Privacy Policy
Last updated: 19 June 2026
1. Introduction and who we are
This Privacy Policy explains how [Klypse Ltd] ("Klypse", "we", "us" or "our") collects, uses, discloses and otherwise processes personal data. It applies to:
- our website at klypse-uhnw.com (the "Site");
- the Klypse private-markets intelligence and access platform and all related products, features and APIs (the "Service" or "Platform"); and
- our processing of personal data relating to the individuals profiled within the Service (each a "Principal").
Klypse is a business-to-business platform. We provide professional firms (for example venture capital and private equity firms, family offices, private banks, and executive search and recruitment firms) with structured, verified intelligence on the ultra-high-net-worth ("UHNW") world. We refer to the subscribing organisation as the "Customer" or "you", and to an individual who uses the Service under that Customer's account as an "Authorised User". The structured data, profiles, signals and analysis that we make available through the Service are referred to as the "Intelligence".
For the purposes of UK data protection law, Klypse is the controller of:
- personal data about Customers and Authorised Users; and
- personal data about Principals contained within the Intelligence.
In respect of Customer Data that a Customer uploads or creates within the Service (see Section 3), Klypse generally acts as a processor on the Customer's behalf, and the relevant terms are set out in our Data Processing Agreement ("DPA").
Our details are:
- Operating entity: [Klypse Ltd], a company incorporated in [England and Wales] under company number [Company No.].
- Registered office: [Registered Office Address].
- General enquiries: [hello@klypse-uhnw.com].
- Data protection enquiries: [privacy@klypse-uhnw.com].
- Legal notices: [legal@klypse-uhnw.com].
This policy should be read together with our Cookie Policy, our Terms of Service, and (for Customers) our DPA.
2. The two kinds of personal data we process
The most important thing to understand about Klypse is that we process two distinct categories of personal data, for different reasons, under different lawful bases, and affecting different groups of people. We address them separately throughout this policy.
(A) Personal data about Customers and Authorised Users
This is personal data about the people who buy from us and use the Platform. It includes:
- Account and identity data: name, job title, employer, business email address, business telephone number, username and authentication credentials.
- Billing and financial data: billing contact, billing address, purchase order references, and transaction records. Card payments are processed by our third-party payment processor; we do not store full payment card numbers.
- Usage and analytics data: log data, IP address, device and browser information, pages and features accessed, searches run within the Service, queries put to the AI assistant, and similar telemetry.
- Support and communications data: the content of enquiries, support tickets, correspondence, and feedback, together with records of our responses.
- Marketing data: marketing preferences and your engagement with our communications, where applicable.
(B) Personal data about Principals (the Intelligence corpus)
This is personal data about UHNW individuals whom we profile so that our Customers can understand and, where appropriate, approach them. Principals do not register with Klypse, are not our customers, and do not provide this data to us directly. Categories include:
- Identity and biographical details: name, approximate age or date of birth where publicly reported, nationality, and city or region of residence or operation. As a deliberate design choice we record city or region rather than residential street addresses (see Section 10).
- Professional roles and corporate interests: directorships, officerships, shareholdings and beneficial interests, founder or executive positions, and other business affiliations.
- Estimated wealth and financial interests: estimated net worth, the composition of holdings, and notable assets, in each case derived from public and licensed sources and presented as estimates.
- Relationships and network connections: documented professional and personal connections, co-investment and board relationships, and other associations relevant to access and introductions.
- Publicly-reported affiliations and activities: philanthropic activity, memberships, public statements, and other matters reported in reputable sources.
- Compliance and screening signals: matches or potential matches against sanctions lists, watchlists, politically-exposed-person ("PEP") status, and adverse-media indicators.
We apply data-minimisation by design to the Intelligence. In particular, we exclude information about children (see Sections 10 and 15).
