GDPR Transparency statement

Bamboo Capital Partners and Subsidiaries




Bamboo Capital Partners and Subsidiaries have issued below Privacy Statement in the light of the enactment of GDPR, the new data protection and privacy regulation of the European Union (EU).

Data Protection Information

With the following information, we would like to give you an overview of how we will process your data and of your rights according to data privacy laws. The details on what data will be processed and which method will be used depend significantly on the services applied for or agreed upon.

Who Is Responsible for Data Processing and How Can I Contact Them?

The unit responsible is and you can reach our group of companies at:

Bamboo Capital Partners
7, Rue Robert Stümper,

L-2557 Luxembourg
+352 26 09 57

What Sources and Data Do We Use?

We process personal data that we obtain from our business clients and suppliers in the context of business relationships. We also process – insofar as necessary to provide our services and organize our procurement of services – personal data that we obtain from publicly accessible sources, (e.g. debt registers, commercial and association registers, press, internet) or that is legitimately transferred between Bamboo Capital Partners and its subsidiaries or from other third parties (e.g. event organizations).

Relevant data is personal information of contact persons from our clients and suppliers (e.g. name, address and other contact details, date and place of birth, and nationality), and identification data (e.g. ID card details). Furthermore, this can also be order data (e.g. payment order), data from the fulfillment of our contractual obligations (e.g. sales and order data in payment and investment transactions), marketing and sales data, documentation data (e.g. meeting protocols), and other data similar to the categories mentioned.

What Do We Process Your Data for (Purpose of Processing) and On What Legal Basis?

We process personal data in accordance with the provisions of the European General Data Protection Regulation (GDPR):

a) For fulfillment of contractual obligations (Art. 6 para. 1b of the GDPR)

Data is processed in order to provide and receive services in the context of carrying out our contracts with our clients and suppliers or to carry out pre-contractual measures that occur as part of a request. The purposes of data processing are primarily in compliance with the specific services provided or received. You can find more specific details about the purposes of data processing in the relevant contract documents and terms and conditions.

b) In the context of balancing interests (Art. 6 para. 1f of the GDPR)

Where required, we process your data beyond the actual fulfillment of the contract for the purposes of the legitimate interests pursued by us or a third party. Examples:

  • Consulting and exchanging data with third parties (e.g. debt register to investigate creditworthiness and credit risks)
  • Reviewing and optimizing procedures for needs assessment for the purpose of direct client discussions
  • Marketing or market and opinion research, unless you have objected to the use of your data
  • Asserting legal claims and defense in legal disputes
  • Guarantee of our company’s IT security and IT operation
  • Prevention and clarification of crimes
  • Video surveillance to protect the right of owner of premises to keep out trespassers or for collecting evidence in hold-ups or fraud
  • Measures for building and site security (e.g. access controls)
  • Measures for ensuring the right of owner of premises to keep out trespassers
  • Measures for business management and further development of services and products
  • Risk control in Bamboo Capital Partners

In addition, we obtain personal data from publicly available sources for client acquisition purposes.

c) As a result of your consent (Art. 6 para. 1a of the GDPR)

As long as you have granted us consent to process your personal data for certain purposes (e.g. analysis of certain activities for marketing purposes), this processing is legal on the basis of your consent. Consent given can be withdrawn at any time. This also applies to withdrawing declarations of consent that were given to us before the GDPR came into force, i.e. before May 25, 2018. Withdrawal of consent does not affect the legality of data processed prior to withdrawal.

d) Due to statutory provisions (Art. 6 para. 1c of the GDPR) or in the public interest (Art. 6 para. 1e of the GDPR)

Furthermore, as an asset manager in the field of development investments offering professionally-managed investment solutions to private, institutional and public investors, we are subject to various legal obligations, meaning statutory requirements and financial services provider regulatory requirements. Purposes of processing include assessment of creditworthiness, identity and age checks, fraud and money laundering prevention, fulfilling control and reporting obligations under fiscal laws, and measuring and managing risks within Bamboo Capital Partners.

Who Receives My Data?

