Legal & policy
Privacy Policy
Effective Date: July 29, 2025
This Privacy Policy explains how Fairclough Palmer AG, together with its subsidiary network including EquityLink, its capital raising platform connecting founders and small and medium sized enterprises with global investors (collectively "the Group"), collects, uses, stores and discloses personal data belonging to visitors, registered users, founders, investors and subscribers across its websites, the EquityLink portal and the iOS application.
Anyone who browses the Platform, registers an account, subscribes to a paid tier, purchases VIP Access, or otherwise submits personal data to the Group is taken to have read this Policy and to understand how their data will be handled, including where that data is transferred outside Switzerland or the European Economic Area.
LEGAL DOCUMENT: This is a legally binding agreement. Please read carefully and, if necessary, consult legal counsel to ensure you fully understand its contents.
1. Scope, Group Perimeter and Controller
This Policy applies to every website, application and service operated by Fairclough Palmer AG and by each present or future subsidiary or affiliate through which those services are delivered, including EquityLink and the associated iOS application. Where a given entity within the Group determines the purposes and means of processing a particular set of personal data, that entity acts as controller for that processing, whilst other Group entities may act as processors carrying out instructed tasks on the controller's behalf.
The controller responsible for personal data collected through the Platform, unless stated otherwise at the point of collection, is Fairclough Palmer AG, Schifflände 26, 8001 Zürich, Switzerland, reachable using the contact details set out at the end of this Policy.
Processing is carried out primarily in accordance with the Swiss Federal Act on Data Protection and its implementing ordinance. Where a data subject is located in the European Economic Area, or where processing otherwise falls within its territorial reach, the Group additionally observes the requirements of the EU General Data Protection Regulation.
2. Categories of Personal Data and Sources
Personal data is obtained directly from the data subject, generated automatically through use of the Platform, or received from a third party such as a verification provider, payment processor or another user who names the data subject in a submission. The categories collected depend on the nature of the interaction and may include the following.
2.1 Categories Collected:
- Identity Data: full name, date of birth, nationality, government issued identification and specimen signature, gathered chiefly for onboarding and verification purposes.
- Contact Data: postal address, telephone number, email address and messaging handles used to correspond with the Company.
- Corporate Data: company name, registration details, ownership structure, sector and stage of development, submitted by founders establishing a fundraising profile.
- Financial Data: subscription tier held, VIP Access purchases, billing address, payment card token, transaction history and, for investors, self declared investment capacity or accreditation status.
- Verification Data: information produced through identity checks, sanctions screening and politically exposed person screening carried out before or during onboarding.
- Device Data: IP address, device identifier, operating system, browser type, and diagnostic data generated by the iOS application.
- Behavioural Data: pages viewed, listings interacted with, time spent on the Platform, search queries and click patterns.
- Communications Data: messages exchanged through in-app messaging, support correspondence, and records of consent to marketing.
2.2 Sources of Data:
Personal data reaches the Group through the following channels:
- Direct submission by the data subject during registration, subscription purchase or profile creation.
- Automatic generation through cookies, software development kits embedded in the iOS application, and server logs.
- Third party identity verification and sanctions screening providers engaged to fulfil compliance obligations.
- Payment processors confirming successful completion of a transaction.
- Other users of the Platform who reference the data subject within a submitted profile or message.
3. Purposes of Processing and Lawful Bases
Personal data is processed only where a legitimate purpose exists and, where the GDPR applies, only where a corresponding lawful basis is available. The principal purposes and their bases are set out below.
- Account creation and platform operation: processed on the basis of contractual necessity, to establish and administer the User's account and deliver the subscribed features.
- Facilitating investor introductions: processed on the basis of contractual necessity and the Group's legitimate interest in operating a functioning capital raising marketplace.
- Billing for subscriptions and VIP Access: processed on the basis of contractual necessity, to charge and reconcile the fees described in the Terms and Conditions.
- Identity verification, sanctions screening and fraud prevention: processed on the basis of compliance with a legal obligation and the Group's legitimate interest in preventing financial crime.
- Product analytics and service improvement: processed on the basis of legitimate interest, generally using aggregated or pseudonymised data where feasible.
- Marketing communications: processed on the basis of consent where required by applicable law, or legitimate interest for existing customers contacted about similar services, subject always to an opt out.
- Handling enquiries and disputes: processed on the basis of legitimate interest and, where litigation arises, the establishment or defence of legal claims.
4. Automated Decision Making, Marketing and Cookies
4.1 Automated Decision Making and Profiling
The Group does not subject data subjects to decisions based solely on automated processing that produce legal effects or similarly significant consequences for them. Limited automated filtering may be used to rank or surface fundraising profiles to relevant investors, but any decision affecting eligibility, account status or verification outcome involves human review before it is finalised.
