OUR PRIVACY POLICY

Privacy Policy

For more information about our privacy policy at Belstark, please read below.

Privacy Policy

Belstark

Last updated: August 2026


1. Who we are

[Belstark Ltd] ("Belstark", "we", "us", "our") is a company incorporated in England and Wales (company number [NUMBER]), registered office [REGISTERED ADDRESS]. We provide AI governance and AI-risk due diligence services to investors, advisers and their legal teams.

For the personal data we control, we are the "controller" under the UK GDPR. We are registered with the Information Commissioner's Office (ICO) under registration number [ICO NUMBER].

Contact for privacy matters: [privacy@belstark.com] · [POSTAL ADDRESS]. [We have appointed a data protection point of contact / Data Protection Officer, reachable at the address above.]


2. When we are a controller and when we are a processor

Our role under data protection law depends on the activity:

  • We are a controller for personal data we decide how and why to process — for example, data about visitors to our website, prospects, client contacts, suppliers, and candidates. This Privacy Policy governs that data.

  • We are a processor when we process personal data contained in transaction materials, data rooms or systems that a client makes available to us so that we can perform a due diligence engagement. In that case our client (typically the acquirer or investor) is the controller, we act only on the client's documented instructions, and our processing is governed by a separate written data processing agreement, not by this Policy. If you are an individual whose data appears in a Target's records, the client controller (and, usually, the Target) is responsible for informing you about that processing.


3. Personal data we collect (as controller)

Depending on your relationship with us, we may collect:

  • Identity and contact data — name, job title, employer, email, phone, business address.

  • Client and prospect data — records of enquiries, engagements, correspondence, and the contact details of individuals at client, investor, adviser and Target organisations.

  • Website and technical data — IP address, device and browser information, and usage data collected via cookies and similar technologies (see our Cookie Policy).

  • Communications — the content of emails, forms, calls and meetings you have with us.

  • Marketing preferences — your consents and preferences.

We do not seek to collect special category data as a controller in the ordinary course. Please do not send us sensitive personal data unless we ask for it.


4. How we collect it

  • Directly from you (enquiries, forms, correspondence, engagements).

  • Automatically when you use our website (cookies and analytics).

  • From third parties and public sources, such as business contact databases, professional networks, referrals and publicly available registers, for legitimate business development.


5. Why we use it, and our legal bases

PurposeLegal basis (UK GDPR)Providing and administering our servicesPerformance of a contract; legitimate interestsResponding to enquiriesLegitimate interests; steps prior to a contractBusiness development and marketing to organisationsLegitimate interests (and consent where required, e.g. certain electronic marketing)Managing our relationship, invoicing and recordsContract; legitimate interests; legal obligationComplying with legal, regulatory and accounting obligationsLegal obligationSecurity, and establishing, exercising or defending legal claimsLegitimate interests; legal obligation

Where we rely on legitimate interests, our interest is in operating, promoting and protecting our business; we balance this against your rights. You can ask us for more detail on this balancing.


6. Who we share it with

We may share personal data with:

  • Service providers and sub-processors who support our business — including IT, hosting, cloud storage, email, analytics, CRM, and artificial-intelligence tools we use to assist in delivering our services. These providers act on our instructions under appropriate contracts.

  • Professional advisers (lawyers, accountants, insurers).

  • Authorities, regulators or courts where required by law.

  • A buyer or successor in the event of a business reorganisation or sale.

We do not sell your personal data.

Where we use AI or cloud tools to process personal data, we assess each provider for confidentiality, security and, where relevant, whether they use your data to train models. Sub-processor details are available on request.


7. International transfers

Some of our providers are located outside the UK. Where personal data is transferred outside the UK, we rely on an adequacy decision where available, or on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for a copy of the relevant safeguards.


8. How long we keep it

We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Typical periods: client and financial records for [6–7] years after the end of the relationship (to meet legal and tax requirements); enquiries and prospect data for [24] months from last contact; and website analytics data as set out in our Cookie Policy. Data processed on behalf of a client under a data processing agreement is retained and deleted in accordance with that agreement and the client's instructions.


9. Security

We maintain appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, secure hosting, confidentiality obligations and staff training. No system is completely secure, but we take reasonable steps to prevent unauthorised access, loss or misuse.


10. Your rights

Under the UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict or object to processing (including objecting to direct marketing at any time); data portability; and to withdraw consent where we rely on it. Where we act as a processor for a client, please direct requests to that client controller; we will assist them as required.

To exercise your rights, contact us at [info@belstark.com]. We will respond within one month. You can also complain to the ICO (ico.org.uk, 0303 123 1113), though we would welcome the chance to address your concerns first.


11. EU representative (Article 27 EU GDPR)

Where our processing is subject to the EU GDPR — for example, where we process the personal data of individuals in the EU or EEA in connection with our services — and we do not have an establishment in the EU, we have appointed a representative in the EU under Article 27 EU GDPR:

[EU REPRESENTATIVE NAME] [EU REPRESENTATIVE ADDRESS, MEMBER STATE] [EU REPRESENTATIVE EMAIL]

Individuals in the EU/EEA may contact our EU representative on any matter relating to our processing of their personal data under the EU GDPR.

Note for your solicitor: whether Article 27 is triggered by processing personal data found in a Target's EU data room (as opposed to offering goods/services to, or monitoring, EU data subjects) is fact-specific under Article 3(2) EU GDPR. Please confirm applicability and appoint a representative before this section goes live. The same analysis affects whether a UK representative is needed for any purely-EU controller you work with.


12. Changes

We may update this Policy from time to time. The current version is always available here with its "last updated" date.

