Last updated: October 2026 | Grand Duchy of Luxembourg
1. Who We Are
This privacy notice (the "Privacy Notice") is issued by Fundequate Sàrl, a Luxembourg société à responsabilité limitée registered with the Luxembourg Trade and Companies Register under number B250530, with its registered office at 2, rue Siggy vu Lëtzebuerg, L-1933 Luxembourg ("Fundequate" or "we").
It applies where Fundequate acts as controller of the personal data of users of the website https://fundequate.com and of the Fundequate platform (the "Platform"). Where we process investor data on behalf of a fund, its general partner or its AIFM, we act as processor under Article 28 GDPR and that fund's privacy notice applies.
Contact: privacy@fundequate.com
2. Applicable Law
We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and the Luxembourg Law of 1 August 2018 on the organisation of the National Data Protection Commission and the general data protection framework. We may update this Privacy Notice by posting a new version on the website; where a change requires renewed consent, we will ask for it.
3. Why We Process Personal Data (Legal Basis)
- Creating and managing your account and providing the Platform services (contract, Art. 6(1)(b) GDPR).
- Investor onboarding, subscriptions, capital calls, distributions and reporting on behalf of funds (contract; legal obligation of the fund).
- Identity verification, sanctions and PEP screening under the Luxembourg Law of 12 November 2004 on the fight against money laundering and terrorist financing (legal obligation, Art. 6(1)(c) GDPR).
- FATCA and CRS due diligence under the Luxembourg Laws of 24 July 2015 and 18 December 2015 (legal obligation).
- Keeping accounting records under Article 16 of the Luxembourg Commercial Code (legal obligation).
- Service emails about your account, changes to the services or to our policies (contract).
- Customer support and management of business relationships (contract; legitimate interest, Art. 6(1)(f) GDPR).
- Newsletters and marketing, where you have agreed (consent, Art. 6(1)(a) GDPR, withdrawable at any time).
- Website analytics and campaign measurement, where you have agreed (consent).
- Platform security and the establishment or defence of legal claims (legitimate interest).
4. What Personal Data We Collect
- Account data: name, email address, phone number, nationality, date of birth, address.
- KYC data: identity document, proof of address, source of funds and wealth, photograph, sanctions and PEP screening results.
- KYB data for investments made through a company: name, legal form, registration number, articles, accounts and ultimate beneficial owners.
- Tax data: tax residence, tax identification number, FATCA/CRS self-certification.
- Banking and transaction data: bank account details, commitments, and payments received and made.
- Investment data: holdings, capital account, investor classification, votes and documents signed.
- Communication data: support chat messages and attachments, correspondence and relationship notes.
- Usage data: IP address, browser, device, pages visited and session data.
You must provide the data required by law, in particular for AML/KYC and FATCA/CRS purposes; without it, an account or subscription cannot be completed.
5. Identification And Account Security
Investor identity is verified remotely, using images of you and of your identity document captured with your device's camera. Access to the Platform is protected by multi-factor authentication; passwords are never stored in readable form. We do not take decisions based solely on automated processing within the meaning of Article 22 GDPR; screening alerts are always reviewed by a person.
6. Retention
Unless the law requires a longer period:
- Account and investment data: for the duration of the relationship and five (5) years after it ends.
- AML/KYC records: five (5) years after the end of the business relationship, under the Law of 12 November 2004.
- Accounting records: ten (10) years, under Article 16 of the Commercial Code.
- Support and contact requests without an account: one (1) year from the last contact.
- Server logs: thirty (30) days.
7. Security
We protect personal data against loss, misuse, unauthorised access, disclosure and alteration through access control, multi-factor authentication, encryption, backups and audit logs. Our service providers are bound to the same standard.
8. Recipients And Transfers
We share personal data only as needed with:
- Our hosting, IT and identity verification providers, and the following online service providers:
- Microsoft Clarity (Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA) for heatmaps, session recordings and usage statistics, with form fields and sensitive data masked; only with your consent, Art. 6(1)(a) GDPR.
- LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company, Wilton Plaza, Wilton Place, Dublin 2, Ireland) for campaign measurement and retargeting; data is anonymised within 7 days and deleted within 90 days; joint controllership under Art. 26 GDPR (https://legal.linkedin.com/pages-joint-controller-addendum); only with your consent.
- LiveChat (LiveChat, Inc., Boston, USA; EU entity Text S.A., ul. Zwycięska 47, 53-033 Wrocław, Poland) for our support chat, processing the details and messages you share in it; Art. 6(1)(b) and (f) GDPR.
- Pipedrive (Pipedrive OÜ, Mustamäe tee 3a, 10615 Tallinn, Estonia) as our CRM for client and business contacts, under a data processing agreement pursuant to Art. 28 GDPR; Art. 6(1)(b) and (f) GDPR.
- The fund in which you invest, its general partner and its AIFM.
- Fund service providers: depositary, auditor, notary, banks.
- Authorities where the law requires it: the CSSF, the Administration des contributions directes, the Luxembourg Business Registers and the Cellule de renseignement financier.
- A buyer or successor in case of merger, acquisition or reorganisation, with notice to you.
We do not sell personal data. Where data leaves the European Economic Area, we rely on an adequacy decision, including the EU-U.S. Data Privacy Framework for certified recipients, or on EU Standard Contractual Clauses. The list of providers outside the EEA is available at privacy@fundequate.com.
Fundequate maintains a profile on LinkedIn (LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland — linkedin.com/legal/privacy-policy). When you interact with it, LinkedIn processes your data as its own controller, possibly outside the EEA; we receive only aggregated, anonymised statistics. Our processing relies on consent (Art. 6(1)(a) GDPR) where applicable, on contract (Art. 6(1)(b) GDPR) for contract-related enquiries, and on our legitimate interest in corporate communication (Art. 6(1)(f) GDPR).
9. Cookies
We use strictly necessary cookies for the website and Platform to work, including session cookies for the support chat. Analytics and marketing cookies (Microsoft Clarity, LinkedIn Insight Tag) are set only with your consent through the cookie banner, under Article 4(3)(e) of the Luxembourg Law of 30 May 2005 on electronic communications, and expire no later than thirteen (13) months after being set. You can withdraw consent or delete cookies at any time.
10. Your Rights
You have the right to access, rectify, erase, restrict, object to and port your personal data, and to withdraw consent at any time (Articles 15 to 21 GDPR). Write to privacy@fundequate.com. Data we must keep by law is retained after account deletion until the legal period expires. Where we act as processor for a fund, we forward your request to that fund.
You may lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD), 15, Boulevard du Jazz, L-4370 Belvaux — www.cnpd.lu.