Pario Ventures aims to use personal data fairly, transparently and only where there is a clear business or legal reason to do so. This notice applies to information collected through this website and through related business communications.
Who we are and who controls your data
Pario Ventures is the controller responsible for personal data collected through this website and through direct business contact with our team. Where EU GDPR applies to a particular processing activity, we apply the relevant EU GDPR requirements as well as the UK requirements that apply to us.
Building 41, Newport Road, Cowes, Isle of Wight, England, PO31 8BX
For privacy matters, contact compliance@parioventures.com.
Information we may collect
The information we collect depends on how you interact with us. It may include:
- Contact and identity information: name, email address, telephone number, job title and company.
- Enquiry information: funding stage, raise amount, business description and anything else you choose to include in a website enquiry or message.
- Business relationship information: meeting notes, introductions, correspondence, transaction or opportunity context and professional preferences.
- Technical and security information: IP address, browser and device information, request headers, timestamps and server or security logs generated when the website is used.
- Administration information: limited authentication and session information used by authorised administrators of the restricted website administration area.
Please do not include special-category or other highly sensitive personal data in the website contact form unless it is genuinely necessary. The public website is not directed at children and we do not intentionally seek personal data from children.
Where personal data comes from
Most information is provided directly by you when you complete the contact form, email us, meet us or otherwise communicate with Pario Ventures.
We may also receive professional information from a referrer, strategic partner, portfolio company, adviser or another business contact, or from publicly available professional sources such as company websites and professional networking platforms. Where data-protection law requires us to provide additional information because data was obtained indirectly, we will do so within the required timeframe unless a lawful exception applies.
Why we use personal data and our lawful bases
We use personal data only where an applicable lawful basis exists. Depending on the activity, the principal purposes and bases are:
- Responding to enquiries and managing business relationships: our legitimate interests in responding to people who contact us, assessing relevant business opportunities and maintaining professional relationships. Where discussions concern a possible contract, processing may also be necessary to take steps at your request before entering into that contract.
- Evaluating investment, commercial or partnership opportunities: our legitimate interests in operating, developing and protecting the Pario Ventures business, carrying out appropriate diligence and deciding which opportunities to pursue.
- Making relevant introductions and communicating with business contacts: our legitimate interests in maintaining an effective professional network and facilitating appropriate business discussions. We consider the reasonable expectations, privacy impact and rights of the people concerned before relying on this basis.
- Operating and securing the website: our legitimate interests in providing a reliable website, preventing spam, fraud and misuse, troubleshooting faults and protecting our systems and users.
- Maintaining records and complying with law: compliance with legal obligations, regulatory requirements, court orders, accounting requirements and the establishment, exercise or defence of legal claims where applicable.
- Activities requiring consent: where the law requires consent for a specific activity, such as certain non-essential cookies or optional electronic marketing, we will ask separately. Consent can be withdrawn at any time.
Submitting an enquiry is not marketing consent
We do not treat completion of the website contact form as consent to add you automatically to a marketing list.
Our legitimate interests include responding to business enquiries, developing and managing commercial relationships, evaluating opportunities, protecting the website and systems, preventing misuse and operating Pario Ventures efficiently. When we rely on legitimate interests, we consider whether the processing is necessary and balance those interests against your rights and reasonable expectations.
Contact-form fields marked as required are needed for us to receive and respond meaningfully to an enquiry. Other fields are optional. If required information is not provided, we may be unable to respond.
Who we may share personal data with
We disclose personal data only where it is reasonably necessary for the purposes described above. Recipients may include:
- Website and infrastructure providers, currently including Vercel for website hosting, serverless processing and related infrastructure.
- Email and communications providers, currently including Google Workspace for business email and delivery of website enquiries.
- Professional advisers and service providers such as lawyers, accountants, auditors, consultants and IT or security providers where relevant.
- Portfolio companies, strategic partners, investors or counterparties where an introduction, opportunity, diligence exercise or transaction makes the disclosure appropriate and lawful.
- Courts, regulators, law-enforcement bodies and public authorities where disclosure is required or permitted by law.
- A purchaser, investor or successor organisation if Pario Ventures or relevant assets are reorganised, financed, sold or transferred, subject to appropriate confidentiality and data-protection safeguards.
Pario Ventures does not sell personal data to data brokers or third parties for their own advertising purposes.
International transfers
Pario Ventures works internationally and some of our technology or communications providers operate infrastructure in more than one country. This means personal data may be processed outside the UK and, where EU GDPR applies, outside the European Economic Area.
Where an international transfer requires a safeguard, we use an appropriate transfer mechanism available under the applicable law. Depending on the transfer, this may include an adequacy regulation or decision, the UK International Data Transfer Agreement or UK Addendum, European Commission Standard Contractual Clauses, and supplementary technical or organisational measures where required.
You can contact compliance@parioventures.com if you would like more information about the safeguards relevant to your personal data.
How long we keep personal data
We keep information only for as long as it is reasonably needed for the purpose for which it was collected, taking account of the nature of the relationship, legal requirements and the possibility of disputes or claims.
- Website enquiries and general correspondence: normally up to two years after the last meaningful contact, unless the discussion develops into an active business relationship or a longer period is justified.
- Active commercial, investment or contractual records: for the duration of the relationship and, where necessary, up to six years afterwards for accounting, tax, audit, contractual or legal-claims purposes.
- Technical and security records: for the period reasonably required for security, troubleshooting, fraud prevention and incident investigation, taking account of provider settings and applicable legal requirements.
Information may be retained for longer where required by law, litigation, an investigation or a legal hold. When information is no longer required, we aim to delete it or anonymise it.
Your data-protection rights
Depending on the law and the circumstances, you may have the right to:
- request access to the personal data we hold about you;
- ask us to correct inaccurate or incomplete information;
- request erasure of personal data in appropriate circumstances;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain information in a portable format where the right to data portability applies; and
- withdraw consent at any time where processing is based on consent, without affecting processing already carried out lawfully.
These rights are not absolute and exemptions may apply. We may need to verify your identity before acting on a request. To exercise a right, email compliance@parioventures.com.
If you are in the UK, you also have the right to complain to the Information Commissioner’s Office. If EU GDPR applies, you may have the right to complain to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.
Cookies and similar technologies
The public Pario Ventures website does not currently use advertising or behavioural-tracking cookies and does not currently run non-essential analytics that require cookie consent.
The restricted administration area may use an essential, secure session cookie when an authorised administrator signs in. Essential technical mechanisms may also be used by hosting and security infrastructure to deliver and protect the service.
If we introduce non-essential analytics, advertising or similar technologies in the future, we will update this notice and provide a consent mechanism before using them where applicable law requires it.
Automated decision-making and profiling
Pario Ventures does not currently use personal data collected through this website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
How we protect personal data
We use proportionate technical and organisational measures intended to protect personal data against accidental loss, unauthorised access, misuse, alteration or disclosure. These include HTTPS encryption in transit, controlled administrative access and established hosting and communications providers with security measures appropriate to their services.
No internet service can guarantee absolute security. If we identify a personal-data breach, we will assess and respond to it in accordance with applicable legal requirements.
Changes to this notice
We may update this privacy notice when our website, services, providers or legal obligations change. Material changes will be reflected on this page and the effective date will be updated.