Lumino Capital Ltd
  • Home
  • Contact

Privacy Policy

Last updated: October 15, 2025 | Version 2.1

Lumino Capital Ltd ("Lumino Capital", "we", "us", "our") is committed to protecting the personal data of individuals who interact with us through our website, our investment activities, and our professional relationships. This Privacy Policy explains how we collect, use, store, and share personal data, and sets out the rights you have in relation to your data under applicable data protection law.

Lumino Capital Ltd is registered in England and Wales (Company Number: 12183740). Our registered office is at 14 Cornhill, Fourth Floor, London EC3V 3ND, United Kingdom. We are registered with the Information Commissioner's Office (ICO) under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (ICO Registration Number: ZB481920).

1. Who This Policy Applies To

This Privacy Policy applies to all individuals whose personal data we process, including:

  • Visitors to our website at luminomaltd.com and any subdomains;
  • Founders, entrepreneurs, and company representatives who submit pitches or enquiries to us;
  • Current and prospective limited partners and investors;
  • Portfolio company founders, executives, and employees with whom we interact in our capacity as investors;
  • Business contacts, service providers, and professional advisors;
  • Applicants for employment or advisory positions with Lumino Capital;
  • Any other individuals whose personal data we collect in connection with our business activities.

2. Data Controller Information

For the purposes of UK GDPR, Lumino Capital Ltd is the Data Controller responsible for your personal data.

Data Controller: Lumino Capital Ltd
Registered Address: 14 Cornhill, Fourth Floor, London EC3V 3ND, United Kingdom
Email: privacy@luminomaltd.com
Data Protection Officer: Available via dpo@luminomaltd.com
EU Representative: Available via eu-rep@luminomaltd.com

3. Personal Data We Collect

3.1 Information You Provide Directly

When you contact us, submit a pitch, complete a form on our website, or otherwise communicate with us, we may collect:

  • Identity data: First and last name, job title, professional role, and employer or organisation name;
  • Contact data: Email address, telephone number, postal address, and LinkedIn profile URL;
  • Business and investment data: Company name, business description, technology details, financial projections, investment history, and other information included in pitch materials;
  • Financial data: Bank account details, investment amounts, and related financial information provided by limited partners or in connection with our investment activities;
  • Communications data: Records of communications you have with us, including emails, meeting notes, and telephone call records;
  • Professional background data: Academic qualifications, employment history, publications, and other professional information relevant to our assessment of an investment opportunity or employment application.

3.2 Information We Collect Automatically

When you visit our website, we automatically collect certain technical information through cookies and similar technologies, including:

  • Device and browser data: IP address, browser type and version, operating system, device type, and screen resolution;
  • Usage data: Pages visited, time spent on each page, referring URLs, navigation paths, and interactions with page elements;
  • Location data: General geographic location derived from IP address (country and city level only; we do not collect precise GPS location data);
  • Cookie data: Session identifiers and preference settings stored through cookies (see our Cookie Policy for full details).

3.3 Information From Third Parties

We may receive personal data about you from third parties in the following circumstances:

  • From co-investors, accelerators, or other venture capital firms who refer founders or investment opportunities to us;
  • From publicly available sources, including company registers, professional networking sites (such as LinkedIn), academic publication databases, and press coverage;
  • From our portfolio companies in connection with our board or investor rights;
  • From background check and due diligence service providers in connection with our investment or employment processes;
  • From our limited partners in connection with their own due diligence on Lumino Capital.

4. How We Use Your Personal Data

4.1 Investment and Business Activities

We use personal data to evaluate, execute, and manage our investment activities, including:

  • Reviewing and assessing pitch materials and investment opportunities submitted to us;
  • Conducting due diligence on potential investments, including technical, commercial, and financial assessment;
  • Managing our relationships with portfolio company founders and executives;
  • Exercising our rights as investors, including board participation, reporting, and governance activities;
  • Managing our relationships with limited partners, including reporting, distributions, and investor communications;
  • Complying with our legal obligations as a regulated investment firm.

4.2 Website Operation and Improvement

We use technical data collected from website visitors to:

  • Deliver, maintain, and improve the performance of our website;
  • Diagnose technical errors and security issues;
  • Understand how visitors use our website in order to improve its content and navigation;
  • Ensure compliance with our legal obligations regarding website accessibility and data security.

