MIG Minerals & Metals Capital — A Mbombo Investment Group Company

Draft — Pending Legal Review

Article 14 GDPR Privacy Notice

For people whose personal information MIG obtained indirectly from a lawful source rather than directly from them.

This draft is not published or effective. It must not be used for Article 14 outreach until written legal-counsel approval and separate Super Administrator approval are recorded.
Version
draft-1.0-us-article-14
Proposed effective date
September 22, 2026
Publication status
Draft — Pending Legal Review

1. Purpose of this notice

This Article 14 GDPR Privacy Notice explains how Mbombo Investment Group processes personal information through MIG Minerals & Metals Capital when that information was obtained from a source other than the individual concerned. It supplements MIG's Privacy Policy and is intended to provide the information required by Article 14 of the General Data Protection Regulation and corresponding UK GDPR requirements where those laws apply.

This notice does not authorize indiscriminate collection, data scraping, unauthorized marketing or the purchase of personal contact lists. Every collection must be linked to a defined, documented and lawful business, compliance or legal purpose.

2. Data controller identity

The data controller is Mbombo Investment Group, operator of MIG Minerals & Metals Capital. Its address is 3911 Concord Pike, #8030, Wilmington, Delaware 19803, United States. Privacy questions and requests may be sent to contact@mbomboinvestmentgroup.com.

3. When this notice applies

This notice applies when MIG obtains personal information indirectly, including from public records, company websites, professional directories, transaction participants, business partners or other lawful sources, rather than directly from the individual.

It does not apply where MIG collected the relevant information directly from the individual and provided an appropriate direct-collection notice, or where a documented legal exception applies. A legal exception must be assessed and recorded; it must not be assumed merely because information appears publicly available.

4. Categories of personal information

Depending on the defined purpose, MIG may process a person's name, business contact details, employer or represented organization, professional title, business responsibilities, public professional history, authority to represent an organization, involvement in a proposed transaction, correspondence, and records needed for identity, sanctions, politically exposed person, fraud, conflict, legal or compliance review.

MIG should not collect information that is excessive or unrelated to a defined business, compliance or legal purpose. Private documents, beneficial-owner information, compliance findings, licences, assay results, financial records and deal-room materials remain controlled information and are not public merely because MIG processes them.

5. Sources of personal information

Sources may include official company or government registers, court or regulatory records, company websites, professional directories, conference or industry materials, an individual's employer, authorized representatives, transaction counterparties, advisers, screening providers, business partners, and other lawful sources relevant to a documented purpose.

MIG records the source category, a specific source reference, the date obtained, the purpose and the asserted lawful basis. Source records and related compliance findings are not made publicly available.

6. Purposes of processing

MIG may process indirectly obtained information to assess eligibility and authority; identify and communicate with relevant business representatives; conduct sanctions, fraud, conflict, ownership and responsible-sourcing checks; evaluate or administer a mineral, metals, financing or transaction opportunity; protect the Platform; comply with legal obligations; establish, exercise or defend legal claims; and maintain accountable records.

MIG must not use personal information for a new and incompatible purpose without first establishing a lawful basis and providing any additional notice required by law. Payment, membership or inclusion in a business record does not produce automatic verification, approval, privileged access or a compliance decision.

7. Lawful bases

Where applicable law requires a lawful basis, MIG may rely on legitimate interests, steps connected with or performance of a contract, compliance with a legal obligation, consent, protection of vital interests or performance of a task in the public interest, as appropriate to the documented circumstances.

MIG does not state that legitimate interests automatically permit every use of publicly available or third-party information. Before relying on legitimate interests, MIG should identify the specific interest, assess necessity, balance that interest against the individual's rights and reasonable expectations, document safeguards, and honour applicable objections.

8. Recipients and disclosures

Information may be disclosed only on a need-to-know basis to authorized MIG personnel, professional advisers, contracted service providers, transaction participants with approved access, competent authorities, courts or regulators, where justified and subject to appropriate confidentiality, security and legal controls.

MIG does not sell personal information for monetary consideration. Private documents, beneficial-owner information, compliance findings, licences, assay results, financial records and deal-room materials must not be made publicly available.

