Trust requires clear boundaries around information.
Scope
This notice applies when you install, register or use Capital Blueprint Connect; enrol a trusted device; respond to an authentication or approval request; review connected sessions or security activity; or contact us about the application.
Who is responsible
- Subscriber organisation
- The fund administrator, fund manager, family office or other organisation providing access generally determines which users, investors, applications, workflows and approval policies apply. It will normally act as controller for information processed through its tenant.
- Capital Blueprint
- Capital Blueprint generally acts as processor or service provider for subscriber-controlled information. We may act as controller for application security, account administration, fraud prevention, support, service telemetry and our legal obligations.
- Device platform
- Apple or Google may independently process app-store, operating-system, notification, location or device-security information under their own terms and privacy notices.
Questions about a specific fund, investor record, transaction or tenant instruction should normally be directed to the subscriber organisation first.
Information we process
| Category | Examples | Why it is used |
|---|---|---|
| Identity and account | Name, email address, account type, tenant membership, role and account status. | Register the identity, establish access and present the correct tenant context. |
| Trusted device | Device name, platform, operating-system version, app version, device identifier, key status, enrolment and last activity. | Bind trust to a device, support multiple devices and allow independent revocation. |
| Authentication and session | Login requests, requesting application, browser or device context, session identifiers, timestamps, status and revocation events. | Confirm access, display connected sessions and respond to suspicious activity. |
| Approval context | Request identifier, workflow type, fund or investor context, amount, currency, policy, decision, actor and time. | Allow an authorised person to understand and confirm or reject a material action. |
| Security and audit | Registration, recovery, permission, authentication, decision and revocation events; integrity and error information. | Protect the service, investigate incidents and preserve accountable evidence. |
| Support | Messages, diagnostic information and correspondence you provide. | Resolve support requests and maintain service quality. |
Connect is not designed to collect contacts, photographs, media libraries or microphone recordings.
Device permissions
- Notifications
- Used for time-sensitive login requests, approval requests and security alerts. You can change notification permission in device settings, but doing so may delay awareness of a request.
- Foreground location
- When you grant permission, approximate or precise location context may be attached to authentication, session or approval audit information while Connect is in use. Connect does not request continuous background location in the current application configuration.
- Biometrics and device passcode
- Connect asks the operating system to authenticate you before protected access or decisions. Facial, fingerprint and passcode templates remain under the control of the device platform. Connect receives the result of the check, not the raw biometric template or passcode.
- Secure storage
- Session credentials and stable installation identifiers are stored using protected operating-system storage. The application database stores operational records and hashed session references needed for the controlled experience.
Permissions can be reviewed or withdrawn through device settings. Some security functions may not operate without the relevant permission.
Purposes and legal bases
Depending on the relationship, jurisdiction and subscriber instruction, information is processed to perform the service contract; follow the subscriber's documented instructions; protect legitimate interests in secure access, fraud prevention and service integrity; comply with legal obligations; and, where required, on the basis of consent for device permissions such as location or notifications.
Connect does not sell personal information and is not designed to use authentication or approval information for third-party behavioural advertising.
International transfers
Capital Blueprint, a subscriber organisation or an authorised service provider may process information in a country different from your own. Where required, contractual safeguards, transfer assessments and other lawful mechanisms will be used. Subscriber-specific hosting and transfer arrangements are governed by the applicable service and data-processing agreements.
Retention and deletion
Information is retained only for as long as required for the relevant account, security, audit, contractual and legal purposes. Retention periods may differ for active sessions, trusted-device records, authentication events, approval evidence and support records. Subscriber-controlled records follow the subscriber's instructions and applicable retention obligations.
Signing out removes the current mobile session but does not necessarily remove connected-application sessions, audit evidence or the underlying identity. Uninstalling the app removes application data from that device but may not delete records held by a subscriber or the connected service.
Security
Connect is designed to use device authentication, protected credential storage, hashed session references, device-specific trust, revocation controls, encryption in transit for connected services, tenant and role boundaries, security monitoring and auditable events. No system can guarantee absolute security. Users should protect their device, install updates promptly and report unexpected requests or suspected compromise.
Your choices and rights
Subject to applicable law, you may have rights to access, correct, delete, restrict or object to processing, obtain portability, withdraw consent and complain to a supervisory authority. Requests concerning subscriber-controlled information should be sent to the subscriber organisation. You may also contact us at compliance@capital-blueprint.com.
Children
Connect is intended for authorised business users and investors and is not directed to children. We do not knowingly offer the application to anyone below the minimum age required to use the service or provide relevant consent in their jurisdiction.
Changes to this notice
We may update this notice as Connect moves from controlled testing into connected production use, as features or service providers change, or to reflect legal requirements. The effective date and version will be updated, and material changes will be communicated where required.
Contact
Capital Blueprint
Privacy and compliance enquiries: compliance@capital-blueprint.com
General enquiries: contact Capital Blueprint
If your concern relates to a subscriber tenant, fund, investor relationship or approval instruction, include the subscriber name and relevant reference without sending passwords, recovery codes or other authentication secrets.
