Data Protection and Privacy Policy
Amended: September 2026 | Version: 2026.1
PROSPERGATE CAPITAL LTD, is a company registered under the laws of the Republic of Cyprus, with registration number C369583. It is a regulated Cyprus Investment Firm (“CIF“) authorised and regulated by the Cyprus Securities and Exchange Commission (“CySEC“) under license number 361/18. The Company also acts as the External Manager of PROSPERGATE FUND AIFLNP V.C.I.C LTD.
The registered office of the Company is situated at 2 Filiou Zannetou street, 3021 Limassol, Cyprus.
Legal Framework
For the purposes of, inter alia, this Data Protection and Privacy Policy, the Company operates under:
- Directive 2014/65/EU (“MiFID II“), as implemented in Cyprus by the Investment Services and Activities and Regulated Markets Law of 2017 (Law 87(I)/2017), as amended;
- The Alternative Investment Funds Law of 2018 (L.124(I)/2018) and, in respect of the Company’s role as External Manager, the Small Alternative Investment Fund Managers Law of 2020 (L.81(I) of 2020) (“the SMALL AIFM Law“), as amended and supplemented;
- Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (“GDPR“), as implemented in Cyprus by Law 125(I)/2018 on the Protection of Natural Persons with regard to the Processing of Personal Data and the Free Movement of Such Data (together, the “Data Protection Legislation“);
- The Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended from time to time, and the CySEC Directive for the Prevention of Money Laundering and Terrorist Financing (R.A.D. 282/2024, as amended); and, at EU level, Regulation (EU) 2024/1624 (the “AML Regulation“), Directive (EU) 2024/1640 (“AMLD6“) and Regulation (EU) 2024/1620 establishing the EU Anti-Money Laundering Authority (“AMLA“), which apply, and must be transposed into Cyprus law, respectively, from 10 July 2027;
- The Criminalisation of Violation of Restrictive Measures Law of 2025, and the Implementation of the Provisions of the Resolutions or Decisions of the United Nations Security Council (Sanctions) and the Decisions and Regulations of the Council of the European Union (Restrictive Measures) Law of 2016 (Law 58(I)/2016); and the Combating of Terrorism Law of 2019 (Law 75(I)/2019).
Scope Of The Policy
Pursuant to the Data Protection Legislation and other applicable laws and regulations governing the establishment and services of CIFs and AIFMs, the Company is required to establish, implement and maintain an effective Data Protection and Privacy Policy, set out in writing. This Policy sets out the Company’s responsibility to manage and protect the privacy of investors’ personal and financial information, and to behave fairly and lawfully in gathering, processing, storing and handling such personal data.
The privacy of investors’ personal data is treated by the Company with the utmost importance.
Overview
Personal data provided to Prospergate — including financial information, investment details and other personal data furnished so that the Company can provide the requested services and act on the data subject’s behalf — is submitted lawfully and processed only by persons responsible for, and performing, data processing, within the framework of the appropriate contractual safeguards and legal obligations required by the Data Protection Legislation.
Clients’ personal data is stored in a manner that guarantees its appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, through appropriate technical and organisational measures.
Prospergate stores personal data for the period required by applicable EU and Cyprus law, and in accordance with the regulations of CySEC and, where applicable, the Central Bank of Cyprus.
This Policy briefly sets out: (a) the lawful basis of processing; (b) the data the Company is legally obliged to collect; and (c) the legal rights of data subjects and the documentation available to exercise them.
Lawful Basis For Processing
Under Article 6 GDPR, there are six available bases for lawfully processing personal data:
- Consent — the individual has given clear consent to the processing of their personal data for a specific purpose. A consent document is provided to the client/investor.
- Contractual obligation — processing is necessary to perform a contract with the individual. The Company relies on this basis to process personal data under its contracts and agreements with data subjects.
