Privacy Policy
PRIVACY POLICY GREN WORLD MANAGEMENT S.à r.l. — Corporate Informational Website Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR") and the Luxembourg Law of 1 August 2018 on the organisation of the National Commission for Data Protection and the general data protection framework — Version 3.0 — July 2026
1. Data Controller
The controller of the personal data collected through the website www.grenfinance.com (the "Website") is GREN WORLD MANAGEMENT S.à r.l., a private limited liability company (société à responsabilité limitée) incorporated under the laws of the Grand Duchy of Luxembourg, registered with the Luxembourg Trade and Companies Register under number B304466, EUID LURCSL.B304466, with registered office at 2-4, Parc d'Activités Capellen, L-8308 Capellen, Grand Duchy of Luxembourg (the "Controller"). The Controller may be contacted, for any matter relating to the processing of personal data, at legal@grenfinance.com.
2. Data Protection Officer
The Controller has assessed the requirement to designate a data protection officer pursuant to Articles 37 to 39 GDPR. As at the date of publication of this Policy, such designation is not mandatory, since the Controller's processing activities do not involve large-scale processing of special categories of data nor regular and systematic monitoring of data subjects on a large scale. The Controller keeps this assessment under periodic review and shall update this Policy should a data protection officer be designated, whether on a mandatory or voluntary basis.
3. Categories of Personal Data Processed
3.1 Browsing data. Technical information transmitted automatically by the data subject's browser in the ordinary operation of the Website, including IP address, device identifiers, log files, browser type and version, operating system, pages visited, referral URLs, and session duration. Such data is processed solely for technical, statistical, and security purposes and is not used to identify data subjects, save where necessary to ascertain liability in connection with unlawful conduct against the Website.
3.2 Data provided voluntarily. Personal data submitted voluntarily through contact forms, requests for brochures or documentation, membership enquiries, or correspondence, which may include: first name and surname, e-mail address, company name and professional role, telephone number, country of residence, information relevant to investor categorisation, and any further information freely provided by the data subject.
3.3 Recruitment data. Personal data submitted through the "Work with us" section or otherwise in connection with an application, including curricula vitae, qualifications, and professional history. Such data is processed exclusively for recruitment and selection purposes and is retained for no longer than twelve (12) months from receipt, unless the candidate consents to a longer period or a contractual relationship is established.
3.4 Cookies and similar technologies. The Website uses strictly necessary cookies required for its proper functioning. Analytics cookies and any other non-essential cookies are activated solely upon the data subject's prior, explicit consent. Complete information on the types, purposes, duration, and management of cookies, including the withdrawal of consent, is set out in the Cookie Policy, accessible at all times from the footer of every page of the Website.
3.5 Special categories of data. The Controller does not collect, through the Website, special categories of personal data within the meaning of Article 9 GDPR, nor personal data relating to criminal convictions and offences within the meaning of Article 10 GDPR. Should such data be communicated inadvertently by the data subject, the Controller shall arrange for its immediate erasure, save where retention is required by law.
4. Purposes of Processing and Legal Bases
Personal data collected through the Website is processed for the following purposes, each resting on a specific legal basis under Article 6 GDPR:
– handling of contact requests, documentation requests, and communications — on the basis of pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR) or the Controller's legitimate interest in responding to enquiries (Article 6(1)(f) GDPR); data is retained for twelve (12) months from the closure of the enquiry, unless a longer period is required by law or by the establishment of a business relationship;
– verification of investor eligibility and professional categorisation, where information is provided in connection with requests for access to reserved documentation — on the basis of pre-contractual measures (Article 6(1)(b) GDPR) and of compliance with legal obligations applicable to entities of the GREN group (Article 6(1)(c) GDPR);
– technical administration, operation, and security of the Website, including the prevention and detection of fraud and unauthorised access — on the basis of the Controller's legitimate interest in the proper functioning and security of its systems (Article 6(1)(f) GDPR); navigation logs are retained for six (6) months, save for such longer period as is strictly necessary for the investigation of security incidents;
– aggregated and anonymised statistical analysis of Website usage — on the basis of the Controller's legitimate interest in improving the Website (Article 6(1)(f) GDPR) and, where reliant on non-essential cookies, exclusively upon the data subject's consent (Article 6(1)(a) GDPR); analytics data is retained for no longer than twenty-six (26) months;
– direct marketing and invitations to events or initiatives of the GREN group — exclusively on the basis of the data subject's explicit consent (Article 6(1)(a) GDPR); data is processed until consent is withdrawn;
– recruitment and personnel selection — on the basis of pre-contractual measures taken at the candidate's request (Article 6(1)(b) GDPR);
– compliance with legal and regulatory obligations applicable to the Controller, including company law, tax law, and, where applicable, anti-money laundering and counter-terrorist financing legislation — on the basis of a legal obligation (Article 6(1)(c) GDPR); data is retained for the periods mandated by the applicable provisions;
– establishment, exercise, or defence of legal claims — on the basis of the Controller's legitimate interest (Article 6(1)(f) GDPR), for the duration of the relevant limitation periods and proceedings.
