Skip to content
Capital BlueprintOperating System
Platform
Solutions
Fund managersFund administratorsFamily officesCompliance & governanceCapital Blueprint ConnectPricing
Capabilities
Fund administrationInvestor lifecycleEntities & complianceCompliance Regulatory GatekeeperData & integrationsReporting & communicationsOperational governanceSpecialist assets
Security
Company
Why Us
Sign inBook a walkthrough

Legal · Privacy

Privacy notice

A detailed explanation of how personal data is handled across the Capital Blueprint website, enterprise platform, onboarding, compliance, reporting, document, signature and support workflows.

Effective date
3 August 2026
Document version
Version 1.0 · Approved
Publication status
Replace bracketed placeholders and obtain legal approval.

On this page

Scope and document hierarchyWho we areController and processor rolesPersonal data we processWhere data comes fromPurposes and legal basesSensitive and regulated dataRisk scoring and decisionsWho receives dataService providers and subprocessorsInternational transfersRetention and deletionSecurity and incident handlingYour data protection rightsCustomer responsibilitiesChildrenChanges to this noticeContact and complaints
Privacy noticeData subject rightsTerms of useCookie preferences

Privacy depends on context, purpose and responsibility.

Capital Blueprint OS supports multi-tenant operations involving investors, clients, users, representatives, beneficial owners, advisers and service providers. This notice explains our own processing and the circumstances in which an enterprise customer controls the processing carried out through the platform. It is designed to be read with the applicable order form, master services agreement, data processing agreement and customer privacy notices.
01

Scope and document hierarchy

This notice applies to personal data processed when you:

  • visit or interact with the Capital Blueprint marketing website;
  • request information, a demonstration, security material or commercial contact;
  • create, administer or use an authorised Capital Blueprint OS account;
  • participate in onboarding, risk assessment, compliance, reporting, document, electronic-signature, support or service workflows;
  • appear in records submitted by an enterprise customer, authorised user, adviser, investor, client or service provider; or
  • communicate with our commercial, implementation, security, support or legal teams.
Contract documents take priorityFor enterprise services, the signed order form, master services agreement, data processing agreement, security schedule, service-level terms and any customer-specific instructions govern the service. Where those documents conflict with this public notice, the signed contractual documents apply to the extent permitted by law.

This notice does not replace a customer's own privacy notice. An investor, applicant, beneficial owner, employee or client whose information was entered by a Capital Blueprint customer should normally contact that customer first.

02

Who we are

The organisation responsible for the Capital Blueprint website and Capital Blueprint OS and the independent processing described in this notice is:

Capital Blueprint Group
14 Warbreck Road, Lansdowne, Cape Town, Western Cape, 7780, South Africa
South African company registration: 2026/698677/07
Privacy contact: compliance@capital-blueprint.com
Data Protection Officer: Aamirah Speelman | compliance@capital-blueprint.com

“Capital Blueprint”, “we”, “us” and “our” refer to that legal entity and, where clearly stated, its authorised affiliates.

03

Controller and processor roles

Website and direct business relationship
We generally act as controller for website visits, demonstration requests, sales contacts, account administration, billing contacts, service security, fraud prevention, support management and our own legal obligations.
Customer tenant data
For personal data an enterprise customer uploads, imports, creates or directs us to process in its tenant, the customer generally acts as controller and Capital Blueprint acts as processor under a data processing agreement.
Customer configuration and authorised users
The customer determines permitted users, roles, data scope, workflow configuration, retention instructions and the lawful basis for processing customer tenant data.
Limited independent processing
We may act as controller for narrowly defined purposes such as platform security, abuse detection, service communications, billing records, legal claims and compliance with binding law, even where those activities relate to customer accounts.

Actual roles depend on the facts and the service configuration. Any joint-controller arrangement must be expressly agreed in writing; it is not created merely because the platform enables collaboration.

