Skip to content
Capital BlueprintOperating System
Platform
Solutions
Fund managersFund administratorsFamily officesCompliance & governanceCapital Blueprint ConnectPricing
Capabilities
Fund administrationInvestor lifecycleEntities & complianceCompliance Regulatory GatekeeperData & integrationsReporting & communicationsOperational governanceSpecialist assets
Security
Company
Why Us
Sign inBook a walkthrough

Capital Blueprint Connect · Legal

Connect privacy notice

How the Capital Blueprint Connect mobile companion handles information used to authenticate access, protect trusted devices, present approval requests and control connected sessions.

Effective date
1 September 2026
Document version
Version 1.0 · Controlled testing
Publication status
Published for controlled testing · Review before production launch

On this page

ScopeWho is responsibleInformation we processDevice permissionsPurposes and legal basesSharing and service providersInternational transfersRetentionSecurityYour choices and rightsChildrenChangesContact
Connect overviewConnect terms of usePrivacy noticeData subject rightsTerms of useCookie preferences

Trust requires clear boundaries around information.

Capital Blueprint Connect is the companion authentication and approval application for Capital Blueprint OS. This notice explains what the mobile application processes, why it is needed, how device permissions are used, and the choices available to users. It should be read with the privacy notice of the subscriber organisation that invited or authorised you to use Connect.
01

Scope

This notice applies when you install, register or use Capital Blueprint Connect; enrol a trusted device; respond to an authentication or approval request; review connected sessions or security activity; or contact us about the application.

Controlled-testing positionConnect is currently in controlled testing. Test builds may keep account, device, session and workflow information locally on the device using encrypted platform storage and an application database. When a subscriber environment is connected, relevant records will also be exchanged with the Capital Blueprint identity and workflow services described in this notice.
02

Who is responsible

Subscriber organisation
The fund administrator, fund manager, family office or other organisation providing access generally determines which users, investors, applications, workflows and approval policies apply. It will normally act as controller for information processed through its tenant.
Capital Blueprint
Capital Blueprint generally acts as processor or service provider for subscriber-controlled information. We may act as controller for application security, account administration, fraud prevention, support, service telemetry and our legal obligations.
Device platform
Apple or Google may independently process app-store, operating-system, notification, location or device-security information under their own terms and privacy notices.

Questions about a specific fund, investor record, transaction or tenant instruction should normally be directed to the subscriber organisation first.

03

Information we process

CategoryExamplesWhy it is used
Identity and accountName, email address, account type, tenant membership, role and account status.Register the identity, establish access and present the correct tenant context.
Trusted deviceDevice name, platform, operating-system version, app version, device identifier, key status, enrolment and last activity.Bind trust to a device, support multiple devices and allow independent revocation.
Authentication and sessionLogin requests, requesting application, browser or device context, session identifiers, timestamps, status and revocation events.Confirm access, display connected sessions and respond to suspicious activity.
Approval contextRequest identifier, workflow type, fund or investor context, amount, currency, policy, decision, actor and time.Allow an authorised person to understand and confirm or reject a material action.
Security and auditRegistration, recovery, permission, authentication, decision and revocation events; integrity and error information.Protect the service, investigate incidents and preserve accountable evidence.
SupportMessages, diagnostic information and correspondence you provide.Resolve support requests and maintain service quality.

Connect is not designed to collect contacts, photographs, media libraries or microphone recordings.

04

Device permissions

Notifications
Used for time-sensitive login requests, approval requests and security alerts. You can change notification permission in device settings, but doing so may delay awareness of a request.
Foreground location
When you grant permission, approximate or precise location context may be attached to authentication, session or approval audit information while Connect is in use. Connect does not request continuous background location in the current application configuration.
Biometrics and device passcode
Connect asks the operating system to authenticate you before protected access or decisions. Facial, fingerprint and passcode templates remain under the control of the device platform. Connect receives the result of the check, not the raw biometric template or passcode.
Secure storage
Session credentials and stable installation identifiers are stored using protected operating-system storage. The application database stores operational records and hashed session references needed for the controlled experience.

