Privacy Policy
Effective date: [DATE]
1. Who we are
Email: [PRIVACY EMAIL]
Postal address: [PRIVACY CONTACT ADDRESS]
Data Protection Officer, if appointed: [DPO CONTACT DETAILS / NOT APPLICABLE]
Baseload is a Luxembourg-based venture capital business focused on the nuclear energy supply chain.
This Privacy Policy (the “Policy”) explains how [FULL LEGAL NAME OF THE CONTROLLER], with its registered office at [REGISTERED ADDRESS] and registration number [REGISTRATION NUMBER, IF APPLICABLE] (“Baseload”, “we”, “us” or “our”), collects, uses, discloses and otherwise processes personal data.
Where another Baseload entity, fund, general partner, alternative investment fund manager, administrator or other regulated service provider acts as a controller for a particular processing activity, that entity may provide a separate privacy notice. In the event of a conflict, the more specific notice will apply to that processing activity.
For questions about this Policy or the use of personal data, or to exercise a data protection right, please contact us at:
Email: [PRIVACY EMAIL]
Postal address: [PRIVACY CONTACT ADDRESS]
Data Protection Officer, if appointed: [DPO CONTACT DETAILS / NOT APPLICABLE]
2. Scope of this Policy
the website at baseload.vc and its related pages (the “Website”);
enquiries and information submitted to us, including through the Website;
the sourcing, assessment and management of potential and actual investments;
communications and relationships with founders, portfolio companies, prospective and existing investors, service providers, advisers and other business contacts;
investor relations and fund-related activities, to the extent not covered by a separate investor privacy notice;
recruitment and employment applications submitted to us; and
our legal, regulatory, compliance, security and record-keeping obligations.
This Policy applies to personal data that we process in connection with:
the website at baseload.vc and its related pages (the “Website”);
enquiries and information submitted to us, including through the Website;
the sourcing, assessment and management of potential and actual investments;
communications and relationships with founders, portfolio companies, prospective and existing investors, service providers, advisers and other business contacts;
investor relations and fund-related activities, to the extent not covered by a separate investor privacy notice;
recruitment and employment applications submitted to us; and
our legal, regulatory, compliance, security and record-keeping obligations.
The Website may contain links to third-party websites. We do not control those websites and this Policy does not apply to their privacy practices. We encourage visitors to review the privacy notices of any third-party websites they use.
3. Personal data we collect
Depending on the nature of our relationship with you, we may process the following categories of personal data.
3.1 Identity, contact and professional information
This may include your name, business or employer, job title, postal address, email address, telephone number, professional biography, professional qualifications and social-media or professional-network profile details.
3.2 Enquiry, communication and submission information
This may include correspondence with us, information entered into a contact form, meeting notes, pitch materials, business plans, presentations, information about a company or project, and any other information you choose to provide.
Please avoid submitting personal data that is not relevant to your enquiry or proposal, particularly sensitive personal data relating to other individuals.
3.3 Investment, investor and transaction information
Where relevant, this may include information concerning an investment opportunity, ownership and management structures, beneficial owners, directors, shareholders, investors, representatives, transaction participants, capital commitments, bank or payment details, investment history and other information required to evaluate, complete, administer or monitor an investment or fund relationship.
3.4 Legal and compliance information
Where required for legal, regulatory, anti-money laundering, counter-terrorist financing, sanctions, anti-fraud, tax or similar compliance purposes, we may process identification documents, date and place of birth, nationality, country of residence, tax residency and identification numbers, source of funds or wealth, beneficial ownership information, politically exposed person status, sanctions-screening results, relevant litigation or regulatory information, and information obtained from public registers, screening databases or other lawful sources.
3.5 Recruitment information
If you apply for a role or otherwise express an interest in working with us, we may process your CV, cover letter, employment and education history, professional references, interview notes, compensation expectations, right-to-work information and other information you provide during the recruitment process.
3.6 Website and technical information
When you use the Website, technical information may be processed to deliver and secure it. Depending on the Website configuration, this may include IP address, browser type and version, device type, operating system, referring page, pages viewed, date and time of access, approximate country or region, form-security signals and other diagnostic or interaction information.
The Website is hosted and operated using Framer. Framer may process Website and form-related data on our behalf as a service provider. Further information is available in Framer’s privacy and data-processing documentation.
3.7 Preferences and consent records
This may include communication preferences, marketing choices, records of privacy notices presented to you and any consent you give or withdraw.
3.8 Publicly available and third-party information
We may receive information from public registers, company websites, professional networks, news sources, compliance databases, referrals, co-investors, advisers, counterparties, portfolio companies, service providers and other lawful sources.