04

Personal data we process

CategoryExamplesTypical context
Identity and contactName, business contact details, address, date and place of birth, nationality, identifiers, profile photograph and language.Accounts, onboarding, KYC/AML, investor and entity records.
Organisation and authorityEmployer, role, directorship, trustee or fiduciary capacity, authorised representative status, signatory authority and delegation.Access control, approvals, governance and electronic signing.
Account and authenticationUser ID, tenant membership, role, authentication factors, session metadata, login history, password-reset and access-review records.Identity, security and audit.
Financial and investmentCommitments, holdings, transactions, capital activity, bank details, tax information, portfolio and reporting data.Fund, investor, portfolio, accounting and reporting workflows.
Compliance and riskKYC/AML records, PEP or sanctions indicators, beneficial ownership, source of wealth or funds, risk factors, review notes, remediation and evidence.Onboarding, customer risk assessment and regulatory workflows.
Entity and ownershipLegal entities, trusts, foundations, partnerships, SPVs, ownership percentages, control relationships, UBO information and governance records.Entity management, ownership analysis and compliance.
Documents and signaturesIdentity documents, agreements, tax forms, statements, uploaded files, signatures, certificates, timestamps, signing events and audit trails.Document vault, onboarding, reporting and trust-signing workflows.
Communications and serviceEmails, messages, cases, questions, notifications, meeting notes, support requests and response history.Investor relations, servicing, implementation and support.
Technical and usageIP address, device and browser information, diagnostic events, API and webhook logs, import/export activity, page or feature usage and error data.Security, service operation, troubleshooting and improvement.
Website preference dataCookie choices, consent record, language, accessibility or display preferences and campaign-source data where permitted.Website operation and consent management.

The exact fields depend on enabled modules, customer configuration, jurisdiction, participant type and workflow. Customers should configure forms and imports to collect only information that is necessary for a defined purpose.

05

Where data comes from

We may receive personal data:

  • directly from you, including through forms, account registration, support, uploads and electronic-signature steps;
  • from the enterprise customer responsible for the tenant;
  • from an investor, applicant, representative, employer, adviser, administrator or authorised service provider;
  • through configured imports, APIs, webhooks and integrations;
  • from public or licensed sources selected by the customer, such as company registers, sanctions or PEP data, where lawfully used;
  • from our security, authentication, hosting, communications and support systems; and
  • from cookies or similar technologies in accordance with your preferences.

Where data is not obtained directly from the individual, the relevant controller is responsible for providing required transparency information unless a lawful exception applies.

06

Purposes and legal bases

PurposeTypical dataLegal basis where we are controller
Respond to enquiries and provide demonstrationsBusiness identity, contact, organisation, role and areas of interest.Steps requested before a contract; legitimate interests in business development; consent where specifically required.
Create and administer accountsIdentity, business contact, role, tenant, authentication and access records.Performance of contract; legitimate interests in secure service administration.
Operate and secure the serviceTechnical, authentication, audit, diagnostic and support data.Performance of contract; legitimate interests in availability, integrity, misuse prevention and defence of claims; legal obligation where applicable.
Provide implementation and supportContacts, configuration, tickets, meeting records, diagnostics and authorised sample data.Performance of contract; legitimate interests in service delivery and improvement.
Billing and commercial administrationCustomer contacts, order details, invoices, payment and tax records.Performance of contract; legal obligation; legitimate interests in financial administration.
Send service and security communicationsAccount and administrator contacts, incidents, maintenance and policy updates.Performance of contract; legitimate interests; legal obligation.
Send optional marketingBusiness contact, interests, event and engagement data.Consent where required; otherwise legitimate interests subject to applicable direct-marketing law and an effective opt-out.
Comply with law and protect rightsRecords relevant to legal obligations, investigations, disputes or regulatory requests.Legal obligation; public interest where applicable; legitimate interests in establishing, exercising or defending legal claims.
Website preferences and optional analyticsConsent choices, device and interaction data.Strictly necessary operation; consent for non-essential storage or access unless a lawful exemption applies.

When we process customer tenant data as processor, the customer determines the legal basis and purpose. We process that data only on documented instructions, subject to the data processing agreement and applicable law.

