Legal

Data Privacy Notice

Wincent Capital Management Limited

Last updated 28 September 2026

Wincent Capital Management Limited (“Wincent” together, with Wincent Investment Fund PCC Limited and its affiliated entities, “we”, “us” or “our”) is committed to protecting the privacy and personal data of individuals who interact with us. This Data Privacy Notice explains how we collect, use, disclose, and safeguard your personal data, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Gibraltar GDPR and Data Protection Act 2004 (“DPA”) (together, the (“Privacy Legislation”).

We are also committed to ensuring we use artificial intelligence systems (“AI Systems”) responsibly, with regard to our obligations under Regulation (EU) 2024/1689 (the “EU AI Act”). Where applicable, this Data Privacy Notice discloses how we use AI Systems to process personal data.

We aim to present this information in a concise, transparent, intelligible, and easily accessible manner. If you require clarification or an alternative format, please contact our Data Protection Officer (“DPO”) on the details below.

Glossary

AI System
Means a machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
Controller
Means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data subject
Means an identified or identifiable natural person whose personal data is processed by a data controller or data processor.
Personal data
Means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processor
Means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Special Category Personal Data
Refers to specific types of Personal data that are considered more sensitive and thus require higher levels of protection. The definition includes racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation.

Who We Are (Data Controller)

The data controller responsible for your personal data is:

Wincent Capital Management Limited

Address: Unit 101, Eurocity, Europort Avenue, Gibraltar, GX11 1AA

For any questions or to exercise your rights, please contact the DPO:

Luke McMorrow

Postal Address: Unit 101, Eurocity, Europort Avenue, Gibraltar, GX11 1AA

Email: GDPR@wincent.co

When Do We Collect Your Data

We collect your personal data:

  • Directly from you: e.g. when you submit a subscription form as an investor, apply directly for a role at Wincent, enter into an agreement with Wincent as a counterparty, or provide personal data as a UBO, director or shareholder of a counterparty as part of an onboarding.
  • Indirectly from other sources: e.g. applying for a role via LinkedIn, receiving a referral from a recruitment agency you are working with, background check providers.

When data is collected indirectly, we will provide you with this Data Privacy Notice at the earliest opportunity and no later than one month from collection, in accordance with GDPR Article 14.

Categories of Personal Data

We collect and process personal data where necessary for the performance of a contract, to comply with legal obligations, to pursue our legitimate business interests (balanced against your rights), or based on your consent where required in accordance with Article 6 GDPR. We may also process Special Category Personal Data where strictly required to fulfil our legal obligations (such as Anti-Money Laundering and Know Your Customer checks). The Personal Data we collect depends on manner in which you interact with us:

Prospective Job Candidates
Types of dataPurpose of processingAccessThird parties/ Service providersLawful basisData transfers
NameEvaluating the candidateHR TeamGoogle services (Drive, Gmail, Calendar)Legitimate interest to find new employeesPrivate Data shared to the HR Service Providers based in EEA
CV and cover letterPerforming interviewsSenior ManagementAsana
Contact informationPre-employment obligations and screeningTeam LeaderSlack
Interview notes (if any)AshbyProcessing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract
Details of offers (where applicable)DeelAnthropic
Assessment ResultsExplicit consent (LinkedIn, Website)
Prospective Investors
DataPurpose of processingAccessThird parties/ Service providersLawful basisData transfers
PassportBackground screeningRamparts (GFSC Regulated Fund Administrator)Google services (Drive, Gmail, Calendar, Gemini)Performance of a contractData shared with Ramparts, Wincent, its affiliated entities and Services Providers based in EEA and Gibraltar.
AddressKYC, AML/CTF checksBusiness Development TeamSlackCompliance with legal obligations (AML/CTF/KYC checks)
Date of birthOngoing administrative and accounting purposesFinance TeamTelegram
Income statements, tax information, TINLegal TeamDocusign
Source of wealth informationCompany Secretarial TeamIronClad
Contact information
Prospective OTC Counterparties or their related persons
DataPurpose of processingAccessThird parties/ Service providersLawful basisData transfers
PassportBackground screeningBusiness Development Team, Compliance TeamSumSubExplicit consent (given to our data processor SumSub)Data shared with Wincent, its affiliated entities and Service Providers based in EEA and Gibraltar.
AddressAdministrative and accounting purposesFinance Team, Compliance TeamTelegramCompliance with legal obligations (AML/CTF checks)
Liveness checkClient administrationCompliance Team, Legal TeamAsanaPerformance of a contract (parties sign our Trading Agreement)
Transaction InfoKYC, AML/CTF checksCompany Secretarial Team, Compliance TeamGoogle services (Drive, Gmail, Calendar, Gemini)Ironclad
Wallet InformationCompliance TeamDocusignOpenAIAnthropic
Slack

In accordance with GDPR Article 5(1)(a), and DPA Articles 14(2) and 8(a), Wincent Processes Personal Data lawfully, fairly, and transparently, ensuring that individuals are informed about the collection and use of their Personal Data. In addition, in accordance with GDPR Article 6 and DPA Article 10, all Processing activities have a valid lawful basis, as displayed in the above table.

Wincent collects and Processes Personal Data solely for specified, explicit, and legitimate purposes, as mandated by GDPR Article 5(1)(b) and DPA Article 43, ensuring that data collected is (i) adequate, (ii) relevant, and (iii) limited to what is necessary for the relevant business functions, in compliance with the principle of data minimisation under GDPR Article 5(1)(c).

