Privacy Policy
Last updated: 24 August 2026
This policy describes how MARPON Capital ("MARPON") processes personal data in connection with this website and its correspondence, in accordance with Regulation (EU) 2016/679 (GDPR).
1. Controller
MARPON Capital. Contact: legal@marponcapital.com.
2. Data processed
This website sets no cookies and uses no analytics, trackers or forms. Technical connection data (IP address, user agent, timestamp) is processed by the hosting provider, Cloudflare, to deliver the site and protect it against abuse. If you contact us by email, we process the data contained in your message: name, email address, organisation and content.
3. Purposes and legal basis
Data is processed to respond to and follow up on enquiries, to negotiate and perform professional engagements, to keep business records, and to maintain the security of the website (Articles 6(1)(b), (c) and (f) GDPR). No marketing communications are sent, and no profiling or automated decision-making takes place.
4. Recipients
Personal data is processed on our behalf by Zoho Corporation (email hosting, EU data centre) and Cloudflare, Inc. (DNS and website delivery). It is not sold or shared for third-party purposes. Transfers outside the European Economic Area are covered by Standard Contractual Clauses or an adequacy decision. Data may be disclosed where required by law.
5. Retention
Enquiry correspondence is deleted within 12 months of the last message. Correspondence relating to an engagement is kept for its duration and for 6 years thereafter, in line with commercial and tax record-keeping obligations.
6. Rights
You may request access, rectification, erasure, restriction, objection and portability by writing to legal@marponcapital.com. Requests are answered within one month; proof of identity may be required. Complaints may be addressed to the Agencia Española de Protección de Datos (aepd.es).
7. Security
Systems are protected with two-factor authentication, the website is served over HTTPS only, and the email domain enforces SPF, DKIM and DMARC (Article 32 GDPR).