Time to allocate capital
The operating system for private capital.
Mav9 applies AI to proprietary knowledge and private data to support better capital decisions.
Time to allocate capital
Mav9 applies AI to proprietary knowledge and private data to support better capital decisions.
We believe privacy is a fundamental right — not fine print. This policy explains clearly and honestly what personal data we collect, why we collect it, and what we do with it. We will never sell your personal data. We will never use your data to train AI models. We will always give you control over your information.
Depending on where you are located, the controller of your personal data is:
Managing Directors: Andreas Groke, Marius Groke
If you are located in the EEA or Switzerland, Mav9 Technologies GmbH is your data controller. If you are located in the United Kingdom, MAV9 Technologies Ltd is your data controller. For all other locations, Mav9 Technologies GmbH is your data controller unless otherwise specified in your agreement with us.
Both entities are established in their respective jurisdictions and do not require the appointment of an EU or UK representative under Article 27 of the EU GDPR or UK GDPR respectively.
We have not appointed a Data Protection Officer because we are not legally required to do so under § 38 of the German Federal Data Protection Act (BDSG) read together with Article 37 of the EU GDPR. Instead, you may contact our dedicated internal privacy team for any questions or requests:
This Privacy Policy applies to personal data we process when you:
Customer Data processed on behalf of our clients: When our customers (venture capital and private equity firms) upload or process data through the Mav9 platform, we act as a data processor on their behalf. That processing is governed by our Data Processing Agreement (DPA), available at trust.mav9.com, not this Privacy Policy. If your personal data was submitted to our platform by one of our customers, please contact that organisation directly regarding your data rights.
This Privacy Policy is part of a suite of legal documents available at our Trust Center (trust.mav9.com): the Master Service Agreement (MSA), the Terms of Service (ToS), the Data Processing Agreement (DPA), the Cookie Policy, the Acceptable Use Policy (AUP), and the Service Level Agreement (SLA). In the event of conflict between this Privacy Policy and the DPA with respect to the processing of Personal Data, the DPA shall prevail.
We collect different types of data depending on how you interact with us. We have organised this section by category of data subject.
We will always ask for your explicit consent before recording any call. You may decline to be recorded, and we will still conduct the meeting. Under German law (§ 201 StGB — Verletzung der Vertraulichkeit des Wortes), recording conversations without consent is a criminal offence. We take this obligation extremely seriously.
In accordance with Article 14 GDPR, we inform you that we collect certain professional data from publicly accessible sources to enrich our platform's knowledge graph and provide comprehensive B2B insights to our customers.
If your data is processed for this purpose, you have the right to object to its inclusion. Contact Turn on Javascript to see the email adress [code: p01]. We will process your objection without undue delay and cease processing your data for this purpose unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
In accordance with Article 13(2)(e) GDPR, we inform you: the provision of your personal data when using our platform is a contractual requirement necessary to perform the agreement between your organisation and Mav9. If you do not provide the required account and authentication data, we cannot provide you with access to the Services. The provision of data when submitting contact forms, demo requests, or waitlist sign-ups is voluntary; however, without this information we cannot respond to your enquiry. The provision of data for marketing purposes is entirely voluntary and has no impact on your ability to use the Services.
We only process personal data when we have a lawful basis to do so. The list below maps each processing purpose to the applicable legal basis under the EU GDPR.
Where we rely on legitimate interest (Art. 6(1)(f) GDPR), we have conducted a balancing test (Legitimate Interest Assessment) to confirm that our interests do not override your fundamental rights and freedoms. You may request a copy of our assessments by contacting Turn on Javascript to see the email adress [code: p01].
Important: You have the right to object at any time to the processing of your personal data which is based on our legitimate interests (Art. 6(1)(f) GDPR), on grounds relating to your particular situation. Upon receiving your objection, we will cease processing your data for that purpose unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
Where your personal data is processed for direct marketing purposes (including profiling related to direct marketing), you have an absolute, unconditional right to object at any time. We will stop processing your data for direct marketing immediately upon receiving your objection.
To exercise your right to object, email Turn on Javascript to see the email adress [code: p01] or use the unsubscribe link in any marketing communication.
The Mav9 platform uses artificial intelligence to deliver core features:
We do not use your personal data or customer data to train, fine-tune, or improve any AI or machine learning model. This is a contractual commitment in our DPA and is mirrored in our agreements with all AI sub-processors. All AI processing within the platform is inference-only (generating outputs from pre-trained models). AI model inference does not constitute model training.
