Skip to main content

Privacy Policy

Last updated: 2 September 2026

1. Data Controller

The controller responsible for processing your personal data is:

Caproom B.V.

Jacob Bontiusplaats 9, 1018 LL Amsterdam, The Netherlands

Trade register (KvK): 42151311

VAT: NL869941288B01

Email: hi@caproomfunds.com

1A. Our Role: Controller and Processor

Caproom acts in two distinct capacities. We are the controller for personal data we process for our own purposes: website visitors, marketing contacts, platform user accounts, security and audit logging, and our own business administration. We act as a processor on behalf of a fund manager for the personal data that manager uploads or generates in relation to its funds, investors, advisors and portfolio companies. In that capacity we process only on the manager's documented instructions under a Data Processing Agreement concluded with that manager. If you are an investor and wish to exercise your rights in respect of fund data, your request is addressed to the fund manager as controller; we will assist them in responding and will forward any request we receive directly.

2. Personal Data We Collect

We collect the following categories of personal data:

CategoryExamples
Account DataName, email address, phone number, organisation, role
KYC / AML DataGovernment-issued ID, proof of address, UBO declarations, PEP status, source of wealth documentation
Financial DataCommitment amounts, capital call payments, distribution records, bank account details
Usage DataLogin timestamps, IP addresses, pages visited, browser type, device information
Cookies & TrackingSession identifiers, consent preferences (see Section 9)
Screening DataResults of sanctions, PEP and adverse-media screening, including match details, risk scores and reviewer decisions

2A. Where We Obtain Your Data

Not all personal data we process is provided by you directly. Where we obtain it from another source, that source is one of the following:

  • The fund manager or its advisors, who enter investor, contact and commitment data when onboarding you to a fund;
  • Your own organisation, where a colleague invites you to the platform or is named as a signatory, director or ultimate beneficial owner;
  • Sanctions, PEP and adverse-media data sources, including official EU, UN and OFAC consolidated lists, used for statutory screening;
  • Public registers and publicly available sources, such as chamber of commerce filings, used to verify entity and UBO details.

3. Legal Bases for Processing

We process your personal data based on the following legal grounds under Article 6(1) GDPR:

  • Contract (Art. 6(1)(b))Processing necessary to provide our fund administration services: account management, document generation, capital call/distribution processing, and investor communications.
  • Legal Obligation (Art. 6(1)(c))KYC/AML screening, sanctions checking, UBO identification, and record retention as required by the Dutch Anti-Money Laundering and Terrorist Financing Prevention Act (Wwft), the Markets in Financial Instruments Directive (MiFID II), and the Alternative Investment Fund Managers Directive (AIFMD).
  • Legitimate Interest (Art. 6(1)(f))Platform security (fraud prevention, audit logging), service improvement, and usage analytics.
  • Consent (Art. 6(1)(a))Marketing communications and non-essential cookies. You may withdraw consent at any time via your account settings or the panel.

4. Data Retention

  • KYC/AML records: Retained for a minimum of 7 years after the end of the business relationship, as required by the Wwft.
  • Financial records: Retained for 7 years in accordance with Dutch fiscal retention requirements.
  • Account data: Retained for the duration of your account. Upon a deletion request, data is deleted or irreversibly anonymised within 30 days, subject to legal retention obligations. Records subject to a statutory retention period are retained in restricted form until that period expires.
  • Usage data & logs: Retained for up to 12 months, then aggregated or deleted.
  • Cookie consent records: Retained for 12 months, after which consent is re-requested.

5. Third-Party Processors

We engage the following sub-processors under appropriate Data Processing Agreements (DPAs):

ProcessorPurposeLocation
Supabase Inc.Database, authentication and file storageEU (Frankfurt)
Lovable (GPT Engineer Inc.)Application hosting and build infrastructureEU
LettermintTransactional email deliveryEEA (Netherlands)
Cloudflare Inc.Content delivery, DDoS protection and bot/CAPTCHA verificationGlobal, EU processing
Ascensio System SIA (OnlyOffice)Document editing and comparisonSelf-hosted, EEA
Mistral AI SASAI processing of confidential and privileged content, EU zero-retention endpointEEA (France)
Google LLC / OpenAI Inc. (via AI gateway)AI processing of non-confidential content onlyGlobal, EU data protection terms
Microsoft Ireland Operations Ltd.Business correspondence and emailEEA

