1 (1)
Home
Privacy statement

PRIVACY STATEMENT

Version: 23 June 2026

  1. GENERAL INFORMATION
  2. NEWSLETTER AND DIRECT MARKETING COMMUNICATIONS
  3. USE OF THE WEBSITE
  4. USE OF THE APP
  5. CHANGES TO THIS PRIVACY STATEMENT
  6. QUESTIONS AND COMMENTS

This Privacy Statement (“Statement”) explains how Marktlink Capital (“we”, “us” and “our”) collects, uses, shares and protects personal data.

This Statement applies to:

  • Visitors of our website (https://www.marktlinkcapital.com/nl/),
  • Users of our investor platform
  • Users of our app
  • Clients/investors and business partners
  • Job applicants and event participants

We are committed to processing personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), its implementation in national law (Uitvoeringswet Algemene verordening gegevensbescherming (“UAVG”)), its amendments and other applicable data protection laws.

Personal data is any information relating to an identified or identifiable natural person, such as their name or IP address.

By using any part of our services, visiting our website or app and/or applying for a job application through our website, you acknowledge that your information will be collected, used, and disclosed as outlined in this Privacy Statement.

    1. Controller Information
    2. Purposes of Processing and Legal Bases
    3. Data Sharing
    4. Transfer of personal data to third parties
    5. Data Processing outside the EEA
    6. Data Storage (Location)
    7. Data Retention (Storage duration)
    8. Data Subjects Rights
    9. How to Exercise your Rights
    10. Obligation to provide data
    11. No automatic decision making

The controller of personal data within the meaning of Art. 4(7) GDPR is Marktlink Capital Management Coöperatief U.A., Trompenburgstraat 2 C, 1079TX Amsterdam, the Netherlands.

If you have any questions related to this Privacy Statement, please reach out at: privacy@marktlinkcapital.com

 

We only process personal data if this permitted by one of the following legal bases for data processing:

  • Art. 6(1)(a) GDPR serves as our legal basis for processing operations for which you have explicitly agreed to such processing (for example, newsletters, non-essential cookies, and consent about retaining data from job applications beyond the standard period).
  • Art. 6(1)(b) GDPR is the legal basis when the processing of your personal data is necessary for the performance of a contract (for example, investor onboarding or providing access to the investor platform). This legal basis also applies to processing that is necessary for pre-contractual measures, such as in cases of inquiries about our products.
  • Art. 6(1)(c) GDPR applies when the processing of personal data is required by law. These cases may include, not exhaustively, for example, obligations under the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act ("Wwft"), tax law and/or financial regulatory requirements we are subject to. Most of the personal data we process in this context is provided directly by you. Where necessary, however, we may supplement this with information obtained from external sources such as public company registers, trade registries and specialized screening providers. This may include identification data, beneficial ownership information, PEP status and sanctions screening results of natural persons connected to our clients, including directors, shareholders and beneficial owners.
  • Art. 6(1)(f) GDPR serves as the legal basis when we can rely on legitimate interests to process personal data (for example, cookies that are strictly necessary for the technical operation of our website or inquiries submitted via our contact form).

Within Marktlink Capital, access to personal data is limited to employees and departments that need it to fulfil our contractual and legal obligations or to perform operational tasks. This ensures that data are shared strictly on a need-to-know basis. All external sharing is carried out in accordance with section 1.4 below.

We may share data with trusted service providers, who process data on our behalf under Data Protection Agreements, in accordance with Art. 28 GDPR. These providers acting as processors are bound by our instructions, are contractually required to implement appropriate security measures, and are subject to periodic review by us. We limit any disclosure of personal data to what is strictly necessary and always take into account the relevant data protection requirements.

In addition, we may share personal data with public authorities, regulators, professional advisors, or other third parties, acting as independent controllers, where this is necessary to perform a contract (Art. 6(1)(b) GDPR), to comply with a legal obligation (Art. 6(1)(c) GDPR), or where we have a legitimate interest in doing so (Art. 6(1)(f) GDPR). Before relying on legitimate interest, we ensure that your rights and freedoms are not overridden.