07

Sensitive, criminal-offence and regulated data

Depending on customer configuration, the platform may contain special categories of personal data, criminal-offence information, government identifiers, financial account data, source-of-wealth information, sanctions or PEP review material, and confidential family or ownership information.

Restricted collectionCustomers must not collect sensitive or criminal-offence data merely because a field exists. They must identify a lawful condition, apply appropriate access restrictions, configure retention, provide required notices and obtain professional advice where necessary.

Capital Blueprint provides configurable controls for scoped access, workflow review, reason capture, audit history and evidence handling. These capabilities do not determine whether a customer's processing is lawful.

08

Risk scoring, profiling and material decisions

Customer risk assessments, KYC/AML indicators, ownership thresholds, transaction warnings, regulatory-health views and similar features may organise facts, configured rules and review states. Unless expressly agreed and legally permitted, Capital Blueprint does not use platform outputs to make solely automated decisions that produce legal or similarly significant effects for individuals.

  • Scores and status labels are decision-support inputs, not legal conclusions.
  • Customers remain responsible for the methodology, data quality, thresholds and human review used in their workflows.
  • Material acceptance, rejection, restriction, filing, reporting or transaction decisions should be reviewed by authorised personnel.
  • Where applicable law grants rights relating to automated decisions or profiling, the relevant controller must provide the required information and review mechanism.
09

Who receives personal data

Personal data may be made available to:

  • the enterprise customer and its authorised users, subject to configured tenant, module, role, object and action permissions;
  • investors, clients, representatives, advisers, administrators or service providers invited into a controlled workflow;
  • Capital Blueprint personnel and contractors who need access for authorised implementation, security, support, legal or operational purposes;
  • hosting, infrastructure, authentication, communications, monitoring, support and other approved service providers;
  • professional advisers, auditors, insurers and financing counterparties where necessary and lawful;
  • courts, regulators, law-enforcement bodies or public authorities where disclosure is legally required or necessary to protect rights; and
  • a buyer, investor or successor in a properly governed corporate transaction, subject to confidentiality and applicable law.

We do not sell personal data to advertisers. We do not permit service providers to use customer tenant data for their own unrelated marketing.

10

Service providers and subprocessors

Where Capital Blueprint acts as processor, it may appoint subprocessors to provide hosting, storage, authentication, email delivery, support, monitoring, document processing, backup or other necessary services. The contractual subprocessor process, notice period and objection mechanism are set out in the data processing agreement.

A current subprocessor register can be requested by contacting support@capital-blueprint.com. This register identifies the provider, service purpose, processing location and relevant transfer mechanism.

Customers are responsible for reviewing and approving optional integrations they enable. A provider selected or directly contracted by a customer may act under the customer's instructions rather than as a Capital Blueprint subprocessor.

11

International data transfers

Personal data may be processed outside the country in which it was collected where the service architecture, support model, customer configuration or selected integration requires this. For transfers from the European Economic Area to a country not recognised as providing adequate protection, appropriate safeguards may include the European Commission's standard contractual clauses, supplementary technical and organisational measures, or another lawful transfer mechanism.

The applicable hosting regions, data-residency options, transfer locations and safeguards must be confirmed in the order form, data processing agreement and subprocessor register. No public statement on residency or localisation should be treated as a contractual commitment unless incorporated into signed terms.

12

Retention, export and deletion

We keep personal data only for as long as needed for the relevant purpose, subject to legal, contractual, security, audit and dispute requirements.

Record typeRetention approachOwner of instruction
Marketing enquiriesUntil the enquiry is resolved, followed by a limited relationship-management period or earlier objection.Capital Blueprint as controller.
Account and security recordsFor the active account and a proportionate period afterwards for security, audit and claims.Capital Blueprint and customer, according to role.
Customer tenant dataDuring the subscription and then according to customer instructions, contractual exit periods, backup cycles and legal holds.Customer as controller, subject to contract and law.
Billing and contract recordsFor statutory accounting, tax, audit and limitation periods.Capital Blueprint as controller.
Consent recordsFor the preference period and a proportionate evidentiary period.Capital Blueprint as controller.