Belstark · [Belstark Ltd] · Company number [NUMBER] · ICO registration [ICO NUMBER] · [privacy@belstark.com] · [URL]

Privacy Policy

Belstark

Last updated: August 2026


1. Who we are

[Belstark Ltd] ("Belstark", "we", "us", "our") is a company incorporated in England and Wales (company number [NUMBER]), registered office [REGISTERED ADDRESS]. We provide AI governance and AI-risk due diligence services to investors, advisers and their legal teams.

For the personal data we control, we are the "controller" under the UK GDPR. We are registered with the Information Commissioner's Office (ICO) under registration number [ICO NUMBER].

Contact for privacy matters: [privacy@belstark.com] · [POSTAL ADDRESS]. [We have appointed a data protection point of contact / Data Protection Officer, reachable at the address above.]


2. When we are a controller and when we are a processor

Our role under data protection law depends on the activity:

  • We are a controller for personal data we decide how and why to process — for example, data about visitors to our website, prospects, client contacts, suppliers, and candidates. This Privacy Policy governs that data.

  • We are a processor when we process personal data contained in transaction materials, data rooms or systems that a client makes available to us so that we can perform a due diligence engagement. In that case our client (typically the acquirer or investor) is the controller, we act only on the client's documented instructions, and our processing is governed by a separate written data processing agreement, not by this Policy. If you are an individual whose data appears in a Target's records, the client controller (and, usually, the Target) is responsible for informing you about that processing.


3. Personal data we collect (as controller)

Depending on your relationship with us, we may collect:

  • Identity and contact data — name, job title, employer, email, phone, business address.

  • Client and prospect data — records of enquiries, engagements, correspondence, and the contact details of individuals at client, investor, adviser and Target organisations.

  • Website and technical data — IP address, device and browser information, and usage data collected via cookies and similar technologies (see our Cookie Policy).

  • Communications — the content of emails, forms, calls and meetings you have with us.

  • Marketing preferences — your consents and preferences.

We do not seek to collect special category data as a controller in the ordinary course. Please do not send us sensitive personal data unless we ask for it.


4. How we collect it

  • Directly from you (enquiries, forms, correspondence, engagements).

  • Automatically when you use our website (cookies and analytics).

  • From third parties and public sources, such as business contact databases, professional networks, referrals and publicly available registers, for legitimate business development.


5. Why we use it, and our legal bases

PurposeLegal basis (UK GDPR)Providing and administering our servicesPerformance of a contract; legitimate interestsResponding to enquiriesLegitimate interests; steps prior to a contractBusiness development and marketing to organisationsLegitimate interests (and consent where required, e.g. certain electronic marketing)Managing our relationship, invoicing and recordsContract; legitimate interests; legal obligationComplying with legal, regulatory and accounting obligationsLegal obligationSecurity, and establishing, exercising or defending legal claimsLegitimate interests; legal obligation

Where we rely on legitimate interests, our interest is in operating, promoting and protecting our business; we balance this against your rights. You can ask us for more detail on this balancing.


6. Who we share it with

We may share personal data with:

  • Service providers and sub-processors who support our business — including IT, hosting, cloud storage, email, analytics, CRM, and artificial-intelligence tools we use to assist in delivering our services. These providers act on our instructions under appropriate contracts.

  • Professional advisers (lawyers, accountants, insurers).

  • Authorities, regulators or courts where required by law.

  • A buyer or successor in the event of a business reorganisation or sale.

We do not sell your personal data.

Where we use AI or cloud tools to process personal data, we assess each provider for confidentiality, security and, where relevant, whether they use your data to train models. Sub-processor details are available on request.


7. International transfers

Some of our providers are located outside the UK. Where personal data is transferred outside the UK, we rely on an adequacy decision where available, or on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for a copy of the relevant safeguards.


8. How long we keep it

We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Typical periods: client and financial records for [6–7] years after the end of the relationship (to meet legal and tax requirements); enquiries and prospect data for [24] months from last contact; and website analytics data as set out in our Cookie Policy. Data processed on behalf of a client under a data processing agreement is retained and deleted in accordance with that agreement and the client's instructions.


9. Security

We maintain appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, secure hosting, confidentiality obligations and staff training. No system is completely secure, but we take reasonable steps to prevent unauthorised access, loss or misuse.


10. Your rights

Under the UK GDPR you have the right to: access your data; have inaccurate data corrected; have data erased in certain circumstances; restrict or object to processing (including objecting to direct marketing at any time); data portability; and to withdraw consent where we rely on it. Where we act as a processor for a client, please direct requests to that client controller; we will assist them as required.

To exercise your rights, contact us at [info@belstark.com]. We will respond within one month. You can also complain to the ICO (ico.org.uk, 0303 123 1113), though we would welcome the chance to address your concerns first.


11. EU representative (Article 27 EU GDPR)

Where our processing is subject to the EU GDPR — for example, where we process the personal data of individuals in the EU or EEA in connection with our services — and we do not have an establishment in the EU, we have appointed a representative in the EU under Article 27 EU GDPR:

[EU REPRESENTATIVE NAME] [EU REPRESENTATIVE ADDRESS, MEMBER STATE] [EU REPRESENTATIVE EMAIL]

Individuals in the EU/EEA may contact our EU representative on any matter relating to our processing of their personal data under the EU GDPR.

Note for your solicitor: whether Article 27 is triggered by processing personal data found in a Target's EU data room (as opposed to offering goods/services to, or monitoring, EU data subjects) is fact-specific under Article 3(2) EU GDPR. Please confirm applicability and appoint a representative before this section goes live. The same analysis affects whether a UK representative is needed for any purely-EU controller you work with.


12. Changes

We may update this Policy from time to time. The current version is always available here with its "last updated" date.

Belstark · [Belstark Ltd] · Company number [NUMBER] · ICO registration [ICO NUMBER] · [privacy@belstark.com] · [URL]