The handling of your personal data is particularly important to Threestones Capital Management (or “we”). We, as controller, would like to provide you with information on how we manage and process your personal data.
The applicable regulation in this notice is as follows: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Threestones Capital Management S.A. is an independent investment management headquartered in Luxembourg. The company manages private equity real estate regulated investment vehicles under the supervision of the Luxembourg financial authorities (Commission Surveillance du Secteur Financier, CSSF) in compliance with European financial regulations. Threestones Capital Management S.A. is an AIFM (Alternative Investment Fund Manager) in accordance with the AIFM Directive.
Threestones Capital Management S.A., as a controller, is responsible for collecting and processing personal data in relation to the above-mentioned activities.
Controller responsible for the data processing
Threestones Capital Management S.A.
50-52, route d'Esch
What information do we collect?
We collect and use personal data, meaning any information that identifies or allows to identify you. Depending on the type of activities and services we provide and depending on the contractual agreements, we collect several types of personal data. We are also due to collect data as part of statutory requirement to fulfil our regulatory obligations namely our Anti-Money Laundering and Counter Terrorist Financing obligations. For those two reasons (contractual and regulatory), we are compelled to collect and store personal data.
- Identification information: Name, gender, place and date of birth, nationality, identity card number, passport number, social security number, signature, professional title and occupation, marital status, country of residence, professional photos;
- Contact information: Address, e-mail address, telephone number;
- Data collected from correspondence: Email or telephone communications;
- Personalized login credentials to access our secured Data Room;
- Other information you provide during your relationship with us or which we require you to provide in order to fulfil our activities;
- Information we obtain from other sources: This may include information from publicly accessible sources, including databases, registers and information obtained through screening tools.
How do we collect your information?
- Information is collected through contractual agreements or other material you submit to us;
- The information is collected through the business relationship with Threestones Capital Management, including email and telephone communications;
- Information is collected through third parties, when conducting certain activities, such as anti-money laundering and countering of terrorism financing (AML/CTF) analysis;
- Information is collected through monitoring tools that we use for compliance purposes.
How is the information used?
- The information is mainly used to process our investment management activities and all our operational activities;
- The information is also used to comply with AML / CFT obligations on a regular basis. The information is used to maintain accurate records in our systems;
- The information is made available to service providers (IT service providers for example), auditors, regulatory authorities to help Threestones fulfil contractual and regulatory obligations;
- The information is used to market our activities and services;
- Threestones Capital Management does not undertake marketing activities for third parties, nor does it provide information to third parties for their own marketing purposes;
- There is no existence of any automated decision-making system, including profiling within Threestones Capital.
On what legal basis do we process your Personal Data?
- Personal Data is processed to fulfil our contractual obligations;
- Personal data is processed where necessary to enable us to comply with the regulations to which we are subject to;
- For the purposes of legitimate interests pursued by Threestones Capital Management, i.e., to market our services and inform about our activities (through mailings, newsletters and other marketing material);
- Other processing may only be performed with your consent.
How long do we keep the Personal Data?
We will only keep your personal data for as long as it is required for us to comply with applicable laws and regulations and as long as is necessary to perform our activities required through contractual obligations.
Transfers of Personal Data
We may also share your personal data outside of Threestones Capital Management with the following categories of recipients who may receive it and process it for the purposes outlined in this Notice, recipients that support our provision of services to you:
- Processors and services providers which perform services on our behalf (e.g., IT services, printing services, distribution and marketing services);
- Entities of the group that may need the data for contractual or regulatory obligations;
- Certain regulated professions such as banks, lawyers, or auditors when needed under specific circumstances (execution of payments, litigations, audits, etc.);
- Any government bodies in case we are required by law or regulation to share your personal data (e.g., local tax, administrative, criminal or judicial authorities, public authorities, regulators);
- Your personal data is currently not transferred outside of EU/EEA.
What are your rights as Data Subject?
You have the following rights in compliance with the GDPR:
- To be informed about the processing of your personal data, for instance the purpose of the processing, the categories of personal data, the recipients, the storage periods, the third-party sources from which the personal data was obtained, the confirmation about automated decision-making, including profiling.
- To request access to or a copy of any personal data which we hold about you. In case you need to have access to your personal data, we will provide you with a copy of the personal data you requested as well as information related to their processing.
- To request rectification of your personal data, if you consider that it is inaccurate or incomplete. To assist us in ensuring that your information is up to date, do let us know if any of your personal details change.
- To ask us for erasure of your personal data (right to be forgotten), in case you consider that we do not have the right to store your personal data to the extent permitted by the law.
- To withdraw your consent to the processing of your personal data.
- To restrict processing of your personal data.
- To request data portability, you may request a copy of the personal data that you have provided to us. Where technically feasible, you may request that we transmit this copy to a third party.
- To object to your personal data being processed based on legitimate interests (namely for marketing purposes).
- To lodge a complaint with the competent supervisory authority, if you think that the processing of your personal data is in breach with the GDPR.
How is your information protected?
We ensure that there are appropriate technical, physical, electronical safeguards in place to protect your personal data from unauthorized access.
Changes to the Data Protection Privacy Notice
This Data Protection Privacy Notice may be amended from time to time to ensure regular updates about the information collected and how the information is used. Upon amendment, the Data Protection Notice will be updated on our website.
Contact information of the data protection officer
If you have any questions regarding the content of this Data Protection Privacy Notice, please do not hesitate to contact us:
Threestones Capital Management S.A.
50-52, route d'Esch
For further questions regarding the data protection and the processing of personal data at Threestones Capital Management, please contact our Data Protection Officer, Fernanda Teixeira firstname.lastname@example.org.