top of page

Cookies Policy

1. Institutional Commitment to Digital Discretion

Governing the deployment of digital telemetry, session management, and tracking architecture across the BlackLeaf™ ecosystem.

 

Effective Date: 28 September 2026

​

BlackLeaf™ Holdings and its subsidiary network (“the Firm”, “we”, or “our”) serve an exclusive demographic of ultra-high-net-worth families, corporate founders, and institutional partners. Consequently, our digital infrastructure is engineered for maximum security and absolute discretion.

​

This Institutional Cookie & Digital Tracking Policy explicitly outlines the deployment of cookies, web beacons, and cryptographic session tokens across our public web presence, the BlackLeaf™ Business Marketplace, and our secure Client Portals. We strictly subordinate all commercial tracking capabilities to our overarching mandates of cybersecurity, client confidentiality, and statutory compliance under the Protection of Personal Information Act (POPIA) and the General Data Protection Regulation (GDPR).

2. Technological Definitions

For the purposes of this governance document:

  • Cookies: Encrypted alphanumeric identifiers transferred to a user’s device hardware to enable our systems to recognize the device and provide secure, continuous session architecture.

  • Session Cookies: Temporary diagnostic and security tokens that are automatically permanently erased the moment a user closes their web browser or logs out of the Client Portal.

  • Persistent Cookies: Tokens that remain on a user's device for a pre-determined statutory or operational period to enforce security protocols or maintain authorized user preferences.

  • Web Beacons / Pixel Tags: Microscopic digital graphics embedded in portal interfaces or institutional communications strictly utilized to verify the successful transmission and receipt of sensitive communications.

3. Categorization and Operational Deployment of Cookies

The Firm deploys digital tracking technologies strictly within the following operational parameters:

​

  • 3.1 Strictly Necessary (Cryptographic & Security) Cookies These tokens are fundamentally integrated into the architecture of the BlackLeaf™ digital platforms. They are unconditionally required to authenticate user identity, facilitate Multi-Factor Authentication (MFA), prevent Cross-Site Request Forgery (CSRF) attacks, and enforce Anti-Money Laundering (AML) geofencing parameters during portal access.

    • Regulatory Status: Because these cookies form the baseline of our cybersecurity and fraud-prevention infrastructure, their deployment does not require user consent and they cannot be disabled by the user without terminating access to the secure portal.

​

  • 3.2 Performance and Institutional Analytics Cookies We deploy enterprise-grade, anonymized telemetry to monitor the structural integrity, latency, and load-balancing of our digital platforms. This data is aggregated and stripped of Personally Identifiable Information (PII) before analysis, ensuring we can optimize the digital experience without compromising client anonymity.

    • Regulatory Status: Deployed exclusively subject to the active, explicit opt-in consent of the user.

​

  • 3.3 Functional and Jurisdictional Cookies These localized tokens allow our infrastructure to recognize a returning authenticated user, automatically applying their strict jurisdictional privacy settings, preferred cryptographic dashboard layouts, and communication preferences.

    • Regulatory Status: Deployed exclusively subject to the active, explicit opt-in consent of the user.

​

  • 3.4 Strategic and Targeting Cookies BlackLeaf™ expressly prohibits the use of mass retail advertising cookies and unconditionally forbids the monetization, syndication, or sale of client digital footprints to third-party data brokers. We may deploy highly restricted, B2B-focused targeting cookies strictly for the purpose of disseminating institutional thought leadership or notifying corporate partners of relevant M&A market developments.

    • Regulatory Status: Deployed exclusively subject to the active, explicit opt-in consent of the user.

4. Consent Architecture and Granular Control

In strict adherence to global data sovereignty standards, BlackLeaf™ operates on a "Privacy by Design" framework.

​

  • Zero Pre-Authorization: We do not utilize pre-ticked consent boxes. No non-essential cookies or tracking pixels will be executed on your hardware prior to your active, affirmative consent.

  • Dynamic Preference Management: Users maintain absolute sovereignty over their digital footprint. Consent for non-essential tracking can be audited, modified, or permanently revoked at any time via the "Institutional Privacy Preferences" node located in the encrypted footer of our platform.

5. Third-Party Ecosystem and Secure Integrations

To execute complex Multi-Family Office mandates, the Firm integrates with specialized, ISO-certified third-party infrastructure (e.g., encrypted document vault providers and secure digital signature protocols). While these institutional partners may deploy their own necessary session cookies to maintain the integrity of a transaction, BlackLeaf™ imposes strict contractual data-processing agreements on all vendors to ensure compliance with our internal privacy parameters.

6. Hardware-Level Browser Configurations

Users retain the ability to configure their localized web browsers to reject all cookies proactively or trigger alerts when a tracking token is initiated. However, overriding the Firm's Strictly Necessary Security Cookies at the hardware level will trigger our automated security tripwires, immediately nullifying your ability to authenticate into the BlackLeaf™ Client Portal or access secure documentation.

7. Policy Governance and Amendments

The BlackLeaf™ Privacy & Compliance Office formally reviews this policy bi-annually to ensure continuous alignment with the directives of the South African Information Regulator and the European Data Protection Board (EDPB). Material architectural changes to our tracking deployment will be communicated to active clients via secure internal portal memorandums.

8. Designated Compliance Officer Contact

For inquiries regarding our cryptographic session management, or to exercise your rights under POPIA or the GDPR, please direct your correspondence to our statutory Information Officer:

​

  • Information Officer: Talita Clarke, Vice President

  • Physical Domicile: The Loft Office, 439 Diagonal Street, Pringle Bay, Western Cape, 7196

  • Encrypted Communications: compliance@blackleafwealth.com

  • Secure Office Line: +27 79 203 5844

bottom of page