Legal
Privacy Policy
How MPA Capital collects, uses, shares, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679.
1. Who Are We?
This privacy policy ("Privacy Policy") describes how the Fund (hereafter "We", "us" or the "Fund"), acting as controller, may collect, use, share, and otherwise process personal data, whether online or offline and when interacting with data subjects.
We value your right to privacy and make every effort to protect your personal data in accordance with applicable data protection law, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and national implementing legislation. In this Privacy Policy, we explain what personal data we collect from you, for what purposes we will process this data, on what legal basis we base this processing, to whom your personal data may be transferred, how long we keep your data, how we protect your data and what rights you have in relation to the processing of your personal data.
All concepts not explicitly defined in this Privacy Policy have the same meaning as in the GDPR.
2. From Whom Do We Collect Data?
The Fund may process the personal data of the following data subjects:
- Visitors and users to the website https://www.mpa.capital/ ("Visitors"), as well as visitors to the Fund's offices and premises.
- Representatives in portfolio companies in which the Fund has made or is considering making an investment ("Portfolio Companies Representatives").
- Suppliers of goods or services, investment bankers, consultants, lawyers, accountants, and other third-party providers interacting with the Fund, and their representatives ("Suppliers and Service Providers").
- Business partners interacting with the Fund in relation to their business activities, and their representatives ("Partners").
- Representatives of investors and former investors who have made or are considering making an investment in the Fund ("Investors") / (candidate) shareholders of the Fund ("(Candidate) Shareholders").
- Applicants that apply for a position with the Fund, either online or offline ("Applicants").
- Any other individuals who interact with the Fund.
3. Which Personal Data Do We Process?
The Fund processes the following types of personal data about data subjects when they interact with the Fund, either online or offline, including:
- Individual Basic Data (such as name, birth date, address, etc.)
- Business Data (such as name of organization, registered office, department and job title)
- Contractual Data (such as date of agreement, type of commercial relationship, etc.)
- Investments and Financial Data (such as transactions effected, information on capital calls and distribution notices, bank account numbers, account balances, investment information, etc.)
- Compliance Data: including but not limited to government identifiers, passport or other information regarding identification, individual beneficial ownership data and other "Know Your Customer" due diligence data.
- Partner Data: information that the Fund collects, generates and receives from or about (potential) Partners or their representatives, including income, assets, other financial information, bank details, investment history, tax residency and tax identification information.
- Investee Data: information that the Fund collects, generates or receives from or about (i) (potential) portfolio companies or (ii) Portfolio Companies Representatives.
- Supplier Data: information such as history of purchase, invoicing details, payments history, evaluation and feedback.
- (Candidate) Investor or Shareholder Data: information including name, contact details, place and date of birth, national registry number, bank account details.
- Applicant Data: information provided by Applicants in connection with employment opportunities, including professional qualifications, experience, skills, preferences, motivation, and interests.
Where a Visitor uses the Fund's Website, the Fund may collect information about your visit using cookies and similar technologies as described in the Fund's Cookie Policy. When legally required, your prior consent will be collected through an appropriate cookie consent form or banner on the Website.
4. For Which Purposes Do We Process Your Personal Data?
We may use the aforementioned personal data for the following purposes:
- (1) Managing commercial and contractual relationships with data subjects, for payment and invoicing and/or to answer questions about the Fund's activities.
- (2) Managing business operations, administering investments, issuing and redeeming shares, carrying out the Fund's business activities and administering Portfolio Companies/Supplier/Partner/(Candidate) Shareholder relationships.
- (3) Providing data subjects with information about the Fund's business activities, sharing reports and other relevant information by email or other communication means.
- (4) Addressing compliance and legal obligations, such as checking identity in relation to know-your-client procedures (including anti-money laundering, counter-terrorist financing, politically-exposed-person checks and sanctions checks).
- (5) Considering individuals for employment and contractor opportunities and managing recruitment processes.
- (6) Ensuring safety and security at the Fund's premises.
- (7) Promoting and informing existing customers and subscribers about similar services through electronic communications, such as newsletters and events via email.
