Privacy Policy
How we process personal data in the closed member area, whom we share it with and what rights you have.
Controller and contact
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
| Controller | Burdorf Consulting Ltd., Pano Arodes, Paphos, Cyprus |
| team.equex@burdorfconsulting.com | |
| Data protection officer | Based on our current assessment, no data protection officer is required to be appointed. Please direct enquiries to the email address above. |
| Supervisory authority | Office of the Commissioner for Personal Data Protection, Nicosia, Cyprus |
What data we process
We process only data required to operate the closed marketplace:
| Category | Data | Origin |
|---|---|---|
| Access request | Name, email address, optional phone/WhatsApp number, reference or invitation code, professional background, language | Entered by the data subject |
| Account | Email, password hash, time of email confirmation, Marketplace ID (pseudonym), display name | Registration / system |
| Status | Verification, qualification and suspension status, role | Assigned by the controller |
| Identity verification (KYC) | Verification status, verification session identifier and a summary of the result: name per ID document, date of birth, document type and number, issuing state, match and liveness scores, warnings | Verification provider (see recipients) |
| Investor profile | Answers to the voluntary questionnaire (volume, ticket size, horizon, deal types, experience, risk capacity, focus, free-text fields) | Entered by the data subject |
| Holdings and register | Assignment to listings, ownership quota, transactions and distributions with type, price per share, month, confirmation status | Controller, confirmation by the data subject |
| Usage | Views of individual listings and detail pages with timestamp and account reference | System |
| Technical | Server and access logs of the hosting provider, IP address, time, resource requested, browser identifier | System / hosting provider |
ID documents are not stored on our systems. Images and videos from identity verification remain with the verification provider; we receive only the result and the summary described above.
Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Access request, account, login | Initiation and performance of the usage relationship | Art. 6(1)(b) GDPR |
| Identity verification | Ensuring that only identified persons receive access to confidential company information; fraud prevention | Art. 6(1)(b) and (f) GDPR |
| Investor profile | Assessment of suitability and targeted outreach | Art. 6(1)(a) and (b) GDPR |
| Register and confirmations | Documentation of bilaterally confirmed transactions, record keeping | Art. 6(1)(b) and (f) GDPR |
| Usage tracking (listing views) | Understanding interest, operating and improving the service | Art. 6(1)(f) GDPR |
| Notifications (email) | Status messages regarding account, confirmations and new listings | Art. 6(1)(b) or (a) GDPR |
| Logs, security | Operational security, abuse prevention | Art. 6(1)(f) GDPR |
Legitimate interests are the secure operation of a closed circle, the protection of confidential issuer information and the traceability of documented transactions.
Recipients and processors
We use carefully selected service providers. Where required, data processing agreements pursuant to Art. 28 GDPR are in place with them.
| Service | Purpose | Place of processing |
|---|---|---|
| Supabase (database, authentication, server functions) | Storage of account, profile, register and status data | EU (Ireland region)(sub-processor: Amazon Web Services) |
| Netlify (hosting, delivery of the website) | Serving the pages, server and access logs | USA / global CDN |
| Didit (identity verification) | Verification of ID document, liveness and face match; transmission of the result | EU (Spain) |
| Formspree (form submission) | Forwarding of access requests and questionnaire answers to our internal systems | USA |
| Airtable (internal CRM) | Management of requests and investor profiles | USA |
| Telegram (internal notification) | Alerting the team on new requests and verification results | EU / third countries |
| Google Workspace (email delivery) | Sending confirmation and system emails | EU/USA |
| Google Fonts, jsDelivr, Cloudfront (delivery of fonts, code libraries and images) | Rendering of the pages | worldwide |
Transfers to third countries
Where service providers process data outside the European Economic Area (in particular in the United States), this takes place on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR, a certification under the EU-US Data Privacy Framework, or another permissible basis.
Retention periods
- Account and profile data: for the duration of membership and thereafter until statutory retention periods expire.
- Identity verification result: ten years from the end of the business relationship, unless a shorter period is permissible. The verification provider applies its own configurable retention period.
- Register and transaction data: permanently, insofar as they serve to document confirmed events; legitimate interest in record keeping.
- Investor profile: until withdrawal of consent or the end of membership.
- Usage data (listing views): 12 months.
- Log data: as determined by the hosting provider, typically a few weeks.
Cookies and local storage
We use no third-party advertising or tracking technologies and embed no external analytics services.
Local storage in the browser is technically required for login: the authentication system stores session attributes (access and refresh tokens) in the browser's local storage. In addition, the selected language is stored. This storage is strictly necessary to provide the service you have expressly requested; consent is not required for it under the ePrivacy Directive.
Automated decisions
Identity verification is carried out in a technically automated manner. However, the result does not automatically lead to approval or rejection: admission to the member circle is always decided by a natural person after individual review. An automated decision within the meaning of Art. 22(1) GDPR therefore does not take place. No profiling for advertising purposes is carried out.
Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future.
To exercise your rights, a message to team.equex@burdorfconsulting.com is sufficient. Independently of this, you have the right to lodge a complaint with a supervisory authority, in particular the Office of the Commissioner for Personal Data Protection in Cyprus or the authority of your habitual residence.
Please note: register entries that have already been confirmed by both sides serve as evidence towards all parties involved. A request for erasure may be limited in this respect; we examine each case individually and pseudonymise where complete erasure is not possible.
Data security
Transmission is encrypted (TLS). Access to data is restricted at database level through row-based access rules: members can read only their own data; administrative rights are limited to named accounts. System keys for privileged operations are held exclusively server-side. Incoming notifications from the verification provider are transmitted with cryptographic signatures and verified before processing.
Last updated: July 2026