VEV Services Limited - Privacy Notice

1. Introduction and what this Privacy Notice covers

This Privacy Notice has been drafted to address the data protection laws applicable in the European Union, including the EU General Data Protection Regulation (GDPR), and the United Kingdom, including the UK GDPR and the Data Protection Act 2018.

This Privacy Notice explains how VEV collects, uses, shares and protects personal data when you interact with us, and what rights you may have in respect of that personal data. VEV is committed to protecting privacy and processing personal data in accordance with applicable data protection laws.

This Privacy Notice may be relevant where you:

  • visit or use a VEV website or another VEV digital service that links to this notice;
  • are, or represent, a prospective or existing counterparty, customer, supplier or business partner of VEV, including as a director, officer, beneficial owner, authorised representative, agent or other associated individual;
  • register for or attend a VEV-hosted, sponsored or co-organised event, or are nominated as a delegate by your employer;
  • visit a VEV office or other VEV-operated site, or use visitor Wi-Fi made available by VEV; or
  • are otherwise in contact with VEV in a business or professional context, for example as a journalist, regulator or professional adviser.
  • directly from you, for example when you contact VEV, attend an event, apply for a role or communicate during a business relationship;
  • from your employer or the organisation you represent, for example when you are nominated as a counterparty contact, director, beneficial owner or authorised representative;
  • from service providers, including identity-verification, KYC, sanctions-screening, adverse-media, credit-reference, background-check, recruitment, professional-advisory, business-introduction and event-management providers;
  • from publicly available sources, including public registers, regulatory filings, court records, company registries, news media, professional networking sites , such as LinkedIn and sanctions and PEP lists;
  • from counterparties or transaction parties, including target companies and advisers in a corporate transaction; and
  • from information generated by VEV, including records of meetings, correspondence, calls, transactions, screening outcomes and internal analysis.
  • banks, financial institutions, credit-reference agencies, insurers and reinsurers;
  • commercial counterparties, brokers, intermediaries, exchanges, clearing houses or repositories, where relevant to VEV’s activities;
  • regulators, supervisory authorities, tax authorities, customs authorities, courts and other competent governmental, regulatory or judicial bodies;
  • law-enforcement and sanctions authorities;
  • our professional advisers, including auditors, lawyers, tax and accounting advisers and information-security consultants;
  • prospective purchasers, sellers, investors, joint-venture partners, lenders or other parties connected with corporate transactions, restructurings, joint ventures or financings, )and their professional advisers); and
  • another third party where you have specifically directed VEV to do so.
  • an adequacy decision by the relevant authority;
  • the transfer is made subject to appropriate safeguards
  • approved binding corporate rules approved by the competent supervisory authority are in place, where applicable; or
  • a specific legal derogation applies - used only on an exceptional, non-routine basis.
  • For individuals in the EEA: the authority in the place of habitual residence, place of work or place of the alleged infringement, and the supervisory authority for the relevant VEV controller; and
  • For individuals in the United Kingdom: the Information Commissioner’s Office.

There may be other circumstances in which VEV collects personal data and provides a separate privacy notice. Where a separate notice applies, that notice will govern the relevant processing.

2. Who we are

The terms “VEV”, “the Company”, “the Group”, “we”, “us” and “our” may be used for convenience. Unless the context requires otherwise, VEV means VEV Services Limited and those direct and indirect subsidiaries and affiliates that participate in the relevant processing, each of which is a separate legal entity.

The VEV entity responsible for processing personal data as controller depends on the relationship a person has with VEV and the relevant processing activity. The applicable controller, registered office and supervisory authority must be confirmed and published in the approved notice.

Controller

Registered office

Relevant supervisory authority

VEV Services Limited

Nova South, 160 Victoria Street, London, SW1E 5LB, United Kingdom

Information Commissioner’s Office (ICO)

VEV Platform Services France

505 route des Lucioles, 06560, Valbonne, France

Commission Nationale de l’Informatique et des Libertés (CNIL)

3. How to contact us

Questions about this Privacy Notice, requests to exercise data protection rights, and privacy concerns should be sent to: privacy@vev.com.

Postal correspondence may be sent to: VEV Services Limited, Manning House, 22 Carlisle Place, London SW1P 1JA.

4. When and how we collect personal data

The personal data VEV collects, and the reasons for collecting it, depend on how a person interacts with VEV. Principal interaction scenarios are described below.

