Gemcorp Capital Management Limited
Privacy Notice
May 2026
Introduction
This Privacy Notice sets out Gemcorp Capital Management Limited, Gemcorp Capital Management Middle East Limited and Gemcorp Sub-Holding Company Limited (collectively, “Gemcorp” or “the Firm”)’s commitment to data protection, and individual rights and obligations to personal data. Where applicable, it draws on the rules and principles under the General Data Protection Regulation 2016 (“GDPR”), Data Protection Act 2018 (“DPA”) and ADGM Data Protection Regulations 2021 (“ADGM DPR”) (referred to throughout as “Data protection Laws”). After Brexit, UK organisations handling personal data must comply with both the GDPR (if there is any connection to the EEA from a data protection perspective) and the DPA. As a result, the UK’s data protection framework remains largely unchanged from its pre-Brexit state.
Gemcorp is classified as a ‘Controller’ and a ‘Processor’ of personal data depending on your relationship with us and subject to the Data Protection Laws.
The Data Protection Laws apply to the collection, processing and storage of personal data undertaken by organisations within the European Economic Area (EEA) and ADGM, as well as to firms outside the EEA or ADGM that handle personal data relating to the offering of services to individuals in the EEA or ADGM.
Data Protection Laws have two key purposes: (a) to set guidelines for the collection, processing and protection of personal data and (b) to give individuals certain rights in relation to their personal data (such as to access and correct it and object to further processing)
This Privacy Notice is intended to ensure that prospective investors, clients or similar contacts (including such prospective investor’s, client’s or similar contact’s individual directors, officers, employees and/or owners) and other individuals outside of our organisation such as the representatives of our service providers(“you”, or “your”) are aware of the categories of your personal data Gemcorp (“we”, “us” or “our”) may collect, how we collect it, what we use it for and with whom we share it with.
“Personal data” means any information relating to you but does not include data where you can no longer be identified from it such as anonymised aggregated data.
We will be a data controller in respect of your relationship with us. A data controller is responsible for deciding how to hold and use personal data about you. We may process your personal data ourselves or through others acting as data processors on our behalf.
We may provide supplemental privacy notices on specific occasions when we are collecting or processing personal data about you so that you are fully aware of how and why we are using your personal data. These supplemental notices should be read together with this Privacy Notice. If you have any questions about this Privacy Notice, please contact Compliance at compliance@gemcorp.net.
What information do we collect about you and what do we use it for?
Personal data held by us or on our behalf may include, but is not necessarily limited to:
- Personal data collected as part of our due diligence and onboarding processes and to comply with ongoing legal obligations such as name, signature, postal address, email address, date and place of birth, nationality, professional or employment related information, source of funds/wealth details, tax identification, other contact details, account numbers (or functional equivalent) and transaction details (including transactions with our affiliates), your tax or other government issued ID numbers, utility bills for the purposes of address verification, photographic identification and verification such as copies of your passport, passport number, visa information and driver’s license, information relating to your status as an ultimate beneficial owner of an entity, a politically exposed person or a designated individual on a sanctions list.
- Personal data relating to you in connection with our ongoing relationship with you, such as via correspondence and calls, and in connection with the administration of our relationship with you. Telephone calls with you may be recorded for the purpose of record keeping, security and training.
- Technical data collected when you visit our website such as your IP address, browser type and version, time zone setting and location. We also provide you with an option to accept, reject or manage cookies that may be dropped on your device while you navigate our website. Details of such cookies can be found in the section on ‘cookies’ below.
- Your name, contact details, image collected in relation to your attendance at our offices or at an event or seminar organised by the Firm or its business partners
The purposes for which we may collect, store and use personal data about you and our ‘lawful basis’ for processing such data are set out in the table below. The law specifies certain ‘lawful bases’ for which we are allowed to use your personal data.
| Purpose | Lawful basis for processing |
To undertake pre-investment steps including but not limited to:
| In order to take steps prior to the contract between you and us/the fund in which you may invest, compliance with applicable legal obligations and our legitimate interests in establishing your preferred investment strategies. |
| To correspond with you. | Our legitimate interests in responding to your enquiry, contacting you in relation to the services you provide or otherwise communicating with you in the course of our business |
| To undertake business development and marketing activities in relation to making suggestions and recommendations to you about products or services that may be of interest to you. This may include direct electronic marketing | Our legitimate interests in promoting our products and services and growing our business. We only send direct electronic marketing where individuals have consented to this or as otherwise permitted by the law. Individuals can opt-out of receiving such messages at any time by using the opt-out mechanisms that may be available in those messages or by contacting Compliance |
| To disclose information to other third parties such as service providers, legal advisors, auditors and technology providers and regulatory authorities to comply with any legal obligation imposed on us or in order to pursue our legitimate business interests. | Compliance with applicable legal obligations. Our legitimate interests in conducting our business in a proper manner. |
| To maintain our records. | Our legitimate interests in conducting our business in a proper manner |
| Our legitimate interests in studying how our services are used, keeping our website updated and relevant, to develop our business and inform our marketing strategy |
In addition to the uses above, please note that we may also process your information where we are required by law to do so or if we reasonably believe that it is necessary to protect our rights and/or to comply with judicial or regulatory proceedings, a court order or other legal processes.
