30. Who is responsible for your information?
OuterBlue Ltd is the controller of the personal information described in this Privacy Notice. This means that OuterBlue decides why and how that information is used.
Controller: OuterBlue Ltd
Company number: 17327773
Registered office: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
Privacy contact: privacy@outer.blue
31. Scope of this Privacy Notice
This Privacy Notice applies to personal information relating to:
- Website visitors
- Data Room users
- current and prospective investors
- representatives of investment funds, family offices and other organisations
- advisers and introducers
- commercial and research contacts
- people who communicate with OuterBlue; and
- other people whose information is processed in connection with our Website, fundraising or corporate activities
It does not apply to personal information processed solely by another organisation acting as an independent controller.
32. Information we collect
32.1 Information you provide
We may collect:
- your name
- email address
- telephone number
- job title
- employer or organisation
- professional role
- location or jurisdiction
- investor type or classification
- information included in an investor-status declaration
- investment interests
- communications and correspondence
- meeting notes
- questions, feedback and due-diligence requests
- information provided in connection with a proposed investment
- acceptance of legal terms; and
- any other information you choose to provide
At present, a Data Room account may require only an email address. The other categories apply only where they are relevant and provided or generated during an investment or business relationship.
32.2 Information collected automatically
When you visit the Website or use the Data Room, the OuterBlue application may collect:
- access dates and times
- login history
- authentication events
- pages and documents opened
- downloads, where enabled
- error records
- security events; and
- the session identifier necessary to keep you signed in
The OuterBlue application does not intentionally retain persistent IP addresses, device fingerprints, precise or approximate geolocation, session-replay data, dwell time, click paths, advertising identifiers or cross-site tracking data. Our hosting, email and security providers may process limited technical information where necessary to deliver and secure their services, subject to their own legal obligations and contractual controls.
32.3 Information received from other sources
We may receive personal information from:
- an investor, adviser or colleague who introduces you
- your employer or organisation
- professional advisers
- service providers supporting the Data Room
- event organisers
- universities, research bodies and commercial partners
- publicly available professional profiles
- company websites
- Companies House and other public registers; and
- lawful commercial or professional databases
Where we receive information about you from another source, we will provide privacy information as required by law.
32.4 Information we do not seek
We do not ordinarily seek:
- health information
- biometric information
- information about race, ethnicity, religion, political opinions, trade-union membership or sexual orientation
- criminal-conviction information; or
- other sensitive or special-category information
Please do not provide such information unless it is genuinely necessary and we have agreed in advance that it should be provided securely. The Website and Data Room are not intended for children and access is limited to people aged 18 or over.
33. How and why we use personal information
We use personal information only where we have a lawful basis.
33.1 Providing and administering Data Room access
We use account, identity, contact and authentication information to:
- create and administer accounts
- authenticate users
- provide requested access
- record acceptance of terms
- respond to access requests
- manage permissions; and
- provide technical support
Lawful bases: performance of the Data Room agreement, taking steps at your request before entering into that agreement and our legitimate interests in administering a secure investor process.
33.2 Protecting confidential information and maintaining security
We use login records, document-access records and necessary authentication or security events to:
- protect confidential information
- prevent credential sharing
- detect unauthorised access
- investigate suspected misuse
- protect our systems
- enforce these terms; and
- maintain evidence of activity where reasonably necessary
Lawful basis: our legitimate interests in protecting our business, intellectual property, confidential information, systems and users.
33.3 Managing investor relationships and fundraising
We use contact, professional, correspondence and Data Room activity information to:
- understand investor interest
- prioritise and manage follow-up
- arrange meetings
- respond to questions
- manage due diligence
- assess potential investment relationships
- record discussions and decisions; and
- prepare for and complete a possible investment
Lawful bases: our legitimate interests in raising finance and managing professional relationships, taking steps at your request in contemplation of a possible transaction, performance of any agreement and compliance with legal obligations.
33.4 Assessing access and regulatory eligibility
We may use identity, professional and investor-status information to:
- determine whether Investment Materials may lawfully be communicated
- obtain and retain investor declarations
- apply access restrictions
- comply with financial-promotion requirements
- prevent unlawful distribution; and
- establish or defend our legal position
Lawful bases: compliance with legal obligations and our legitimate interests in conducting fundraising lawfully and maintaining appropriate records.