4.1 When you use a VEV website or digital service

When you visit a VEV website or use a VEV digital service, VEV may collect limited technical data automatically, including IP address, browser type and version, operating system, device identifiers, referrer URL, pages visited and timestamps, together with cookie and similar-technology information described in Section 7 and the applicable Cookie Policy. Where you submit a contact form or enquiry, VEV may also collect the information you provide through that form.

4.2 When you use visitor Wi-Fi

If you connect to a VEV visitor Wi-Fi service, VEV or the relevant host may collect your name(s), business email address and company name to create your Wi-Fi account and manage access. During use, VEV may record the MAC address, IP address and visitor Wi-Fi username associated with the device. VEV uses this information to operate the service securely and investigate misuse or cyber-security incidents.

4.3 When you are, or represent, a prospective or existing business partner

If you are, or represent, a prospective or existing counterparty, customer, supplier or other business partner of VEV, VEV may collect personal data about you and, where applicable, individuals associated with the organisation you represent, such as directors, officers, beneficial owners and authorised representatives. This may include identification and contact details, professional information, financial information and identity-verification documents.

If required information is not provided, you or the organisation you represent may not be able to enter into or continue a business relationship with VEV.

4.4 When you apply for a role or other engagement

Where you apply for a role or other engagement with VEV, or are introduced by a recruitment agency or other intermediary, VEV may collect information described in our separate Fair Processing Notice for Job Applicants which will be made available to you. That notice will prevail over this notice for recruitment-related processing.

4.5 When you register for or attend an event

If you register for or attend an event hosted, sponsored or co-organised by VEV, VEV may collect registration details, including name, employer, job title and contact details. If VEV organises travel, accommodation or visas, VEV may also collect passport, visa and related travel information.

4.6 When you visit VEV premises

When you visit a VEV office or other premises, VEV may record your name, company name, arrival and departure times, and the name of your host in our visitor logs. For security reasons, premises may be monitored by CCTV in accordance with applicable signage and local requirements.

4.7 When you are connected with a corporate transaction

Where VEV is considering an acquisition, investment, divestment, financing, restructuring or other corporate transaction, VEV may collect personal data about directors, shareholders, officers, employees or other associated individuals of a target, investor, purchaser, seller or other transaction party. Such information may be obtained from public registers, professional advisers, data rooms, the transaction party, or the relevant organisations.

4.8 When you are granted or hold a power of attorney

If a VEV entity grants a power of attorney to you, VEV may collect identification, contact and authority information necessary to evidence, administer and rely on that authority.

5. What personal data we process, where we get it, and why

The table below sets out the categories of personal data we process, the purposes, the legal basis we rely on, and our rationale.

Category

Examples

Purpose

Lawful basis

Rationale / notes

Identification data

Name, employer, job title, nationality, date of birth; identity, residence and source-of-funds documents

KYC/AML checks; counterparty/transaction party identity verification; onboarding

Legal obligation; legitimate interest

Legal obligation: AML/KYC requirements. Legitimate interest:; verifying persons VEV transacts with as part of risk management function.

General business and compliance records

Business phone, email, address, messaging identifiers; relationship-management records; accounting, tax, insurance and risk-management data and records

Managing commercial relationships; communicating with counterparties; executing transactions; record-keeping; accounting; tax; insurance; governance; dealing with claims

Contract; legal obligation; legitimate interest

Contract: to communicate with you and where you are personally a party to an agreement. Legal obligation: accounting, tax and other statutory obligations. Legitimate interest: managing relationships, good governance, insurance requirements and risk management.

Professional, ownership, financial and compliance data

Role, signing authority, qualifications, beneficial-ownership information, bank details, sanctions, PEP and adverse-media screening results; criminal-conviction data where lawful

KYC onboarding and understanding counterparty/transaction party governance, ownership and authority; executing and settling transactions; credit and risk management; sanctions, AML, anti-bribery compliance; fraud prevention and crime detection; credit/risk management; accounting and tax records

Contract; legal obligation; legitimate interest; substantial public interest

Legal obligation: UBO identification required under AML directives; tax, accounting and regulatory record-keeping; sanctions, AML and anti-bribery laws mandate these checks. Contract: necessary to execute and settle trades. Legitimate interest: understanding authority structures of counterparties; credit and risk management. Substantial public interest: preventing financial crime. Special category note: criminal conviction data is processed only where lawful and subject to appropriate safeguards/additional conditions.