Under Article 22 of the GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. Our AI systems are decision-support tools, not decision-makers. All AI outputs within the Mav9 platform require human review and judgement before any action is taken. We do not make any automated decisions that produce legal effects or similarly significant effects on individuals.
We classify our AI systems under the risk framework of the EU AI Act (Regulation (EU) 2024/1689). In compliance with the transparency requirements of Article 50 (applicable from 2 August 2026): (a) you will always know when you are interacting with an AI system — AI-generated insights and outputs are clearly identifiable, typically presented within a dedicated AI chat interface; and (b) where our AI agents synthesise external research or compile data, outputs feature explicit citations to original sources so you can verify information manually.
Under § 25 of the German Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG), and the Privacy and Electronic Communications Regulations 2003 (PECR) in the UK, we require your explicit prior consent before setting any non-essential cookies. Strictly necessary cookies (Cloudflare security, Auth0 session management) are set without consent because they are technically required for the website or platform to function securely — specifically, they provide bot protection, DDoS mitigation, rate limiting, CSRF protection, and session state management. All other cookies are only set after you have given your explicit consent via our cookie consent banner.
For an exhaustive list, see Appendix A and our separate Cookie Policy at trust.mav9.com.
You have absolute control over your cookie preferences. You may revoke your consent at any time via the cookie settings accessible from the footer of every page of our website. In accordance with the guidance of the Datenschutzkonferenz (DSK), revoking your consent requires no more effort than initially providing it. You can also manage preferences via your browser settings or by sending a Global Privacy Control (GPC) signal, which we natively respect.
Our public website forms (such as the waitlist sign-up) are protected by Cloudflare Turnstile, which verifies that a visitor is human. Turnstile operates in invisible mode: it runs silently in the background and does not display a challenge or any visual indication. To perform this verification, Turnstile evaluates browser characteristics and interaction signals and processes your IP address. This data is not used to track you across websites, and any cookies Turnstile relies on are strictly necessary (see Appendix A). This processing is based on our legitimate interest in protecting our website from bots and abuse (Art. 6(1)(f) GDPR) and is governed by Cloudflare's Turnstile Privacy Addendum.
We share personal data only when necessary and only with the categories of recipients described below. We never sell your personal data.
For full geographic locations and transfer mechanisms, see Section 8 and Appendix B.
Our primary data processing infrastructure is hosted on Amazon Web Services within the European Union (Frankfurt, Germany). All primary databases and their routine backups are hosted strictly within the EU. However, some service providers are based in or operate from the United States.
We use the following legal mechanisms to safeguard international transfers: (a) EU-US Data Privacy Framework (DPF) for certified US recipients; (b) EU Standard Contractual Clauses (SCCs) approved by Commission Implementing Decision (EU) 2021/914; (c) UK International Data Transfer Addendum issued by the ICO under section 119A of the DPA 2018; and (d) UK-US Data Bridge for DPF-certified US recipients.
For transfers to the United States where the recipient is not certified under the EU-US Data Privacy Framework (notably Perplexity AI, Vanta, and Featurebase), we rely on SCCs supplemented by a Transfer Impact Assessment (TIA). Our TIA evaluates the legal framework of the recipient country, the specific nature and sensitivity of the data transferred, and the technical and organisational measures implemented by the recipient. Supplementary measures include: contractual prohibitions on government access disclosure, encryption in transit and at rest, data minimisation (only query data is sent, not bulk Customer Data), and access controls limiting processing to the specific service purpose.
We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law. The following list sets out our retention periods for each category of data:
Our security measures are designed to meet the requirements of SOC 2 Type II and ISO/IEC 27001:
Current certification status is available at trust.mav9.com.
Depending on your jurisdiction, you have the following rights:
To exercise any of these rights, email Turn on Javascript to see the email adress [code: p01]. We will acknowledge your request within five (5) Business Days and respond substantively within one (1) month. If your request is complex or we receive a high volume of requests, we may extend this by a further two (2) months, and we will inform you of any extension within the first month. We will not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive.
Right to complain to Mav9 (UK users): Under the Data (Use and Access) Act 2025, Section 103 (inserting Section 164A into the Data Protection Act 2018), expected to be effective mid June 2026, you have a statutory right to complain directly to us if you believe that the way we process your personal data breaches data protection legislation.
