1. Who we are (data controller)
Refuge Rock Capital Group ("Refuge Rock", "we", "us") is the controller of the personal data described in this notice. You can reach us about any privacy matter at privacy@refugerock.co or by writing to us at our office in Atherton, California, United States.
We are not currently required to appoint a Data Protection Officer. Privacy requests are handled directly by the address above. If we appoint an EU or UK representative under Article 27 GDPR, we will publish their details here.
2. What we collect
- Information you give us
- Name, email address, and the content of any message you send through our contact form or by email; the subject you select; and, if you request investor access, information relevant to determining accredited or qualified investor status.
- Investor portal data
- Where an account is issued, the identifiers and records needed to operate it — login credentials, position and distribution records, and documents we make available to you.
- Technical data
- Server logs generated when you load a page, including IP address, browser and device type, referring page, and timestamps. These are used for security and to keep the site available.
- Consent record
- Your cookie choice is stored in your own browser so we can honour it and evidence it. See our Cookie Notice.
We do not knowingly collect special-category data, and we do not collect personal data from children. Please do not send sensitive personal information through the contact form.
3. Why we use it, and our lawful basis
We do not sell personal data, we do not share it with advertising networks, and we do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
4. Who we share it with
We share personal data only where it is necessary, and only with recipients bound by confidentiality and, where they process on our behalf, by a written data-processing agreement:
- Hosting, email, and infrastructure providers that operate this site and our correspondence.
- Professional advisers — counsel, accountants, auditors, and fund administrators engaged on a mandate.
- Licensed partners in our asset-engineering network, where you have engaged us on a mandate that requires it.
- Regulators, tax authorities, and law enforcement where we are legally required to disclose.
5. International transfers
We operate from the United States. If you contact us from the European Economic Area, the United Kingdom, or Switzerland, your personal data will be transferred outside your jurisdiction. Where we make such a transfer we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supplemented by technical and organisational safeguards. You can request information about the safeguards in place by writing to privacy@refugerock.co.
6. How long we keep it
- General enquiries: up to 24 months from our last exchange, unless you ask us to erase them sooner.
- Investor and subscription records: for the life of the relationship and then for the period required by securities, AML, and tax law — generally at least seven years.
- Server and security logs: typically 90 days.
- Cookie consent record: up to 12 months, after which we ask again.
7. Your rights
Subject to the conditions in applicable law, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing (including objecting to processing based on legitimate interests); receive your data in a portable format; and withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any right, email privacy@refugerock.co. We respond within one month and will tell you if we need an extension. There is no charge for a first request. We may need to verify your identity before acting.
You may also lodge a complaint with your local supervisory authority — in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office. We would appreciate the chance to address your concern first.
Some rights are limited where we are required by securities, AML, or tax law to retain records. Where we cannot fully comply with a request, we will explain why.
8. Cookies
We set strictly necessary cookies only. Anything else requires your consent, which you can give, refuse, or change at any time.
or read the full Cookie Notice.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls on the investor portal, and least-privilege access to records. No system is perfectly secure; if a breach affects your rights and freedoms, we will notify you and the relevant supervisory authority as required by Articles 33 and 34 GDPR.
10. Changes to this notice
We update this notice when our practices change. The date at the top reflects the current version. Material changes will be highlighted on this page.