Privacy depends on context, purpose and responsibility.
Scope and document hierarchy
This notice applies to personal data processed when you:
- visit or interact with the Capital Blueprint marketing website;
- request information, a demonstration, security material or commercial contact;
- create, administer or use an authorised Capital Blueprint OS account;
- participate in onboarding, risk assessment, compliance, reporting, document, electronic-signature, support or service workflows;
- appear in records submitted by an enterprise customer, authorised user, adviser, investor, client or service provider; or
- communicate with our commercial, implementation, security, support or legal teams.
This notice does not replace a customer's own privacy notice. An investor, applicant, beneficial owner, employee or client whose information was entered by a Capital Blueprint customer should normally contact that customer first.
Who we are
The organisation responsible for the Capital Blueprint website and Capital Blueprint OS and the independent processing described in this notice is:
Capital Blueprint Group
14 Warbreck Road, Lansdowne, Cape Town, Western Cape, 7780, South Africa
South African company registration: 2026/698677/07
Privacy contact: compliance@capital-blueprint.com
Data Protection Officer: Aamirah Speelman | compliance@capital-blueprint.com
“Capital Blueprint”, “we”, “us” and “our” refer to that legal entity and, where clearly stated, its authorised affiliates.
Controller and processor roles
- Website and direct business relationship
- We generally act as controller for website visits, demonstration requests, sales contacts, account administration, billing contacts, service security, fraud prevention, support management and our own legal obligations.
- Customer tenant data
- For personal data an enterprise customer uploads, imports, creates or directs us to process in its tenant, the customer generally acts as controller and Capital Blueprint acts as processor under a data processing agreement.
- Customer configuration and authorised users
- The customer determines permitted users, roles, data scope, workflow configuration, retention instructions and the lawful basis for processing customer tenant data.
- Limited independent processing
- We may act as controller for narrowly defined purposes such as platform security, abuse detection, service communications, billing records, legal claims and compliance with binding law, even where those activities relate to customer accounts.
Actual roles depend on the facts and the service configuration. Any joint-controller arrangement must be expressly agreed in writing; it is not created merely because the platform enables collaboration.
Personal data we process
| Category | Examples | Typical context |
|---|---|---|
| Identity and contact | Name, business contact details, address, date and place of birth, nationality, identifiers, profile photograph and language. | Accounts, onboarding, KYC/AML, investor and entity records. |
| Organisation and authority | Employer, role, directorship, trustee or fiduciary capacity, authorised representative status, signatory authority and delegation. | Access control, approvals, governance and electronic signing. |
| Account and authentication | User ID, tenant membership, role, authentication factors, session metadata, login history, password-reset and access-review records. | Identity, security and audit. |
| Financial and investment | Commitments, holdings, transactions, capital activity, bank details, tax information, portfolio and reporting data. | Fund, investor, portfolio, accounting and reporting workflows. |
| Compliance and risk | KYC/AML records, PEP or sanctions indicators, beneficial ownership, source of wealth or funds, risk factors, review notes, remediation and evidence. | Onboarding, customer risk assessment and regulatory workflows. |
| Entity and ownership | Legal entities, trusts, foundations, partnerships, SPVs, ownership percentages, control relationships, UBO information and governance records. | Entity management, ownership analysis and compliance. |
| Documents and signatures | Identity documents, agreements, tax forms, statements, uploaded files, signatures, certificates, timestamps, signing events and audit trails. | Document vault, onboarding, reporting and trust-signing workflows. |
| Communications and service | Emails, messages, cases, questions, notifications, meeting notes, support requests and response history. | Investor relations, servicing, implementation and support. |
| Technical and usage | IP address, device and browser information, diagnostic events, API and webhook logs, import/export activity, page or feature usage and error data. | Security, service operation, troubleshooting and improvement. |
| Website preference data | Cookie choices, consent record, language, accessibility or display preferences and campaign-source data where permitted. | Website operation and consent management. |
The exact fields depend on enabled modules, customer configuration, jurisdiction, participant type and workflow. Customers should configure forms and imports to collect only information that is necessary for a defined purpose.