3. Customer Data
Customers and Authorised Users may create and store their own records within the Service, for example notes, tags, research, pipeline status and CRM-style records about Principals or about the Customer's own contacts ("Customer Data"). Where we process Customer Data, we do so as a processor acting on the documented instructions of the Customer, who is the controller of that data. Our handling of Customer Data is governed by the DPA. This policy governs our processing as a controller; it does not displace the DPA in respect of Customer Data.
4. Where Principal data comes from
We compile the Intelligence from public and lawfully licensed sources only. We do not obtain Principal data covertly, and Principals are not asked to provide it to us. Our sources include:
- public registers and regulatory filings (for example the U.S. Securities and Exchange Commission, Companies House, and equivalent registers and regulators in other jurisdictions);
- reputable news media and journalistic reporting;
- company disclosures, prospectuses, annual reports and investor materials;
- sanctions lists, watchlists and other compliance and screening data sources; and
- other lawfully available public or licensed sources.
We structure, cross-reference, verify and enrich this material to produce the Intelligence. Our editorial and verification processes are designed to improve accuracy and to flag uncertainty, but estimates (for example of wealth) remain estimates.
5. Lawful bases for processing
We rely on the following lawful bases under Article 6 of the UK GDPR.
5.1 Customer and Authorised User data
- Performance of a contract (Article 6(1)(b)): to create and administer accounts, provide the Service, manage subscriptions, and provide support.
- Legitimate interests (Article 6(1)(f)): to operate, secure, maintain and improve the Service, to understand usage, to prevent fraud and misuse, and to conduct business-to-business relationship management. Our legitimate interests are balanced against your interests and rights.
- Consent (Article 6(1)(a)): for certain marketing communications and for non-essential cookies, where consent is required.
- Legal obligation (Article 6(1)(c)): to comply with our legal, accounting, tax and regulatory obligations.
5.2 Principal data
Our primary lawful basis for processing Principal data is legitimate interests (Article 6(1)(f)). The legitimate interests pursued are those of Klypse and of our Customers in obtaining accurate, structured, verifiable intelligence about UHNW individuals for legitimate professional purposes, including investment, capital-raising, recruitment, relationship development, due diligence and compliance screening.
Before relying on legitimate interests we carry out, and keep under review, a legitimate-interests assessment that weighs three things in plain terms:
- Purpose: there is a genuine and lawful business interest in compiling and providing this Intelligence to professional firms, as described above.
- Necessity: the processing is a targeted and proportionate way to achieve that purpose, and we minimise what we hold (for example city or region rather than street addresses, and no children's data) so that we do not process more than is needed.
- Balancing: we weigh our interests and those of our Customers against the interests, rights, freedoms and reasonable expectations of the Principal. We take into account that the data is drawn from public and licensed sources, that Principals are public-facing or commercially prominent individuals, that the Service is restricted to vetted professional Customers under contractual confidentiality and acceptable-use obligations, and that we apply safeguards and minimisation. Where the balance would not favour processing, we do not process, or we adjust what we hold.
Right to object. Because we rely on legitimate interests, a Principal has the right to object to our processing of their personal data at any time on grounds relating to their particular situation. Where a Principal objects, we will stop processing unless we can demonstrate compelling legitimate grounds that override the Principal's interests, rights and freedoms, or that the processing is necessary for the establishment, exercise or defence of legal claims. Section 11 explains how a Principal can exercise this and other rights.
6. Special category data
This section concerns sensitive personal data and we draw particular attention to it.
The Intelligence is compiled from public and licensed sources. In some cases, information that those sources have made public about a Principal may constitute special category personal data under Article 9 of the UK GDPR. The most likely example is information revealing political opinions or affiliations (for example reported donations, party roles or public political activity). Other Article 9 categories (such as data concerning religion, trade-union membership, or health) may occasionally appear where they have been reported in public sources, for example in connection with a Principal's well-documented philanthropy or public life.
