This EU Privacy Notice applies to the extent that EU Data Protection Legislation applies to the processing of personal data by an Authorized Entity (as defined below) or to the extent that a data subject is a resident of the United Kingdom (the “UK”), the European Union (“EU”) or the European Economic Area (“EEA”). If this EU Privacy Notice applies, the data subject has certain rights with respect to such personal data, as outlined below.
For purpose of this EU Privacy Notice, “EU Data Protection Legislation” means all applicable legislation and regulations relating to the protection of personal data in force from time to time in the EU, the EEA, or the UK, including, without limitation: the Data Protection Directive (95/46/EC), the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Data Protection (Processing of Sensitive Personal Data) Order 2000, or any other legislation which implements any other current or future legal act of the European Union concerning the protection and processing of personal data (including Regulation (EU) 2016/679 (the General Data Protection Regulation) and any national implementing or successor legislation), and including any amendment or re-enactment of the foregoing. The terms “data controller”, “data processor”, “data subject”, “personal data” and “processing” in this EU Privacy Notice shall be interpreted in accordance with the applicable EU Data Protection Legislation.
Please contact Nisha Kumar, Chief Compliance Officer of Greenbriar email@example.com with any queries arising out of this EU Privacy Notice.
Categories of personal data collected and lawful bases for processing In connection with offering, forming and/or operating the private investment funds set forth in Appendix A hereto (each, a “Partnership” and collectively, the “Partnerships”), Greenbriar Equity Group, L.P., its affiliates and, in each case, their administrators, legal and other advisors and agents (each, an “Authorized Entity” and collectively, the “Authorized Entities” ) collect, record, store, adapt, and otherwise process and use personal data either relating to existing or potential investors or to their respective partners, officers, directors, employees, shareholders, ultimate beneficial owners or affiliates or to any other data subjects from the following sources (and all references to “existing investor(s)” or “potential investor(s)” in this EU Privacy Notice shall be to such existing investor(s) or potential investor(s), respectively, and, as applicable, any of these other persons as relate to such existing investor(s) or potential investor(s), respectively):
information received in telephone conversations, in voicemails, through written correspondence, via e-mail, or on subscription agreements, investor questionnaires, applications or other forms (including, without limitation, any anti-money laundering, “know-your-client”, identification, and verification documentation);
information about transactions with any Authorized Entity or others;
information captured on any Authorized Entity’s website, including registration information and any information captured via “cookies” and
information from available public sources, including from:
publicly available and accessible directories and sources;
tax authorities, including those that are based outside the UK and the EEA if an existing or potential investor is subject to tax in another jurisdiction;
governmental and competent regulatory authorities to whom any Authorized Entity has regulatory obligations;
credit agencies; and
fraud prevention and detection agencies and organisations.
Any Authorized Entity may process the following categories of personal data:
names, dates of birth and birth place;
contact details and professional addresses (including physical address, email address and telephone number);
account data and other information contained in any document provided by existing or potential investors to the Authorized Entities (whether directly or indirectly);
risk tolerance, transaction history, investment experience and investment activity;
information regarding an existing or potential investor’s status under various laws and regulations, including their social security number, tax status, income and assets;
accounts and transactions with other institutions;
information regarding an existing or potential investor’s interest in any of the Partnerships, including ownership percentage, capital investment, income and losses;
information regarding an existing or potential investor’s citizenship and location of residence;
source of funds used to make the investment in any of the Partnerships; and
anti-money laundering, identification (including passport and drivers’ license), and verification documentation.
Any Authorized Entity may, in certain circumstances, combine personal data it receives from an existing or potential investor with information that it collects from, or about, such existing or potential investor, as applicable. This will include information collected in an online or offline context.
One or more of the Authorized Entities are “data controllers” of personal data collected in connection with the Partnerships. In simple terms, this means such Authorized Entities: (i) “control” the personal data that they or other Authorized Entities collect from existing investors, potential investors or other sources; and (ii) make certain decisions on how to use and protect such personal data.
There is a need to process personal data for the purposes set out in this EU Privacy Notice as a matter of contractual necessity under or in connection with the governing agreements of the applicable Partnerships and associated fund documentation, and in the legitimate interests of the Authorized Entities (or those of a third party) to operate their respective businesses. From time to time, an Authorized Entity may need to process the personal data on other legal bases, including: with consent; to comply with a legal obligation; if it is necessary to protect the vital interests of an existing investor, a potential investor or other data subjects; or if it is necessary for a task carried out in the public interest.