Communications data

Correspondence, emails, instant messages, call or meeting records and, where applicable, communications recordings

Maintaining business records; regulatory record-keeping where applicable; resolving disputes

Legal obligation; legitimate interests

Legal obligation: MiFID II, REMIT mandate recording of trade communications. Legitimate interest: accurate records and dispute resolution.

Event, travel and visit data

Registration details, passport/visa data; dietary, accessibility or health requirements

Organising events, travel and accommodation; visa support; accommodating your requirements

Legitimate interest; consent (explicit, for special category data); health and safety legal obligation

Legitimate interest: organising events and travel logistics. Explicit consent: health/dietary info. Visa data may reveal race/ethnicity — processed with your consent and at your request; Legal obligation: accessibility and health info needed to comply with HSE obligations – processed with your consent.

Website and device data

IP address, browser and device information, OS, pages visited, cookie identifiers

Website operation, security, performance monitoring, analytics (with consent)

Legitimate interests; consent

Legitimate interest: strictly necessary cookies ensure website functions securely. Consent: analytics, functional and advertising cookies set only with prior consent.

Visitor and security data

Visitor-log entries, CCTV footage and Wi-Fi connection logs

Physical security of premises; IT network integrity; incident investigation

Legitimate interest

Legitimate interest: protecting premises, people, visitors and systems.

Corporate transaction data

Director, shareholder, officer and employee information/data relating to transaction parties

Transaction due diligence; acquisitions, investments, divestments, financings, restructurings, reviewing key employee remuneration

Legitimate interest

Legitimate interest: making informed transaction and investment decisions and conducting proportionate due diligence.

Power of attorney data

Identification, contact and authority information

Evidencing and relying on authorities granted by VEV entities

Contract; legal obligation; legitimate interest

Contract: necessary to formalise the arrangement. Legal obligation: legal requirements around authority. Legitimate interest: facilitating authorised business operations.

Regulatory cooperation data

Data shared with courts, regulators, law-enforcement bodies and other authorities

Responding to binding and, where lawful and proportionate, non-binding requests from authorities

Legal obligation (binding); legitimate interest (non-binding)

Legal obligation: compliance with binding requests. Legitimate interest: cooperating with lawful proportionate non-binding requests.

5.1 Sources of personal data

VEV may obtain personal data:

5.2 Anonymisation and aggregation

VEV may convert personal data into statistical or aggregated form, or otherwise de-identify it, so that individuals cannot reasonably be identified. VEV may use properly anonymised information for research, analysis and statistical reporting without further notice, subject to applicable law.

6. Automated decision-making

VEV may use automated tools to assist us. Where the outcome of such a tool could have legal or similarly significant effects on you, the result is always subject to meaningful human review before any decision is taken, and we do not make such decisions on a solely automated basis.

7. Cookies

VEV websites and digital services may use cookies and similar technologies to distinguish users, operate securely, remember preferences and, where permitted, measure usage. Information about the cookies we use, their purposes, duration and recipients is set out in our Cookie Policy.

8. Marketing and event communications

From time to time, VEV may invite business contacts to events or send information that may be relevant or of interest to you in a professional capacity. Individuals may object to direct marketing at any time by contacting privacy@vev.com.

9. Who we share personal data with

9.1 Within VEV

VEV may share personal data with VEV entities where necessary for the purposes described in Section 5 of this notice, including centralised or shared functions such as IT, finance, Legal and Compliance, HR, treasury, risk, audit and corporate governance, for the management of our commercial relationships, for risk and exposure management and for regulatory reporting. Access is limited according to role, purpose and need to know.

9.2 Outside VEV

VEV may engage third parties to perform business functions such as IT support, hosting and cloud services, KYC and sanctions screening, background and credit checks, recruitment, event management, communications, physical security and travel management. Where a third party acts as processors on our behalf, VEV will ensure appropriate contractual, organisational and security measures are in place.

VEV may also share personal data with independent controllers, including:

10. International transfers

Personal data collected in the EEA, or the United Kingdom may be transferred to, stored in or processed in other countries where VEV entities, personnel or service providers or their staff operate. We take all steps reasonably necessary to ensure that personal data is treated securely and in accordance with this notice.

VEV will transfer personal data outside the EEA or the UK only where an applicable transfer mechanism or exception is available, which may include:

Where we rely on appropriate safeguards, we assess the level of protection in the destination country and put in place any additional measures needed to ensure your data remains adequately protected.

11. How we keep personal data secure

VEV will implement appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and accidental loss, destruction or damage. These measures may include encryption, access controls, multi-factor authentication, vulnerability management, service-provider due diligence, incident-response procedures, disaster-recovery arrangements and staff training, as appropriate to the risk and VEV’s actual control environment.

