility Services Inc. provides periodic privacy and security awareness training and requires employees to maintain confidentiality commitments.

Training and internal guidance address relevant responsibilities associated with:

The company recognizes the importance of reinforcing these standards as employees, systems, and operational responsibilities evolve.

19. Governance and Accountability

The management of CMR Global Mobility Services Inc. oversees the company’s data protection and information security framework.

Management is responsible for coordinating policy implementation, evaluating relevant risks, supporting appropriate safeguards, and overseeing privacy-related concerns.

The company assesses the need for additional designated privacy roles, external professional support, or jurisdiction-specific representation according to applicable legal requirements and the nature of its processing activities.

Data protection responsibilities are reviewed as part of the company’s ongoing organizational development.

20. Continuous Improvement and Policy Review

CMR Global Mobility Services Inc. recognizes that privacy and information security require ongoing attention, evaluation, and improvement.

This policy is reviewed at least annually and whenever material legal, technological, contractual, or operational developments warrant an update.

The company is committed to strengthening its internal procedures, reviewing relevant security risks, and maintaining responsible information governance standards.

Our objective is to support professional international mobility operations while respecting the privacy, confidentiality, and security interests of the people and organizations we serve.

21. Contact and Privacy Inquiries

Questions about this policy, personal information processing, privacy rights, or potential security concerns may be addressed to:

CMR Global Mobility Services Inc.
Georgetown, Guyana
Email: info@cmrmobility.gy
Website: www.cmrmobility.com

Requests will be assessed according to their nature and applicable legal requirements.

Our Commitment to Trust

Over the years, our experience supporting international assignments has reinforced a simple but fundamental belief: responsible relocation begins with respect for the people behind every process.

Protecting information is not simply a regulatory responsibility. It is an essential part of the care, professionalism, and trust that define our services.

Our business is relocation. What we do best is care for people.

© 2026 CMR Global Mobility Services Inc. All rights reserved.