Privacy Policy
Last updated: 2 September 2026
1. Data Controller
The controller responsible for processing your personal data is:
Caproom B.V.
Jacob Bontiusplaats 9, 1018 LL Amsterdam, The Netherlands
Trade register (KvK): 42151311
VAT: NL869941288B01
Email: hi@caproomfunds.com
1A. Our Role: Controller and Processor
Caproom acts in two distinct capacities. We are the controller for personal data we process for our own purposes: website visitors, marketing contacts, platform user accounts, security and audit logging, and our own business administration. We act as a processor on behalf of a fund manager for the personal data that manager uploads or generates in relation to its funds, investors, advisors and portfolio companies. In that capacity we process only on the manager's documented instructions under a Data Processing Agreement concluded with that manager. If you are an investor and wish to exercise your rights in respect of fund data, your request is addressed to the fund manager as controller; we will assist them in responding and will forward any request we receive directly.
2. Personal Data We Collect
We collect the following categories of personal data:
| Category | Examples |
|---|---|
| Account Data | Name, email address, phone number, organisation, role |
| KYC / AML Data | Government-issued ID, proof of address, UBO declarations, PEP status, source of wealth documentation |
| Financial Data | Commitment amounts, capital call payments, distribution records, bank account details |
| Usage Data | Login timestamps, IP addresses, pages visited, browser type, device information |
| Cookies & Tracking | Session identifiers, consent preferences (see Section 9) |
| Screening Data | Results of sanctions, PEP and adverse-media screening, including match details, risk scores and reviewer decisions |
2A. Where We Obtain Your Data
Not all personal data we process is provided by you directly. Where we obtain it from another source, that source is one of the following:
- The fund manager or its advisors, who enter investor, contact and commitment data when onboarding you to a fund;
- Your own organisation, where a colleague invites you to the platform or is named as a signatory, director or ultimate beneficial owner;
- Sanctions, PEP and adverse-media data sources, including official EU, UN and OFAC consolidated lists, used for statutory screening;
- Public registers and publicly available sources, such as chamber of commerce filings, used to verify entity and UBO details.
3. Legal Bases for Processing
We process your personal data based on the following legal grounds under Article 6(1) GDPR:
- Contract (Art. 6(1)(b)) — Processing necessary to provide our fund administration services: account management, document generation, capital call/distribution processing, and investor communications.
- Legal Obligation (Art. 6(1)(c)) — KYC/AML screening, sanctions checking, UBO identification, and record retention as required by the Dutch Anti-Money Laundering and Terrorist Financing Prevention Act (Wwft), the Markets in Financial Instruments Directive (MiFID II), and the Alternative Investment Fund Managers Directive (AIFMD).
- Legitimate Interest (Art. 6(1)(f)) — Platform security (fraud prevention, audit logging), service improvement, and usage analytics.
- Consent (Art. 6(1)(a)) — Marketing communications and non-essential cookies. You may withdraw consent at any time via your account settings or the panel.
4. Data Retention
- KYC/AML records: Retained for a minimum of 7 years after the end of the business relationship, as required by the Wwft.
- Financial records: Retained for 7 years in accordance with Dutch fiscal retention requirements.
- Account data: Retained for the duration of your account. Upon a deletion request, data is deleted or irreversibly anonymised within 30 days, subject to legal retention obligations. Records subject to a statutory retention period are retained in restricted form until that period expires.
- Usage data & logs: Retained for up to 12 months, then aggregated or deleted.
- Cookie consent records: Retained for 12 months, after which consent is re-requested.