In the event of a personal data breach, VEV will assess the risk to individuals and take appropriate containment, investigation and remediation steps. Where required by applicable law, VEV will notify the competent supervisory authority and affected individuals within the applicable legal timeframes.

12. How long we keep personal data

VEV keeps personal data only for as long as reasonably necessary for the purposes for which it was collected, including compliance with legal, regulatory, tax, accounting, reporting, contractual and dispute-management requirements.

When determining retention periods, VEV considers the nature, sensitivity and volume of personal data; the purpose of processing; potential harm from unauthorised use or disclosure; applicable legal tax, accounting, reporting and regulatory obligations; contractual requirements; and relevant legitimate interests.

At the end of the applicable retention period, VEV will securely delete, destroy or anonymise personal data, subject to applicable law and technical constraints. Where data has been anonymised so that it can no longer be associated with you, we may continue to use the anonymised information without further notice to you.

13. Your rights

Subject to the conditions, exemptions and limitations of applicable data protection law, you have the following rights in respect of the personal data we hold about you. Please note that your ability to exercise these rights may be limited in circumstances where we are obliged to retain certain data.

Your right

What it means

Right to be informed

To receive information about who processes personal data, for what purposes, on what basis, with whom it is shared and how long it is retained. This notice is designed to give you this information.

Right of access

To obtain confirmation that we are processing your data and to receive a copy of the data we hold about you. Where compliance with your request would adversely affect the rights and freedoms of others (for example the privacy of our staff, counterparties or third parties), we may redact or withhold the relevant information.

Right to rectification

To require correction of inaccurate personal data or completion of incomplete personal data.

Right to erasure (“right to be forgotten”)

To require us to delete your personal data in defined circumstances (for example where the data is no longer necessary; consent is withdrawn and no other basis applies; or the data was unlawfully processed). We will not be able to erase your personal data where we need to retain it to comply with a legal, regulatory, tax or accounting obligation (for example our AML, sanctions, or REMIT record-keeping obligations), to exercise or defend legal claims, or where another exception applies.

Right to restrict processing

To require us to limit the way we use your data in defined circumstances (for example pending verification of a rectification request, or the outcome of an objection).

Right to data portability

Where applicable, to receive personal data provided to VEV in a structured, commonly used and machine-readable format and request transmission to another controller. This right applies only where (i) our processing is based on your consent or on the performance of a contract to which you are a party, and (ii) the processing is carried out by automated means. It does not apply to data we have derived or inferred about you, nor to paper records.

Right to object

To object, on grounds relating to your particular situation, to processing based on legitimate interests. The right to object to direct marketing is absolute.

Right not to be subject to automated decision-making

Not to be subject to a solely automated processing decision - including profiling - producing legal or similarly significant effects, except where legally permitted and safeguards apply.

Right to withdraw consent

Where processing is based on consent, to withdraw consent at any time without affecting earlier lawful processing.

Right to complain

To lodge a complaint with a competent supervisory authority.

We will respond to any request without undue delay and in any event within one month of receipt, extendable by a further two months for complex or numerous requests (in which case we will inform you of the extension within one month). We do not generally charge a fee, save where requests are manifestly unfounded or excessive.

To exercise your rights, please contact privacy@vev.com. We may ask you for additional information to confirm your identity before responding. If any of the personal data you have provided to us changes, or you believe something we hold about you is incorrect, please let us know without delay.

To help us deal with your request as quickly as possible, please tell us as clearly as you can which personal data your request relates to (for example by reference to a date range, a specific VEV entity or a specific business interaction). Where you wish to update or correct personal data we hold about you, please first check whether the relevant information can be updated directly (for example through any account or registration portal you may have with us).

14. Right to lodge a complaint

VEV encourages individuals to raise privacy concerns with VEV first so that they can be addressed. However, this does not affect the right to lodge a complaint at any time with a competent supervisory authority.

15. Children

VEV websites and services are not directed to , or intended for use by, children under the age of 16, or such lower age as Member State law permits (e.g. 13 in the United Kingdom). If you believe we have inadvertently collected personal data of a child, please contact privacy@vev.com and we will take appropriate steps.

16. Changes to this Privacy Notice

VEV may update this Privacy Notice from time to time to reflect changes in processing activities, organisational structure or applicable law. The effective date and version will be updated when a revised notice is issued.

17. Contact

For further information or to discuss a concern, please contact privacy@vev.com.