Privacy

Privacy Policy

How we process personal data in the closed member area, whom we share it with and what rights you have.

Controller and contact

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

ControllerBurdorf Consulting Ltd., Pano Arodes, Paphos, Cyprus
Emailteam.equex@burdorfconsulting.com
Data protection officerBased on our current assessment, no data protection officer is required to be appointed. Please direct enquiries to the email address above.
Supervisory authorityOffice of the Commissioner for Personal Data Protection, Nicosia, Cyprus

What data we process

We process only data required to operate the closed marketplace:

CategoryDataOrigin
Access requestName, email address, optional phone/WhatsApp number, reference or invitation code, professional background, languageEntered by the data subject
AccountEmail, password hash, time of email confirmation, Marketplace ID (pseudonym), display nameRegistration / system
StatusVerification, qualification and suspension status, roleAssigned by the controller
Identity verification (KYC)Verification status, verification session identifier and a summary of the result: name per ID document, date of birth, document type and number, issuing state, match and liveness scores, warningsVerification provider (see recipients)
Investor profileAnswers to the voluntary questionnaire (volume, ticket size, horizon, deal types, experience, risk capacity, focus, free-text fields)Entered by the data subject
Holdings and registerAssignment to listings, ownership quota, transactions and distributions with type, price per share, month, confirmation statusController, confirmation by the data subject
UsageViews of individual listings and detail pages with timestamp and account referenceSystem
TechnicalServer and access logs of the hosting provider, IP address, time, resource requested, browser identifierSystem / hosting provider

ID documents are not stored on our systems. Images and videos from identity verification remain with the verification provider; we receive only the result and the summary described above.

Purposes and legal bases

ProcessingPurposeLegal basis
Access request, account, loginInitiation and performance of the usage relationshipArt. 6(1)(b) GDPR
Identity verificationEnsuring that only identified persons receive access to confidential company information; fraud preventionArt. 6(1)(b) and (f) GDPR
Investor profileAssessment of suitability and targeted outreachArt. 6(1)(a) and (b) GDPR
Register and confirmationsDocumentation of bilaterally confirmed transactions, record keepingArt. 6(1)(b) and (f) GDPR
Usage tracking (listing views)Understanding interest, operating and improving the serviceArt. 6(1)(f) GDPR
Notifications (email)Status messages regarding account, confirmations and new listingsArt. 6(1)(b) or (a) GDPR
Logs, securityOperational security, abuse preventionArt. 6(1)(f) GDPR

Legitimate interests are the secure operation of a closed circle, the protection of confidential issuer information and the traceability of documented transactions.

Recipients and processors

We use carefully selected service providers. Where required, data processing agreements pursuant to Art. 28 GDPR are in place with them.

ServicePurposePlace of processing
Supabase (database, authentication, server functions)Storage of account, profile, register and status dataEU (Ireland region)(sub-processor: Amazon Web Services)
Netlify (hosting, delivery of the website)Serving the pages, server and access logsUSA / global CDN
Didit (identity verification)Verification of ID document, liveness and face match; transmission of the resultEU (Spain)
Formspree (form submission)Forwarding of access requests and questionnaire answers to our internal systemsUSA
Airtable (internal CRM)Management of requests and investor profilesUSA
Telegram (internal notification)Alerting the team on new requests and verification resultsEU / third countries
Google Workspace (email delivery)Sending confirmation and system emailsEU/USA
Google Fonts, jsDelivr, Cloudfront (delivery of fonts, code libraries and images)Rendering of the pagesworldwide

Transfers to third countries

Where service providers process data outside the European Economic Area (in particular in the United States), this takes place on the basis of standard contractual clauses pursuant to Art. 46(2)(c) GDPR, a certification under the EU-US Data Privacy Framework, or another permissible basis.

Retention periods

Cookies and local storage

We use no third-party advertising or tracking technologies and embed no external analytics services.

Local storage in the browser is technically required for login: the authentication system stores session attributes (access and refresh tokens) in the browser's local storage. In addition, the selected language is stored. This storage is strictly necessary to provide the service you have expressly requested; consent is not required for it under the ePrivacy Directive.

Automated decisions

Identity verification is carried out in a technically automated manner. However, the result does not automatically lead to approval or rejection: admission to the member circle is always decided by a natural person after individual review. An automated decision within the meaning of Art. 22(1) GDPR therefore does not take place. No profiling for advertising purposes is carried out.

Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21 GDPR). You may withdraw any consent you have given at any time with effect for the future.

To exercise your rights, a message to team.equex@burdorfconsulting.com is sufficient. Independently of this, you have the right to lodge a complaint with a supervisory authority, in particular the Office of the Commissioner for Personal Data Protection in Cyprus or the authority of your habitual residence.

Please note: register entries that have already been confirmed by both sides serve as evidence towards all parties involved. A request for erasure may be limited in this respect; we examine each case individually and pseudonymise where complete erasure is not possible.

Data security

Transmission is encrypted (TLS). Access to data is restricted at database level through row-based access rules: members can read only their own data; administrative rights are limited to named accounts. System keys for privileged operations are held exclusively server-side. Incoming notifications from the verification provider are transmitted with cryptographic signatures and verified before processing.

Last updated: July 2026