5. Third-Party Processors
We engage the following sub-processors under appropriate Data Processing Agreements (DPAs):
| Processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication and file storage | EU (Frankfurt) |
| Lovable (GPT Engineer Inc.) | Application hosting and build infrastructure | EU |
| Lettermint | Transactional email delivery | EEA (Netherlands) |
| Cloudflare Inc. | Content delivery, DDoS protection and bot/CAPTCHA verification | Global, EU processing |
| Ascensio System SIA (OnlyOffice) | Document editing and comparison | Self-hosted, EEA |
| Mistral AI SAS | AI processing of confidential and privileged content, EU zero-retention endpoint | EEA (France) |
| Google LLC / OpenAI Inc. (via AI gateway) | AI processing of non-confidential content only | Global, EU data protection terms |
| Microsoft Ireland Operations Ltd. | Business correspondence and email | EEA |
6. International Data Transfers
Your data is primarily processed within the European Economic Area (EEA). Our database, file storage, email delivery and document editing all take place within the EEA. A limited number of processors are established outside the EEA: Cloudflare (content delivery and bot protection) and, for non-confidential content only, the AI providers Google and OpenAI. For those transfers we rely on EU-approved Standard Contractual Clauses (SCCs) or an adequacy decision pursuant to Chapter V GDPR. Confidential and legally privileged content is never transferred outside the EEA. No data is transferred to countries without an adequate level of protection unless appropriate safeguards are in place.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of Access (Art. 15) — Request a copy of all personal data we hold about you.
- Right to Rectification (Art. 16) — Correct inaccurate or incomplete data via your Settings page.
- Right to Erasure (Art. 17) — Request deletion of your personal data, subject to legal retention obligations.
- Right to Restriction (Art. 18) — Request that we restrict processing of your data in certain circumstances.
- Right to Data Portability (Art. 20) — Download your data in a machine-readable format (JSON) from Settings → Security → "Download My Data".
- Right to Object (Art. 21) — Object to processing based on legitimate interest or for direct marketing purposes.
- Right to Lodge a Complaint (Art. 77) — You may file a complaint with the Dutch Data Protection Authority (see Section 11).
To exercise any of these rights, contact us at hi@caproomfunds.com or use the self-service tools in your account settings. We will respond within 30 days.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including: encryption in transit (TLS 1.2+) and at rest, row-level security policies on all database tables, role-based access controls, audit logging of sensitive operations, and regular security reviews. Access to personal data is limited to authorised personnel on a need-to-know basis.
8A. Artificial Intelligence and Automated Processing
Certain platform features use AI models to assist with document drafting, document comparison, data extraction and screening review. Content is classified before it is sent to any model. Confidential and legally privileged content — including draft fund documentation, side letters and KYC files — is routed exclusively to a model provider established in the European Union under a zero-retention arrangement, meaning the provider does not store the content and does not use it for model training. Non-confidential content may be processed by providers outside the EEA under EU data protection terms. No personal data is used to train any model.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Sanctions and PEP screening, risk scoring and compliance checks produce advisory results that are always reviewed and decided upon by a human before any action is taken.
8B. Data Breach Notification
In the event of a personal data breach, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR). Where the breach is likely to result in a high risk to you, we will inform you without undue delay (Article 34 GDPR). Where we act as processor for a fund manager, we notify that manager without undue delay so they can meet their own notification obligations.
9. Cookie Policy
We use cookies categorised as follows:
| Category | Purpose | Expiry |
|---|---|---|
| Necessary | Authentication session, CSRF protection, cookie consent state | Session / 12 months |
| Analytics | Usage patterns, feature adoption, error tracking. No analytics cookies are currently placed; this category is reserved and only used if you opt in. | 12 months |
| Marketing | Communication preferences. No marketing cookies are currently placed; this category is reserved and only used if you opt in. | 12 months |
You can manage your cookie preferences at any time by clicking or via the link at the bottom of every page.
10. Children's Privacy
Caproom is a professional fund administration platform and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If we become aware that we have collected data from a minor, we will delete it promptly.
11. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30, 2594 AV Den Haag
Phone: +31 (0)70 888 85 00
Website: autoriteitpersoonsgegevens.nl
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email notification and/or a prominent notice on our platform at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact Us
For questions about this Privacy Policy or to exercise your data protection rights, contact us at hi@caproomfunds.com.
Caproom is not required to appoint a Data Protection Officer under Article 37 GDPR and has not appointed one. Privacy matters are handled directly by our management, at the address and email above.