Privacy Policy

Last updated: July 2026

Crane Venture Partners LLP (the “Firm”) is a limited liability partnership registered in England and Wales with company number OC401243. Crane Venture Partners LLP is authorised and regulated by the Financial Conduct Authority (“FCA”) with Firm Reference Number 1036077.

For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and, where applicable, the EU General Data Protection Regulation (“EU GDPR”) and other applicable data protection legislation Crane Venture Partners LLP will be the ‘controller’ of the personal data you provide. Please read the following information carefully in order to understand the Firm’s practices in relation to the treatment of your personal data. Should you have any questions, please email us at team@crane.vc.

What data privacy principles does the Firm adhere to?

  • The Firm will process all personal data in a lawful, fair and transparent manner.
  • The Firm will only collect personal data where it is necessary:
    • for the Firm to provide a service to you;
    • for you to provide a service to the Firm;
    • for the Firm to keep you informed of its products and services; or
    • for the Firm to comply with its legal and regulatory obligations.
  • The personal data collected by the Firm will be adequate, relevant and limited to what is necessary in relation to the specific purpose for which your data will be processed.
  • The Firm will take all reasonable steps to ensure that personal data is accurate and, where necessary, kept up-to-date.
  • The Firm will maintain personal data in a form that permits identification no longer than is necessary for the purposes for which the personal data has been collected for processing, in accordance with the Firm’s record retention requirements as mandated by the FCA and any applicable law, regulation or guidance.
  • The Firm will hold and process personal data in a manner that ensures appropriate security.
  • The Firm will only share personal data where it is necessary to provide the agreed service or where it is necessary for the Firm to comply with its legal and regulatory requirements.
  • The Firm will only utilise a service provider based outside of the UK and EEA for the processing of personal data where this is strictly necessary to facilitate our services to you. In all cases, we will ensure service providers are fully compliant with applicable data protection legislation ahead of transferring any personal data and as follows:
  • The Firm may sometimes use third party data processors that are located outside of the United Kingdom and European Economic Area (“the EEA”). (The EEA consists of all EU member states, plus Norway, Iceland, and Liechtenstein). Where the Firm transfers any personal data outside the EEA, we will take all reasonable steps to ensure that your data is treated as safely and securely as it would be within the UK under the data protection legislation.  This includes ensuring one of the following conditions is satisfied:
    • using the UK's International Data Transfer Agreement ("IDTA") and/or Standard Contractual Clauses ("SCCs"), together with the UK Addendum where required, as mechanisms to safely process data outside of the UK and EEA to third countries which have not been granted adequacy; or is a Country that has been granted adequacy which confirms its data protection legislation is adequate to safeguard data processing;
    • where the Firm transfers personal data to India or Singapore in the course of its activities, it will comply with India’s Digital Personal Data Protection Act 2023 (“DPDPA”) and Singapore’s Personal Data Protection Act (“PDPA”) respectively, and will implement appropriate contractual or other safeguards as required under those laws; and
    • where the Firm transfers personal data to the United States it will do so in reliance on the UK-US Data Bridge (where the recipient is certified) or, where applicable, by entering into an International Data Transfer Agreement ("IDTA") or equivalent approved safeguards.
  • In certain circumstances, the Firm may be legally required to share certain data held by us, which may include your personal data, for example, where we are involved in legal proceedings, where we are complying with legal requirements, a court order, or a governmental authority.

What personal data does the Firm collect and why?

In the course of providing products/ services to you, the Firm may collect information that is considered personal information (e.g. name, contact details, address, passport number, driving licence).

As a client, contact or employee of Crane Venture Partners LLP, we will require some personal information in order to verify your identity and have the applicable relationship with you. Some of this information may be required to satisfy legal obligations (e.g. to comply with obligations arising under the money laundering regulations whereas other information may be required in connection with the provision of services to you). The information collected will vary depending on the service the Firm provides to you or you provide to the Firm, but typically includes:

  • Personal information: such as your name, date of birth, passport number or national insurance number;
  • Contact information: including your address, telephone number and email address;
  • Images: including photographs, videography and CCTV footage collected at the Firm’s premises or at events;
  • KYC Data/Criminal Convictions: in connection with certain relationships including those with clients, founders, employees and limited partners the Firm may also obtain data relating to criminal convictions or offences where this is revealed in the course of anti-money laundering ("AML") or know-your-client ("KYC") checks. Such data will only be processed to the extent required to comply with the Firm's legal and regulatory obligations, including those arising under the Money Laundering Regulations. This data may be obtained from third party sources, such as disclosure and barring check databases or specialist compliance providers;
  • Investor Portal Access: where the Firm provides limited partners or other authorised individuals with access to a secure investor portal or data room, we may collect and process your name, email address, username and login credentials for the purpose of administering that access and enabling you to view confidential information securely. The legal basis for this processing is our legitimate interest in restricting access to sensitive information to authorised individuals
  • Portfolio Reporting and Information Tool: where the Firm utilises a secure portfolio management and reporting platform or tool, we may collect, ingest, and process certain operational and financial data provided to us by our portfolio companies. This information may include limited personal data relating to portfolio company founders, directors, employees, and key service providers (such as names, business contact details, job titles, salary bandings, and equity or option allocations). We process this data for the purpose of monitoring the financial performance, operational health, and development metrics of our investments, as well as preparing aggregated evaluation reports and disclosures for our own investors.  The legal basis for this processing is our legitimate interest in effectively managing our investment portfolio, tracking pipeline performance, and fulfilling our fiduciary and reporting obligations to our investors.
  • Diversity Data: we may collect certain special category personal data including ethnicity and gender.  This data is used solely for the purpose of internal diversity monitoring across our investment pipeline and activities. It will be processed anonymously in aggregate and will not be used in connection with any decision made in respect of any individual. The legal basis for this processing is substantial public interest (equality of opportunity monitoring).

