PRIVACY POLICY

Last updated: 23 September 2025

 
 

1. Introduction

This Privacy Policy explains how we process your personal data when you visit www.cocoa.vc (the “Website”) and outlines your rights under data protection law. We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”) and other applicable UK data protection laws.

2. Controller

References to “we”, “us” or “our” are to Cocoa Advisor LLP (“Cocoa”), a limited liability partnership in England and Wales (registered number OC450336). Cocoa is an Appointed Representative of The Fund Incubator Limited, which is authorised and regulated by the Financial Conduct Authority (FRN 208716).

Controller (Art. 4(7) UK GDPR):

Cocoa Advisor LLP

Connect House, 133–137 Alexandra Road, Wimbledon, London, SW19 7JY, United Kingdom

Email: ops@cocoa.vc

Data protection contact: ops@cocoa.vc (Attn: Data Protection

3. Updates to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will appear on this page with an updated “Last updated” date.

4. Use of Third-Party Tools and International Transfers

We use third-party providers to operate and improve our Website (see sections 6 and 7). Some providers are located outside the UK/EEA. Where data is transferred to a country without a UK adequacy regulation, we implement appropriate safeguards under Arts. 44–49 UK GDPR (e.g., UK IDTA or Standard Contractual Clauses with the UK Addendum). You can request a copy of these safeguards by contacting us.

5. How We Collect Personal Data

5.1 Direct interactions. You may provide data when you:

  • request our products/services;
  • complete Website forms;
  • subscribe to updates/marketing;
  • submit funding applications (e.g., slide decks, presentations, web submissions);
  • apply for roles or consulting engagements;
  • contact us by email/phone/post;
  • use of our website (cocoa.vc); or use of our social media pages including Twitter (twitter.com/@cocoadotvc) and LinkedIn (https://www.linkedin.com/company/cocoadotvc)

 

5.2 Automated technologies. When you use the Website we collect technical data via server logs and similar technologies (e.g., IP address, browser/OS, time stamps, pages viewed).

5.3 Cookies. See section 7.

5.4 Third parties and public sources. We may receive data from analytics providers, advertising networks, search providers, data brokers/aggregators, and public sources (e.g., Companies House, Electoral Register). We require third parties to have lawful rights to share data with us.

6. How We Use Personal Data (Purposes and Legal Bases)

We do not sell your personal data. We only process it where a UK GDPR legal basis applies:

6.1 Website operation and security (server logs).

  • Data: IP address, browser type/version, OS, referrer URL, hostname, date/time.
  • Purpose: ensure stable and secure operation; detect/prevent abuse or fraud; diagnose issues.
  • Legal basis: legitimate interests (Art. 6(1)(f) UK GDPR) in Website stability and security.
  • Retention: server logs are typically kept up to 7 days, then deleted (longer if needed for evidence).
  • Recipient (hosting): TerraHost AS, Klinestadmoen 10, 3241 Sandefjord, Norway (EEA).

 

6.2 Communications and enquiries.

  • Purpose: respond to messages and requests; manage relationships.
  • Legal basis: performance of a contract/steps prior to it (Art. 6(1)(b)), and/or legitimate interests (Art. 6(1)(f)) in providing support and running our business.

 

6.3 Marketing (emails/updates).

  • Purpose: send news and updates where permitted.
  • Legal basis: consent (Art. 6(1)(a)) or legitimate interests (Art. 6(1)(f)) where the “soft opt-in” under PECR applies. You can opt out at any time (see section 11).

 

6.4 Recruitment and collaborations.

  • Data: name, contact details, CV, cover letter, references, and similar application materials.
  • Purpose: assess and manage applications.
  • Legal basis: steps prior to entering into a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for talent pipeline management where applicable.
  • Retention: if unsuccessful, we usually retain for 6 months after the process ends (unless you consent to longer). If hired/engaged, your data will be processed for the relationship.

 

6.5 Analytics and measurement (Google Analytics).

  • Data: time of request; IP address; online identifiers (incl. cookie IDs); device/browser/OS; pages viewed; session duration/bounce; referral URL; and, where relevant, e-commerce events.
  • Purpose: understand Website usage and improve content, product and marketing.
  • Legal basis: consent (Art. 6(1)(a)). Analytics will only run if you consent via our cookie banner/settings.
  • Provider/recipient: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (with global processing, including the US, under appropriate safeguards).
  • Retention: in line with our Google Analytics settings (cookies typically persist for months; aggregated reports may be retained longer).

 

6.6 Tag orchestration (Google Tag Manager, “GTM”).

  • Purpose: deploy and manage tags on the Website. GTM itself does not set cookies or read identifiers; it loads other tools.
  • Legal basis: legitimate interests (Art. 6(1)(f)) in efficient Website management. Tags that set non-essential cookies only fire if you have given consent.
  • Provider/recipient: Google Ireland Limited, Dublin, Ireland.

 

6.7 Aggregated/anonymous insights.

We may create aggregated or anonymised statistics. This information is not personal data unless it can identify you; if it does, we treat it as personal data.

Sensitive data: Please do not send us special category data (e.g., health, beliefs) or criminal records via the Website unless we expressly request it.

7. Cookies

7.1 What cookies we use.

  • Strictly necessary cookies (e.g., security, load balancing): enable core functionality.
    • Legal basis: legitimate interests (Art. 6(1)(f)).
  • Analytics/measurement cookies: help us improve the Website.
    • Legal basis: consent (Art. 6(1)(a)).

 

7.2 How to control cookies.

You can manage your preferences through our cookie banner or your browser settings. If you refuse or disable certain cookies, parts of the Website may not function properly. You can withdraw consent at any time via the cookie settings.

8. Social Media

We maintain profiles on LinkedIn and X (Twitter). If you interact with us there, the platforms process your data under their own privacy policies. We may receive aggregated insights about page interactions.

9. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, loss or disclosure. Access is limited to personnel and service providers with a business need to know, subject to confidentiality obligations and instructions.

10. Who We Share Data With

We share personal data with:

  • Service providers acting on our instructions (e.g., hosting, analytics, communications, recruitment).

  • Professional advisers (e.g., legal, compliance) where necessary.

  • Authorities where required by law.

    We require all recipients to protect your data and to process it only as instructed.

11. Your Rights

Under the UK GDPR you have the right to:

  • Access your personal data;
  • Rectify inaccurate data;
  • Erase your data (in certain cases);
  • Restrict processing (in certain cases);
  • Object to processing based on legitimate interests or to direct marketing;
  • Data portability (for data you provided, where processing is based on consent or contract and carried out by automated means);
  • Withdraw consent at any time, where processing relies on consent (this does not affect prior lawful processing).

 

You have the right to make a complaint at any time to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection issues: www.ico.org.uk. We would appreciate the chance to deal with your concerns before you approach the ICO, so please contact us first.

12. Contact

If you have questions about this Privacy Policy or how we handle your data, contact:

Cocoa Advisor LLP

Connect House, 133–137 Alexandra Road, Wimbledon, London, SW19 7JY, United Kingdom

Email: ops@cocoa.vc (Attn: Data Protection)