6. International Data Transfers

Your data is primarily processed within the European Economic Area (EEA). Our database, file storage, email delivery and document editing all take place within the EEA. A limited number of processors are established outside the EEA: Cloudflare (content delivery and bot protection) and, for non-confidential content only, the AI providers Google and OpenAI. For those transfers we rely on EU-approved Standard Contractual Clauses (SCCs) or an adequacy decision pursuant to Chapter V GDPR. Confidential and legally privileged content is never transferred outside the EEA. No data is transferred to countries without an adequate level of protection unless appropriate safeguards are in place.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of Access (Art. 15)Request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16)Correct inaccurate or incomplete data via your Settings page.
  • Right to Erasure (Art. 17)Request deletion of your personal data, subject to legal retention obligations.
  • Right to Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances.
  • Right to Data Portability (Art. 20)Download your data in a machine-readable format (JSON) from Settings → Security → "Download My Data".
  • Right to Object (Art. 21)Object to processing based on legitimate interest or for direct marketing purposes.
  • Right to Lodge a Complaint (Art. 77)You may file a complaint with the Dutch Data Protection Authority (see Section 11).

To exercise any of these rights, contact us at hi@caproomfunds.com or use the self-service tools in your account settings. We will respond within 30 days.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS 1.2+) and at rest, row-level security policies on all database tables, role-based access controls, audit logging of sensitive operations, and regular security reviews. Access to personal data is limited to authorised personnel on a need-to-know basis.

8A. Artificial Intelligence and Automated Processing

Certain platform features use AI models to assist with document drafting, document comparison, data extraction and screening review. Content is classified before it is sent to any model. Confidential and legally privileged content — including draft fund documentation, side letters and KYC files — is routed exclusively to a model provider established in the European Union under a zero-retention arrangement, meaning the provider does not store the content and does not use it for model training. Non-confidential content may be processed by providers outside the EEA under EU data protection terms. No personal data is used to train any model.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Sanctions and PEP screening, risk scoring and compliance checks produce advisory results that are always reviewed and decided upon by a human before any action is taken.

8B. Data Breach Notification

In the event of a personal data breach, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR). Where the breach is likely to result in a high risk to you, we will inform you without undue delay (Article 34 GDPR). Where we act as processor for a fund manager, we notify that manager without undue delay so they can meet their own notification obligations.

9. Cookie Policy

We use cookies categorised as follows:

CategoryPurposeExpiry
NecessaryAuthentication session, CSRF protection, cookie consent stateSession / 12 months
AnalyticsUsage patterns, feature adoption, error tracking. No analytics cookies are currently placed; this category is reserved and only used if you opt in.12 months
MarketingCommunication preferences. No marketing cookies are currently placed; this category is reserved and only used if you opt in.12 months

You can manage your cookie preferences at any time by clicking or via the link at the bottom of every page.

10. Children's Privacy

Caproom is a professional fund administration platform and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.

11. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens

Bezuidenhoutseweg 30, 2594 AV Den Haag

Phone: +31 (0)70 888 85 00

Website: autoriteitpersoonsgegevens.nl

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email notification and/or a prominent notice on our platform at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact Us

For questions about this Privacy Policy or to exercise your data protection rights, contact us at hi@caproomfunds.com.

Caproom is not required to appoint a Data Protection Officer under Article 37 GDPR and has not appointed one. Privacy matters are handled directly by our management, at the address and email above.

10bn+

AUM ADVISED ON BY THE FOUNDER SINCE 2017

9 yrs

Years of Dutch fund formation and corporate practice

EU Hosted · AI Confidentiality

Compliant data processing

  • EU-hosted (Frankfurt)
  • GDPR-native
  • Third-party pentested
  • ISO 27001 / SOC 2 aligned
  • AFM / AIFMD-framework aligned

Get in Touch

Have questions about Caproom? We'd love to hear from you. Reach out directly or schedule a call.

Office

Jacob Bontiusplaats 9, 1018 LL Amsterdam, The Netherlands

Speak with the founder

You'll speak with Duco.

A 30-minute call with the founder, a former fund formation lawyer. No discovery deck, no qualification gate. Bring a draft term sheet or just your structuring questions.

Built by Duco Poppema, former Dutch fund formation and corporate lawyer, in practice from 2017 to 2026, recognised in Legal 500.

Read more