Special categories of personal data
There are more limited bases for processing special category personal data. This is personal data which reveals or contains racial or ethnic origin, political opinions, religious and philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life and sexual orientation. We do not intend to actively collect special category data about you. Whilst we will use reasonable efforts to limit our holding of such data, please be aware that we may hold such data incidentally. For example, where:
- you volunteer special category data to us or one of our processors, such as if you send us an email containing special category data;
- documents gathered for legal and regulatory purposes contain special category data, such as a due diligence search from public sources which includes special category data.
What if you do not provide the personal data requested?
Unless and until you make a decision to invest or otherwise engage in a business transaction with us or invest in one of our investment products (at which point we will send you a copy of any relevant privacy notice) you are not required to provide us with any information, although please note that our website may automatically collect certain technical data (further details on this are in the 'How do we collect this information?' section).
Change of purpose
We will only use your personal data for the purposes for which we collected it (as identified above in the ‘Purpose’ column), unless we reasonably consider that we need to use it for another reason which is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
How do we collect this information?
We typically collect personal data about you when you provide information to us or others acting on our behalf when communicating or transacting with us in writing, electronically, by telephone or otherwise. For instance, when you request product documentation, forms of literature, request information from us or otherwise correspond with us. As you interact with our website, we may automatically collect technical data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies.
- public sources or information vendors;
- introducers, distributors or other intermediaries who market or provide services to you.
With who will we share your information?
We may share your personal data with a third party where this is required by law, where it is necessary to fulfil our contract with you, or where we have another legitimate interest in doing so. We may need to share your personal data with:
- other entities within our group as part of our regular reporting activities in company performance, in the context of a business reorganisation or group restructuring exercise or for assistance in relation to marketing and business development;
- introducers, distributors or other intermediaries who market or provide services to you;
- professional advisers including lawyers, bankers, auditors and insurers to the extent such information is relevant to their performance of their services;
- regulators;
- tax authorities;
- cloud service providers; and
- any of our service providers where such information is relevant to their performance of such services;
We may share your personal data with third parties, for example in the context of the possible sale or restructuring of the business. We may also need to share your personal data with a regulator or to otherwise comply with applicable law or judicial process or if we reasonably believe that disclosure is necessary to protection our rights and/or to comply with judicial or regulatory proceedings, a court order or other legal process.
We may transfer the personal data we collect about you to certain non-EEA countries including in particular Angola, Switzerland and the United Arab Emirates, where the parties listed above are based for the purposes outlined in the table above. Those countries may not have the same standard of data protection laws as the EEA or ADGM.
Where this is the case, we will (or will require a processor to) put in place appropriate safeguards such as standard contractual clauses to ensure that your personal data is treated in a manner that is consistent with and respects the applicable laws on data protection. If you require further information about this you can request it from Compliance.
Use of cookies
During your interaction with our website, we may use cookies to improve security, enhance functionality, and remember your preferences. A cookie is a small text file containing a unique identification number that helps our website recognise your browser and respond accordingly.