Deletion from active systems may not immediately remove data from secured backups. Backup copies should be isolated from ordinary use and expire through documented cycles unless preservation is required by law or legal hold.

13

Security, confidentiality and incident handling

We use technical and organisational measures designed to protect personal data against unauthorised access, alteration, loss, disclosure or destruction. Measures may include tenant-scoped access, role and action permissions, multi-factor authentication, encryption controls, logging, monitoring, secure development, vulnerability management, backups, support-access controls and incident-response procedures.

No absolute security guaranteeNo internet, cloud or software service can guarantee complete security. Specific architecture, encryption, hosting, assurance reports, recovery objectives and regulatory requirements are confirmed during solution design and in signed service documents.

Customers must promptly report suspected compromise, unauthorised access, erroneous disclosure or misuse through compliance@capital-blueprint.com. Where we act as processor, we notify the customer of a personal-data breach in accordance with the data processing agreement so the customer can assess its own notification obligations.

14

Your data protection rights

Subject to applicable law and exceptions, you may have rights to:

  • receive transparent information about processing;
  • access personal data and obtain a copy;
  • correct inaccurate or incomplete data;
  • request deletion or restriction;
  • object to processing based on legitimate interests or to direct marketing;
  • withdraw consent without affecting prior lawful processing;
  • receive certain data in a portable format;
  • request human intervention in qualifying automated-decision situations; and
  • complain to a competent supervisory authority.

To exercise rights relating to data held in a customer tenant, contact that customer first. We will assist the customer as required by the data processing agreement. For processing controlled directly by Capital Blueprint, contact compliance@capital-blueprint.com. We may verify identity and authority before acting on a request.

15

Enterprise customer responsibilities

Each enterprise customer is responsible for:

  • having a lawful basis for the personal data it enters, imports, collects or discloses through the service;
  • providing required privacy notices and obtaining valid consent where consent is the appropriate basis;
  • configuring access, roles, approval paths, retention, exports and integrations appropriately;
  • ensuring authorised users process data only for permitted purposes;
  • maintaining accurate data and resolving known quality or identity issues;
  • responding to data-subject requests, regulatory enquiries and customer-specific incidents;
  • completing required impact, vendor, transfer, outsourcing or regulatory assessments; and
  • not using the service to make unlawful, discriminatory or unreviewed high-impact decisions.

Capital Blueprint may provide security, privacy and audit information to support due diligence, but the customer remains responsible for its own legal and regulatory obligations.

16

Children

The website and enterprise platform are intended for organisations and authorised professional users, not for children. Do not submit a child's personal data unless the processing is necessary, lawful, covered by the customer's documented instructions and protected by appropriate safeguards. Public demonstration or contact forms must never be used to submit information about minors.

17

Changes to this notice

We may update this notice to reflect changes in law, service functionality, processing practices or company structure. Material changes should be communicated through the website, account administrator notices or another appropriate channel before they take effect where required.

The effective date and version shown above identify the current publication.

18

Contact, unresolved concerns and complaints

Questions and requests may be sent to:

Privacy team
compliance@capital-blueprint.com
support@capital-blueprint.com

If you are not satisfied with our response, you may lodge a complaint with the competent supervisory authority. In Luxembourg, the supervisory authority is the Commission nationale pour la protection des données (CNPD). Its complaint information is available on the CNPD website. You may also complain to the authority in the country where you live, work or believe an infringement occurred.

Cookie choices are managed separately on the Cookie preferences page.

Capital BlueprintOS

The operating system for private capital and complex wealth. Connect operations, experience and control without losing the context behind the work.

Platform

  • Overview
  • Security & governance
  • Book a walkthrough

Solutions

  • Fund managers
  • Fund administrators
  • Family offices
  • Compliance teams
  • Capital Blueprint Connect

Company

  • Product vision
  • Contact
  • Sign in

© 2026 Capital Blueprint. All rights reserved.

PrivacyData rightsTermsCookie preferencesContact

Website content is provided for informational purposes only and does not constitute legal, tax, investment or regulatory advice. Specific controls, integrations, hosting arrangements, certifications and regulatory requirements should be confirmed during solution design.