9. International transfers

MIG operates from the United States and may need to process information across borders. Before a restricted international transfer occurs, MIG must identify the countries involved, assess the applicable law and put in place a lawful transfer arrangement and supplementary safeguards where required.

MIG does not state in this draft that it currently relies on Standard Contractual Clauses, an adequacy decision, the UK International Data Transfer Agreement or any other specific transfer mechanism. Any such mechanism must first be confirmed and documented by legal counsel.

10. Retention

MIG keeps personal information only for a period reasonably necessary for the documented purpose, applicable legal and regulatory duties, security, dispute resolution and the establishment, exercise or defence of legal claims. Retention periods should take account of the information's sensitivity, volume, context, risk and legal requirements.

Information will not be retained indefinitely or merely because it may remain commercially valuable. When continued retention is no longer justified, information should be securely deleted, anonymized or placed beyond routine use, subject to documented legal holds.

11. Individual rights

Depending on the applicable law, an individual may have rights to request access, correction, deletion, restriction, portability, withdrawal of consent and information about processing. A request may be sent to contact@mbomboinvestmentgroup.com.

MIG may request reasonable information to verify the requester's identity and authority before acting. Exercising a right will not result in unlawful discrimination, although some rights are limited by law and may not apply in every circumstance. MIG will explain a lawful refusal or limitation where required.

12. Right to object

Where processing is based on legitimate interests, an individual may object on grounds relating to their particular situation. MIG will stop the challenged processing unless it demonstrates compelling legitimate grounds that override the individual's interests, rights and freedoms, or the processing is needed for legal claims.

An individual may object at any time to processing for direct marketing. When such an objection applies, MIG must stop that marketing use and maintain only the minimum suppression information needed to honour the request.

13. Timing of this notice

MIG should provide this notice within a reasonable period after obtaining the information and no later than one month, having regard to the circumstances. If MIG uses the information to communicate with the individual, notice should be provided no later than the first communication. If disclosure to another recipient is contemplated, notice should be provided no later than the first disclosure.

Any reliance on an exception must be assessed, approved and documented. Delivery records should identify the notice version, delivery date and time, channel, destination fingerprint and result without exposing the underlying personal information publicly.

14. Automated decision-making

MIG may use tools to organize information, identify inconsistencies or support risk screening, but material eligibility, access and approval decisions should remain subject to authorized human review. The Platform does not treat a subscription payment, automated match, screening flag or data point as an automatic approval or rejection.

If MIG later introduces decision-making based solely on automated processing that produces legal or similarly significant effects, it must first establish a lawful basis, provide the disclosures and safeguards required by applicable law, and enable appropriate human intervention and challenge rights.

15. Security and confidentiality

MIG applies role-based access, multi-factor authentication for privileged personnel, controlled document access, activity records, confidentiality requirements and other administrative and technical measures appropriate to the risks. Access is limited by role, verification status and approved purpose.

No security measure eliminates every risk. Suspected misuse, loss or unauthorized access should be reported promptly to contact@mbomboinvestmentgroup.com so MIG can assess and respond.

16. Complaints

Individuals are encouraged to contact MIG first so concerns can be investigated. They may also complain to the supervisory authority responsible for their residence, workplace or the alleged infringement where applicable.

Official supervisory-authority information is available from the European Data Protection Board directory at European Data Protection Board directory. UK complaints may be directed to the Information Commissioner's Office at Information Commissioner’s Office.

17. EU/UK representatives and Data Protection Officer

MIG has not identified an EU representative, UK representative or Data Protection Officer in this draft. No organization or person should be displayed in one of those roles unless a formal appointment has been made and its scope has been documented.

Before making the Platform available to individuals in the EEA or UK, legal counsel must determine whether Mbombo Investment Group must appoint an EU representative under Article 27 GDPR, a UK representative under the UK GDPR, or a Data Protection Officer. This notice must be updated if an appointment is required and formally made.

18. Contact information

Data controller: Mbombo Investment Group Platform: MIG Minerals & Metals Capital Address: 3911 Concord Pike, #8030, Wilmington, Delaware 19803, United States Privacy contact: contact@mbomboinvestmentgroup.com

This draft has a proposed effective date of September 22, 2026. It is not published or effective and must not be used to begin outreach until written legal-counsel approval and separate Super Administrator publication approval are recorded.