We use the following types of cookies:
| Name: | Domain | Purpose: | Expires: | Type |
| .AspNetCore.Antiforgery.* | http://gemcorpcapital.com/ | Cross-site request forgery (CSRF) protection. Set by Microsoft ASP.NET. | Session | Necessary |
| ARRAffinity | http://gemcorpcapital.com/ | Set by Azure App Service. Routes user requests to the same server instance throughout a session. | Session | Necessary |
ARRAffinitySameSite | http://gemcorpcapital.com/ | Load balancing cookie set by Windows Azure Cloud. Ensures requests are routed to the same server within a session. | Session | Necessary |
PHPSESSID | http://gemcorp.profundcom.net/ | Native PHP cookie. Stores a unique session ID to manage the user's session. Deleted when all browser windows are closed. | Session | Necessary |
VISITOR_PRIVACY_METADATA | https://www.youtube.com/ | Set by YouTube to store the user's cookie consent state for the current domain. | 6 months | Necessary |
| _ga | http://gemcorpcapital.com/ | Installed by Google Analytics. Calculates visitor, session and campaign data. Assigns a randomly generated number to recognise unique visitors | 13 months | Analytics |
| _ga_* | http://gemcorpcapital.com/ | Set by Google Analytics to store and count page views. | 13 months | Analytics |
| YSC | https://www.youtube.com/ | Set by YouTube to track views of embedded videos. | Session | Analytics |
| VISITOR_INFO1_LIVE | https://www.youtube.com/ | Set by YouTube to measure bandwidth and determine whether the user gets the new or old player interface. | 6 months | Functional |
| ytidb::LAST_RESULT_ENTRY_KEY | https://www.youtube.com/ | Used by YouTube to store the last search result entry clicked by the user, to improve future search relevance. | 30 days | Functional |
| __Secure-BUCKET | https://www.youtube.com/ | It is a YouTube cookie used for distributing users into groups (bucketing) as part of A/B testing and gradual feature rollouts. | 6 months | Functional |
| __Secure-YNID | https://www.youtube.com/ | YouTube cookie used to protect user security and prevent fraud, especially during the login process. | 6 months | Advertisement |
| __Secure-ROLLOUT_TOKEN | Youtube.com | Set by YouTube to manage feature rollout and A/B experimentation, ensuring a consistent experience during staged rollouts. | 6 months | Advertisement |
| PFCE | http://gemcorp.profundcom.net/ | Set by ProFundCom. Encodes the email parameter from the last tracked link opened in an email campaign. When a recipient opens an email and clicks a tracked link, the link contents are encoded in this cookie so that ProFundCom can identify the individual when they subsequently access other non-email content on the site. | 1 month | Marketing |
| PFCT | http://gemcorp.profundcom.ne/ | Set by ProFundCom. Records the time the cookie was last set, enabling ProFundCom to track the last time any digital content was accessed and tracked by a known individual. | 1 month | Marketing |
You may choose to adjust your browser settings to refuse cookies or to notify you when a cookie is being set. However, please note that if you refuse certain cookies, parts of the website may not function as intended.
How long will we retain your information?
We will retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements and our legitimate interest in maintaining such personal information in our records. This will normally include any period during which we are dealing or expect to deal with you and what we consider to be a suitable period thereafter for our internal record-keeping purposes. In doing this we will have regard to the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. Generally, we will keep information relevant to our dealings with you for seven years following the last date of activity or longer as required by applicable law or regulation. In the ADGM, this may be for a period of six years following the last date of activity or longer as required by applicable law or regulation.
In some circumstances your personal data may be anonymised so that it can no longer be associated with you, in which case it is no longer personal data..
Once we no longer require your personal data for the purposes for which it was collected, we will securely destroy your personal data in accordance with applicable laws and regulations.
Once we no longer require your personal data for the purposes for which it was collected, we will securely destroy your personal data in accordance with Applicable Laws.
Accuracy of information
It is important that the personal data we hold about you is accurate and current. Please let us know if your personal data which we hold changes during your relationship with us.
Your rights in relation to your information
You have rights as an individual which you can exercise in relation to the information we hold about you under certain circumstances. These rights are to:
- request access to your personal data (commonly known as a “data subject access request”) and request certain information in relation to its processing;
- request rectification of your personal data;
- request the erasure of your personal data;
- request the restriction of processing of your personal data;
- object to the processing of your personal data;
- request the transfer of your personal data to another party.
- object to automated processing, including profiling which produces legal or other seriously impactful consequences concerning you.
If you would like to exercise one of these rights, please contact Compliance. You also have the right to make a complaint at any time to a supervisory authority for data protection issues.
Fees
You will not usually have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is manifestly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure you have your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
Right to withdraw consent
In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your personal data for a specific purpose, you have the right to withdraw your consent for that specific processing at any time, and this will not affect the lawfulness of processing before the consent has been withdrawn. To withdraw your consent, please contact Compliance. Once we have received notification that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless we now have an alternative legal basis for doing so
Changes to this privacy notice
We reserve the right to update this Privacy Notice at any time, and we will make an updated copy of such Privacy Notice available to you on our website, therefore please regularly review this. We may also notify you in other ways from time to time about the processing of your personal data.
Further information
This Privacy Notice was written with brevity and clarity in mind and is not an exhaustive account of all aspects of our collection and use of personal data. If you require any further information, please do not hesitate to contact Compliance.
Contacting us about this Notice or making a complaint
If you have any queries about the contents of this Notice, wish to exercise any of your Data Subject rights, or would like to raise a complaint or comment, please contact Compliance.
If you are not satisfied with our response or believe we are not processing your Personal Data in accordance with the Applicable Laws, you can escalate your complaint to the applicable supervisory authority via the details below:
Information Commissioner’s Office (ICO)
Contact details:
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, England.
+44 303 123 1113
icocasework@ico.org.uk
ADGM Commissioner of Data Protection Contact Details:
ADGM Authorities Building, ADGM Square, Al Maryah Island, PO Box 111999, Abu Dhabi, UAE Telephone: +97 123 338 888 data.protection@adgm.com