- (8) Promoting and informing legal entities through electronic communications directed at a non-personal email address (B2B communications).
- (9) Fulfilling other legitimate purposes disclosed to data subjects at the time they provide personal data or as otherwise permitted or required by applicable laws and regulations.
The Fund processes personal data on the following legal grounds: necessity for the performance of a contract (Art. 6.1.b GDPR); compliance with a legal obligation (Art. 6.1.c GDPR); legitimate interests pursued by the Fund or a third party (Art. 6.1.f GDPR); and, in specific circumstances, the data subject's freely given consent.
5. With Whom Do We Share Your Personal Data?
The Fund will only grant access to personal data on a need-to-know basis, limited to what is necessary to perform the function for which such access is granted.
For the purposes identified above, personal data may be shared with the following third parties:
- The Fund's trusted third-party service providers (acting as processors), such as IT and cloud services providers, accountants, statutory auditors, depositary banks, attorneys, fiduciaries and financial institutions.
- Certain third parties in the event of a merger, acquisition, sale of assets, joint venture, or any other transaction that results in a change in control or ownership of the Fund, if permitted by and done in accordance with applicable law.
When transferring personal data to third parties, we always ensure appropriate technical and organisational protection measures, including transfer agreements or processor agreements as necessary. For transfers outside the European Union, we ensure an adequate level of protection, including through Standard Contractual Clauses (SCC).
6. How Long Do We Store Your Personal Data?
We do not keep your personal data longer than necessary for the purposes for which it is collected and processed, unless shorter or longer retention periods apply under applicable law, including applicable statutes of limitation for invoicing, payment, accounting, tax and regulatory compliance, and the establishment, exercise or defense of legal claims.
The Fund may retain a data subject's personal data relating to a specific job application and selection process for a period of 5 years following the selection process.
7. How Do We Secure Your Personal Data?
We take appropriate technical and organisational measures to ensure a level of security appropriate to the specific risks we have identified. We protect your personal data against destruction, loss, alteration or unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. We restrict access to personal data about you to those employees who need to know that information for the abovementioned processing purposes.
Please remember that no data storage or data transmission is guaranteed to be 100% secure. While we strive to protect your personal data, the Fund cannot ensure or warrant the security of any information you transmit to us.
8. What Rights Do You Have as a Data Subject?
- Withdraw consent at any time where you have previously given consent to the processing of your personal data.
- Object to processing of your personal data where processing is carried out on the basis of a legitimate interest, including profiling. You also have an absolute right to object to processing for direct marketing purposes.
- Right to access: obtain confirmation as to whether or not we are processing your personal data, access to that data, and a copy thereof.
- Right to rectification: obtain a correction of your personal data if you notice we are processing incorrect or incomplete data.
- Right to erasure: obtain data erasure in certain specific cases.
- Right to restriction: have the processing of your personal data restricted in certain specific cases.
- Right to data portability: obtain your personal data in a structured, commonly used and machine-readable form.
You may exercise the above rights by sending an email to benoit@mpa.capital. The exercise of these rights is in principle free of charge. We always try to answer requests as quickly as possible and may first ask you for proof of identity.
You also have the right at any time to lodge a complaint with the Data Protection Authority at contact@apd-gba.be or by mail at:
Gegevensbeschermingsautoriteit
Drukpersstraat 35
1000 Brussels
For further information, please visit: www.gegevensbeschermingsautoriteit.be
9. References to Other Websites
Our Website may contain links to other sites that are not operated by us. If you click on a third-party link, you will be redirected to that third-party site. We strongly recommend that you review the Privacy Policy of each site you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services.
10. Changes to This Privacy Policy
From time to time it may be necessary to amend this Privacy Policy. When we post changes to the policy, we will change the "last updated" date at the top of the document. The most recent version of this Privacy Policy will be available on our website at all times.
11. Contact
If you have any questions or concerns regarding this Privacy Policy or our processing of your personal data, you may contact us at:
benoit@mpa.capital
Cantersteen 12, B-1000 Brussels