GMV INVEST
DEENBack to home

Last updated: 31 July 2026

Privacy Policy

Information pursuant to Articles 12, 13 and 14 of the General Data Protection Regulation (GDPR).

ControllerWebsite operationCommunicationsMandate relationshipsRecipients & third countriesYour rights

01

Controller

GMV Invest GmbH
Bergesgrundweg 3
60599 Frankfurt am Main
Germany

Telephone: +49 69 680 919 20
Email: Office@GMV-Invest.EU

GMV Invest GmbH is the controller within the meaning of Article 4(7) GDPR. This Privacy Policy applies to visits to this website and to the business contact and mandate processes described below.

02

Website provision and technical log data

When you access this website, the technical infrastructure used to provide it may process, in particular, your IP address, date and time of access, the resource requested, volume of data transferred, referring URL, browser type, operating system and technical status and error data. This processing is required to deliver the website, ensure stability and security, prevent misuse and analyse technical errors.

Legal basis
Article 6(1)(f) GDPR; our legitimate interest is the secure and functional operation of this online service.
Retention
Log data are deleted or anonymised once no longer required for the purposes stated, unless statutory retention duties or legitimate security interests require otherwise.
Hosting
We engage technical service providers as processors pursuant to Article 28 GDPR for provision, maintenance and security.

Cookies, tracking and external media

In its current configuration, this website does not use analytics, marketing or profiling technologies. GMV Invest GmbH does not place any non-essential cookies. If the website's functionality changes in the future, this Privacy Policy will be updated and any consent required under Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) will be obtained before accessing or storing information on your device.

03

Contact and business communications

If you contact us by email, telephone or another business channel, we process the information you provide, typically your name, company, role, contact details, communication content and any documents. Processing takes place to handle your enquiry, communicate with you and initiate or perform a business relationship.

Legal bases
Article 6(1)(b) GDPR for pre-contractual or contractual measures; Article 6(1)(f) GDPR for other business communications; and Article 6(1)(c) GDPR where legal obligations apply.
Retention
We retain communications for as long as required to handle the matter and manage the business relationship. They are then deleted unless statutory retention duties or legitimate interests, such as the establishment, exercise or defence of legal claims, require otherwise.

04

Mandate initiation, KYC and compliance reviews

When initiating and performing a mandate, we may process identity, contact, professional and corporate data, authority to represent, information on ultimate beneficial owners, ownership and control structures, politically exposed persons, sanctions exposure, source of funds, transaction background and supporting evidence. Sources may include data subjects, their companies, counterparties, registers, authorities, professional data providers and publicly available sources.

Processing serves to assess and perform the mandate, manage risk, prevent money laundering and terrorist financing, comply with foreign trade and sanctions requirements and protect against legal, reputational and default risks.

Legal bases
Article 6(1)(b), (c) and (f) GDPR; where legally permissible and necessary for special categories of personal data, additionally Article 9(2) GDPR.
Legitimate interests
Transaction integrity and security, prevention of unlawful business relationships, protection of our company, clients and partners, and traceable governance.
Retention
Data are retained for the duration of the business relationship and subsequently in accordance with applicable statutory retention periods. Where the GwG applies, retention is governed in particular by Section 8 GwG; commercial and tax retention periods may apply under the HGB and AO.

05

Recipients, service providers and international transfers

Within GMV Invest GmbH, personal data are accessible only to those who require them for their respective responsibilities. Where necessary and lawful, data may be disclosed to clients, transaction parties, banks and financing participants, lawyers, tax advisers, auditors, corporate finance and sector experts, identification and compliance providers, IT and communications providers, authorities and courts.

Service providers are carefully selected and contractually bound in accordance with Articles 28 and 32 GDPR. We do not disclose personal data for third parties' independent advertising purposes or sell personal data.

Third countries

International mandates or global technical infrastructure may require transfers to countries outside the European Union or European Economic Area. Such transfers take place only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision under Article 45 GDPR, appropriate safeguards under Article 46 GDPR — such as standard contractual clauses and supplementary safeguards — or an applicable derogation under Article 49 GDPR.

06

Your data protection rights

Subject to the applicable statutory conditions, you have the right of access (Article 15 GDPR), rectification (Article 16 GDPR), erasure (Article 17 GDPR), restriction of processing (Article 18 GDPR), data portability (Article 20 GDPR) and objection (Article 21 GDPR). You may withdraw consent at any time with effect for the future (Article 7(3) GDPR).

Objection under Article 21 GDPR: Where we process data on the basis of legitimate interests under Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation. You may object to direct marketing at any time without stating reasons.

To exercise your rights, please contact us using the details above. You also have the right under Article 77 GDPR to lodge a complaint with a data protection supervisory authority. The Hessian Commissioner for Data Protection and Freedom of Information is one competent authority; you may also contact the supervisory authority at your habitual residence, place of work or the place of the alleged infringement.

Requirement to provide data and automated decisions

You are generally under no statutory obligation to provide personal data merely to visit this website. Certain information may be contractually or legally required to initiate or perform a mandate; without it, we may be unable to accept or perform the mandate. We do not engage in solely automated decision-making, including profiling, within the meaning of Article 22 GDPR.

07

Data security and updates

Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of processing, we maintain appropriate technical and organisational measures pursuant to Article 32 GDPR. This Privacy Policy will be updated where the legal framework, processing activities or technical functions materially change.

GMV INVEST
ImprintPrivacy Policy
© 2026 GMV Invest GmbH