4.2 Marketing and Consent
Marketing communications are sent only to users who have consented to receive them or who fall within an exemption permitted under applicable law for existing customers. Consent may be withdrawn at any time through the unsubscribe mechanism included in every marketing message or by contacting the Company directly.
4.3 Cookies and Analytics
The Platform uses strictly necessary cookies to maintain sessions and secure logins, together with analytics cookies and comparable technologies within the iOS application to understand usage patterns. Non essential cookies are placed only after the User has given consent through the cookie banner presented on first visit, and preferences can be adjusted at any time through browser or device settings.
5. Disclosure, Recipients and International Transfers
Personal data is not sold to third parties. It is shared only with recipients that require it to fulfil one of the purposes described above, including the following categories.
- Processors and service providers: cloud hosting providers, customer support tooling, email delivery platforms and analytics vendors engaged under written data processing agreements.
- Verification providers: specialist firms retained to perform identity checks and sanctions and politically exposed person screening.
- Payment processors: third parties that process subscription and VIP Access payments and handle card data under their own security standards.
- Professional advisers: lawyers, auditors and consultants engaged by the Group who require access to specific data to advise on a matter.
- Authorities: regulators, tax authorities, courts and law enforcement bodies where disclosure is compelled by law or necessary to defend a legal claim.
- Successors in a business transaction: a prospective acquirer or successor entity in the event of a merger, reorganisation or transfer of business, subject to confidentiality undertakings.
Where personal data is transferred to a recipient located outside Switzerland or the European Economic Area in a jurisdiction not recognised as offering adequate protection, the transfer is made subject to the European Commission's standard contractual clauses, the corresponding Swiss transborder data flow safeguards, or another mechanism recognised under applicable law, and a copy of the relevant safeguard can be requested using the contact details below.
6. Retention and Security
6.1 Retention Schedule
Personal data is kept only for as long as necessary, informed by the following considerations.
- Account and profile data is retained for the duration of the relationship and for a further period following closure to address residual queries.
- Billing and transaction records connected with subscriptions and VIP Access are retained for the period required under the Swiss Code of Obligations, generally ten years from the close of the relevant financial year.
- Verification and screening records are retained for the period mandated under applicable anti money laundering rules.
- Marketing consent records are retained until consent is withdrawn and for a further short period to evidence compliance.
- Analytics and device data is retained in identifiable form for a limited period before being aggregated or deleted.
6.2 Security Measures
Access to personal data is restricted on a need to know basis, data in transit and at rest is encrypted, and hosting infrastructure is provided by vendors holding recognised certifications such as ISO 27001 or SOC 2. Personnel are bound by confidentiality obligations, and vendor arrangements are reviewed periodically to confirm continued adequacy of their safeguards.
7. Data Subject Rights and Complaints
Subject to the conditions and exceptions set out in the FADP and, where applicable, the GDPR, a data subject may exercise the following rights in relation to personal data the Group holds about them:
- Access: to obtain confirmation of what personal data is processed and to receive a copy of it.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure: to request deletion of data no longer needed for the purposes for which it was collected, subject to retention obligations described above.
- Restriction: to request that processing be limited pending resolution of a dispute over accuracy or lawfulness.
- Portability: to receive certain data in a structured, machine readable format where processing relies on consent or contract.
- Objection: to object to processing carried out on the basis of legitimate interest, including for direct marketing.
- Withdrawal of consent: to withdraw consent at any time where processing depends on it, without affecting the lawfulness of processing carried out beforehand.
Requests may be submitted using the contact details set out below and will be answered within the timeframe required by applicable law. A data subject dissatisfied with the Group's response may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with the supervisory authority of their habitual residence, place of work or the place of the alleged infringement.
8. Children, Third Party Sites and Breach Notification
8.1 Children
The Platform is not directed at, and must not be used by, anyone below the age of majority in their jurisdiction. Where the Group becomes aware that it has inadvertently collected data from a minor, it will delete that data promptly save where retention is required by law.
8.2 Third Party Sites
Links to external websites are provided for convenience. This Policy does not extend to, and the Group accepts no responsibility for, the privacy practices of any site not operated by the Group.
8.3 Breach Notification
Where a security incident results in a breach of personal data likely to result in a risk to affected individuals, the Group will notify the FDPIC, the competent EU supervisory authority where applicable, and affected data subjects, within the timeframe and to the extent required by the FADP and the GDPR respectively.
9. Changes to this Policy
This Policy may be updated from time to time to reflect changes in processing activity or legal requirements. The revised version will be published on the Platform with an updated effective date, and material changes will be brought to the attention of registered users through the Platform or by email in advance of taking effect.
Contact Information
Fairclough Palmer AG
Schifflände 26, 8001 Zürich, Switzerland
Email: Privacy@FaircloughPalmer.com
Contact Telephone: +41 (0) 44 505 33 47
Commercial Register Number: CHE-171.548.749