Finally, we will only transfer your personal data to third parties in certain cases if you have given your express consent to do so in accordance with Art. 6 (1)(a) GDPR. You can withdraw your consent at any time by contacting us at the email address mentioned in this Statement.

We ensure that all data sharing is limited to what is necessary and carried out under appropriate safeguards in compliance with applicable data protection laws. In case more information is needed, you can contact us at the email address mentioned in this Privacy Statement.

In principle, we are not transferring personal data to service providers or partners (including the administrator of our funds and their affiliates) located outside the European Union (EU) or the European Economic Area (EEA). However, in cases where this may happen, we ensure that such transfers are carried out in accordance with applicable data protection laws (Art. 44 – 50 GDPR) and that an adequate level of protection is guaranteed at all times.

Specifically, for service providers or other third parties outside the EEA, the security of the data during the transfer is guaranteed by adequacy decisions of the EU Commission, insofar as they exist and apply (e.g. for Great Britain, Canada and Israel) (Art. 45(3) GDPR).

In the case of data transfer to service providers in the USA, the legal basis for the data transfer is an adequacy decision of the EU Commission if the service provider has also certified itself under the EU-US Data Privacy Framework.

In all other cases, transfers are carried out on the basis of Standard Contractual Clauses adopted by the European Commission pursuant to Art. 46(2)(c) GDPR, which form part of our agreements with the relevant third parties and ensure an adequate level of protection for the data transferred. For further information on the safeguards applicable to any specific transfer and to obtain a copy thereof, you may contact us at the email address mentioned in this Privacy Statement.

We generally only store personal data on our servers within the EU/EEA.

Where we engage external service providers to process data on our behalf, these processors may only store or use the data for as long as necessary to perform their contractual duties and must delete or return the data once their assignment ends, unless a longer retention period is required by law.

Any disclosures or transfers outside the EU/EEA will take place only as described in this Statement and in compliance with the applicable data protection requirements.

Unless otherwise specified in this Privacy Statement, we retain personal data only for as long as necessary to achieve the purposes for which they are processed. The applicable retention period depends on the legal basis relied upon for the processing, as further detailed below.

Personal data processed on the basis of your consent (Art. 6(1)(a) GDPR) are retained for as long as the consent remains valid. You may withdraw your consent at any time, in which case the personal data will be deleted unless their retention is required for another legal purpose (e.g. compliance with statutory obligations or the establishment, exercise or defense of legal claims).

Personal data processed for the performance of a contract or for taking pre-contractual steps at your request (Art. 6(1)(b) GDPR) are retained for the duration of the contractual relationship. After termination of the contract, such data may be retained for the applicable statutory retention or limitation periods (e.g. for accounting purposes or to handle potential disputes).

Where the processing of personal data is required to comply with a legal obligation (Art. 6(1)(c) GDPR), the data are retained for the period prescribed by the relevant legislation. This may include, inter alia, obligations under tax law, accounting law, financial regulatory requirements and the Dutch Wwft (Dutch Anti-Money Laundering and Anti-Terrorist Financing Act).

Where personal data are processed on the basis of our legitimate interests (Art. 6(1)(f) GDPR), the data are retained for as long as necessary to pursue those legitimate interests, subject to a periodic assessment of the continued necessity of the processing and your right to object.

If, after expiry of the applicable retention period, deletion is not possible because the personal data must be retained for other legitimate or legal reasons, the processing of such data will be restricted. In such cases, the data will be securely blocked and not processed for any other purposes than those for which retention is required.