33.5 Communicating with you
We use contact and correspondence information to:
- respond to enquiries
- send account and security notices
- provide requested materials
- update you about relevant Data Room changes
- continue an existing professional conversation; and
- send other business or fundraising communications where permitted by law
Lawful bases: performance of an agreement, our legitimate interests in communicating with professional contacts and consent where consent is required. You may object to direct marketing at any time by contacting us or using any unsubscribe mechanism provided. Account, security, legal and transaction-related messages are not marketing and may still be sent where necessary.
33.6 Operating and improving the Website
We may use technical and usage information to:
- operate the Website
- diagnose errors
- understand aggregate usage
- improve performance and usability; and
- develop our systems
Lawful bases: our legitimate interests in operating and improving the Website and consent where required for non-essential cookies or tracking technologies.
33.7 Corporate administration and legal compliance
We may use personal information to:
- maintain corporate and accounting records
- obtain professional advice
- conduct audits
- respond to legal claims
- comply with court orders
- respond to regulators and public authorities
- prevent or investigate fraud
- support a financing, restructuring, acquisition or sale; and
- comply with applicable law
Lawful bases: compliance with legal obligations and our legitimate interests in administering and protecting OuterBlue.
34. Our legitimate interests
Where we rely on legitimate interests, those interests may include:
- operating a secure Website and Data Room
- protecting confidential information and intellectual property
- managing access
- preventing misuse, fraud and cyber incidents
- raising capital
- managing current and prospective investor relationships
- maintaining accurate records
- improving our systems
- protecting legal rights; and
- operating and developing OuterBlue
We consider whether our use is necessary and balance our interests against the rights and interests of the affected person. You may object to processing based on legitimate interests. Further information appears in section 42.
35. Data Room activity information and automated decision-making
We may review limited account activity, including login, document-open and download records, to administer access, confirm that requested materials have been received and manage relevant follow-up. We do not create investor engagement scores, use dwell-time monitoring or infer investor interest from browsing duration. We do not use this information to make a decision based solely on automated processing that produces legal or similarly significant effects.
Material decisions about access or an investment relationship involve human judgement.
36. When information must be provided
You may choose whether to provide most personal information.
However, we may be unable to provide or continue Data Room access unless you provide:
- a valid email address
- information required to authenticate access
- acceptance of the Data Room Terms
- information reasonably required to confirm your authority; and
- any investor-status information required for lawful access
If you do not provide information necessary to authenticate and secure access, we may be unable to continue providing the Data Room.
37. Sharing personal information
We may share personal information with the following categories of recipient where reasonably necessary.
37.1 Technology providers
These may include providers of:
- website hosting
- cloud infrastructure
- databases
- authentication
- email
- security
- file storage
- Data Room software
- technical support; and
- analytics used in accordance with applicable law
Such providers generally act as processors and may use information only under our instructions, subject to their own legal obligations.
37.2 Professional advisers
We may share information with:
- solicitors
- accountants
- tax advisers
- corporate-finance advisers
- insurance advisers
- consultants; and
- other professional advisers
An adviser may act as our processor or as an independent controller depending on the circumstances.
37.3 Investors and transaction participants
Where reasonably necessary in connection with a proposed transaction, we may share information with:
- existing or prospective lead investors
- co-investors
- investment committees
- nominee providers
- due-diligence providers
- banks
- payment providers; and
- other transaction participants
We will not ordinarily disclose one prospective investor’s detailed activity to another prospective investor without a legitimate reason.
37.4 Authorities and legal recipients
We may share information with:
- courts
- regulators
- law-enforcement bodies
- tax authorities
- government departments; and
- another person where disclosure is required or permitted by law
37.5 Corporate transactions
Information may be disclosed to potential buyers, investors, lenders, professional advisers and counterparties in connection with:
- an investment
- merger
- acquisition
- reorganisation
- financing
- sale of assets
- insolvency process; or
- other corporate transaction
Recipients will be expected to protect confidential information appropriately. We do not sell personal information to data brokers or advertisers.
38. International transfers
Some service providers or recipients may be located outside the United Kingdom or may make personal information accessible from another country.
