Privacy

1. Data controller

The data controller is:

factum ventures S.A.
33, rue Gabriel Lippmann
L-5364 Munsbach
Grand Duchy of Luxembourg

Registered with the Luxembourg Trade and Companies Register under number: RCS Luxembourg B 164098
VAT ID: LU 24997058

2. Personal data we process

We may process the following categories of personal data:

When you visit the website:

  • IP address

  • browser type and version

  • device information

  • operating system

  • date and time of access

  • pages visited

  • referrer URL

  • technical log data necessary for website security and operation

When you contact us:

  • name

  • email address

  • phone number, if provided

  • company or organisation, if provided

  • message content

  • any other information you voluntarily provide

We do not intentionally collect special categories of personal data through this website.

3. Purposes of processing

We process personal data for the following purposes:

  • operating and securing the website

  • responding to enquiries

  • communicating with potential clients, partners or other contacts

  • preparing or managing business relationships

  • improving the website and user experience

  • complying with legal obligations

  • protecting our legitimate interests, including IT security and legal defence

4. Legal basis

We process personal data under the following legal bases:

  • Consent, where you have given consent, for example for non-essential cookies or optional communications.

  • Contractual necessity, where processing is required to respond to your request or prepare a possible business relationship.

  • Legal obligation, where we are required to process or retain data under applicable law.

  • Legitimate interests, including website operation, IT security, communication with business contacts and protection of legal rights.

5. Contact form and email communication

If you contact us by email or through a contact form, we process the information you provide in order to respond to your request and manage the communication.

Please do not send confidential, sensitive or legally privileged information through the website unless we have expressly agreed to receive it.

6. Website hosting and technical service providers

This website may be hosted and technically operated by external service providers. These providers may process technical data such as IP addresses, log files and usage data on our behalf.

Where required, such providers act as processors under Article 28 GDPR and are bound by appropriate contractual obligations.

7. Squarespace

This website may be built and hosted using Squarespace. Squarespace may process technical and usage-related data necessary to provide hosting, security, analytics and website functionality.

For more information about Squarespace’s processing activities, please refer to Squarespace’s own privacy documentation.

8. Cookies and similar technologies

This website may use cookies or similar technologies.

Cookies may be used for:

  • essential website functionality

  • security

  • performance measurement

  • analytics

  • embedded third-party services, if any

Non-essential cookies are only used where legally permitted and, where required, based on your consent. You can usually disable cookies through your browser settings. However, some website functions may not work properly without essential cookies.

If we activate analytics, tracking, embedded videos, maps or marketing tools later, this Privacy Policy and the cookie notice should be updated accordingly.

9. Data sharing

We do not sell personal data.

We may share personal data with:

  • hosting and IT service providers

  • website service providers

  • professional advisers, such as lawyers, accountants or consultants

  • public authorities, courts or regulators where legally required

  • business partners where necessary to respond to your enquiry or manage a potential cooperation

Personal data is only shared where there is a valid legal basis and where appropriate safeguards are in place.

10. International transfers

Some service providers may process personal data outside the European Economic Area. Where this occurs, we rely on appropriate safeguards under GDPR, such as adequacy decisions, standard contractual clauses or other lawful transfer mechanisms.

11. Retention period

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy.

Contact enquiries are generally retained for as long as needed to respond to the enquiry and manage any resulting business relationship. Data may be retained longer where required by law or where necessary to establish, exercise or defend legal claims.

Technical log data is usually retained for a limited period unless longer retention is required for security, troubleshooting or legal reasons.

12. Your rights

Under GDPR, you may have the following rights:

  • right of access

  • right to rectification

  • right to erasure

  • right to restriction of processing

  • right to data portability

  • right to object

  • right to withdraw consent at any time, where processing is based on consent

  • right to lodge a complaint with a supervisory authority

You may exercise your rights by contacting us at:

[email address]

In Luxembourg, you also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données — CNPD.  

13. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. However, no internet-based service can be guaranteed to be completely secure.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the website, our processing activities or applicable law. The latest version published on this website applies.