- Legal obligation — processing is necessary for the Company to comply with the law. As a licensed CIF, the Company is subject to various laws and regulations issued by, inter alia, CySEC in order to maintain its licence and authorisation. This lawful basis is relied on to comply with legislative and statutory obligations, including, among others:
- customer identification and due diligence under Articles 60–66 of the Prevention and Suppression of Money Laundering and Terrorist Financing Law of 2007 (Law 188(I)/2007), as amended, and the CySEC Directive for the Prevention of Money Laundering and Terrorist Financing (R.A.D. 282/2024, as amended);
- Law 87(I)/2017 on the provision of investment services, the exercise of investment activities and the operation of regulated markets;
- the Combating of Terrorism Law of 2019 (Law 75(I)/2019);
- Regulation (EU) No 596/2014 (MAR); Regulation (EU) No 648/2012 (EMIR); Regulation (EU) No 600/2014 (MiFIR);
- the Assessment and Collection of Taxes Laws of 1978–2015;
- the CRS Decree on the Assessment and Collection of Taxes (Exchange of Information), issued under the Multilateral Competent Authority Agreement;
- the Automatic Exchange of Financial Account Information Decree of 2016.
- Vital interests — processing is necessary to protect someone’s life.
- Public task — processing is necessary to perform a task carried out in the public interest, as clearly set out in law.
- Legitimate interests — processing is necessary for the Company’s legitimate interests, or those of a third party, unless overridden by the data subject’s own interests or fundamental rights.
Data We Are Legally Obliged To Collect
- The Company uses clients’ personal data only in accordance with international data protection practice. It is registered as a Data Controller with the Office of the Commissioner for Personal Data Protection, and collects, processes, maintains, stores, uses and handles clients’ personal data in accordance with the Data Protection Legislation, this Policy, and the Company’s Trading Terms and Conditions.
- The Company may collect personal information from other sources, including fraud prevention agencies, banks and other financial institutions, third-party authentication service providers, and providers of public registers, as required from time to time for the Company’s legitimate purposes.
- “Personally identifiable information” (or “Personal Information”) means any information that may be used, alone or in combination with other information, to personally identify, contact or locate a customer of the Company.
- Personal Information includes, but is not limited to: (1) first and last name; (2) ID/passport numbers; (3) physical address; (4) date of birth; (5) contact details such as telephone number and email address; (6) identity and address verification documents such as passport, ID, utility bills and/or bank statements; (7) company information and incorporation documents/certificates for corporate accounts; (8) financial data, such as estimated annual income and net worth, trading experience and investment knowledge, including trading data, deposits, withdrawals and credit; and (9) payment and bank account details.
- The Company is required by law to identify a client/investor when opening a new account or adding a new signatory to an existing account. Anti-money laundering legislation requires the Company to “sight and record” details of certain documents (photographic and non-photographic) to meet applicable standards. Identification documentation, as required under AML legislation or other relevant legislation, may include: passport; national identity card (if applicable); CV; tax declarations/tax ID; a statement as to criminal record; a statement as to bankruptcy; utility bills; bank statements; trust deed; and any other information the Company considers necessary for its functions and activities. The Company also collects data regarding trustees, partners, company directors and officers, officers of co-operatives and associations, client agents, and individuals dealing with the Company on a one-off basis.
- To fulfil its legal obligation to apply due diligence and to guard against dealings with persons subject to sanctions, the Company uses a risk-intelligence screening system, in line with CySEC’s guidance on sanctions-screening systems set out in Circular C685. This screening helps the Company meet its regulatory obligations, make informed decisions, and avoid inadvertent association with money laundering, corrupt practices or sanctioned individuals/entities, by screening relevant personal information against data derived from publicly available and other appropriate sources.