Where processing rests on legitimate interest, the Controller has carried out and documented a balancing test between such interest and the fundamental rights and freedoms of data subjects, concluding that its interest prevails for the purposes indicated above. Data subjects may obtain information on the relevant assessments by writing to legal@grenfinance.com.
5. Data Retention
Personal data is retained solely for the period strictly necessary to fulfil the purposes for which it was collected and, in any event, for no longer than the periods indicated in Sections 3 and 4. Upon expiry of the applicable retention period, data is erased or irreversibly anonymised. Retention beyond such periods is permitted only where required by law (including tax, corporate, anti-money laundering, or financial-sector record-keeping obligations), where necessary for the establishment, exercise, or defence of legal claims, or where the data subject has consented to a longer period.
6. Recipients and Data Sharing
Personal data is not disseminated to the public and is never sold, rented, or otherwise made available to third parties for their own commercial purposes. Data may be disclosed, to the extent strictly necessary and on a need-to-know basis, to the following categories of recipients:
– technical service providers — including the website hosting platform, e-mail and communication service providers, and IT infrastructure and maintenance providers — acting as processors pursuant to Article 28 GDPR under written data processing agreements;
– other entities of the GREN group, including Gren Italia S.r.l., the entity providing operational and administrative support in Italy, strictly for internal administrative purposes within the meaning of Recital 48 GDPR and subject to appropriate intra-group arrangements;
– legal, tax, audit, and other professional advisers assisting the Controller, bound by statutory or contractual confidentiality obligations;
– the alternative investment fund manager, the depositary, and other service providers of funds of the GREN group, exclusively where the data subject initiates a subscription or onboarding process, and as further described in the documentation provided in that context;
– public authorities, supervisory bodies, and courts, where disclosure is required by applicable law, regulation, or enforceable order.
7. International Data Transfers
Personal data is processed primarily within the European Economic Area ("EEA"). Where personal data is transferred to countries outside the EEA — including in connection with the use of technical providers established in third countries or with the operational presence of GREN group entities outside the EEA (including the United Arab Emirates and Singapore) — the Controller ensures that the transfer complies with Chapter V GDPR, namely: on the basis of an adequacy decision of the European Commission pursuant to Article 45 GDPR (including, for providers established in the United States, certification under the EU–U.S. Data Privacy Framework, where applicable); or subject to appropriate safeguards pursuant to Article 46 GDPR, including Standard Contractual Clauses approved by the European Commission, supplemented where necessary by additional technical and organisational measures identified through a transfer impact assessment; or, residually, on the basis of one of the derogations set out in Article 49 GDPR. Data subjects may request a copy of the safeguards adopted, or information on where they have been made available, by writing to legal@grenfinance.com.
8. Security Measures
The Controller implements appropriate technical and organisational measures to ensure a level of security commensurate with the risk, pursuant to Article 32 GDPR, including: transmission of data via encrypted HTTPS/TLS protocol; access controls based on authentication and the least-privilege principle; logging, backup, and recovery procedures; internal procedures for the management of security incidents and personal data breaches, including the notification obligations under Articles 33 and 34 GDPR; periodic awareness and training of personnel involved in processing; and the selection of providers offering sufficient guarantees pursuant to Article 28 GDPR.
