Legal

Privacy policy

Who we are

VesperStone Ltd (company number 16183218, registered office 124-128 City Road, London, England, EC1V 2NX) is the controller of personal data described in this Policy.

This Policy explains how we collect and use personal data when you visit our Website, contact us, engage us, invest or consider investing alongside us, or otherwise deal with us. It applies under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation ("EU GDPR").

Contact: privacy@vesperstone.com or by post to the address above.

Personal data we collect

CategoryExamples
Identity and contactName, title, employer, role, email, phone, postal address, LinkedIn profile
Professional and investor profileInvestment mandate, sectors of interest, ticket size, investor classification, accreditation or professional status
Due diligence (KYC/AML)ID documents, proof of address, date of birth, nationality, source of funds/wealth, beneficial ownership, sanctions and politically exposed person (PEP) screening results
Transaction and engagementEngagement terms, deal information, commitments, fees, bank details for payments
CommunicationsEmails, call and meeting notes, call recordings (only with notice), messages through forms, chat or messaging apps
Technical and usageIP address, device and browser type, pages visited, referral source, data collected by cookies (see Cookie Policy)
Marketing preferencesYour preferences about receiving updates from us

We may process criminal-offence data or special category data (for example, data revealed by sanctions, adverse-media or PEP screening) only where required for anti-money-laundering, fraud-prevention or other legal obligations, under the conditions in Schedule 1 of the Data Protection Act 2018.

Where we obtain it

  • Directly from you (forms, emails, meetings, onboarding documents).
  • From your organisation, colleagues or introducers.
  • From publicly available sources, such as Companies House and equivalent registries, company websites, professional networking sites and press.
  • From third-party data, screening and identity-verification providers.
  • Automatically, via cookies and similar technologies on the Website.

How we use it and our lawful bases

PurposeLawful basis
Responding to enquiries and submissionsLegitimate interests (running our business and responding to you); steps prior to a contract
Delivering advisory, capital-raising and fund services under an engagementPerformance of a contract
Identifying and introducing investors, counterparties and opportunitiesLegitimate interests (developing our advisory and investment business)
Client, investor and counterparty onboarding, KYC/AML, sanctions screeningLegal obligation; legitimate interests (preventing fraud and financial crime)
Regulatory, tax, accounting and record-keepingLegal obligation
Business-to-business marketing and relationship updatesLegitimate interests; consent where required by the Privacy and Electronic Communications Regulations (PECR)
Operating, securing and improving the WebsiteLegitimate interests; consent for non-essential cookies
Establishing, exercising or defending legal claimsLegitimate interests

Where we rely on legitimate interests, we have balanced those interests against your rights. You may ask us for details of that assessment.

Technology and AI-assisted processing

We use business software, including customer relationship management, email, scheduling, document and AI-assisted tools, to organise research, communications and workflows. These tools act as our processors under written terms. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. A member of our team reviews any consequential decision.

Marketing

We may send relevant business updates to professional contacts. You can opt out at any time using the unsubscribe link in any message or by emailing privacy@vesperstone.com. Where PECR requires consent (for example, for electronic marketing to individual subscribers), we will ask for it first.

Who we share it with

  • Service providers acting as our processors: IT and cloud hosting, email and CRM, document and data-room platforms, AI tools, identity-verification and screening providers, and payment providers.
  • Regulated partners where needed to carry out a transaction, including the registered broker-dealer we work with for US securities activity, and fund administrators, custodians or placement agents.
  • Counterparties to a proposed transaction (for example, an issuer or investor), only as needed for that transaction and, where appropriate, under confidentiality terms or with your agreement.
  • Professional advisers, such as lawyers, accountants, auditors and insurers.
  • Regulators, tax authorities, law enforcement and courts where required by law.
  • A buyer or successor in the event of a reorganisation, merger or sale of our business.

We do not sell personal data.

International transfers

Some recipients are located outside the UK and EEA, including in the United States. Where we transfer personal data internationally, we rely on an adequacy decision or data bridge (including the UK Extension to the EU-US Data Privacy Framework, where the recipient is certified), or appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or the EU Standard Contractual Clauses. Contact us for a copy of the relevant safeguards.

How long we keep it

DataRetention
Enquiries and prospect contacts with no engagement24 months after last meaningful contact, unless you ask us to delete it earlier
Client, investor and transaction recordsDuration of the relationship plus 6 years
KYC/AML recordsAt least 5 years from the end of the business relationship or transaction, as required by the Money Laundering Regulations 2017
Accounting and tax recordsAt least 6 years
Website analyticsPer Cookie Policy, typically no longer than 14 months

We may keep data longer where needed for legal claims or regulatory requirements.

Security

We use appropriate technical and organisational measures, including access controls, multi-factor authentication, encryption in transit and restricted access to confidential data rooms. No transmission over the internet is completely secure.

Your rights

Subject to conditions and exemptions, you have the right to:

  • access your personal data;
  • have inaccurate data corrected;
  • have data erased;
  • restrict processing;
  • object to processing based on legitimate interests, and to object at any time to direct marketing;
  • data portability;
  • withdraw consent at any time, where we rely on consent.

To exercise a right, email privacy@vesperstone.com. We will respond within one month, extendable where permitted by law. We may need to verify your identity.

Complaints

Please contact us first. You may also complain to the UK Information Commissioner's Office (ico.org.uk, 0303 123 1113). If you are in the EEA, you may complain to your local supervisory authority (for example, in Italy, the Garante per la protezione dei dati personali).

Children

Our Website and services are not directed at children under 18, and we do not knowingly collect their personal data.

Changes

We may update this Policy. The current version will always be posted on this page with its "Last updated" date.

Last updated: 5 October 2026