Where data comes from
We may receive personal data:
- directly from you, including through forms, account registration, support, uploads and electronic-signature steps;
- from the enterprise customer responsible for the tenant;
- from an investor, applicant, representative, employer, adviser, administrator or authorised service provider;
- through configured imports, APIs, webhooks and integrations;
- from public or licensed sources selected by the customer, such as company registers, sanctions or PEP data, where lawfully used;
- from our security, authentication, hosting, communications and support systems; and
- from cookies or similar technologies in accordance with your preferences.
Where data is not obtained directly from the individual, the relevant controller is responsible for providing required transparency information unless a lawful exception applies.
Purposes and legal bases
| Purpose | Typical data | Legal basis where we are controller |
|---|---|---|
| Respond to enquiries and provide demonstrations | Business identity, contact, organisation, role and areas of interest. | Steps requested before a contract; legitimate interests in business development; consent where specifically required. |
| Create and administer accounts | Identity, business contact, role, tenant, authentication and access records. | Performance of contract; legitimate interests in secure service administration. |
| Operate and secure the service | Technical, authentication, audit, diagnostic and support data. | Performance of contract; legitimate interests in availability, integrity, misuse prevention and defence of claims; legal obligation where applicable. |
| Provide implementation and support | Contacts, configuration, tickets, meeting records, diagnostics and authorised sample data. | Performance of contract; legitimate interests in service delivery and improvement. |
| Billing and commercial administration | Customer contacts, order details, invoices, payment and tax records. | Performance of contract; legal obligation; legitimate interests in financial administration. |
| Send service and security communications | Account and administrator contacts, incidents, maintenance and policy updates. | Performance of contract; legitimate interests; legal obligation. |
| Send optional marketing | Business contact, interests, event and engagement data. | Consent where required; otherwise legitimate interests subject to applicable direct-marketing law and an effective opt-out. |
| Comply with law and protect rights | Records relevant to legal obligations, investigations, disputes or regulatory requests. | Legal obligation; public interest where applicable; legitimate interests in establishing, exercising or defending legal claims. |
| Website preferences and optional analytics | Consent choices, device and interaction data. | Strictly necessary operation; consent for non-essential storage or access unless a lawful exemption applies. |
When we process customer tenant data as processor, the customer determines the legal basis and purpose. We process that data only on documented instructions, subject to the data processing agreement and applicable law.
Sensitive, criminal-offence and regulated data
Depending on customer configuration, the platform may contain special categories of personal data, criminal-offence information, government identifiers, financial account data, source-of-wealth information, sanctions or PEP review material, and confidential family or ownership information.
Capital Blueprint provides configurable controls for scoped access, workflow review, reason capture, audit history and evidence handling. These capabilities do not determine whether a customer's processing is lawful.
Risk scoring, profiling and material decisions
Customer risk assessments, KYC/AML indicators, ownership thresholds, transaction warnings, regulatory-health views and similar features may organise facts, configured rules and review states. Unless expressly agreed and legally permitted, Capital Blueprint does not use platform outputs to make solely automated decisions that produce legal or similarly significant effects for individuals.
- Scores and status labels are decision-support inputs, not legal conclusions.
- Customers remain responsible for the methodology, data quality, thresholds and human review used in their workflows.
- Material acceptance, rejection, restriction, filing, reporting or transaction decisions should be reviewed by authorised personnel.
- Where applicable law grants rights relating to automated decisions or profiling, the relevant controller must provide the required information and review mechanism.
Service providers and subprocessors
Where Capital Blueprint acts as processor, it may appoint subprocessors to provide hosting, storage, authentication, email delivery, support, monitoring, document processing, backup or other necessary services. The contractual subprocessor process, notice period and objection mechanism are set out in the data processing agreement.
A current subprocessor register can be requested by contacting support@capital-blueprint.com. This register identifies the provider, service purpose, processing location and relevant transfer mechanism.
Customers are responsible for reviewing and approving optional integrations they enable. A provider selected or directly contracted by a customer may act under the customer's instructions rather than as a Capital Blueprint subprocessor.
International data transfers
Personal data may be processed outside the country in which it was collected where the service architecture, support model, customer configuration or selected integration requires this. For transfers from the European Economic Area to a country not recognised as providing adequate protection, appropriate safeguards may include the European Commission's standard contractual clauses, supplementary technical and organisational measures, or another lawful transfer mechanism.