We apply restraint to such data. We do not seek out special category data for its own sake, we do not infer sensitive characteristics, and we include such information only where it is already in the public domain through reputable sources and is relevant to the legitimate professional purposes described in this policy.
Where we process special category data, we rely on one or more of the following conditions:
- Data manifestly made public by the data subject (Article 9(2)(e)), for example where a Principal has themselves publicly disclosed or openly engaged in the relevant activity; and/or
- Substantial public interest (Article 9(2)(g)), read together with the relevant condition in Schedule 1 to the Data Protection Act 2018 (for example the conditions relating to the prevention or detection of unlawful acts, or to regulatory requirements relating to unlawful acts and dishonesty, in the context of sanctions, watchlist and compliance screening).
Where we rely on a Schedule 1 condition that requires it, we maintain an Appropriate Policy Document explaining how we comply with the data protection principles and our retention and erasure policies for special category data. A copy is available on request to [privacy@klypse-uhnw.com].
7. Purposes of processing
We process personal data for the following purposes.
For Customer and Authorised User data:
- to provide, administer and support the Service, including authentication and account management;
- to take payment and manage subscriptions and renewals;
- to operate, secure, monitor, troubleshoot and improve the Service and the Site;
- to communicate with you about the Service, including service and security notices;
- to send marketing communications where permitted, and to manage your preferences;
- to detect, prevent and investigate fraud, abuse and breaches of our terms; and
- to comply with legal obligations and to establish, exercise or defend legal claims.
For Principal data:
- to compile, structure, verify, de-duplicate and enrich profiles of Principals;
- to make the Intelligence available to Customers through the Service, including search, profiles, network mapping, signals and suggested approach strategies;
- to power the AI assistant so that Authorised Users can ask questions over the corpus and receive decision-support answers;
- to generate and surface compliance and screening signals (for example sanctions, watchlist and PEP indicators);
- to maintain the accuracy, currency and integrity of the corpus, including responding to rights requests and corrections; and
- to establish, exercise or defend legal claims, and to comply with legal obligations.
8. Disclosure and recipients
We do not sell personal data. We disclose personal data only as described below.
- Hosting and infrastructure providers: cloud hosting, storage, content delivery, database and related infrastructure providers that operate the Platform [e.g., named cloud provider].
- AI and large-language-model sub-processors: providers that power the AI assistant and related machine-learning features [e.g., named LLM provider]. These providers process queries and relevant context to generate responses. We contract for appropriate confidentiality and security, and (where offered) we use enterprise terms under which provider use of inputs and outputs to train their own models is not permitted.
- Analytics and product-telemetry providers: providers that help us understand and improve usage of the Site and Service [e.g., named analytics provider].
- Payment processors: to take and reconcile payments.
- Professional advisers: lawyers, auditors, accountants, insurers and consultants, where necessary and under duties of confidentiality.
- Corporate transactions: in connection with a merger, acquisition, financing, reorganisation or sale of assets, a successor or prospective counterparty and its advisers may receive personal data, subject to appropriate confidentiality protections.
- Legal and regulatory disclosures: courts, regulators, law-enforcement and government authorities where we are required to disclose by law or where disclosure is necessary to protect our rights, users or the public.
We engage sub-processors to process personal data on our behalf under written contracts that meet the requirements of Article 28 of the UK GDPR. A current list of sub-processors is maintained as part of, or alongside, our DPA and is available to Customers on request via [privacy@klypse-uhnw.com].
9. International transfers
We are based in the United Kingdom and we work with service providers that may be located outside the UK, including in the United States and elsewhere. Where we transfer personal data outside the UK to a country that is not covered by UK adequacy regulations, we put in place an appropriate transfer mechanism, which may include:
- the UK International Data Transfer Agreement ("IDTA"); or
- the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum to those clauses.
We carry out transfer risk assessments where required and, where appropriate, apply supplementary measures (such as encryption in transit and at rest, access controls and contractual commitments) to protect transferred personal data. You may request further information about the safeguards we use by contacting [privacy@klypse-uhnw.com].
