← Back

Privacy Policy

Last updated: 24 August 2026

This policy describes how MARPON Capital ("MARPON") processes personal data in connection with this website and its correspondence, in accordance with Regulation (EU) 2016/679 (GDPR).

1. Controller

MARPON Capital. Contact: legal@marponcapital.com.

2. Data processed

This website sets no cookies and uses no analytics, trackers or forms. Technical connection data (IP address, user agent, timestamp) is processed by the hosting provider, Cloudflare, to deliver the site and protect it against abuse. If you contact us by email, we process the data contained in your message: name, email address, organisation and content.

3. Purposes and legal basis

Data is processed to respond to and follow up on enquiries, to negotiate and perform professional engagements, to keep business records, and to maintain the security of the website (Articles 6(1)(b), (c) and (f) GDPR). No marketing communications are sent, and no profiling or automated decision-making takes place.

4. Recipients

Personal data is processed on our behalf by Zoho Corporation (email hosting, EU data centre) and Cloudflare, Inc. (DNS and website delivery). It is not sold or shared for third-party purposes. Transfers outside the European Economic Area are covered by Standard Contractual Clauses or an adequacy decision. Data may be disclosed where required by law.

5. Retention

Enquiry correspondence is deleted within 12 months of the last message. Correspondence relating to an engagement is kept for its duration and for 6 years thereafter, in line with commercial and tax record-keeping obligations.

6. Rights

You may request access, rectification, erasure, restriction, objection and portability by writing to legal@marponcapital.com. Requests are answered within one month; proof of identity may be required. Complaints may be addressed to the Agencia Española de Protección de Datos (aepd.es).

7. Security

Systems are protected with two-factor authentication, the website is served over HTTPS only, and the email domain enforces SPF, DKIM and DMARC (Article 32 GDPR).