Skip to content

Legal

Privacy Policy

OverCap UK Limited (“OverCap”, “we”, “us”) respects the privacy of visitors to overcap.me (the “Site”) and of the people who contact us. This policy explains what personal data we collect through the Site, when you get in touch with us and about the business contacts we work with or may want to work with, why we use it, how long we keep it, who we share it with, and your rights under the UK GDPR and the Data Protection Act 2018.

This policy covers the Site and our direct contact with you. The platforms we build and operate — such as Secondaries, Semiliquids, Stellon and Yestella — have their own privacy notices, which apply when you use them.

Who we are

The controller of your personal data is OverCap UK Limited, registered in England and Wales under company number 13731322, with its registered office at Third Floor, 207 Regent Street, London W1B 3HH.

For any question or request about your personal data, email hello@overcap.me or write to us at our registered office marked “Data protection”. We are not required to appoint a data protection officer and have not done so; these contact details reach the people at OverCap responsible for data protection.

Data we collect

  • Partner enquiries: when you use the form on our Partner page, we collect your name, email address, organisation, the partnership model you are interested in and, if you add one, your message. We need your name, email address, organisation and chosen model to reply to you; if you prefer not to use the form, you can email us instead.
  • Emails and calls: when you email us (including to book a call) or speak with us, we collect your name, contact details, job title and organisation, and anything else you choose to tell us.
  • Job applications: when you apply to hr@overcap.me, we collect your CV, covering letter, contact details, work history, qualifications and anything else you send, and any interview notes and (with your agreement) references. Please do not include sensitive information — such as health, ethnicity or religious beliefs — unless it is relevant, for example if you need adjustments for an interview.
  • Technical data: when you visit the Site, our web server records your IP address, browser type, the page you requested, the page you came from and the date and time. If our spam filter blocks a form submission, we record the IP address it came from. If an error occurs on the Site, our error-monitoring service receives technical details of the error (not the contents of forms).

The Site does not use analytics, advertising or other tracking tools, and you do not need an account to use it.

We also hold information about people who work at organisations we deal with or may want to deal with — see “Business contacts, prospects and marketing” below.

We often collect personal data directly from you. We also obtain it from other sources: colleagues or introducers, recruiters, LinkedIn, commercial providers of business-contact data and public sources. If we obtain your details from someone other than you, we will give you the information in this policy within one month, and at the latest in our first message to you.

How we use it and our lawful basis

  • Replying to enquiries, holding introductory conversations and managing business relationships: our legitimate interests in responding to people who contact us and developing our business, or taking steps at your request before entering into a contract.
  • Assessing job applications: taking steps at your request before a possible employment contract, and our legitimate interests in recruiting the right people. If you tell us about a disability or health condition so that we can make adjustments, we use it to meet our obligations under employment law.
  • Running, securing and fixing the Site (including blocking spam and investigating errors): our legitimate interests in keeping the Site available, secure and free of abuse.
  • Meeting legal obligations and protecting our legal rights: our legal obligations, and our legitimate interests in establishing, exercising or defending legal claims.

We will not add you to a mailing list because you have contacted us, although we may record your details and our correspondence in our CRM (see below). Where we rely on legitimate interests, we have weighed them against your rights and interests; you can ask us for more detail, and you can object (see “Your rights”).

We do not sell personal data. We do not make decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects on you (the profiling we do use is described below). The Site is not intended for children.

Business contacts, prospects and marketing

We keep a business-relationship database (CRM) about people who work at organisations we deal with or may want to deal with — such as asset and wealth managers, family offices, banks, fund managers, allocators and their advisers. It can include your name, work email and phone number, job title and seniority, employer and its details, country and city, LinkedIn profile, the funds or products your organisation holds or is interested in, our emails and LinkedIn messages with you, notes made by our team, and whether and how you responded to our messages.

Where it comes from: you (when you email, message or meet us); your LinkedIn profile and our LinkedIn connections and conversations; commercial providers of business-contact data; our earlier CRM systems; public sources such as company websites, regulatory registers and web search; and colleagues or introducers.

Why, and our lawful basis: to identify and contact organisations that may be interested in our platforms and services, to manage our relationship with you, and to make sure we do not contact people who have asked us not to. Our lawful basis is our legitimate interests in developing our business. We contact people only in a professional capacity, about matters relevant to their role.

Profiling: we use automated tools, including AI models, to group contacts by seniority, job function and type of organisation, to score engagement with our messages, to classify replies (for example “interested” or “unsubscribe”) and to spot job changes. This helps us decide whom to contact and when; it has no legal or similarly significant effect on you.

Marketing emails and messages: we may send you emails or LinkedIn messages about our services at your work address. We send unsolicited marketing emails only to corporate email addresses; we do not email individuals, sole traders or partnerships without their consent, except where the law allows it for existing customers. Every email identifies us and gives you a simple way to opt out. Our emails may contain tracking links and pixels that tell us whether an email was opened or a link was clicked.

Your right to object: you can object at any time — reply “unsubscribe”, use the link in any of our emails, or write to hello@overcap.me. We will stop and add your email address to a suppression list, which we keep only so that we do not contact you again.