You can assert your rights as a data subject with regard to your processed personal data against us at any time using the contact details provided in this Privacy Statement. As a data subject, you have the following rights, provided that the legal requirements are met:

- Right of access (Art. 15 GDPR): request information about your personal data processed by us;
- Right to correction (Art. 16 GDPR): request the immediate correction of incorrect personal data stored by us or the completion of your personal data;
- Right to deletion (“right to be forgotten”) (Art. 17 GDPR): request the erasure of your personal data stored by us, unless processing is necessary for reasons arising from the law;
- Right to restrict the processing (Art. 18 GDPR): request the restriction of the processing of your personal data, insofar as the legal requirements are met;
- Right to data portability (Art. 20 GDPR): receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller;
- Right to object to the processing (Art. 21 GDPR): object to the processing of your personal data if there are reasons for doing so that arise from your particular situation. You can also object to the processing of your personal data for direct marketing purposes, including profiling to the extent that it is related to such direct marketing, in which case the personal data will no longer be processed for these purposes;
- Right to revoke consent at any time (Art. 7(3) GDPR). As a result, we are no longer allowed to continue the data processing based on this consent in the future;
- Right to lodge a complaint (Art. 77 GDPR): file a complaint with the competent supervisory authority. The competent authority in the Netherlands is the Autoriteit Persoonsgegevens ("Dutch Data Protection Authority"). Further information and contact details are available at https://www.autoriteitpersoonsgegevens.nl/en

To exercise your rights, please contact us using the contact details provided in this Privacy Statement. We will respond to your request without undue delay and within the statutorily prescribed time limits and in accordance with the applicable data protection laws, in particular Art. 12 GDPR.

In the context of establishing and maintaining a business- or investment relationship, we are legally required to collect certain personal data. We may only be able to provide certain services to a limited extent or not at all if you do not provide the necessary data.

In principle, we do not use a fully automated decision-making process in accordance with Art. 22 GDPR when establishing or managing business or other relationships. Should we apply such procedures in individual cases, we will inform you separately in advance, where required by law.

We collect:

  • Name and email address
  • Subscription preferences and consent record

We reserve the right to occasionally contact investors who have already used our services, by e-mail to inform them about new investment opportunities. This processing is based on our legitimate interest in maintaining customer relationships and promoting our own services (Art. 6(1)(f) GDPR, recital 47). Clients maintain the right to object to receiving this type of communication at any time, free of charge, by using the unsubscribe link included in each e-mail or by contacting us at privacy@marktlinkcapital.com. This right is unconditional.

For persons who have downloaded our teaser or expressed an interest without entering into a business relationship with us, we rely on consent (Art. 6(1)(a) GDPR). Recipients may withdraw that consent at any time, free of charge, by using the unsubscribe link included in each e-mail or by contacting us at the email address mentioned in this Privacy Statement. Withdrawal does not affect the lawfulness of processing carried out prior to it.

Based on the consent of the recipients (Art. 6(1)(a) GDPR), we also measure the opening and click-through rate of our newsletters to understand what is relevant for our audience. This consent can be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal.

We retain personal data used for direct marketing purposes for as long as the relevant business relationship subsists and for a reasonable period thereafter, taking into account the nature of our relationship with you and the lifecycle of our investment products, or until you object or unsubscribe, whichever is earlier. For persons who have not entered into a business relationship with us, we retain data for a shorter period, reflecting the more limited nature of that relationship. For further information on the applicable retention period in your specific case, you may contact us at the email address mentioned in this Statement.

We send newsletters with HubSpot of the provider HubSpot Netherlands B.V., Raamplein 1, 1016XK Amsterdam. The provider processes content, usage, meta/communication data and contact data in the EU. Further information is available in the provider's privacy policy at https://legal.hubspot.com/privacy-policy

3.1. Personal data we collect

During the use of our website, we collect the personal data that the browser transmits to our server in order to ensure the stability and security of our website. The legal basis for that collection is Art. 6(1)(f) GDPR.