4. How we collect personal data
We may collect personal data:
directly from you, including through forms, email, telephone calls, meetings, applications, agreements and other communications;
from an organisation you represent or with which you are associated;
from founders, portfolio companies, prospective or existing investors, co-investors, advisers, counterparties and service providers;
automatically when you visit or interact with the Website;
from public sources, professional networks, public registers and reputable third-party databases; and
where another person lawfully provides information about you in connection with an investment, transaction, business relationship or legal obligation.
If you provide personal data relating to another person, you should ensure that you are authorised to do so and, where required, that the person has received the information contained in this Policy.
5. Why we use personal data and our legal bases
We process personal data only where we have a lawful basis under applicable data protection law. The purposes and principal legal bases may include:
Purpose
Principal legal basis
Operating, maintaining, improving and securing the Website and our IT systems
Our legitimate interests in operating a secure and effective business and online presence; compliance with legal obligations
Receiving and responding to enquiries and arranging meetings
Steps taken at your request before entering into a contract; performance of a contract; our legitimate interests in communicating with business contacts
Sourcing, assessing, conducting due diligence on and completing potential investments
Steps taken before entering into a contract; our legitimate interests in identifying, assessing and executing investment opportunities; compliance with legal obligations
Managing investments, portfolio relationships and business relationships
Performance of a contract; our legitimate interests in managing investments and business relationships; compliance with legal obligations
Establishing, operating and administering funds and investor relationships
Performance of a contract; compliance with legal and regulatory obligations; our legitimate interests in operating and administering our business and funds
Performing identity, AML/KYC, sanctions, anti-fraud and other compliance checks
Compliance with legal and regulatory obligations; our legitimate interests in preventing fraud, financial crime and misuse of our services
Managing service providers, advisers, accounts, audits, reporting, governance, tax and corporate administration
Performance of a contract; compliance with legal obligations; our legitimate interests in administering and protecting our business
Sending relevant business updates, invitations or marketing communications
Your consent where required; otherwise our legitimate interests in maintaining business relationships and communicating about our activities, subject to your right to object
Assessing candidates and managing recruitment
Steps taken at your request before entering into an employment contract; compliance with legal obligations; our legitimate interests in recruiting and managing personnel
Establishing, exercising or defending legal claims, responding to authorities and protecting our rights and those of others
Compliance with legal obligations; our legitimate interests in protecting our business, rights, personnel and stakeholders
Business reorganisations, financings, acquisitions, disposals or similar transactions
Our legitimate interests in evaluating and completing corporate or fund-related transactions; compliance with legal obligations
Where we rely on legitimate interests, we consider whether those interests are overridden by your interests or fundamental rights and freedoms. Where we rely on consent, you may withdraw that consent at any time. Withdrawal does not affect processing carried out before the withdrawal.
If providing certain personal data is required by law or contract, or is necessary to enter into a contract, we will indicate this where appropriate. If the required information is not provided, we may be unable to proceed with an enquiry, investment, transaction, application or business relationship.
6. Sensitive personal data and criminal-offence data
We do not seek to collect sensitive personal data through the Website. However, where such information is relevant and lawful in connection with compliance, due diligence, litigation, recruitment or another legitimate activity, we will process it only where an additional legal condition under applicable law is satisfied and appropriate safeguards are in place.
The same applies to personal data relating to criminal convictions or offences. Such data will be processed only where authorised by applicable law and subject to appropriate safeguards.
7. How we disclose personal data
We may disclose personal data, where relevant and lawful, to:
Baseload affiliates and personnel who need the information for the purposes described in this Policy;
funds, general partners, alternative investment fund managers, investment committees, administrators, depositaries, registrars, placement agents, banks and other fund or transaction service providers;
portfolio companies, prospective portfolio companies, founders, co-investors, lenders, counterparties and transaction participants;
professional advisers, including lawyers, accountants, auditors, tax advisers, consultants and insurers;
technology, hosting, email, cloud-storage, data-room, CRM, communications, cybersecurity, screening, verification and other service providers, including Framer in connection with the Website and its forms;
courts, regulators, tax authorities, law-enforcement bodies and other public authorities where disclosure is required or permitted by law;
a prospective purchaser, investor, financier, successor or other relevant party in connection with a reorganisation, financing, merger, acquisition, disposal or similar transaction; and
any other recipient where you have requested or authorised the disclosure or where we are otherwise legally entitled to make it.
Service providers acting on our instructions are required to process personal data only for authorised purposes and to apply appropriate security and confidentiality measures.
8. International transfers
Some recipients or service providers may be located outside Luxembourg or the European Economic Area (the “EEA”), including in countries whose data protection laws may not provide the same level of protection as EEA law.
Where personal data is transferred outside the EEA, we will use a lawful transfer mechanism where required. This may include an adequacy decision adopted by the European Commission, the European Commission’s standard contractual clauses together with any necessary supplementary measures, or another mechanism permitted by applicable law.