To submit a data protection complaint:
We will: (a) acknowledge receipt of your complaint within thirty (30) days; (b) investigate your complaint without undue delay; (c) inform you of the outcome and any actions taken; and (d) record the complaint and its resolution for audit and compliance purposes.
Right to complain to a supervisory authority: You also have the right to lodge a complaint with a data protection supervisory authority. In Germany: the Berliner Beauftragte für Datenschutz und Informationsfreiheit. In the UK: the Information Commissioner's Office (ICO), or its successor body, the Information Commission. In any other EU Member State: the supervisory authority of your habitual residence or place of work.
In accordance with the EU Data Act (Regulation (EU) 2023/2854), we support your right to export your data and switch to another provider free of technical or commercial barriers. Standard data exports (CSV, JSON, API) are provided free of charge once per twelve (12)-month period and upon termination.
Our platform is designed for B2B professionals. We do not knowingly collect personal data from individuals under 16 years of age (EEA) or 13 years of age (UK/US). If we become aware that we have collected data from a child, we will delete it promptly.
Our Services may integrate with external platforms (such as LinkedIn for marketing or DocuSign for contracts). When you interact directly with these third-party services, their respective privacy policies apply. We encourage you to review their privacy practices before engaging with them.
We may update this policy periodically to reflect changes in law, regulation, or our data practices. We will notify you of material changes by email or website notice at least thirty (30) days before the changes take effect. The effective date at the top of this policy indicates when it was last updated. Minor, non-substantive changes (such as corrections of typographical errors) may be made without advance notice.
Our processing is regulated by the EU GDPR, the German Federal Data Protection Act (BDSG), and the TDDDG. Mav9 is not required to appoint a DPO under § 38 BDSG but maintains a dedicated internal privacy team. Our competent supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
Our processing is regulated by the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025. The DUAA's new right to complain directly to controllers takes effect 19 June 2026 (see Section 11.3). Our competent supervisory authority is the Information Commissioner's Office (ICO), or its successor body, the Information Commission, established under the DUAA.
The following disclosures are provided in accordance with the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Even where Mav9 may not meet the CCPA's applicability thresholds, we provide these disclosures voluntarily as a commitment to transparency for our US clients and their data subjects.
We do not sell or share personal information. Mav9 does not sell personal information (as defined under CCPA § 1798.140(ad)) and does not share personal information for cross-context behavioural advertising (as defined under CCPA § 1798.140(ah)). We have not sold or shared personal information in the preceding 12 months.
Service provider status: When Mav9 processes personal information on behalf of our customers, we act as a "service provider" as defined in CCPA § 1798.140(ag). We process personal information solely to provide the Services and do not retain, use, or disclose personal information for any purpose other than performing the Services, except as permitted by the CCPA.
Categories of personal information collected in the preceding 12 months:
Categories of personal information disclosed for a business purpose in the preceding 12 months: Identifiers (A) and Internet/network activity (F) to analytics providers (PostHog); Identifiers (A) to authentication providers (Auth0); Professional information (I) to CRM tools (Notion); Identifiers (A) to email service providers (Brevo). No personal information was sold or shared.
California consumer rights: California residents have the following rights under the CCPA/CPRA: the right to know what personal information we collect and how it is used and shared; the right to delete personal information (subject to exceptions); the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information (though we do not sell or share); the right to limit the use of sensitive personal information (though we do not collect sensitive PI as defined by the CCPA); and the right to non-discrimination for exercising your CCPA rights.
To exercise any CCPA right, contact Turn on Javascript to see the email adress [code: p01] or submit a request via trust.mav9.com/privacy-request. We will verify your identity before processing your request. We will respond within forty-five (45) days, with one forty-five (45) day extension if reasonably necessary. We honour Global Privacy Control (GPC) signals natively as valid opt-out requests.
To the extent that privacy laws of other US states (including Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and others) apply to our processing of personal information, we extend the rights described in Section 16.3 to residents of those states. Where a state law provides additional or different rights, we will comply with those requirements.
For any questions about this Privacy Policy or our data practices:
We provide at least 30 days' advance notice via our Trust Center before engaging a new sub-processor. The current list is also maintained at trust.mav9.com.
[ End of Privacy Policy ]
© 2026 Mav9 Technologies GmbH.