Legal

Privacy Policy

Last updated: July 28, 2026

This Privacy Policy describes how LiorLink, operated by iCapital Ventures (EIC Corporation), collects, uses, stores and protects your personal data when you use our platform at liorlink.icapitalventures.io and our mobile application iCV Intelligence.

1. Who We Are

Data controller:

2. Data We Collect

Depending on how you use the platform, we collect the following categories of data:

a) Identity data

  • Full name, email address, phone number
  • Role on the platform (Enterprise, NED, Admin)
  • Password (hashed with bcrypt — never readable)

b) Company data (Enterprise profile)

  • KYB information: legal documents, articles of association, registers
  • Financial data: balance sheets, income statements, cash flows
  • Governance data: policies, organisational charts, compliance records
  • Due diligence data: audit results and reports

c) Usage data

  • IP address, browser, operating system
  • Pages visited, session duration, actions taken
  • Activity logs for security purposes

d) Communication data

  • Verification and notification emails sent by the platform
  • Support tickets submitted via the contact form

3. How We Use Your Data

Your data is processed for the following purposes:

  • Service delivery: Managing your account, providing dashboard access, processing due diligence files.
  • Identity verification: KYB checks, company ownership verification (NED → