Last updated: 21 August 2026
Privacy Policy
This policy explains how BlackFries processes personal data in connection with the blackfries.ventures website (the “Site”), its public forms, community and investor portal.
It applies in particular to visitors, applicants, founders, experts, partners, investors and prospective investors, complainants, subscribers and authorised users of the Site.
1. Data controller
As of the date of this policy, BlackFries is in the process of incorporation. Until the company is incorporated, the controller must be the person or persons who actually operate the Site and determine the purposes and means of the processing:
Passage à arbitrer avant publication : TO BE CONFIRMED BEFORE PUBLICATION: David Francotte, Eileen Cols, or both as joint controllers
Operating under the name “BlackFries”
Business address: Passage à arbitrer avant publication : TO BE COMPLETED
Brussels, Belgium
General contact: hello@blackfries.ventures
Data protection: privacy@blackfries.ventures
Service complaints: complaints@blackfries.ventures
Once BlackFries has been incorporated, this section will be replaced with the company’s registered name, legal form, registered office, enterprise number and, where applicable, VAT number.
2. Principles we apply
BlackFries processes personal data lawfully, fairly and transparently. We limit data to what is necessary, control access to it and do not retain it longer than required for the purposes described below, our legal obligations or the establishment, exercise or defence of legal claims.
We do not sell or rent personal data. We do not use advertising trackers and do not enable Google Analytics advertising features.
3. Data, purposes and legal bases
3.1 Site access, operation and security
When you visit or use the Site, we may process your IP address, or a non-reversible hash of it, the date and time, requested resource, device type, browser, operating system, language, referring URL, request identifier, authentication events and information required to detect errors or misuse.
We use this data to provide the Site, protect accounts and documents, diagnose incidents, prevent attacks, limit abusive attempts and maintain an audit trail. Processing is based on our legitimate interest in operating a reliable and secure service and, where the security of a contractual service is concerned, on performance of the contract.
Data used solely for rate limiting and abuse prevention is automatically deleted after 24 hours. Session cookies expire as stated in section 9. Security and audit logs follow the periods stated in section 7.
3.2 Contact form and professional communications
We process your name, email address, organisation, subject, message, language, the date of your request, a hash of your IP address and subsequent communications.
We use this information to reply, arrange a conversation, follow up on the request and manage the professional relationship. Depending on the context, processing is based on steps taken at your request before entering into a contract or our legitimate interest in responding to requests and developing our activities.
When the CRM service is enabled, the only data sent to it is the name, email address, organisation, subject, message, language, date and internal contact reference. No KYC data, investment information or information about a confidential venture is sent to the CRM.
3.3 CEO and other collaboration applications
To assess an application, we may process:
- first and last name, email, telephone number, place of residence and languages;
- LinkedIn profile and other professional links provided;
- background, skills and sectors or markets known;
- entrepreneurial experience, motivations, answers, availability and proposed start date;
- CV and other documents submitted;
- interview notes, assessments and communications concerning the application.
We use this data to assess the application, determine its fit with an opportunity, arrange interviews and consider a partnership. Processing is primarily based on steps taken at your request before entering into a contract. Limited retention for process traceability is based on our legitimate interest in managing selections and defending our rights.
Confirming that you have read this policy is not the legal basis for the processing. Separate and optional consent will be requested if BlackFries wishes to retain an application for longer in order to propose future opportunities.
Please do not include unnecessary sensitive data in your CV or answers, such as information concerning health, beliefs, origin, sex life or sexual orientation.
3.4 Submitting a project or company
We may process the founder’s identity and contact details, LinkedIn profile, company name and website, team composition, problem addressed, market, product, customers, stage, commercial evidence, revenue, funding raised, stated needs, form responses, pitch deck and subsequent communications or assessments.
We use this information to assess the project and consider a partnership, support arrangement or investment. Processing is based on steps taken at your request before entering into a contract and our legitimate interest in selecting and developing projects consistent with BlackFries’ activities.
If you provide data concerning co-founders, team members, customers or other persons, you must ensure that the disclosure is necessary and that you are authorised to make it.
3.5 Newsletter and communications
When you subscribe to “The Logbook”, we process your email address, language, subscription date and source, proof of consent and information necessary to manage unsubscribing.
Sending communications is based on your consent. You may withdraw it at any time using the unsubscribe link in each message or by emailing privacy@blackfries.ventures. Withdrawal does not affect the lawfulness of messages sent before it.
After unsubscribing, minimal information may be retained on a suppression list to ensure that your choice continues to be respected.
3.6 Creating and managing an investor account
When you create or use an investor portal account, we may process:
- first and last name, email, telephone number, country, language, company, role and investor type;
- email and telephone verification dates;
- a password stored only as a salted cryptographic hash;
- verification and reset tokens, also stored only as hashes;
- login attempts, lockouts, sessions, last login and activity dates;
- a non-reversible hash of the IP address, browser details and security events;
- account status, pre-screening notes and the human decision to admit, suspend or archive the account;
- versions and hashes of terms, policies and other documents accepted.
We use this data to create and secure the account, verify contact details, manage access and assess admission to the private portal. Processing is based on pre-contractual steps, performance of a contract, our legitimate interest in protecting the private portal and, for certain records, compliance with applicable legal obligations.
Telephone verification uses a one-time code. BlackFries stores the telephone number, a hash of the code, its expiry, the number of attempts and, where available, a provider reference. The plain-text code is not stored.
3.7 NDA, data room, opportunities and reports
When you access an opportunity or data room, we may record:
- the invitation, its basis, date, opening, acceptance, expiry or revocation;
- the exact version and hash of the confidentiality agreement accepted, the date, IP hash and browser;
- permissions granted or revoked for documents;
- downloads or views needed for security and access evidence;
- reports made available to you and the date of first access.
We use this data to protect confidential information, limit private offerings to authorised persons, manage access and demonstrate what was presented or accepted. Processing is based on performance of a contract, our legitimate interest in protecting projects and, where required by the applicable framework, compliance with legal obligations.
3.8 Expressions of interest and waiting lists
We may process the relevant project, indicative amount, currency, message, date, version of the acknowledgement accepted, change history, internal decision, optional withdrawal or closure reason and any waiting-list entry.
We use this data to collect and manage a non-binding expression of interest, review indicative round capacity and organise communications. Processing is based on pre-contractual steps, performance of a contract, our legitimate interest in administering opportunities and, where applicable, compliance with legal obligations.
An expression of interest does not, by itself, constitute a subscription, reservation of securities or investment commitment.
3.9 Suitability questionnaire
When this feature is enabled, we process the answers to a versioned questionnaire, score, maximum score, outcome, warning presented and any acknowledgement of it, completion date and expiry date.
We use this data to assess knowledge and understanding of risk, present appropriate warnings and, where applicable, comply with investor-protection requirements. Processing is based on compliance with legal obligations where they apply and otherwise on our legitimate interest in avoiding the presentation of an opportunity to a person who does not understand its characteristics and risks.
3.10 KYC/KYB identity verification
This feature remains disabled until the required contracts, legal basis, retention periods and validations have been formalised.
Once enabled, verification will be carried out using Sumsub or another provider expressly identified before the check starts. Depending on whether you act individually or for a company, the provider may process:
- name, date and place of birth, nationality and address;
- an identity document and proof of address;
- a facial photograph or video and biometric data used to verify identity and liveness;
- company documents, representatives, authority and beneficial owners;
- politically exposed person, sanctions and adverse-media checks;
- technical information necessary for the check.
BlackFries is designed not to retain identity documents, selfies, liveness recordings, biometric templates, payment data or detailed AML rejection reasons. It retains only the case references, provider, workflow, dates, status, expiry and a limited operational outcome category.
Where the check is required by applicable law, processing is based on compliance with a legal obligation and, for special categories of data, the basis provided by applicable anti-money-laundering and substantial-public-interest legislation. The provider’s precise role, its own legal bases and retention periods will be stated in the information shown before the check.
A favourable provider result does not automatically result in admission. Admission is subject to a separate decision by an authorised person at BlackFries.
3.11 Subscription or investment
If a subscription journey is enabled, BlackFries may process the project and opportunity concerned, amount and currency, subscription status, KYC, signature and payment statuses, relevant dates and references assigned by the investment provider.
Identity documents, bank details, card data, raw signatures and detailed payment information remain with the regulated provider; BlackFries does not retain them in its database.
We use this information to execute and monitor the subscription, observe any cooling-off period, maintain evidence and comply with legal and regulatory requirements. Processing is based on performance of a contract and compliance with legal obligations. The investment provider and its role will be identified before any real subscription.
3.12 Complaints
When you make a complaint, we process your name, email, optional telephone number, language, category, subject, description, any reference, IP hash, applicable deadlines, communications, actions taken, internal notes, response and outcome.
We use this information to register, investigate and resolve the complaint, communicate with you and retain evidence of its handling. Processing is based on compliance with legal obligations where applicable and our legitimate interest in handling complaints and defending our rights.
3.13 Administrative users
For persons authorised to administer the Site, we process professional contact details, identifiers, role, password hash, recovery address, access events, sessions, IP hash and data needed for two-factor authentication. TOTP secrets are encrypted and recovery codes are stored only as hashes.
Processing is based on performance of the contractual relationship and our legitimate interest in protecting the Site, maintaining accountability and allocating responsibilities.