This data is:

    • IP address and browser type/version
    • Operating system and its interface
    • Date and time of access
    • Time zone difference to Greenwich Mean Time (GMT)
    • Access status/HTTP status code
    • Amount of data transferred in each case
    • Language and version of the browser software

3.2. Web Hosting

Our website is hosted by Hubspot. The provider is HubSpot Netherlands B.V., Raamplein 1, 1016XK Amsterdam. In doing so, the provider processes the personal data transmitted via the website, e.g. content, usage, meta/communication data, or contact data, in the EU. Further information is available in the provider's privacy policy at https://legal.hubspot.com/privacy-policy

    1. Log-in area

We maintain a log-in area for our clients, operated on our behalf by Eleven. To access this area, users enter their email address and password directly into the provider’s environment. These credentials are processed and stored solely by the provider for authentication purposes, in the EU as per our Data Processing Agreement with Eleven. We do not have access to or store these login details. The processing is carried out for the purpose of providing clients with secure access to their account and related services. The legal basis for this processing is the performance of a contract (Article 6(1)(b) GDPR).

The provider is HFIN One, LLC (Eleven), 33 Nasau Ave, Brooklyn, NY 11222, USA. Further information is available in the provider’s privacy policy at https://platformeleven.io/privacy

3.4. Contact Form

Through the contact form we may further collect the data requested there, such as name, email address and the content of the message with any other details provided voluntarily. The legal basis for the processing of this data is our legitimate interest in answering inquiries directed to us and therefore the legal basis for the processing is Art. 6(1)(f) GDPR.

For this purpose we use Hubspot. The provider is HubSpot Netherlands B.V., Raamplein 1, 1016XK Amsterdam. In doing so, the provider processes the personal data transmitted via the website, e.g. content, usage, meta/communication data or contact data, in the EU. Further information is available in the provider's privacy policy at https://legal.hubspot.com/privacy-policy

3.5. Vacancies

We publish vacant positions on our website, on pages linked to the website or on third-party websites.

The processing of personal data provided as part of a job application is carried out for the purpose of implementing the recruitment process. Where the processing of this information is necessary to decide whether to enter into an employment relationship, the legal basis is Art. 88 GDPR. We indicate which information is essential for the application process. If applicants do not provide this data, we cannot process the application. Any additional information provided voluntarily is used with consent as legal basis (Art. 6(1)(a) GDPR).

We ask applicants to refrain from providing information on political opinions, religious beliefs and similarly sensitive data in their CV and cover letter. They are not required for an application. If applicants nevertheless provide such information, we cannot prevent their processing as part of the processing of the resume or cover letter. Their processing is then also based on the consent of the applicants (Art. 9(2)(a) GDPR).

Finally, we process the applicants' data for further application procedures if they have given us their consent to do so. In this case, the legal basis is Art. 6(1)(a) GDPR.

We pass on the applicants' data to the responsible employees in the HR department and to the employees otherwise involved in the application process. Under this context the following data is being processed: name, email address, CV and cover letter if sent.

For the recruitment process we share the data with Recruitee, LinkedIn and Marktlink Group. These third parties are processing the data in accordance with Art. 28 GDPR.

Recruitee B.V., Keizersgracht 313, 1016 EE Amsterdam The Netherlands. Further information at https://recruitee.com/privacy-policy

LinkedIn Ireland Unlimited Company, Wilton Place Dublin 2, Ireland. Further information at https://www.linkedin.com/legal/privacy-policy

Marktlink Fusies & Overnames B.V., Wismarstraat 1, 7418 BN Deventer The Netherlands. Further information at https://www.marktlink.com/nl/privacyverklaring

If we enter into an employment relationship with the applicant following the application process, this data will become part of their personnel record and will be deleted only after the employment relationship has ended. Otherwise, we delete the data no later than four (4) weeks after rejecting an applicant.

If applicants have given us their consent to use their data for further application procedures as well, we will not delete their data until one year after the end of the application process.

3.6. Cookies and Similar Technologies

Our website uses cookies. Cookies are small text files that are stored in the web browser on the end device of a site visitor. Cookies help to make the use of the website more user-friendly, effective, and secure.