You may contact us to request further information about the safeguards used for relevant international transfers and, where available, a copy of those safeguards.
9. Retention of personal data
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to satisfy legal, regulatory, accounting, tax, audit, reporting and record-keeping requirements and to establish, exercise or defend legal claims.
Subject to applicable legal requirements and any litigation hold, our intended retention periods are:
Category
Intended retention period
General Website enquiries and related correspondence
[24 MONTHS] after the enquiry is closed or the last meaningful contact
Investment proposals that do not proceed
[3 YEARS] after the last meaningful contact, unless a shorter or longer period is appropriate in the circumstances
Investor, fund, transaction, AML/KYC, accounting and tax records
For the duration of the relationship and thereafter for the period required by applicable law or necessary for legal claims
Marketing records
Until you opt out or the purpose otherwise ends; limited suppression data may be retained to respect your opt-out
Unsuccessful recruitment applications
[RETENTION PERIOD] after completion of the relevant recruitment process, unless you agree to a longer talent-pool period
Website security and technical records
For the shortest period reasonably necessary for security, diagnostics and service operation, subject to the applicable provider configuration
When determining a retention period, we consider the amount, nature and sensitivity of the data, the risk of harm from unauthorised use or disclosure, the relevant purposes, whether those purposes can be achieved by other means, and applicable legal requirements. At the end of the applicable period, data will be deleted, anonymised or securely archived where continued retention is legally required.
10. Security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures are selected having regard to the nature of the processing and the relevant risks and are reviewed as appropriate.
Access to personal data is restricted to personnel and service providers with a legitimate need to know. Those persons are subject to confidentiality and data-protection obligations.
No method of transmission or storage is completely secure. You should therefore use appropriate care when sending information electronically and avoid submitting information that is unnecessary for the relevant purpose.
11. Your data protection rights
Subject to the conditions, limitations and exceptions in applicable law, you may have the right to:
obtain confirmation as to whether we process your personal data and request access to it;
request correction of inaccurate or incomplete personal data;
request deletion of your personal data;
request restriction of processing;
receive certain personal data in a structured, commonly used and machine-readable format and transmit it to another controller;
object to processing based on legitimate interests, including profiling based on those interests;
object at any time to the use of your personal data for direct marketing;
withdraw consent at any time where processing is based on consent; and
lodge a complaint with a competent data protection authority.
In Luxembourg, the competent supervisory authority is the Commission nationale pour la protection des données (CNPD). Information about the CNPD and how to submit a complaint is available at cnpd.public.lu.
To exercise a right, contact us using the details in Section 1. We may need to verify your identity before acting on a request. We will respond within the period required by applicable law.
12. Automated decision-making
We do not currently make decisions about individuals based solely on automated processing where those decisions produce legal effects or similarly significantly affect them. If this changes, we will provide the information and safeguards required by applicable law.
13. Direct marketing
We may send you relevant business communications where permitted by law. You can opt out at any time by using the unsubscribe method in the communication, where available, or by contacting us.
Opting out of marketing will not prevent us from sending non-marketing communications that are necessary for an existing relationship, transaction, legal obligation or service request.
14. Children
The Website and our services are intended for business and investment audiences and are not directed to children. We do not knowingly collect personal data from children through the Website. If you believe that a child has provided personal data to us, please contact us so that we can take appropriate action.
15. Cookies and similar technologies
As of the effective date of this Policy, the Website uses Framer’s native website functionality and analytics. According to Framer, its native analytics do not use cookies or generate persistent identifiers. The Website may nevertheless use strictly necessary technical storage or similar functionality where required to deliver a feature requested by a visitor, maintain security, prevent spam or remember a privacy choice.
The Website currently loads certain resources from third-party infrastructure, including Framer and [GOOGLE FONTS / OTHER SERVICES TO CONFIRM]. These providers may receive technical connection data, such as an IP address, when a visitor’s browser requests those resources.
If we introduce non-essential cookies or tracking technologies, we will update this Policy or provide a separate Cookie Notice and, where required, obtain consent before those technologies are used. Consent may be refused or withdrawn as easily as it is given.
Browser settings can also be used to control or delete cookies, although blocking strictly necessary technologies may affect Website functionality.
16. Changes to this Policy
We may update this Policy to reflect changes in our processing activities, the Website, service providers or applicable law. The current version will be published on the Website with an updated effective date. Where required by law, we will provide additional notice of material changes.
17. Contact
Questions, requests and complaints concerning this Policy or our processing of personal data should be sent to:
[FULL LEGAL NAME OF THE CONTROLLER]
[REGISTERED / PRIVACY CONTACT ADDRESS]
[PRIVACY EMAIL]