10. Data retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting requirements.
- Customer and Authorised User data: retained for the duration of the subscription and the business relationship, and thereafter for a limited period to handle post-termination matters and to meet legal obligations [e.g., 6 years from the end of the relationship for records required for tax and limitation purposes].
- Usage and analytics data: retained for [e.g., 24 months] in identifiable form, and may be retained for longer in aggregated or de-identified form.
- Marketing data: retained until you opt out and for a short period thereafter to honour your preferences.
- Principal data: retained for as long as it remains relevant to the legitimate professional purposes described in this policy, and reviewed periodically for accuracy, currency and relevance. We remove or update entries that are no longer accurate or appropriate, and we apply specific retention controls to compliance signals and to special category data as described in our Appropriate Policy Document.
When personal data is no longer required, we securely delete or anonymise it.
11. Your rights and Principals' rights
11.1 Rights available under UK data protection law
Subject to the conditions and exemptions in UK data protection law, individuals have the right to:
- access the personal data we hold about them;
- request rectification of inaccurate or incomplete data;
- request erasure of their data in certain circumstances;
- request restriction of processing in certain circumstances;
- object to processing carried out on the basis of legitimate interests, and to object to direct marketing at any time;
- request portability of personal data they have provided to us, where applicable;
- withdraw consent at any time where we rely on consent (without affecting prior processing); and
- complain to the Information Commissioner's Office ("ICO"), the UK supervisory authority (www.ico.org.uk), although we would welcome the chance to resolve concerns first.
To exercise any of these rights, contact [privacy@klypse-uhnw.com]. We will respond within one month, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you.
11.2 How a Principal (who never signed up) can exercise their rights
We recognise that Principals do not have an account with us and did not provide their data directly. We are nonetheless committed to honouring Principals' rights.
- How to contact us: a Principal (or an authorised representative) may write to [privacy@klypse-uhnw.com] with the request. It helps if the request identifies the profile and the right being exercised.
- Identity verification: we verify identity proportionately. We ask only for information reasonably necessary to confirm that the requester is the Principal (or their authorised representative) and to locate the relevant records. We do not require an account, and we do not use verification as a barrier.
- Timeframe: we respond within the statutory period (one month, extendable by up to two months for complex requests, with notice).
- Right to object and right to erasure for the Intelligence corpus: because we process Principal data on the basis of legitimate interests, a Principal may object to that processing or request erasure. On receiving such a request we will reassess our legitimate-interests balancing in light of the Principal's particular situation. We will stop processing and erase the relevant data unless we can demonstrate compelling legitimate grounds that override the Principal's interests, rights and freedoms, or unless an exemption applies (for example where retention is necessary for compliance, screening, or the establishment, exercise or defence of legal claims). Where we decline a request in whole or in part, we will explain why and inform the Principal of their right to complain to the ICO.
We do not charge a fee for handling requests unless they are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act, as permitted by law.
12. Automated decision-making and the AI assistant
The Service includes an AI assistant and scoring and signalling features. These are designed to provide decision support to professional Authorised Users: they surface, summarise and organise the Intelligence so that a human professional can make their own assessment and decision.
Klypse does not use Principal data, the AI assistant, or any scoring to make decisions based solely on automated processing that produce legal effects concerning a Principal or that similarly significantly affect a Principal. Decisions about whether and how to engage a Principal are taken by the Customer's professional users, who exercise their own judgement. Outputs of the AI assistant may contain inaccuracies and are presented as decision support rather than as definitive determinations.
13. Cookies
The Site and the Service use cookies and similar technologies for essential operation, security, preferences and analytics. We set non-essential cookies only with consent where required under the Privacy and Electronic Communications Regulations ("PECR"). Full details, including the categories of cookie we use and how to manage your choices, are set out in our Cookie Policy.