3.6.1. Technically Necessary Cookies

Some cookies are essential for the proper operation of our website and its core functions (hereinafter "Technically Necessary Cookies"). The use of such cookies and the related data processing are based on Art. 6(1)(f) GDPR. We have a legitimate interest in providing customers and other site visitors with a functional website.

3.6.2. Analytics and Marketing Cookies

We also use cookies that are not strictly necessary but help us improve our website and understand how it is used. These include analytics cookies (for visitor statistics) and, where applicable, marketing cookies (for displaying relevant advertisements or tracking campaign effectiveness). These cookies are only used with the data subject’s prior consent pursuant to Art. 6(1)(a) GDPR. The consent can be given, withdrawn, and managed at any time through the cookie banner displayed on our website or via the browser settings.

Further and detailed information for the Cookies used on our Website can be found in our Cookies Policy.

    1. Downloading the app
    2. App Hosting
    3. Access to functions or data
    4. Personal data we collect
    5. Identity and Account
      1. Account Creation
      2. Verification/ Identification
    6. App Analytics and Tracking Technologies
      1. Technically necessary technologies
      2. Optional Analytics

Our app is ready for download at Apple’s App Store and Google’s Play Store (hereinafter “Stores”). When users download the app, certain data is transmitted to the store and processed by the respective provider, i.e. in particular username, email address and customer number of the account, time of download, and the individual device identification number. We have no influence over this data collection and are not responsible for the processing activities of these Stores.

For more information regarding how these providers handle your data, please refer to their respective privacy policies:

Apple Inc., 1 Infinite Loop, Cupertino, CA 95014, USA. More information is available in the provider's privacy policy https://www.apple.com/legal/privacy/en-ww/

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4 Ireland. More information is available in the provider’s privacy policy at https://policies.google.com/privacy

We process the data only insofar as it is necessary to download the mobile app to the user’s mobile device.

The back end of the app is provided by XLINQ. The provider is XLINQ B.V., Johan Huizingalaan 763a, 1066 VH, Amsterdam, the Netherlands. In doing so, the provider processes transmitted through the app, such as content, usage, technical or contact data, within the EU. Further information is available in the provider's privacy policy at https://www.xlinq.io/privacy-policy

The app requests the user’s access to functions of the end-device or to data of the device in order to be able to execute functions of the app. By allowing access, the user gives consent to the associated data processing, so that the legal basis is Art. 6(1)(a) GDPR. Users can revoke their consent at any time by terminating access in the settings of their end-device. Withdrawal of consent does not affect the lawfulness of processing carried out until the withdrawal.

The data processed or access functions used in this respect are for example camera or existing photos.

During the use of our app, we collect the following information of app-users:

  • Device information (model, operating system version, app version)
  • Technical data such as crash logs, diagnostics and app performance data
  • Analytics and usage data, for example how often features are used and session duration. We use these analytics to understand how our app is used, improve its functionality, and ensure its technical abilities. Where analytics involve assigning a unique identifier or tracking user behaviour across sessions, we do so only with the data subject’s consent, in accordance with Art. 6(1)(a) GDPR and Art. 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet).

 

Users can open a user account in the app. We process personal data required to create and manage the account, such as name and email address in order to provide you with the services and functionalities of the app. Furthermore, the time of registration and date and, where applicable, the consent of the data subject, are also stored. The legal basis for this processing is Art. 6(1)(b) GDPR. If a user registers but does not become an investor, we do not retain the collected account and communication data (email address) longer than necessary, after which they are deleted. If the user becomes an investor, the data are retained for the duration of the business relationship and for the statutory retention period thereafter in accordance with the applicable legislation.

In addition, we process certain identification and verification data in order to comply with our legal obligations under the applicable AML/CTF legislation. For this purpose, we may collect data such as country of residence, date and place of birth, and the citizen service number (BSN). The legal basis for this processing is Art. 6(1)(c) GDPR, in combination with Art. 46 Dutch GDPR Implementation Act (UAVG).