The applicable hosting regions, data-residency options, transfer locations and safeguards must be confirmed in the order form, data processing agreement and subprocessor register. No public statement on residency or localisation should be treated as a contractual commitment unless incorporated into signed terms.
Retention, export and deletion
We keep personal data only for as long as needed for the relevant purpose, subject to legal, contractual, security, audit and dispute requirements.
| Record type | Retention approach | Owner of instruction |
|---|---|---|
| Marketing enquiries | Until the enquiry is resolved, followed by a limited relationship-management period or earlier objection. | Capital Blueprint as controller. |
| Account and security records | For the active account and a proportionate period afterwards for security, audit and claims. | Capital Blueprint and customer, according to role. |
| Customer tenant data | During the subscription and then according to customer instructions, contractual exit periods, backup cycles and legal holds. | Customer as controller, subject to contract and law. |
| Billing and contract records | For statutory accounting, tax, audit and limitation periods. | Capital Blueprint as controller. |
| Consent records | For the preference period and a proportionate evidentiary period. | Capital Blueprint as controller. |
Deletion from active systems may not immediately remove data from secured backups. Backup copies should be isolated from ordinary use and expire through documented cycles unless preservation is required by law or legal hold.
Security, confidentiality and incident handling
We use technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss, disclosure or destruction. Measures may include tenant-scoped access, role and action permissions, multi-factor authentication, encryption controls, logging, monitoring, secure development, vulnerability management, backups, support-access controls and incident-response procedures.
Customers must promptly report suspected compromise, unauthorised access, erroneous disclosure or misuse through compliance@capital-blueprint.com. Where we act as processor, we notify the customer of a personal-data breach in accordance with the data processing agreement so the customer can assess its own notification obligations.
Your data protection rights
Subject to applicable law and exceptions, you may have rights to:
- receive transparent information about processing;
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to processing based on legitimate interests or to direct marketing;
- withdraw consent without affecting prior lawful processing;
- receive certain data in a portable format;
- request human intervention in qualifying automated-decision situations; and
- complain to a competent supervisory authority.
To exercise rights relating to data held in a customer tenant, contact that customer first. We will assist the customer as required by the data processing agreement. For processing controlled directly by Capital Blueprint, contact compliance@capital-blueprint.com. We may verify identity and authority before acting on a request.
Enterprise customer responsibilities
Each enterprise customer is responsible for:
- having a lawful basis for the personal data it enters, imports, collects or discloses through the service;
- providing required privacy notices and obtaining valid consent where consent is the appropriate basis;
- configuring access, roles, approval paths, retention, exports and integrations appropriately;
- ensuring authorised users process data only for permitted purposes;
- maintaining accurate data and resolving known quality or identity issues;
- responding to data-subject requests, regulatory enquiries and customer-specific incidents;
- completing required impact, vendor, transfer, outsourcing or regulatory assessments; and
- not using the service to make unlawful, discriminatory or unreviewed high-impact decisions.
Capital Blueprint may provide security, privacy and audit information to support due diligence, but the customer remains responsible for its own legal and regulatory obligations.
Children
The website and enterprise platform are intended for organisations and authorised professional users, not for children. Do not submit a child's personal data unless the processing is necessary, lawful, covered by the customer's documented instructions and protected by appropriate safeguards. Public demonstration or contact forms must never be used to submit information about minors.
Changes to this notice
We may update this notice to reflect changes in law, service functionality, processing practices or company structure. Material changes should be communicated through the website, account administrator notices or another appropriate channel before they take effect where required.
The effective date and version shown above identify the current publication.
Contact, unresolved concerns and complaints
Questions and requests may be sent to:
Privacy team
compliance@capital-blueprint.com
support@capital-blueprint.com
If you are not satisfied with our response, you may lodge a complaint with the competent supervisory authority. In Luxembourg, the supervisory authority is the Commission nationale pour la protection des données (CNPD). Its complaint information is available on the CNPD website. You may also complain to the authority in the country where you live, work or believe an infringement occurred.
Cookie choices are managed separately on the Cookie preferences page.