14. United States privacy disclosures
This Section 14 applies to residents of the United States and supplements the rest of this policy. Where this section conflicts with the rest of the policy for a US resident, this section controls for that individual.
14.1 California (CCPA as amended by the CPRA)
This part applies to California residents and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA").
Categories of personal information we collect. In the 12 months preceding the date of this policy, we may have collected the following categories of personal information (as defined by the CCPA): identifiers (for example name, business contact details, IP address, online identifiers); commercial information (for example subscription and transaction records); internet or other electronic network activity (for example usage and analytics data); professional or employment-related information (for example job title and employer); financial details relevant to billing; inferences drawn from the above; and, for Principals, the publicly-sourced categories described in Section 2(B), which may include sensitive personal information such as information revealing political affiliation drawn from public sources.
Sources, purposes and disclosures. The sources of personal information are described in Sections 2 to 4, the business and commercial purposes for which we use it are described in Section 7, and the categories of recipient to whom we disclose it for business purposes are described in Section 8.
Sensitive personal information. Where we process sensitive personal information, we use it only for the purposes described in this policy and not for the purpose of inferring characteristics. We do not use or disclose sensitive personal information for purposes that would entitle a consumer to limit such use under the CCPA.
No sale; position on "sharing". We do not sell personal information for money. We also do not "sell" or "share" personal information as those terms are defined under the CCPA, where "sharing" refers to disclosure for cross-context behavioural advertising. We do not engage in cross-context behavioural advertising. We disclose personal information to service providers and contractors for business purposes only, under contracts that restrict their use of the information.
Your California rights. Subject to the CCPA and its exceptions, California residents have the right to:
- know the categories and specific pieces of personal information we have collected about them, and the sources, purposes and recipients;
- delete personal information we have collected, subject to exceptions;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information (noting that we do not sell or share); and
- be free from discrimination for exercising these rights.
How to exercise your rights. California residents may submit a request to [privacy@klypse-uhnw.com]. We will verify your request using information reasonably necessary to confirm your identity. You may use an authorised agent to submit a request on your behalf; we may require the agent to provide proof of authorisation and may require you to verify your own identity directly. We will not discriminate against you for exercising your rights.
14.2 Other US states
Residents of other US states that have enacted comprehensive privacy laws (for example Virginia, Colorado, Connecticut, Utah, Texas and others) may have rights to access, correct, delete and obtain a copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data or use it for targeted advertising as those terms are defined under those laws. To exercise any rights available to you under your state's law, or to appeal a decision we have made about a request, contact [privacy@klypse-uhnw.com] and identify the state in which you reside.
15. Children
The Service is intended solely for professional use by business users and is not directed to individuals under 18. We do not knowingly collect personal data from children, and we do not knowingly include information about children within the Intelligence. As a design choice, we exclude information about Principals' children from the corpus. If you believe we have inadvertently processed a child's personal data, please contact [privacy@klypse-uhnw.com] and we will take appropriate steps to delete it.
16. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify Customers by email or through the Service. We encourage you to review this policy periodically.
17. How to contact us
For any questions, requests or complaints about this policy or our processing of personal data, please contact us:
- General: [hello@klypse-uhnw.com]
- Data protection: [privacy@klypse-uhnw.com]
- Legal: [legal@klypse-uhnw.com]
- Post: [Klypse Ltd], [Registered Office Address]
Data Protection Officer / privacy contact. Our data protection contact is [DPO / Privacy Contact Name and Title], reachable at [privacy@klypse-uhnw.com].
UK / EU representative. [Where applicable, our representative for the purposes of Article 27 is [Representative Name and Address].]
ICO registration. Klypse is registered with the Information Commissioner's Office and pays the data protection fee. Our registration number is [ICO Registration No.]. You have the right to lodge a complaint with the ICO at any time (www.ico.org.uk), though we would appreciate the opportunity to address your concerns first.