In most cases, we collect personal data directly from you. We may, however, also receive personal data from the organisation with which you are affiliated (for example, your employer), or from publicly available sources such as company registries, professional networking platforms, or news sources, where this is relevant to our business activities or investment pipeline.

Where does the Firm store my personal data?

The Firm has comprehensive policies and procedures in place to ensure your personal data is kept safe and secure, including but not limited to:

  • data encryption;
  • firewalls;
  • intrusion detection;
  • 24/7 physical protection of the facilities where your data is stored;
  • background checks for personnel that access physical facilities; and
  • security procedures across all service operations.

The Firm only keeps your personal data for as long as it needs to in order to use it as described above, and/or for as long as we have your permission to keep it.

The Firm will store some of your personal data in the UK. This means that it will be fully protected under the UK’s data protection legislation.

The Firm will store some of your personal data within the EEA. This means that your personal data will be fully protected under the EU GDPR and/or to equivalent standards by law. Transfers of personal data to the EEA from the UK are permitted without additional safeguards.

The Firm may store some or all of your personal data in countries outside of the UK and EEA. These are known as “third countries”. We will take additional steps in order to ensure that your personal data is treated just as safely and securely as it would be within the UK and under the data protection legislation. Data security is very important to us, and to protect your data we have taken suitable measures to safeguard and secure data collected through our website.

The Firm use the following third-party software and some of your data may be stored on their servers:

  • Google email servers and suite of products;
  • Dropbox cloud storage;
  • Microsoft cloud storage;
  • Attio CRM;
  • Quickbooks;
  • Xero
  • Granola
  • Next Matter
  • Docusign
  • Navan
  • Humaans
  • Notion;
  • Slack;
  • Zoom;
  • WhatsApp/ Signal;
  • Mailchimp;
  • WPEngine;
  • Contact books on our devices and computers; and
  • Banking system.

The Firm also may use third-party AI service providers.  These providers are carefully selected to ensure that they comply with our privacy standards and legal requirements.

How long does the Firm retain personal data?

As a regulated entity, the Firm is required to maintain its books and records for a prescribed period (five years from either the ceasing of a business relationship, or, in the case of non-clients, from the making of a record – or alternatively, for seven years, where specifically requested to do so by the FCA). As such, information that falls within the scope of either of these requirements is retained in line with the mandated timeframe.

Any information that is outside the scope of this requirement will be retained whilst relevant and useful, and destroyed where this ceases to be the case or where the data subject specifically requests this.

How have I been categorised under applicable data protection law?

Applicable data protection law requires the Firm to inform you of the legal basis on which we maintain your personal data. Typically, the Firm will reach out to you personally to confirm this; however, as a general rule the following is applicable:

  • Clients: information is maintained on the basis of contractual obligation and/ or legitimate interests (where relevant);
  • Service providers: information is maintained on the basis of contractual obligation; and
  • Database/ marketing contacts: information is maintained on the basis of legitimate interest.

What are my rights?

Once you have provided your details to the Firm, you have certain rights which apply, depending on your relationship with the Firm, the information you have shared with us and the Firm’s legal and regulatory obligations.

  • Where the Firm processes your personal data on the basis of its legitimate interests, you have the right to object to that processing. We will consider and respond to any such objection, though please be aware that in some circumstances we may not be able to comply, for example, where we have overriding legitimate grounds or a legal or regulatory obligation to continue processing.
  • You have the right to request a copy of the information that we hold about you. If you would like a copy of some, or all, of your personal information, please email the Firm at team@crane.vc. The Firm will provide this information to you within one month (with the ability to extend this by an additional two months where necessary), free of charge.
  • You have the right to request that the information the Firm holds about you is erased under certain circumstances including where there is no additional legal and/ or regulatory requirement for the Firm to retain this information.
  • As a client, you have the right to request that any information the Firm holds about you be provided to another company in a commonly used and machine-readable format, otherwise known as ‘data portability’.
  • You have the right to ensure that your personal information is accurate and up to date, or where necessary rectified. Where you feel that your personal data is incorrect or inaccurate and should therefore be updated, please contact team@crane.vc.
  • You have the right to object to your information being processed, for example for direct marketing purposes.
  • You have the right to restrict the processing of your information, for example limiting the material that you receive or where your information is transferred.
  • You have the right to object to any decisions based on the automated processing of your personal data, including profiling.
  • You have the right to lodge a complaint with the Information Commissioner’s Office (https://ico.org.uk/concerns/) if you are not happy with the way that we manage or process personal data.
  • Where the Firm relies on your consent as the legal basis for processing your personal data, you have the right to withdraw that consent at any time by contacting us at team@crane.vc. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to the withdrawal.
  • If you are ordinarily resident in India, you may also have the right to lodge a complaint with India’s Data Protection Board. If you are ordinarily resident in Singapore, you may have the right to lodge a complaint with the Personal Data Protection Commission (https://www.pdpc.gov.sg). If you are resident in California or another US state with applicable privacy laws, you may have additional rights under those applicable state laws; please contact us at team@crane.vc for further information.

Will I be notified of changes to this policy?

The Firm may, from time to time, review and update this policy. The Firm will maintain the latest version of this policy on its website, and where the changes are deemed material, it will make you aware of these.

Who should I direct questions to?

If you have any questions, concerns or complaints about the practices contained within this document or how the Firm has handled your data, please email: team@crane.vc. Alternatively, you may write to: 3rd Floor, 20 Noel Street, London, W1F 8GW.  The Firm will log, acknowledge, and investigate your submission within required legal timeframes in accordance with the Data (Use and Access) Act 2025.