Legal Rights Of The Data Subject & Available Documents
Right of access
Data subjects have the right to access their personal data and supplementary information, allowing them to verify the lawfulness of processing. The Data Protection Officer (“DPO“) may refuse a request that is manifestly unfounded or excessive. Where a request is approved, the DPO liaises with the relevant departments to gather the requested data. Where the Company cannot respond within one month, the DPO will notify the data subject of the delay and its reasons. Data is provided in hard copy or by electronic means.
Right to rectification
Data subjects may request, verbally or in writing, that inaccurate or incomplete personal data be rectified or completed. The Company responds within one calendar month and may refuse a request only in limited circumstances; where data is amended, the DPO confirms this to the data subject in the same format described above.
Right to erasure
Also known as the “right to be forgotten”, this right is not absolute and applies only in certain circumstances. In line with the Company’s regulatory obligations, client personal data is retained for a minimum of five (5) years from the date of the relevant transaction, or from termination of the business relationship, in accordance with the Company’s policies. Requests are made in writing to the DPO, who assesses whether erasure can be granted (having regard to, among other things: whether the data is still necessary for its original purpose; withdrawal of consent; absence of legitimate grounds or legal obligation to continue processing; unlawful processing; or a requirement under GDPR or other legislation), and responds within one month.
Right to restrict processing
Data subjects may request restriction or suppression of processing, subject to certain conditions. The DPO examines and responds to such requests within one month; where processing is restricted, the Company may continue to store, but not use, the relevant data.
Right to data portability
Data subjects may obtain and reuse their personal data across different services, and may move, copy or transfer it safely and securely between IT environments. A data subject wishing to exercise this right completes a Data Transfer Form specifying the recipient and confirming their authorisation for the transfer.
Rights related to automated decision-making, including profiling
The GDPR includes provisions on automated individual decision-making (without human involvement) and profiling. Article 22 GDPR provides additional protection where the Company carries out solely automated decision-making with legal or similarly significant effects, permitting this only where necessary for a contract, authorised by EU or Member State law, or based on explicit consent. Prospergate does not engage in profiling, nor does it take decisions through solely automated decision-making processes.
Right to withdraw consent
Under Article 7(3) GDPR, a data subject may withdraw consent to processing at any time. This right applies only where processing is based solely on consent, and not where another legal basis requires the data to be retained. As a highly regulated CIF, Prospergate Capital Ltd has a legal obligation to retain most client data — for a period of five to seven years following termination of the relevant relationship — under, among others: the CySEC Directive for the Prevention of Money Laundering and Terrorist Financing (R.A.D. 282/2024, as amended); Law 87(I)/2017; Inland Revenue Department legislation; and any legislation issued by MOKAS, CySEC, the Office of the Commissioner for Personal Data Protection, or any other competent authority. A data subject wishing to withdraw consent completes the Company’s ‘Withdrawal of Consent’ form.
Update To This Policy
This Policy may be updated and changed from time to time in order to comply with new legal or regulatory requirements or amendments. Any updated version will be published on the Company’s website.
Contact Us
If you would like to contact us with any queries or comments, please send an email to [email protected]
Disclaimer
Prospergate Capital Ltd is a Cyprus Investment Firm (“CIF”) authorised by the Cyprus Securities and Exchange Commission (“CySEC”) (licence number 361/18), with a licence to perform portfolio management services. The Company externally manages, on a discretionary basis, client funds held with global financial institutions pursuant to a pre-defined investment strategy. As the risk of investing in certain financial instruments is generally high and the market value of such instruments may be affected by factors such as economic and political conditions, foreign exchange fluctuations, and shifts in market sentiment, the investor bears full responsibility for the risks associated with such investments and acknowledges that investment yield and/or capital preservation are not guaranteed. Investors should ensure they are fully aware of the potential risks connected with portfolio management services and their chosen investment strategy, and should note that some strategies carry a higher degree of risk than others, which may result in the loss of all or part of the initial investment. Past performance does not guarantee, and should not be taken as an indication of, future returns.
© Copyright 2026 | Prospergate Capital Ltd | All rights reserved