Where UK data-protection law restricts an international transfer, we will use an appropriate transfer mechanism. This may include:
- transfer to a country covered by UK adequacy regulations
- the UK International Data Transfer Agreement
- the UK Addendum to approved standard contractual clauses
- another approved safeguard; or
- a permitted legal exception
Where required, we will take additional steps to assess and protect the information. You may contact us for further information about the safeguards relevant to your personal information.
39. Security
We use reasonable organisational and technical measures designed to protect personal information against:
- unauthorised access
- accidental loss
- unlawful disclosure
- alteration
- destruction; and
- misuse
Measures may include:
- access controls
- authentication
- encrypted transmission
- restricted administrative access
- logging
- backups
- supplier controls; and
- incident-response procedures
No system is completely secure. You should notify us promptly if you suspect that your account or personal information has been compromised.
40. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this notice, including legal, regulatory, security and record-keeping purposes.
Our normal retention approach is:
40.1 Account and Data Room information
Email addresses, account details and ordinary Data Room activity records are generally retained while the relevant fundraising process remains active and are normally deleted or anonymised within six months after that fundraising process closes. Information may be retained longer where there is an ongoing investment or business relationship, a security incident, suspected misuse, a legal dispute, a legal obligation or another clearly justified need.
40.2 Security records
The OuterBlue application does not intentionally retain persistent IP addresses, device fingerprints or geolocation records.
Limited authentication and security-event records are generally retained on the same basis as ordinary Data Room activity. Relevant records may be retained longer where they relate to:
- a security incident
- suspected misuse
- a legal dispute
- enforcement of confidentiality obligations; or
- another continuing risk
40.3 Terms, declarations and transaction records
Records showing:
- acceptance of legal terms
- confidentiality obligations
- investor-status declarations
- material due-diligence communications; and
- transaction decisions
- may generally be retained for up to six years after the relevant relationship, communication or transaction ends
Information may be retained longer where reasonably necessary to comply with law, respond to a continuing claim or preserve evidence.
40.4 Investor and business contacts
Information about an inactive prospective investor or other business contact will generally be deleted or anonymised within six months after the relevant fundraising process closes, unless:
- there is an ongoing relationship
- the person has asked to receive future communications
- retention remains reasonably relevant to a future financing
- a legal obligation applies; or
- a longer period is otherwise justified
40.5 Marketing objections
Where you object to direct marketing, we may retain a minimal suppression record for as long as reasonably necessary to ensure that your preference is respected.
40.6 Anonymised information
We may retain genuinely anonymised or aggregated information indefinitely where it can no longer identify an individual. Retention periods may be adjusted where technical, legal or operational circumstances reasonably require.
41. Your data-protection rights
Depending on the circumstances, you may have the right to:
- be informed about how your personal information is used
- request access to your personal information
- request correction of inaccurate or incomplete information
- request deletion of your information
- request restriction of processing
- object to processing based on legitimate interests
- object to direct marketing at any time
- receive certain information in a portable format
- withdraw consent where processing is based on consent; and
- complain to a data-protection authority
These rights are not absolute. An exemption or competing legal obligation may apply.
For example, we may retain information where it is necessary to:
- comply with law
- establish, exercise or defend legal claims
- maintain a marketing-suppression record
- protect confidential information
- investigate misuse; or
- preserve necessary transaction records
Withdrawing consent does not affect processing carried out lawfully before withdrawal.
42. Exercising your rights
To exercise a data-protection right, contact:
- Email: privacy@outer.blue
- Please describe:
- the right you wish to exercise
- the information concerned; and
- any information that may help us identify the relevant records
We may ask for reasonable proof of identity where necessary to protect personal information. We will respond within the period required by applicable law. You are not ordinarily required to pay a fee. A fee may be permitted or a request may be refused where a request is manifestly unfounded or excessive, subject to applicable law.
43. Complaints
Please contact us first if you have concerns about how we use personal information. You also have the right to complain to the Information Commissioner’s Office, the United Kingdom’s data-protection regulator. If you live or work outside the United Kingdom, you may also have the right to contact a local data-protection authority.
44. Changes to this Privacy Notice
We may update this Privacy Notice to reflect changes to:
- our processing
- the Website or Data Room
- service providers
- legal requirements; or
- our business
The current version will be published on the Website with its effective date. We will take reasonable steps to notify affected users of a material change. We may require renewed acknowledgement or acceptance where appropriate.