Within Bamboo Capital Partners and its subsidiaries, every unit that requires your data to fulfill our contractual and legal obligations will have access to it. Service providers and vicarious agents appointed by us can also receive access to data for the purposes given, if they maintain confidentiality. These are companies in the categories of banking services, IT services, logistics, printing services, telecommunications, collection, advice and consulting, and sales and marketing.

Will Data Be Transferred to a Third Country or an International Organization?

Your data may be shared with Bamboo Capital Partners subsidiaries and/or specialized IT service providers. As such, your data may be transferred to countries outside the European Economic Area (EEA). Personal data is transferred outside the EEA on the basis of declarations of adequacy or other appropriate safeguards, in particular standard data protection clauses adopted by the European Commission.

Please contact us if you would like to request to see a copy of the specific safeguards applied to the export of your information (Article 13 para 1f of the GDPR).

Security of Processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, we make reasonable efforts to protect personal data against accidental and illegal destruction and loss. We strive to ensure that personal data is used properly and protected from unauthorized access, use or disclosure. We use a combination of process, technology and physical security controls to protect personal data from unauthorized access, use or disclosure.

In addition, access to personal data is restricted to employees, contractors, and agents who need such information to perform their assigned functions and to develop or improve our services.

For How Long Will My Data Be Stored?

We will process and store your personal data for as long as it is necessary in order to fulfill our contractual and statutory obligations. It should be noted here that our business relationship is a long-term obligation, which is set up on the basis of periods of years.

If the data is no longer required in order to fulfill contractual or statutory obligations, it is deleted, unless its further processing is required – for a limited time – for the following purposes:

– Fulfilling obligations to preserve records according to commercial and tax law.

What Data Privacy Rights Do I Have?

Every data subject has the right to access according to Article 15 GDPR (Article 8 FADP), the right to rectification according to Article 16 GDPR (Article 5 FADP), the right to erasure according to Article 17 GDPR (Article 5 FADP), the right to restrict processing according to Article 18 GDPR (Articles 12, 13, 15 FADP), the right of object according to Article 21 GDPR (Article 4 FADP), and if applicable – the right to data portability according to Article 20 GDPR. Furthermore, if applicable on you, there is also a right to lodge a complaint with an appropriate data privacy regulatory authority (Article 77 GDPR).

On grounds relating to your particular situation, you shall have the right of objection, at any time to processing of your personal data which is based on Article 6 para 1 e of the GDPR (data processing in the public interest) and Article 6 para1 f of the GDPR (data processing based on balancing interests). If you submit an objection, we will no longer process your personal data unless we can give evidence of mandatory, legitimate reasons for processing, which outweigh your interests, rights, and freedoms, or processing serves the enforcement, exercise, or defense of interests. Please note, that in such cases we may not be able to continue to provide services and maintain a business relation.

You can withdraw consent granted to us for the processing of personal data at any time. This also applies to withdrawing declarations of consent that were made to us before the GDPR came into force, i.e. before May 25, 2018. Please note that the withdrawal only applies to the future. Processing that was carried out before the withdrawal is not affected by it.

The objection or withdrawal does not need to be made in a particular form and should ideally be addressed to the contact details given above.

Right to lodge a complaint with a supervisory authority (Article 13 para 2 d, 77 para 1 GDPR)

As the controller, we are obliged to notify the data subject of the right to lodge a complaint with a supervisory authority, Article 13 para 2 d of the GDPR. The right to lodge a complaint with a supervisory authority is regulated by Article 77 para 1 of the GDPR. According to this provision, without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes the GDPR. The right to lodge a complaint with a supervisory authority was only limited by the law of the Union in such way, that it can only be exercised before a single supervisory authority (Recital 141 Sentence 1 GDPR). This rule is intended to avoid double complaints of the same data subject in the same matter. If a data subject wants to lodge a complaint about us, we therefore ask to contact only a single supervisory authority.

This arrangement is intended to avoid double complaints in the same case by the same data subject. Therefore, if an affected person wants to complain about us, we ask you to contact only one regulatory body.

To What Extent Is There Automated Decision-Making or Profiling?

In establishing and carrying out a business relationship, we generally do not use any automated decision-making nor any Profiling pursuant to Article 22 GDPR. If we use this procedure in individual cases, we will inform you of this separately, as long as this is a legal requirement.