Who we share it with

We share personal data with these service providers, which process it on our behalf, under contract and only on our instructions:

  • Hetzner Online GmbH — hosts the Site, its server logs and our internal systems, including our CRM, in Germany;
  • Google (Google Workspace) — provides our email and office systems, including the inbox that receives Partner-form enquiries;
  • Resend, Inc. — delivers the emails generated by our Partner form to our inbox;
  • Functional Software, Inc. (Sentry) — monitors the Site for technical errors;
  • Heliom Inc. (Missive) — our shared email inbox;
  • lemlist SAS — sends our business-development emails and records opens, clicks and replies;
  • Unipile SAS — connects our LinkedIn account to our CRM;
  • Zapier, Inc. and Celonis (Make) — move data between these tools;
  • Anthropic PBC and Tavily — provide the AI and web-search services we use to classify and research business contacts;
  • the provider of the cloud computing capacity on which we run our own AI models.

OverCap works with colleagues at OverCap group companies in the Netherlands, Cyprus and Montenegro. They may access your personal data where they need it to deal with your enquiry or application.

We may also share personal data with our professional advisers (such as lawyers, accountants and auditors), who are bound by confidentiality; with a prospective buyer, investor or successor business if we reorganise or sell all or part of our business, under confidentiality terms; and where the law requires it or it is necessary to protect our rights, our users or others — for example with the police, regulators or the courts.

International transfers

Some of our service providers and group companies process personal data outside the UK. Whenever that happens, the data is protected as UK law requires:

  • European Economic Area (including Germany, the Netherlands and Cyprus): recognised under UK law as providing an adequate level of protection.
  • Canada: Missive processes data in Canada, which UK law recognises as providing an adequate level of protection for commercial organisations.
  • United States: Google, Resend, Sentry, Zapier, Anthropic and Tavily may process data in the United States. We rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified under it, and otherwise on the contractual safeguards approved under UK law (the International Data Transfer Addendum to the EU standard contractual clauses) contained in their data processing terms.
  • Montenegro: where colleagues at our group company in Montenegro access personal data, we use the International Data Transfer Agreement approved by the ICO.

You can contact us for more information about these safeguards.

How long we keep it

  • Enquiries and correspondence: we review them regularly and delete them when they are no longer needed, and in any event within 24 months of our last contact with you. If we go on to work together, for as long as the relationship lasts and for six years afterwards, to meet our legal and accounting obligations and deal with any claims.
  • Job applications: we review them regularly and delete them when they are no longer needed, and in any event within six months of the end of the recruitment process, or 12 months if you agree that we can consider you for future roles. If you join us, your application becomes part of your staff record.
  • Business contacts and prospects: up to 24 months after our last meaningful contact or engagement with you, unless we go on to work together.
  • Suppression list: only your email address and the date you objected, kept for as long as we might otherwise contact you, so that we honour your objection.
  • Server logs and spam-filter records: for a short period, after which they are overwritten automatically on a rolling basis.
  • Error reports: no longer than 90 days.

How we keep it secure

The Site is served only over encrypted (HTTPS) connections from servers in a data centre in Germany. Only authorised members of our team can access personal data, using individual company accounts. Partner-form enquiries are not stored in a database on the Site; they are sent straight to our email inbox. We require our service providers to keep personal data secure. No system is completely secure, but if a personal data breach puts your rights at risk we will tell the ICO and, where required, you.

Your rights

You have the right to ask for a copy of the personal data we hold about you; to ask us to correct data that is inaccurate or incomplete; to ask us to delete it; to ask us to restrict how we use it; and, where we process it on the basis of a contract, to ask us to transfer data you gave us to you or to another organisation.

Your right to object: you can object at any time to our use of your personal data where we rely on legitimate interests. We will then stop, unless we have compelling legitimate grounds to continue or need the data for legal claims. You can object to direct marketing at any time, and we will always stop.

To exercise any of these rights, email hello@overcap.me. It is free. We will reply within one month; if your request is complex we may extend this by up to two further months and will tell you if we do. We may ask you to confirm your identity, and we will carry out reasonable and proportionate searches. Some rights have legal limits, and we will explain if one applies.

Complaints

If you are unhappy with how we have handled your personal data, please tell us first at hello@overcap.me. We will acknowledge your complaint within 30 days and respond fully without undue delay.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK data protection regulator: ico.org.uk/make-a-complaint, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.

Cookies

The Site uses only two cookies, both strictly necessary for it to work, so they do not require your consent:

  • overcap_session (set by OverCap, lasts 2 hours) — keeps the Site working during your visit, for example keeping what you typed in a form if it needs correcting;
  • XSRF-TOKEN (set by OverCap, lasts 2 hours) — protects our forms against cross-site request forgery.

We do not use analytics, advertising or social-media tracking cookies. You can block or delete cookies in your browser settings, although the Site’s forms may not work without these two.

Other websites

The Site links to other websites, including our LinkedIn page and the platforms we operate. The Site contains no LinkedIn or other social-media tracking code, so those sites receive nothing about your visit unless you click through. Once you are on another website, its own privacy policy applies. When you interact with our LinkedIn page, LinkedIn provides us with statistics that do not identify you; LinkedIn and OverCap are jointly responsible for those statistics, and LinkedIn’s privacy policy explains how it handles your data.

Changes to this policy

We may update this policy from time to time. The latest version will always be published on this page with its date. If a change significantly affects how we use personal data you have already given us, we will tell you directly where we can.

Last updated 26 September 2026