3.14 Google Analytics
With your prior consent, the Site uses Google Analytics 4, provided by Google Ireland Limited, to produce usage statistics and improve content and performance.
The data may include pages viewed, interaction events, approximate session duration, device and browser type, language, approximate geographic area and referring URL. The IP address is processed when connecting to provide the service and derive technical or geographic information. The Site configuration requests IP anonymisation and keeps advertising signals disabled.
Google Analytics is loaded only after you agree. You may refuse without losing access to the Site and withdraw consent at any time using the “Audience measurement” controls on this page. Withdrawal stops future transmissions but does not affect prior lawful processing.
The retention period for user and event data in Google Analytics must be set to Passage à arbitrer avant publication : TO BE CONFIRMED: 2 or 14 months. Truly anonymous statistics may be retained for longer.
4. Sources of data
Data is obtained primarily from you, your use of the Site and the documents you submit. It may also come from:
- professional sources you make public, including LinkedIn or your organisation’s website;
- an authorised administrator who invites you or records a decision;
- an identity-verification or investment provider;
- professional partners, advisers, notaries, accountants, banks or authorities, where necessary and lawful.
Where substantial information is obtained from another source and you do not already have the required information, we will inform you in accordance with the GDPR.
5. Required data
Fields marked as required are necessary to process the relevant request. Failure to provide them may prevent BlackFries from replying, assessing an application or project, creating an account, granting access or carrying out an investment process.
Newsletter subscription and Google Analytics consent are optional. They do not affect access to the public Site or assessment of a request.
6. Recipients and service providers
To the extent required for their role and on a need-to-know basis, data may be accessible to:
- David Francotte, Eileen Cols and authorised BlackFries team members;
- authorised persons assessing an application, project, request, complaint or opportunity, subject to appropriate confidentiality duties;
- Vercel, for hosting and delivery of the Site;
- Neon, or the PostgreSQL provider actually configured, for the database and private file storage;
- Resend, when enabled, for transactional and verification emails;
- Twilio, when enabled, for SMS verification codes;
- HubSpot, only if the CRM integration is enabled, for limited contact-form data;
- Sumsub, only if KYC/KYB verification has been legally validated and enabled;
- Google Ireland Limited, only after consent, for Google Analytics;
- the investment provider identified before any real subscription;
- subsequently approved external storage, backup, security or monitoring providers;
- lawyers, accountants, auditors, notaries, banks, investment providers and other necessary professional advisers;
- authorities, courts or supervisory bodies where required by law or necessary to defend legal rights.
Where recipients act on our behalf, they are bound by a data-processing agreement. Some providers may also act as independent controllers for their own legal obligations and must then provide their own privacy information.
7. Retention periods
The following periods apply unless a longer legal obligation, dispute or need to establish, exercise or defend a legal claim requires otherwise:
| Data | Intended retention period |
|---|---|
| Abuse-prevention and rate-limit data | 24 hours |
| Investor session cookies | 2 hours by default, unless a different configuration is clearly announced |
| Administrator session cookies | 8 hours by default |
| Contact forms | 24 months after the last exchange or handling of the request |
| Unsuccessful CEO or collaborator applications | Selection period plus 6 months; up to 24 months only with separate consent for future opportunities |
| Projects and partnership requests without a contract | 24 months after the last exchange |
| Newsletter | Until unsubscribe; minimal proof of withdrawal for as long as necessary to respect it |
| Investor account without a transaction | Relationship period plus 24 months after closure, unless evidence or a legal obligation requires longer |
| Verification and reset tokens | Until use or expiry, followed by deletion under the technical cleanup cycle |
| Authentication and security logs | Passage à arbitrer avant publication : TO BE SET AND IMPLEMENTED: recommended period 12 months |
| NDAs, acceptances, invitations, access, expressions of interest and warnings | Relationship period plus up to 10 years where necessary for evidence or a legal obligation |
| Subscription, transaction and KYC reference data | Up to 10 years after the relationship or transaction where financial or anti-money-laundering law requires it |
| Complaints and handling history | Passage à arbitrer avant publication : TO BE SET AND IMPLEMENTED: recommended period 5 years after closure, or longer legal period |
| Google Analytics data | Passage à arbitrer avant publication : 2 or 14 months, subject to confirmation of the setting |
| Neon backups | According to the account setting, with a target of no more than 7 days of continuous history |
| Encrypted external backups | Passage à arbitrer avant publication : TO BE SET AND IMPLEMENTED |
At the end of the applicable period, data is deleted or anonymised. When an investor requests account erasure, BlackFries neutralises directly identifying data, deletes credentials, tokens and sessions, and revokes access. Records that must be preserved—such as an NDA acceptance, invitation, expression of interest or warning—may remain under an identifier that can no longer be attributed to that person.
