Privacy Policy

Burrow Capital Management Ltd

Company number: HE 454836
3rd Floor, Iris House, John Kennedy Street, 3106, Limassol, Cyprus

This Privacy Policy explains how Burrow Capital Management Ltd (“Burrow Capital”, “we”, “us” or “our”) collects, uses and protects personal data when you visit or interact with our corporate website (the “Website”) or otherwise contact us through the Website.

1. Who we are

Burrow Capital Management Ltd, company number HE 454836, with its registered/business address at 3rd Floor, Iris House, John Kennedy Street, 3106, Limassol, Cyprus, is the controller of personal data processed for the purposes described in this Privacy Policy.

This Privacy Policy is intended to provide the information required by Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”) and Cyprus Law 125(I)/2018, as applicable.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal data collected through the Website and to personal data you provide when you contact us through an online form, by email or by other contact method made available on the Website.

It does not necessarily apply to separate services, investment activities, portfolio companies or third-party websites that may have their own privacy notices.

3. Personal data we may collect

Depending on how you use the Website, we may process the following categories of personal data:

  • Contact and identity information, such as your name, business name, job title, email address, telephone number and other details you choose to provide.
  • Enquiry and correspondence information, including the content of messages, attachments and records of our communications with you.
  • Business relationship information, where relevant, such as your organisation, professional role and the nature of your interest in Burrow Capital.
  • Technical and device information, such as IP address, browser type, operating system, device information, referral source, access times and server or security logs.
  • Cookie and similar technology data, where such technologies are used. Please see our Cookie Policy for further information.
  • Other information you voluntarily provide to us through the Website.


We do not ask you to provide special categories of personal data through the Website. Please do not send sensitive personal information through a general website contact form unless it is necessary and appropriate to do so.

4. How we collect personal data

We may collect personal data:

  • directly from you when you submit an enquiry, contact us, subscribe to communications or otherwise interact with us;
  • automatically through our Website, servers, security systems and, where applicable, cookies or similar technologies;
  • from service providers that support the operation, hosting, security or analytics of the Website; and
  • where appropriate in a business context, from publicly available professional or corporate sources.

5. Why we use personal data and our legal bases

We process personal data only where we have a lawful basis under applicable data protection law. The principal purposes and legal bases are set out below.

Purpose

Examples

Legal basis

Responding to enquiries and communications

To receive, assess and respond to questions, introductions, proposals and other communications.

Our legitimate interests in communicating with people who contact us; and, where relevant, taking steps at your request before entering into a contract.

Operating and protecting the Website

Hosting, administration, troubleshooting, fraud prevention, network security and maintaining website availability.

Our legitimate interests in operating a secure and effective corporate website and protecting our systems.

Business and relationship management

Maintaining records of relevant business contacts, introductions and discussions.

Our legitimate interests in managing and developing our business relationships.

Analytics and website improvement

Understanding how visitors use the Website and improving content and performance, where non-essential analytics technologies are enabled.

Your consent where consent is required for the relevant cookies or similar technologies.

Marketing or updates

Sending communications you have requested or, where permitted, relevant business communications.

Your consent where required, or our legitimate interests where applicable law permits such communications.

Legal and regulatory compliance

Complying with legal obligations, responding to lawful requests, establishing or defending legal claims and keeping records required by law.

Compliance with a legal obligation and/or our legitimate interests in protecting our legal rights.

6. Cookies and similar technologies

The Website may use cookies and similar technologies. Strictly necessary technologies may be used where required for the Website to function or remain secure. Non-essential cookies, such as analytics or marketing cookies, will be used only where the required consent has been obtained.

For more information about categories of cookies, consent and how to change your choices, please read our Cookie Policy and use the cookie settings tool made available on the Website, where applicable.

7. Who we may share personal data with

We may disclose personal data where reasonably necessary to:

  • website hosting, information technology, cybersecurity, communications and support service providers;
  • professional advisers, including lawyers, accountants, auditors, consultants and other advisers acting under appropriate duties of confidentiality;
  • analytics, consent-management or other website service providers, where those services are enabled;
  • members of our corporate group, affiliates or portfolio-related entities where there is a legitimate business need and a lawful basis for the disclosure;
  • regulators, supervisory authorities, courts, law-enforcement bodies or other public authorities where required or permitted by law; and
  • a buyer, investor, lender or adviser in connection with a proposed or actual corporate transaction, reorganisation or transfer of business, subject to appropriate confidentiality and data-protection safeguards.


We do not sell personal data obtained through the Website.

8. International transfers

Some of our service providers or business counterparties may process personal data outside Cyprus or the European Economic Area (EEA). Where a transfer is subject to the GDPR, we will use an appropriate transfer mechanism where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful safeguard.

9. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to maintain appropriate business records, comply with legal or regulatory obligations, resolve disputes and establish, exercise or defend legal claims.

Retention periods vary according to the type of information, the nature of our relationship with you, legal requirements and whether there is an ongoing business or legal need to retain the information. When personal data is no longer required, we will delete, anonymise or securely archive it in accordance with applicable requirements.

10. Data security

We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No website or electronic transmission can, however, be guaranteed to be completely secure.

11. Your data-protection rights

Subject to the conditions and limitations in applicable law, you may have the right to:

  • request access to your personal data and receive information about how it is processed;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data in certain circumstances;
  • request restriction of processing in certain circumstances;
  • object to processing based on our legitimate interests, including certain direct-marketing processing;
  • receive personal data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller, where the right to data portability applies;
  • withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal; and
  • lodge a complaint with a competent data-protection supervisory authority.


You may exercise your rights by contacting us using the contact details in section 15 below. We may need to verify your identity before acting on a request. We will respond within the time limits required by applicable law.

12. Marketing communications

If we send you marketing or informational communications, you may ask us to stop at any time by using the unsubscribe mechanism provided in the communication or by contacting us. This does not prevent us from sending non-marketing communications where there is another lawful reason to contact you.

13. Third-party websites and services

The Website may contain links to websites or services operated by third parties. We are not responsible for the privacy practices of those third parties. You should review their privacy notices before providing personal data to them.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Website, business practices or legal requirements. The most recent version will be published on the Website and the ‘Last updated’ date will be revised.

15. Contact and complaints

For privacy enquiries or to exercise your data-protection rights, please contact Burrow Capital Management Ltd using the contact details published on the Website or by post at:

Burrow Capital Management Ltd
3rd Floor, Iris House, John Kennedy Street, 3106, Limassol, Cyprus
Company number: HE 454836

You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus. Information about the Commissioner and how to make a complaint is available at www.dataprotection.gov.cy.