Legal
Privacy policy
Last updated: 10 August 2026
1. Who is responsible
Cinque Monti Ltd., registered in England and Wales under company number 09666608, registered office Dept 9184, 196 High Road, Wood Green, London, N22 8HH, United Kingdom, is the controller for the personal data described here. Contact: privacy@vclist.net.
We process personal data under the UK GDPR and the Data Protection Act 2018. Where we offer the service to people in the European Union, the EU GDPR applies in parallel.
Our representative in the European Union under Article 27 EU GDPR: EU representative, or confirm none is required
2. Visiting the website
Our server processes the connection data a browser sends in order to deliver a page. Your IP address is never stored in the clear: it is hashed with a secret key and kept only in that irreversible form, so that we can detect and limit abuse and automated extraction of the directory. The lawful basis is Article 6(1)(f) UK GDPR, our legitimate interest in protecting the service.
We use no advertising cookies, no profiling and no third-party trackers. There is therefore no cookie banner, because nothing beyond strictly necessary cookies is set. Loading a page on this site sends no request to any other company: fonts, logos and the analytics script named below are all delivered from our own servers.
Reach and usage measurement
We count visits with Umami, an open-source analytics tool we host ourselves on our own infrastructure. It sets no cookie, assigns no lasting identifier and follows nobody across other websites. Your browser communicates only with vclist.net; the measurement is passed on internally on our side. A visit is recognised for one day using a value derived from your IP address, browser and the current date, hashed with a daily changing secret; neither the address nor that hash is stored. We record the page, the referring source and the country.
We also count when a search, a registration, an unlock or a checkout takes place, together with the category of the action - for example the chosen sector, or a size band for the number of results. These records never contain a name, an email address, a fund or an individual contact. The lawful basis is Article 6(1)(f) UK GDPR, our legitimate interest in understanding whether the service is usable and worth continuing. If you would rather not be counted, any browser setting or extension that blocks analytics requests to /api/a is sufficient, and the site works exactly as before.
Anonymous searches
If you use the investor search without an account, we record the filters you chose (sector, stage, region), the number of results and the hashed IP value. This tells us where abuse is coming from and which sectors we need to cover better. It does not allow us to identify you.
3. Accounts and signing in with Google
To create an account we process the email address, name and profile picture that Google passes to us during the OAuth sign-in. The lawful basis is Article 6(1)(b) UK GDPR, performance of a contract. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We request only the permissions needed to sign you in and receive no access to your mail, contacts or files.
4. Payments
Payments are processed by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin, Ireland, and by Stripe, Inc. for card processing. Your payment details are handled solely by Stripe; we store a customer reference, the plan you booked and the billing period. The lawful basis is Article 6(1)(b) UK GDPR. Details at stripe.com/privacy.
5. Usage data inside the product
We record which contacts you have unlocked. This is strictly necessary, because a contact is charged only once per account and stays visible to you permanently. We also log security-relevant events such as exceeding a rate limit. These logs are deleted after twelve months.
6. The investor directory
The directory contains business contact details of people who hold an investment-related role at an investor: name, professional role, business email address, business telephone number and public professional profile. It holds business contact data in a professional capacity only. It contains no private addresses, no private telephone numbers and no special category data.
Where the data comes from
We did not collect these details from the people they describe. They come from publicly accessible sources, in particular fund and company websites, team and portfolio pages and company registers, together with a licensed commercial provider of business contact data. If you are listed and want to know the specific source of your own entry, ask us and we will tell you.
Why we hold it, and on what basis
The lawful basis is Article 6(1)(f) UK GDPR, legitimate interests. Our legitimate interest is enabling founders to reach providers of capital, which matches the reasonable expectation attached to an investment-related role. We have assessed that interest against the rights of the people listed and recorded the assessment. It is why the directory holds business contact data only, and why the removal route below takes one click and asks for no reason.
Who receives it
Subscribers to this service, who unlock individual entries. Their contract with us requires them to say where they obtained your details if you ask, and to stop contacting you if you tell them to. They are separate controllers for what they do next, and responsible for their own compliance when they get in touch.
We write to the people we list
Because we did not obtain these details from you, Article 14 UK GDPR and EU GDPR requires us to tell you that we hold them. We are contacting the people in the directory in writing to do exactly that. Each message explains what we hold and where it came from, and contains a personal link to a page with a single button that deletes the entry. The message is a legal notice: it advertises nothing and asks for nothing.
Rights of people listed in the directory
Anyone listed can request access, rectification, erasure or restriction, or object to the processing, at any time. A message to privacy@vclist.net is enough, and so is the link in the notice described above. We delete the entry in full. We do not ask for a reason, and we do not ask you to prove anything beyond control of the address concerned.
What survives a deletion, and why
Our directory is rebuilt from its sources periodically. If a deletion left no trace, the next rebuild would simply add you again, so a deletion also records a one-way cryptographic hash of your email address on a suppression list, which the rebuild checks before writing anything. The hash cannot be turned back into your address and cannot be used to contact you. It exists solely to keep you out. The lawful basis for retaining it is Article 6(1)(f) and Article 17(3), our legitimate interest in giving effect to your own request. If you would rather we did not keep even that, tell us and we will remove it, but we will then be unable to prevent your details returning in a later rebuild.
We also keep a record that a notice was sent to you and how you responded to it, so we can demonstrate that we met our obligation. That record holds the same one-way hash and no readable address.
Subscribers who unlocked your entry before you asked us to delete it may still hold their own copy. We cannot delete data from their systems, but you can require them to, and they are contractually obliged to tell you where they got it.
7. Recipients and hosting
The service runs on a server operated by Hostinger International Ltd. inside the EU, under a data processing agreement. Beyond the processors named here we pass on no data, and we never sell user data.
8. International transfers
Data is processed in the United Kingdom and the European Economic Area. Transfers between the two are covered by the European Commission's adequacy decision for the UK and the corresponding UK adequacy regulations for the EEA. Where a processor transfers data further, it does so under the applicable standard contractual clauses or the UK International Data Transfer Addendum.
9. How long we keep data
Account data is kept while your account exists and deleted within 30 days of closure, unless we are required to keep it for accounting or tax purposes. Billing records are kept for six years, as required of a UK company.
Directory entries are kept for as long as they remain accurate and relevant to the purpose in section 6, and are reviewed at least once a year; entries we can no longer verify are removed. An entry is deleted immediately on request, at which point only the suppression hash described in section 6 remains.
10. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and to object. You can also complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office, ico.org.uk. If you are in the European Union you may instead complain to the supervisory authority where you live or work.