ImpactMiles Governance Framework
A living set of policies and standards that keep the platform lawful, trustworthy and mission-aligned. Each policy is versioned, has a named owner, is reviewed at least annually and is anchored to KERI as TrustMark evidence on publication.
Governance
Governance Charter
Establishes the governance structure, decision-making processes and oversight mechanisms for ImpactMiles Limited, a Hong Kong incorporated limited liability company operating a closed-loop verifiable impact and loyalty platform on KERI infrastructure.
Legal and Regulatory Compliance Matrix
High-level mapping of ImpactMiles policies to applicable Hong Kong laws, key EU, UK and APAC regulations and relevant international standards.
Diversity, Equity and Inclusion Policy
Commitments to diversity, equity and inclusion across the ImpactMiles workforce, its Board and the communities it serves through the platform.
Third-Party and Ecosystem Governance Policy
Rules for onboarding and governing external participants in the ImpactMiles ecosystem, including charities, corporate partners, community advisors and interoperating KERI networks.
Sustainability and Environmental Policy
ImpactMiles' commitments to reduce the environmental footprint of its own operations and of the events, activities and rewards it facilitates.
Intellectual Property and Openness Policy
Ownership, licensing and openness rules for platform intellectual property, user-generated content, TrustMarks and ACDC credentials.
Dispute Resolution and Grievance Policy
Mechanisms for participants, charities and corporate partners to raise complaints, contest disputed impact milestones, resolve token redemption issues and challenge KERI-related revocations, aligned with Hong Kong law.
Responsible AI Usage Policy
Principles and controls governing the use of AI in matching, drafting, fraud triage and content generation.
Code of Conduct and Ethics
Behavioural expectations for staff, contractors, partners and platform users.
Data & Privacy
Data Protection Impact Assessment (DPIA) Methodology
When and how ImpactMiles conducts DPIAs, including the templated risk register and Board approval gate.
Cookies and Tracking Technologies Policy
Categories of cookies and similar technologies used across ImpactMiles surfaces, and how consent is obtained and recorded.
Data Retention and Deletion Schedule
Retention periods, deletion triggers and archival rules for each category of data held by ImpactMiles.
Data Protection and Privacy Policy
How ImpactMiles collects, uses, shares and protects personal data across all jurisdictions in which it operates.
Trust & Verification
ESG and Impact Measurement Governance
Methodology, data sourcing and assurance for the Impact Miles Index (IMI) and any ESG claims made by ImpactMiles or its Sponsors, designed to prevent greenwashing and impact washing.
KERI Operations and Key Management Policy
Key generation, rotation, custody and recovery rules for KERI AIDs operated by ImpactMiles.
Trust and Verification Policy
Rules for issuing, chaining, revoking and verifying TrustMark credentials (TMIDs) and ACDCs on the KERI backbone.
Financial & Anti-Fraud
Fraud, Abuse and Misuse Policy
Prohibited behaviours, detection controls and response actions for fraudulent, abusive or manipulative use of the platform.
Fee Transparency and Disbursement Policy
How platform fees are calculated, disclosed and disbursed, and how donors can trace every deduction.
Anti-Money-Laundering and Counter-Terrorism Financing Policy
Risk-based controls to prevent misuse of the ImpactMiles platform for money laundering or terrorism financing.
Platform Operations
Business Continuity and Exit Strategy Policy
Continuity planning beyond incident response, plus data portability and orderly exit for users if ImpactMiles winds down a service or the entity.
Audit, Reporting and Transparency Policy
Requirements for external audit, public reporting, governance-effectiveness metrics and whistleblower protection.
Vendor and Sub-processor Management Policy
Due diligence, contractual safeguards and ongoing oversight for third-party vendors and sub-processors.
Change Management and SLA Policy
How changes to the platform are proposed, reviewed, deployed and communicated, and the service levels users can expect.
Incident Response and Breach Notification Policy
How ImpactMiles detects, classifies, contains and reports security and privacy incidents.
Access Control and Admin Role Policy
Rules for assigning and reviewing platform roles including admin, verifier and operator functions.
Information Security Policy
Baseline security controls covering identity, network, application, data and supply chain.
How these policies are applied
- Row Level Security and role-based access enforce data protection at the database layer.
- Admin verifications, Veraf.ai checks and TrustMark issuance apply the Trust and AML policies at onboarding.
- Fee settlement records and provenance trails apply the Fee Transparency Policy on every transaction.
- Incident, change and vendor policies drive our operational runbooks and quarterly reviews.
- Every policy version goes through a 4-eyes review and approval workflow in the admin CMS, with a full audit trail.
Total published policies / 26. Reviewed at least annually or on material change.