Privacy policy
Privacy policy.
Last Updated: 2026. Novapar B.V. is committed to safeguarding personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
1. Data Controller
Novapar B.V.[Street Address / Corporate Center]
[Postal Code], Amsterdam
The Netherlands
Chamber of Commerce (KvK): [KvK Number]
Email: privacy@novapar.nl
2. Categories of Data Processed
We collect and process minimal personal data necessary for institutional communication and website security:
- Direct Communications Data: Full name, corporate title, employer/institution, work email address, telephone number, country of operation, and correspondence history submitted via our institutional contact portal or direct email.
- Technical & Access Logs: Anonymized IP addresses, browser type, device operating system, access timestamps, and referring URLs collected automatically via web server logs to maintain system security and integrity.
3. Legal Bases for Processing
We process personal data strictly pursuant to Article 6(1) of the GDPR under the following legal bases:
- Legitimate Interest (Art. 6(1)(f) GDPR): To communicate with enterprise counterparties, assess incoming co-investment inquiries, protect our technical infrastructure against cybersecurity threats, and conduct corporate administration.
- Pre-contractual & Contractual Measures (Art. 6(1)(b) GDPR): To take necessary steps at the request of the counterparty prior to entering into joint venture, share deal, or intercompany operational contracts.
- Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory reporting, anti-money laundering (AML/Wwft) inquiries, and corporate tax records mandated under Dutch and European law.
4. Data Sharing & Cross-Border Transfers
We do not sell, rent, or commercialize personal data. Data may be shared strictly on a need-to-know basis with:
- Direct operating affiliates within our group, including our Portuguese operating arm Horizonte Desperto – Construções, Lda, for project-specific underwriting and development execution.
- Professional statutory advisors (auditors, legal counsel, notaries, and tax advisors) bound by statutory confidentiality.
- Secure infrastructure hosting and IT service providers operating within the European Economic Area (EEA).
Where cross-border data transfers occur outside the EEA (such as corporate communications with our Brazilian operating relationships), they are executed subject to appropriate safeguards, including European Commission Standard Contractual Clauses (SCCs).
5. Data Retention
Personal data submitted via business inquiries is retained only for the duration required to evaluate the commercial dialogue or fulfill statutory corporate record-keeping requirements (up to 7 years for corporate and accounting records under Article 2:10 of the Dutch Civil Code). Technical server logs are automatically purged after 30 days.
6. Your Statutory Rights
Under Articles 15 through 22 of the GDPR, you hold the right to request:
- Access to, rectification of, or erasure of your personal data.
- Restriction of processing or objection to legitimate interest processing.
- Data portability where processing is automated.
To exercise these rights, submit a written request to privacy@novapar.nl. You also have the right to lodge an official complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens – AP) at autoriteitpersoonsgegevens.nl.