VitaeForge legalBSHQ-LGL-014

Data Governance Framework

The framework governing the responsible management, protection and use of information assets across BioStackHQ.

Version
1.0
Status
Published
Effective
24 July 2026
Authority
Board of Directors
01

Data Governance Principles

BioStackHQ recognises data as an institutional asset and seeks to manage information responsibly through appropriate governance, controls and accountability.

This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.

Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.

Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.

02

Data Management

Information assets are managed through structured processes covering collection, storage, access, usage, retention and disposal.

This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.

Implementation is risk-based and may differ according to the sensitivity of the activity, the systems involved, the scale of potential harm and the operational context. Control effectiveness is reviewed periodically and following material change, identified weakness or incident.

Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.

03

Data Responsibility

Individuals and teams handling institutional information are expected to maintain appropriate standards of accuracy, confidentiality and responsible usage.

This Framework applies to information assets created, collected, received, stored, used, shared or disposed of by BioStack HQ and relevant service providers, regardless of format or location.

Where third parties act for, provide services to or receive protected information from BioStack HQ, the Group may apply proportionate diligence, contractual safeguards, audit rights, approval requirements and remediation measures. Responsibility cannot be avoided by delegating an activity to another person or organisation.

Data owners, custodians and users must apply classification, quality, access, retention, disposal and incident-handling requirements appropriate to the asset and its use. Access is limited to a legitimate business need and may be monitored, reviewed, changed or withdrawn where necessary.