4.3 Communications and Marketing

Where you have provided consent or where we have a legitimate interest, we use your contact data to:

  • Send you our insights, newsletters, and thought leadership content relevant to deep tech investing;
  • Invite you to events, roundtables, and other activities organised by Lumino Capital;
  • Respond to enquiries and provide information you have requested;
  • Maintain our professional network and business relationships.

4.4 Legal and Compliance

We process personal data as required to:

  • Comply with our obligations under the Financial Services and Markets Act 2000 and related regulations;
  • Meet our anti-money laundering and know-your-customer obligations under the Proceeds of Crime Act 2002 and the Money Laundering Regulations 2017;
  • Respond to requests from regulatory authorities including the Financial Conduct Authority;
  • Establish, exercise, or defend legal claims;
  • Comply with tax reporting obligations.

5. Legal Basis for Processing

We rely on the following legal bases under UK GDPR Article 6 to process your personal data:

  • Performance of a contract (Article 6(1)(b)): Where processing is necessary to enter into or perform a contract with you, such as the terms of an investment agreement or a service agreement;
  • Compliance with legal obligations (Article 6(1)(c)): Where we are required by law to process your data, including anti-money laundering requirements and financial regulatory obligations;
  • Legitimate interests (Article 6(1)(f)): Where processing is necessary for our legitimate business interests, including investment evaluation, portfolio management, and professional networking, provided these interests are not overridden by your rights and interests;
  • Consent (Article 6(1)(a)): Where you have given specific, informed consent to processing for a particular purpose, such as receiving our marketing communications. You may withdraw consent at any time by contacting us at privacy@luminomaltd.com;
  • Vital interests (Article 6(1)(d)): In the rare circumstances where processing is necessary to protect the vital interests of a data subject;
  • Public task (Article 6(1)(e)): Where applicable in connection with our regulatory obligations to public authorities.

Where we process special category data (such as health information in exceptional employment circumstances), we rely on Article 9(2) of UK GDPR, including explicit consent, substantial public interest, or as necessary for establishing or defending legal claims.

6. How We Share Your Personal Data

6.1 Within Our Investment Activities

We may share personal data with:

  • Co-investors and syndicate partners: Where we co-invest alongside other venture capital firms or angel investors, we may share relevant information about investment opportunities and portfolio companies;
  • Portfolio companies: We may share information about potential business partners, customers, or advisors with our portfolio companies where relevant to their business development;
  • Limited partners: We share information about portfolio company performance and key personnel with our limited partners in connection with their investor rights, subject to appropriate confidentiality obligations;
  • Professional advisors: We engage lawyers, accountants, technical advisors, and other professionals who may process personal data on our behalf in connection with our investment activities.

6.2 Service Providers

We engage third-party service providers to assist with our business operations, including cloud storage providers, customer relationship management software, email marketing platforms, website analytics services, and due diligence platforms. These providers process personal data on our behalf as data processors and are bound by data processing agreements that impose UK GDPR-compliant obligations.

6.3 Legal and Regulatory Disclosures

We may disclose personal data to law enforcement agencies, regulatory bodies (including the Financial Conduct Authority and the Information Commissioner's Office), courts, and other third parties where required by law, court order, or where we believe disclosure is necessary to protect our legal rights or the rights of others.

6.4 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or part of our business, personal data may be transferred to the relevant acquirer or successor entity, subject to appropriate confidentiality protections and applicable data protection law.

7. International Data Transfers

Lumino Capital is headquartered in the United Kingdom. Some of our service providers and co-investors are located in the European Economic Area, the United States, or other countries outside the UK. Where we transfer personal data outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR, including:

  • Transfers to countries with a UK adequacy decision (currently including the EEA, and a number of other countries);
  • Transfers subject to UK International Data Transfer Agreements (IDTAs) or UK Addendums to EU Standard Contractual Clauses;
  • Transfers to certified members of approved transfer schemes.

You may obtain further details about the safeguards applicable to specific transfers by contacting privacy@luminomaltd.com.

8. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected and to comply with our legal obligations. Our general retention periods are as follows:

  • Investment enquiries and pitch materials: 5 years from the date of our last interaction, to enable us to re-evaluate opportunities and for potential legal claims;
  • Active investment records: 10 years from the realisation of the investment, to comply with financial regulatory obligations;
  • Limited partner records: 10 years from the end of the fund lifecycle;
  • Employment records: 6 years after termination of employment;
  • Website analytics data: 26 months from collection;
  • Marketing communications: Until you withdraw consent or unsubscribe, plus 1 year;
  • Anti-money laundering records: 5 years from the end of the business relationship, as required by the Money Laundering Regulations 2017.

After the applicable retention period, personal data is securely deleted or anonymised in accordance with our data disposal procedures.

9. Your Rights Under UK GDPR

Subject to applicable law and conditions, you have the following rights in relation to your personal data:

  • Right of access (Article 15): You have the right to request a copy of the personal data we hold about you, along with information about how we process it;
  • Right to rectification (Article 16): You have the right to request correction of inaccurate personal data, or to have incomplete data completed;
  • Right to erasure (Article 17): You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the original purpose of collection;
  • Right to restrict processing (Article 18): You have the right to request that we limit the way we use your personal data in certain circumstances;
  • Right to data portability (Article 20): Where processing is based on consent or contract and carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format;
  • Right to object (Article 21): You have the right to object to our processing of your personal data where we rely on legitimate interests as the legal basis, including for direct marketing purposes;
  • Rights relating to automated decision-making (Article 22): You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or significantly affect you;
  • Right to withdraw consent: Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact our Privacy Team at privacy@luminomaltd.com or write to us at 14 Cornhill, Fourth Floor, London EC3V 3ND, United Kingdom. We will respond to your request within one month of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months, notifying you of the extension within the initial one-month period.

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or refuse to act on the request.

10. Data Security

We take the security of personal data seriously and have implemented technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS 1.3) and at rest using AES-256 encryption;
  • Access controls and role-based permissions limiting access to personal data to those with a legitimate business need;
  • Multi-factor authentication for access to systems containing personal data;
  • Regular security assessments and penetration testing of our technology infrastructure;
  • Staff training on data protection obligations and security awareness;
  • Physical security measures at our London office;
  • Incident response procedures for detecting, reporting, and responding to data breaches.

In the event of a personal data breach that poses a risk to the rights and freedoms of individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

11. Children's Privacy

Our website and services are not directed at children under the age of 18, and we do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that data promptly. If you believe we have inadvertently collected such information, please contact us at privacy@luminomaltd.com.

12. Third-Party Links and Services

Our website may contain links to third-party websites, including those of portfolio companies, co-investors, and other organisations. This Privacy Policy applies only to our website and our own data processing activities. We are not responsible for the privacy practices of third-party websites and encourage you to review the privacy policies of any sites you visit.

13. Complaints

If you have concerns about how we have handled your personal data, we encourage you to contact us in the first instance at privacy@luminomaltd.com so that we can try to resolve your concern. If you remain dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
United Kingdom
Website: ico.org.uk
Telephone: 0303 123 1113

If you are located in the European Union, you may also lodge a complaint with the relevant supervisory authority in the EU member state where you reside or work, or where the alleged infringement occurred.

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, applicable law, or regulatory guidance. We will post the updated policy on our website with a revised "last updated" date. Where changes are material, we will endeavour to notify affected individuals by email or by displaying a prominent notice on our website. We encourage you to review this policy periodically.

15. Contact Us

For any questions, requests, or concerns relating to your personal data or this Privacy Policy, please contact us using the details below:

Privacy Team
Email: privacy@luminomaltd.com

Data Protection Officer
Email: dpo@luminomaltd.com

EU Representative
Email: eu-rep@luminomaltd.com

UK Representative (Correspondence)
Lumino Capital Ltd
14 Cornhill, Fourth Floor
London EC3V 3ND
United Kingdom

For written requests, please clearly mark your envelope or the subject line of your email "Data Protection Request" to ensure prompt routing to the appropriate team member.

Lumino Capital Ltd • 14 Cornhill, Fourth Floor, London EC3V 3ND, United Kingdom • Registered in England and Wales No. 12183740 • ICO Registration ZB481920 • This document was last reviewed by our Data Protection Officer on October 15, 2025

© 2025 Lumino Capital Ltd. All rights reserved. Registered in England and Wales.

Privacy Policy Terms of Use Cookie Policy

We use cookies to improve your experience and analyze site traffic. By clicking "Accept", you consent to our use of cookies. Privacy Policy