1. GENERAL PROVISIONS AND CONTROLLER IDENTITY1.1. Purpose of Policy: This Privacy and Data Processing Policy (hereinafter referred to as the
"Policy") defines how
Condus Capital (registry code registered in Estonia, located in Tallinn, Estonia; hereinafter referred to as
"Condus Capital",
"Firm",
"we",
"us", or
"our") collects, processes, stores, protects, and discloses personal data of clients, prospective investors, transaction counterparties, website visitors, and business partners.
1.2. Regulatory Framework: Condus Capital processes personal data in strict compliance with Regulation (EU) 2016/679 (General Data Protection Regulation -
GDPR), the Estonian Personal Data Protection Act (
Isikuandmete kaitse seadus), the Estonian Money Laundering and Terrorist Financing Prevention Act (
Rahapesu ja terrorismi tõkestamise seadus), and other applicable European Union legal frameworks.
1.3. Data Controller: Condus Capital acts as the Data Controller responsible for the processing of your personal data under this Policy.
2. CATEGORIES OF PERSONAL DATA COLLECTEDDepending on the nature of your interaction with Condus Capital (website navigation, M&A engagement, NDA execution, or KYC screening), we may process the following categories of data:
- Identity Data: Full name, date of birth, personal identification code (national ID number), passport/ID card details, nationality, photograph, and legal power of attorney documentation.
- Contact Data: Professional and personal email address, phone number, physical business address, and corporate communication channels.
- Corporate & Beneficial Ownership Data: Job title, role, company ownership percentages, corporate registry extracts, and Ultimate Beneficial Owner (UBO) status.
- Financial & Due Diligence Data: Bank account details, proof/source of funds, wealth origin disclosures, tax identification numbers (TIN), and transaction background records submitted during M&A due diligence.
- Technical & Usage Data: IP address, browser type, device information, geographic location, pages visited, and interaction timestamps collected via cookies or website analytics.
3. LEGAL BASES AND PURPOSES OF DATA PROCESSINGCondus Capital processes personal data strictly under lawful bases defined by Article 6 of the GDPR:
- Execution of Contracts (GDPR Art. 6(1)(b)): Processing is necessary to perform Advisory Mandates, Non-Disclosure Agreements (NDAs), Fee Protection Agreements, or pre-contractual evaluations (e.g., assessing investment teasers or target companies).
- Legal & Regulatory Obligations (GDPR Art. 6(1)(c)): Processing is required to comply with statutory anti-money laundering (AML), Know Your Customer (KYC), economic sanctions screening, tax reporting, and accounting duties under Estonian law.
- Legitimate Business Interests (GDPR Art. 6(1)(f)): Processing is necessary for our legitimate interests in protecting business assets, preventing transaction fraud, ensuring non-circumvention compliance, maintaining secure Virtual Data Rooms (VDR), and communicating with corporate decision-makers.
- Consent (GDPR Art. 6(1)(a)): Where explicitly requested (e.g., analytical cookies or direct marketing communications), data is processed based on your voluntary consent.
4. DATA DISCLOSURE AND RECIPIENTS4.1. Confidential Handling: Condus Capital does not sell, rent, or commercialize personal data to third parties.
4.2. Authorized Recipients: Personal data may be shared strictly on a need-to-know basis with:
- Transaction Counterparties: Verified buyers, sellers, or co-investors bound by strict NDAs during M&A negotiations.
- Licensed Professional Advisors: Estonian and European notaries, banking compliance officers, escrow agents, legal counsels, and audit firms involved in deal execution.
- Regulatory Authorities: Estonian Financial Intelligence Unit (FIU/RAB), Tax and Customs Board (MTA), or law enforcement bodies when legally required.
- IT & Technical Infrastructure: Encrypted Virtual Data Room (VDR) providers, cloud hosting, and secure CRM platforms operating under GDPR-compliant Data Processing Agreements (DPAs).
5. INTERNATIONAL DATA TRANSFERS5.1. Primary Processing Location: Personal data is stored and processed primarily within the European Economic Area (EEA).
5.2. Cross-Border Safeguards: In cross-border M&A transactions involving non-EEA counterparties, Condus Capital ensures transfers are protected using European Commission Standard Contractual Clauses (SCCs), adequacy decisions, or explicit transaction-execution provisions under GDPR Article 49.
6. DATA RETENTION PERIODSCondus Capital retains personal data only as long as necessary to fulfill the operational and legal purposes for which it was collected:
- AML/KYC Compliance Records: Retained for 5 (five) years following the termination of the business relationship, as mandated by Estonian AML legislation.
- Contractual & Accounting Records: Retained for 7 (seven) years in accordance with Estonian accounting laws.
- Pre-Contractual & Transaction Inquiries: Retained for up to 3 (three) years following the last communication, unless required longer to preserve legal claims or non-circumvention rights.
7. DATA SUBJECT RIGHTSUnder the GDPR, you possess the following statutory rights regarding your personal data:
- Right of Access: Request confirmation and copies of your personal data processed by us.
- Right to Rectification: Request correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request deletion of data where statutory retention obligations do not apply.
- Right to Restrict Processing: Request temporary restriction of data processing under specific conditions.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to data processing based on legitimate interests or direct communications.
To exercise your rights, send a written request to
info@condus.eu. We will respond within 30 calendar days.
8. DATA SECURITY MEASURESCondus Capital employs robust technical and organizational measures to safeguard personal data against unauthorized access, loss, or disclosure. These include strict role-based access controls, multi-factor authentication, end-to-end encryption in transit and at rest, secure Virtual Data Rooms (VDR), and continuous system security reviews.
9. SUPERVISORY AUTHORITYIf you believe your privacy rights have been infringed, you have the right to lodge a complaint with the Estonian supervisory authority:
- Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
- Address: Tatari 39, 10134 Tallinn, Estonia | Email: info@aki.ee | Website: www.aki.ee
10. UPDATES TO THIS POLICYCondus Capital reserves the right to amend this Privacy Policy periodically to reflect statutory updates or changes in operational practice. The current version will always be published on our website.
Condus Capital | Advisory & M&A EngineeringHarju maakond, Tallinn, Estonia | www.condus.eu