Permissions can be reviewed or withdrawn through device settings. Some security functions may not operate without the relevant permission.

05

Purposes and legal bases

Depending on the relationship, jurisdiction and subscriber instruction, information is processed to perform the service contract; follow the subscriber's documented instructions; protect legitimate interests in secure access, fraud prevention and service integrity; comply with legal obligations; and, where required, on the basis of consent for device permissions such as location or notifications.

Connect does not sell personal information and is not designed to use authentication or approval information for third-party behavioural advertising.

06

Sharing and service providers

Information may be made available to the subscriber organisation and its authorised users; Capital Blueprint personnel who require access for security, implementation or support; hosting, notification, monitoring and infrastructure providers acting under contract; professional advisers, auditors or insurers where necessary; and authorities where disclosure is legally required.

Access is intended to be limited by tenant, role, purpose and operational need. A current production subprocessor list will be made available before commercial launch and incorporated into applicable customer agreements.

07

International transfers

Capital Blueprint, a subscriber organisation or an authorised service provider may process information in a country different from your own. Where required, contractual safeguards, transfer assessments and other lawful mechanisms will be used. Subscriber-specific hosting and transfer arrangements are governed by the applicable service and data-processing agreements.

08

Retention and deletion

Information is retained only for as long as required for the relevant account, security, audit, contractual and legal purposes. Retention periods may differ for active sessions, trusted-device records, authentication events, approval evidence and support records. Subscriber-controlled records follow the subscriber's instructions and applicable retention obligations.

Signing out removes the current mobile session but does not necessarily remove connected-application sessions, audit evidence or the underlying identity. Uninstalling the app removes application data from that device but may not delete records held by a subscriber or the connected service.

09

Security

Connect is designed to use device authentication, protected credential storage, hashed session references, device-specific trust, revocation controls, encryption in transit for connected services, tenant and role boundaries, security monitoring and auditable events. No system can guarantee absolute security. Users should protect their device, install updates promptly and report unexpected requests or suspected compromise.

10

Your choices and rights

Subject to applicable law, you may have rights to access, correct, delete, restrict or object to processing, obtain portability, withdraw consent and complain to a supervisory authority. Requests concerning subscriber-controlled information should be sent to the subscriber organisation. You may also contact us at compliance@capital-blueprint.com.

Account and data deletion requestsUse our Data Subject Rights page to request partial deletion, full eligible erasure, or deletion of a Connect account and associated personal information. We may need to verify your identity and coordinate with the subscriber controller. Certain security, financial, transaction or audit records may need to be retained where required by law or a valid subscriber obligation.
11

Children

Connect is intended for authorised business users and investors and is not directed to children. We do not knowingly offer the application to anyone below the minimum age required to use the service or provide relevant consent in their jurisdiction.

12

Changes to this notice

We may update this notice as Connect moves from controlled testing into connected production use, as features or service providers change, or to reflect legal requirements. The effective date and version will be updated, and material changes will be communicated where required.

13

Contact

Capital Blueprint
Privacy and compliance enquiries: compliance@capital-blueprint.com
General enquiries: contact Capital Blueprint

If your concern relates to a subscriber tenant, fund, investor relationship or approval instruction, include the subscriber name and relevant reference without sending passwords, recovery codes or other authentication secrets.

Capital BlueprintOS

The operating system for private capital and complex wealth. Connect operations, experience and control without losing the context behind the work.

Platform

  • Overview
  • Security & governance
  • Book a walkthrough

Solutions

  • Fund managers
  • Fund administrators
  • Family offices
  • Compliance teams
  • Capital Blueprint Connect

Company

  • Product vision
  • Contact
  • Sign in

© 2026 Capital Blueprint. All rights reserved.

PrivacyData rightsTermsCookie preferencesContact

Website content is provided for informational purposes only and does not constitute legal, tax, investment or regulatory advice. Specific controls, integrations, hosting arrangements, certifications and regulatory requirements should be confirmed during solution design.