A failure to provide the personal data requested to fulfil the purposes described in this EU Privacy Notice may result in the applicable Authorized Entities being unable to provide the services in connection with the governing agreements of the applicable Partnerships and/or one or more of the investors’ subscription agreements with respect to the applicable Partnerships.
Purpose of processing
The applicable Authorized Entities process the personal data for the following purposes (and in respect of paragraphs (c), (d) and (f) below, in the legitimate interests of the Authorized Entities):
The performance of obligations under the governing agreements of the applicable Partnerships and/or one or more investors’ subscription agreements with respect to the applicable Partnerships (and all applicable anti-money laundering, “know-your-client” and other related laws and regulations), including in assessing suitability of potential investors in the Partnership.
The administrative processes (and related communication) carried out between the Authorized Entities in preparing for the admission of investors to the Partnership.
Ongoing communication with existing investors and potential investors and their respective representatives, advisors and agents, (including the negotiation, preparation and signature of documentation), including during the process of admitting potential investors to the Partnership.
The ongoing administrative, accounting, reporting and other processes and communication required to operate the business of the Partnership in accordance with the Partnership Agreement and other applicable documentation between the parties.
Any legal or regulatory requirement.
Keeping existing and potential investors informed about the business of the General Partner and its affiliates generally, including offering opportunities to make investments other than to the Partnership.
Any other purpose that has been notified, or has been agreed, in writing.
The Authorized Entities monitor communications where the law requires them to do so. The Authorized Entities also monitor communications, where required to do so, to comply with regulatory rules and practices and, where permitted to do so, to protect their respective businesses and the security of their respective systems.
Sharing and transfers of personal data
In addition to disclosing personal data amongst themselves, any Authorized Entity may disclose personal data, where permitted by EU Data Protection Legislation, to other service providers, employees, agents, contractors, consultants, professional advisers, lenders, data processors and persons employed and/or retained by them in order to fulfil the purposes described in this EU Privacy Notice. In addition, any Authorized Entity may share personal data with regulatory bodies having competent jurisdiction over them, as well as with the tax authorities, auditors and tax advisers (where necessary or required by law).
Any Authorized Entity may transfer personal data to a Non-Equivalent Country (as defined below), in order to fulfil the purposes described in this EU Privacy Notice and in accordance with applicable law, including where such transfer is a matter of contractual necessity to enter into, perform and administer the governing agreements of the applicable Partnerships and/or one or more of the investors’ subscription agreements with respect to the applicable Partnerships, and to implement requested pre-contractual measures. For information on the safeguards applied to such transfers, please contact the General Partner. For the purposes of this EU Privacy Notice, “Non-Equivalent Country” shall mean a country or territory other than (i) a member state of the EEA; or (ii) a country or territory which has at the relevant time been decided by the European Commission in accordance with EU Data Protection Legislation to ensure an adequate level of protection for personal data.
Retention and security of personal data
The General Partner and its affiliates consider the protection of personal data to be a sound business practice, and to that end, employ appropriate technical and organisational measures, including robust physical, electronic and procedural safeguards to protect personal data in their possession or under their control.
Personal data may be kept for as long as it is required for legitimate business purposes, to perform contractual obligations, or where longer, such longer period as is required by applicable legal or regulatory obligations. Personal data will be retained throughout the life cycle of any investment in the Partnerships. However, some personal data will be retained after a data subject ceases to be an investor in such Partnerships.
Data Subject Rights
It is acknowledged that, subject to applicable EU Data Protection Legislation, the data subjects to which personal data relates, have certain rights under EU Data Protection Legislation: to obtain information about, or (where applicable) withdraw any consent given in relation to, the processing of their personal data; to access and receive a copy of their personal data; to request rectification of their personal data; to request erasure of their personal data; to exercise their right to data portability; and the right not to be subject to automated decision-making.
Please note that the right to erasure is not absolute and it may not always be possible to erase personal data on request, including where the personal data must be retained to comply with a legal obligation. In addition, erasure of the personal data requested to fulfil the purposes described in this EU Privacy Notice, may result in the inability to provide the services required pursuant to the governing agreements of the applicable Partnerships and/or one or more investors’ subscription agreements with respect to the applicable Partnerships.
In case the data subject to whom personal data relate disagrees with the way in which their personal data is being processed in relation to the governing agreements of the applicable Partnerships and/or their subscription agreement(s) with respect to the applicable Partnership(s), the data subject has the right to object to this processing of personal data and request restriction of the processing. The data subject may also lodge a complaint with the competent data protection supervisory authority in the relevant jurisdiction.
The data subject may raise any request relating to the processing of his or her personal data with Nisha Kumar, Chief Compliance Officer of Greenbriar (firstname.lastname@example.org).