Backups are not rewritten following every deletion. Deletion is reflected when the relevant backup expires; if a backup is restored, erasure requests made after it was created must be reapplied.
8. Transfers outside the European Economic Area
BlackFries favours hosting regions located in the European Economic Area (“EEA”). The deployment provides for a PostgreSQL database in a European region and, if Sumsub is enabled, European hosting where available.
International providers such as Google, Vercel, Resend, Twilio, HubSpot or Sumsub may nevertheless make data accessible from countries outside the EEA. Any such transfer must rely on a European Commission adequacy decision—including the EU–US Data Privacy Framework where its conditions are met—or the European Commission’s Standard Contractual Clauses, supplemented where necessary by additional safeguards.
You may request information about the applicable safeguards at privacy@blackfries.ventures.
9. Cookies and similar technologies
| Name | Function | Basis | Duration |
|---|---|---|---|
bf-analytics-consent | Remembers acceptance or refusal of Google Analytics | Strictly necessary to respect the choice | 182 days |
_ga | Distinguishes visitors for Google Analytics | Consent | Up to 2 years |
_ga_<identifier> | Maintains Google Analytics session state | Consent | Up to 2 years |
__Host-bf_investor_session | Authenticates an investor; random value, HttpOnly, SameSite Strict, Secure, and a __Host- name the browser itself enforces | Necessary for the requested service | 2 hours by default |
__Host-bf_portal | Displays portal access in the interface; grants no access rights | Necessary for the requested interface | 2 hours by default |
__Host-bf_investor_target | Remembers which venture a visitor was looking at before signing up, so the account lands back on it | Necessary for the requested service | 30 minutes |
__Host-bf_admin_session | Authenticates an administrative user; random value, HttpOnly, SameSite Strict, Secure, and a __Host- name the browser itself enforces | Necessary for service security | 8 hours by default |
Refusing Google Analytics does not prevent use of the Site. Account cookies are necessary for signing in; blocking them prevents use of the relevant portal.
10. Automated decisions and profiling
BlackFries does not make decisions based solely on automated processing that produce legal or similarly significant effects.
A suitability questionnaire may automatically calculate a score and a KYC provider may issue a status. These results inform or assist the review. Investor admission and other significant decisions are made separately by an authorised person. If a solely automated decision were introduced, specific information would be provided before it is used.
11. Security
BlackFries implements measures appropriate to the risks, including:
- encrypted connections;
- role-based access and need-to-know controls;
- separate investor and administrator sessions;
- passwords, tokens and codes stored only as cryptographic hashes;
- two-factor authentication for sensitive administrative functions;
- attempt limiting and abuse detection;
- private storage of CVs, decks and data-room documents without public URLs;
- logging of sensitive operations and dual approval for certain actions;
- minimisation of data received from KYC and investment providers;
- backups and restoration procedures.
No system is completely secure. If a breach is likely to create a risk to your rights and freedoms, we will comply with applicable notification duties and inform you where required by law.
12. Your rights
Subject to the conditions of the GDPR, you may:
- access your data and obtain a copy;
- correct inaccurate or incomplete data;
- request erasure;
- request restriction of processing;
- object, on grounds relating to your situation, to processing based on our legitimate interests;
- receive data you provided in a structured, commonly used and machine-readable format, or request its transmission to another controller where portability applies;
- withdraw consent at any time without retroactive effect;
- request human intervention where a decision under Article 22 GDPR is used.
Some rights are not absolute. An erasure request cannot, for example, require deletion of evidence that BlackFries must legally retain. In that event, unnecessary data is deleted or anonymised and the remaining data is restricted to the mandatory retention purpose.
Send requests to privacy@blackfries.ventures. We may request information reasonably necessary to verify your identity. We normally reply within one month; this may be extended by two months for complex or numerous requests, in which case we will inform you within the first month.
You may lodge a complaint with:
Belgian Data Protection Authority
Rue de la Presse 35
1000 Brussels — Belgium
www.dataprotectionauthority.be
You may also contact the supervisory authority of your habitual residence, place of work or the place of the alleged infringement.
13. Third-party links
The Site may link to third-party services, including LinkedIn. When you follow such links, the third party processes data under its own policy. BlackFries is not responsible for independent processing by those services.
14. Minors
The Site and investor portal are intended for adult professionals. They are not directed at children and BlackFries does not knowingly collect their data.
15. Changes
We may amend this policy to reflect changes to our activities, the Site, providers or applicable law. The latest update date appears above. Where a change is material, an appropriate notice will be published on the Site or sent to the affected persons. Where a document accepted in the investor portal changes materially, renewed acceptance may be required.