All data will be deleted when the purpose for which it was collected no longer applies, and there is no obligation to retain it. Deletion can also take place upon request by the user, unless the exceptions of Art. 17 (3) GDPR apply. In such cases, the data will be blocked. Even after termination of the contractual relationship, there may be a need to store your personal data in order to comply with contractual or legal obligations.

We do not use app data for advertising.

In order to enable secure access to the app all users are required to verify their identity before accessing the app. For this purpose, users must upload a valid identity document, such as a passport or driver’s license, which is used solely for the purpose of confirming their identity. To ensure the authenticity of the identification and prevent fraud, the process includes a one-time biometric facial scan carried out at the time of account creation. This involves a comparison between the facial geometry extracted from your face scan and the photo on your identity document. All biometric data is fully encrypted both in transit and at rest. Biometric data is used solely for the duration of the identity verification match, and is not stored permanently. The verification of identity documents is carried out through Ubiqu Access B.V., which processes these data on our behalf under the responsibility of our app provider, XLINQ B.V. The legal basis for this processing is Art. 6(1)(c) GDPR. For the processing of your biometric data we rely on Art. 9(2)(a) GDPR. If you do not wish to consent to biometric processing, and you wish to verify your identity through another method, please contact us at privacy@marktlinkcapital.com before completing the verification step.

The provider is Ubiqu Access B.V., Kerstant van den Bergelaan 13b, 3054 EM in Rotterdam, the Netherlands. In doing so, the provider processes the personal data transmitted during the verification process, such as identity document details and photographs, within the EU. Further information is available on the provider’s privacy policy at https://ubiqu.com/privacy-policy/

Once the account has been verified and activated, users may choose to access the app by using biometric identification methods provided by their device, such as Face ID or fingerprint recognition, or by setting a personal PIN code. Biometric data are processed exclusively on the user’s device and remain under the control of the device provider. We do not have access to or store any biometric data. The use of biometric identification is voluntary and takes place on the basis of the user’s explicit consent in accordance with Art. 9(2)(a) GDPR. Users may withdraw this consent at any time by disabling biometric access in their device settings.

The alternative PIN is processed solely for authentication and access control purposes on the basis of Art. 6(1)(b) GDPR and is deleted when the user account is removed, or the App is uninstalled.

Our mobile application uses analytics technologies that function similarly to cookies to help us understand usage patterns and improve stability and performance. These technologies may collect technical information such as device type, operating system, app version, screen interactions, and crash data.

We use such analytics exclusively for internal performance measurement, not for advertising, profiling, or tracking across other apps or websites.

Where the data is necessary to ensure the technical operation, security of the app and enhanced user experience, the processing is based on our legitimate interest under Art. 6(1)(f) GDPR and no consent is required.

Where optional analytics features are used, we request your consent in accordance with Art. 6(1)(a) GDPR and Art. 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet), which can be withdrawn at any time via the app settings or by contacting us.

We use the following analytics service providers:

XLINQ B.V., Johan Huizingalaan 763a, 1066 VH, Amsterdam, the Netherlands. In doing so, the provider processes transmitted through the app, such as content, usage, technical or contact data, within the EU. Further information is available in the provider's privacy policy at https://www.xlinq.io/privacy-policy

Google Analytics for optional analytics. The provider is Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the USA. The transfer of personal data is based on the adequacy decision of the EU Commission under the EU-US Data Privacy Framework, under which Google LLC is certified. Further information is available in the provider’s privacy policy at https://policies.google.com/privacy?hl=en-US

We reserve the right to update this Statement periodically. Updates will be posted on this page with a revised “last updated” date. For material changes, we will notify you directly where feasible.

If you have any questions or comments regarding this Privacy Statement feel free to contact us at privacy@marktlinkcapital.com