Data Subject Rights

Wincent acknowledges and is fully committed to upholding Data Subjects’ rights, continuously monitoring compliance, rectifying inaccuracies, erasing data, and transparently communicating to Data Subjects their rights as stipulated in Chapter 3, Articles 15-21 of the GDPR and Articles 55, and 56 of DPA. These rights are enshrined in the Privacy Legislation and include, but are not limited to, the following:

  • Right to Be Informed: Transparency regarding data collection and Processing.
  • Right of Access: The ability to obtain a copy of Personal Data.
  • Right to Rectification: Correction of inaccurate or incomplete data.
  • Right to Erasure: Deletion of Personal Data under certain conditions.
  • Right to Restrict Processing: Limiting the Processing of data.
  • Right to Data Portability: Receiving data in a structured format for transfer to another party.
  • Right to Object: Opposing data Processing based on legitimate interests or direct marketing.
  • Right Not to Be Subject to Automated Decision-Making: Protection against solely automated Processing affecting legal or significant decisions.

To exercise your rights, including deletion of your personal data and/or withdrawal of consent to processing of your personal data, please contact us at GDPR@wincent.co. We respond without undue delay and in any case within one month. Where requests are complex or numerous, this may be extended by up to two additional months, in which case we will notify you.

Recipients of Personal Data

We may disclose personal data to the following categories of recipients:

  • Group companies and affiliates
  • Fund administrator
  • IT/cloud service providers
  • Legal, tax, and compliance advisors
  • Background screening providers
  • Recruitment platforms and agencies
  • Regulatory or governmental authorities (e.g. GFSC, FCA)

Wincent engages third-party service providers to process personal data on our behalf under written agreements that comply with Article 28 GDPR. These providers are contractually required to implement appropriate technical and organisational measures, maintain confidentiality, and act only on our instructions.

Sharing and Transfers of Personal Data

Wincent does not sell Personal Data to any third parties.

Wincent may share Personal Data internally within the Wincent Group and externally with service providers, financial institutions, legal advisors, and, where legally required, government authorities. As Wincent is a global entity, Wincent might also transfer Personal Data outside the European Economic Area (EEA). In such cases, Wincent ensures appropriate safeguards are applied to the data transferred in compliance with Chapter V of GDPR (standard contractual clauses or adequacy decisions) and Article 82 - Article 85 of DPA.

You may request further information or a copy of the safeguards in place for international data transfers by contacting us at GDPR@wincent.co.

Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, following Article 5(1)(e) GDPR. Typically, the timeframe for retention is up to five years post-termination of agreements unless a longer retention period is required by law or a competent authority via an official communication to Wincent. Additionally, in order to maintain accuracy and integrity, Wincent commits to promptly rectify any inaccuracies in personal data as per GDPR Article 5(1)(d).

Unless data is the object of a Suspicious Activity Report, and has actively been escalated to the relevant authorities. In such a case, data will be treated in compliance with the indications of the authorities, and in full compliance with regulatory requirements.

Requirement to Provide Data

In many cases, the provision of personal data is a legal or contractual requirement. For example, we cannot process an investment without completing required due diligence or assess a job application without essential candidate information. Failure to provide such data may prevent us from onboarding you, entering into a contract, or proceeding with your investment.

Automated Decision-Making

Where we carry out automated decision-making or profiling that may have a legal or similarly significant effect on you (within the meaning of Article 22 of the GDPR), we implement robust safeguards to protect your rights ensuring that all such automated decisions are subject to meaningful human intervention by a suitably senior and qualified employee with full authority to override or amend the outcome of the automated processing.

Use of AI Systems in Recruitment

Due to the high volume of applications we receive, Wincent uses EU Systems as part of the recruitment process, including filtering job applications and evaluating candidates. Specifically, if you apply for a role at Wincent:

  • CV Review. We may use a tool that gives insights on how well your CV corresponds to the criteria for the role you applied for. These criteria are chosen by our recruiters, not AI. All insights are reviewed by a human, who takes the decision whether to pass your application through to the next stage individually. This improves outcomes by ensuring you receive a timely response to your application and that a recruiter does not miss relevant experience on your CV; and
  • Interview Stage. With your express permission at the start of an interview, we may use an AI system that transcribes the interview, which allows your interviewer to focus more on you instead of notetaking. We may also use an AI system to provide a summary of the transcript so we can keep track of what was discussed, which helps later interviewers avoid repeating questions. A recruiter may consider this transcript and summary in deciding whether to pass your application through to the next round.

Where we use AI Systems for these purposes, we have commercial agreements with providers which ensure your personal data will not be sold or used for training purposes. We also monitor the operation of all such AI Systems and ensure a human has oversight; AI Systems do not result in decisions being taken regarding your application automatically. Any decision about whether to progress your application is taken by a human.

We will let you know if we intend to use an AI System in connection with your application at the point of applying to us. If you have any questions about how Wincent uses AI Systems in connection with your application and/or to process your personal data, please contact: gdpr@wincent.co.

If we make a decision about your application, you can contact gdpr@wincent.co to request an explanation of how AI Systems contributed to the decision. If you make such a request, kindly provide the following information to enable us to process it without delay:

  • Your name;
  • The post you applied for;
  • When you applied for the post;
  • The stage of the recruitment process you reached; and
  • The outcome of your candidacy.

Data Breach Notification

In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Articles 33 and 34 of the GDPR.

Complaints and Supervisory Authority Contact

You may lodge a complaint with your local Data Protection Authority. The appropriate regulatory agency for Gibraltar is:

Gibraltar Regulatory Authority

Website: https://www.gra.gi/data-protection

Phone: (+350) 20074636

If you are based in the EEA, a list of authorities is available here:

Updates

We may update this Data Privacy Notice from time to time. The most current version will always be available on our website. Material changes will be communicated where appropriate.