Governance / Framework

ImpactMiles Governance Framework

A living set of policies and standards that keep the platform lawful, trustworthy and mission-aligned. Each policy is versioned, has a named owner, is reviewed at least annually and is anchored to KERI as TrustMark evidence on publication.

Governance

v1.2 / reviewed 2026-07-20

Governance Charter

Establishes the governance structure, decision-making processes and oversight mechanisms for ImpactMiles Limited, a Hong Kong incorporated limited liability company operating a closed-loop verifiable impact and loyalty platform on KERI infrastructure.

Owner / Board of Directors
✓ Trustmark anchored in TAS
b08432a3844f4f8a84fccf9d
v1.0 / reviewed 2026-07-20

Legal and Regulatory Compliance Matrix

High-level mapping of ImpactMiles policies to applicable Hong Kong laws, key EU, UK and APAC regulations and relevant international standards.

Owner / General Counsel
✓ Trustmark anchored in TAS
14a8c56bb11e8a2caf7bd896
v1.0 / reviewed 2026-07-20

Diversity, Equity and Inclusion Policy

Commitments to diversity, equity and inclusion across the ImpactMiles workforce, its Board and the communities it serves through the platform.

Owner / Ethics and Compliance Committee
✓ Trustmark anchored in TAS
3449cf754deb5c561a1f1ad4
v1.0 / reviewed 2026-07-20

Third-Party and Ecosystem Governance Policy

Rules for onboarding and governing external participants in the ImpactMiles ecosystem, including charities, corporate partners, community advisors and interoperating KERI networks.

Owner / Chief Trust Officer
✓ Trustmark anchored in TAS
a606d2e5cc6f80cd75208f1c
v1.0 / reviewed 2026-07-20

Sustainability and Environmental Policy

ImpactMiles' commitments to reduce the environmental footprint of its own operations and of the events, activities and rewards it facilitates.

Owner / CEO
✓ Trustmark anchored in TAS
41e83ebe5ffd82498d66fcf5
v1.0 / reviewed 2026-07-20

Intellectual Property and Openness Policy

Ownership, licensing and openness rules for platform intellectual property, user-generated content, TrustMarks and ACDC credentials.

Owner / General Counsel
✓ Trustmark anchored in TAS
365ace00c32f591847531013
v1.0 / reviewed 2026-07-20

Dispute Resolution and Grievance Policy

Mechanisms for participants, charities and corporate partners to raise complaints, contest disputed impact milestones, resolve token redemption issues and challenge KERI-related revocations, aligned with Hong Kong law.

Owner / Ethics and Compliance Committee
✓ Trustmark anchored in TAS
e3d8161635698ba069b42860
v1.0 / reviewed 2026-07-19

Responsible AI Usage Policy

Principles and controls governing the use of AI in matching, drafting, fraud triage and content generation.

Owner / Chief Trust Officer
✓ Trustmark anchored in TAS
677c85161420a49e2efac8ca
v1.0 / reviewed 2026-07-19

Code of Conduct and Ethics

Behavioural expectations for staff, contractors, partners and platform users.

Owner / Ethics Committee
✓ Trustmark anchored in TAS
781c7af2ad42b96258e6838a

Data & Privacy

Trust & Verification

Financial & Anti-Fraud

Platform Operations

v1.0 / reviewed 2026-07-20

Business Continuity and Exit Strategy Policy

Continuity planning beyond incident response, plus data portability and orderly exit for users if ImpactMiles winds down a service or the entity.

Owner / CTO
✓ Trustmark anchored in TAS
da3cba4b102484237829519b
v1.0 / reviewed 2026-07-20

Audit, Reporting and Transparency Policy

Requirements for external audit, public reporting, governance-effectiveness metrics and whistleblower protection.

Owner / CFO
✓ Trustmark anchored in TAS
0afe00b4007efdbc6ac35be2
v1.0 / reviewed 2026-07-19

Vendor and Sub-processor Management Policy

Due diligence, contractual safeguards and ongoing oversight for third-party vendors and sub-processors.

Owner / Compliance Lead
✓ Trustmark anchored in TAS
fd5be032425f26d4d2b8413b
v1.0 / reviewed 2026-07-19

Change Management and SLA Policy

How changes to the platform are proposed, reviewed, deployed and communicated, and the service levels users can expect.

Owner / CTO
✓ Trustmark anchored in TAS
643d2da15dc98b2ae574acc7
v1.0 / reviewed 2026-07-19

Incident Response and Breach Notification Policy

How ImpactMiles detects, classifies, contains and reports security and privacy incidents.

Owner / Head of Security
✓ Trustmark anchored in TAS
13eee3015eaaefb8bf99f2fd
v1.0 / reviewed 2026-07-19

Access Control and Admin Role Policy

Rules for assigning and reviewing platform roles including admin, verifier and operator functions.

Owner / Head of Security
✓ Trustmark anchored in TAS
ae417bd9ef32f57c5283ad52
v1.0 / reviewed 2026-07-19

Information Security Policy

Baseline security controls covering identity, network, application, data and supply chain.

Owner / Head of Security
✓ Trustmark anchored in TAS
e03d15b698695e298f3fccab

How these policies are applied

  • Row Level Security and role-based access enforce data protection at the database layer.
  • Admin verifications, Veraf.ai checks and TrustMark issuance apply the Trust and AML policies at onboarding.
  • Fee settlement records and provenance trails apply the Fee Transparency Policy on every transaction.
  • Incident, change and vendor policies drive our operational runbooks and quarterly reviews.
  • Every policy version goes through a 4-eyes review and approval workflow in the admin CMS, with a full audit trail.

Total published policies / 26. Reviewed at least annually or on material change.