9. Rights of Data Subjects
Pursuant to Articles 15 to 22 GDPR, data subjects have the right to: obtain confirmation as to whether personal data concerning them is being processed, and access such data and the related information (Article 15); obtain the rectification of inaccurate data and the completion of incomplete data (Article 16); obtain the erasure of personal data in the cases provided for by law (Article 17); obtain the restriction of processing in the circumstances provided for by law (Article 18); receive the personal data they have provided in a structured, commonly used, and machine-readable format and transmit it to another controller, where technically feasible (Article 20); object at any time, on grounds relating to their particular situation, to processing based on legitimate interest, and object at any time and without justification to processing for direct marketing purposes (Article 21); and not be subject to decisions based solely on automated processing, including profiling, which produce legal effects concerning them or similarly significantly affect them (Article 22).
Where processing rests on consent, the data subject may withdraw consent at any time, without prejudice to the lawfulness of processing carried out prior to withdrawal (Article 7(3) GDPR).
Requests may be submitted to legal@grenfinance.com. The Controller shall respond without undue delay and, in any event, within one (1) month of receipt; such period may be extended by two (2) further months where necessary, having regard to the complexity and number of requests, in which case the data subject shall be informed of the extension and of the reasons therefor within one month of receipt (Article 12(3) GDPR).
Data subjects further have the right to lodge a complaint with the competent supervisory authority, namely the Commission Nationale pour la Protection des Données ("CNPD"), 15, Boulevard du Jazz, L-4370 Belvaux, Grand Duchy of Luxembourg, www.cnpd.lu, or with the supervisory authority of the EU Member State of their habitual residence, place of work, or place of the alleged infringement (Article 77 GDPR), including, for data subjects in Italy, the Garante per la protezione dei dati personali (www.garanteprivacy.it).
10. Nature of Data Provision
The provision of browsing data is inherent to the technical operation of the Website, and its absence prevents access thereto. The provision of data through contact or request forms is voluntary; however, failure to provide the information indicated as mandatory will render it impossible to process the relevant request. The provision of data for direct marketing purposes is entirely optional, and refusal entails no consequence on access to the Website or on the handling of other requests.
11. Data Relating to Minors
The Website is not directed at individuals under the age of eighteen (18). The Controller does not knowingly collect personal data relating to minors and, upon becoming aware that such data has been collected inadvertently, shall arrange for its immediate erasure. Any person who believes that data relating to a minor has been collected through the Website is invited to contact legal@grenfinance.com.
12. Automated Decision-Making and Profiling
The Controller does not carry out, through the Website, processing involving solely automated decision-making, including profiling, which produces legal effects concerning data subjects or similarly significantly affects them, within the meaning of Article 22 GDPR.
13. Updates to This Policy
The Controller reserves the right to amend or update this Policy at any time, including to reflect regulatory developments, guidance of the competent authorities, or changes in processing activities. The most recent version, together with its version number and date, is available at all times on this page. In the event of material changes, the Controller shall inform data subjects through a prominent notice on the Website or, where appropriate, by direct communication.
14. Applicable Law and Regulatory Framework
This Policy is drawn up in accordance with: Regulation (EU) 2016/679 (GDPR); the Luxembourg Law of 1 August 2018 on the organisation of the National Commission for Data Protection and the general data protection framework, as amended; the Luxembourg Law of 30 May 2005 concerning the protection of privacy in the electronic communications sector, as amended, with respect to cookies and similar technologies; the guidelines and decisions of the CNPD; and the guidelines, recommendations, and opinions of the European Data Protection Board.
15. Contact
For any information, request, or enquiry relating to this Policy or to the processing of personal data, please contact GREN WORLD MANAGEMENT S.à r.l. at legal@grenfinance.com. The registered office is located at 2-4, Parc d'Activités Capellen, L-8308 Capellen, Grand Duchy of Luxembourg. Additional information is available at www.grenfinance.com.
GREN WORLD MANAGEMENT S.à r.l. — Privacy Policy — July 2026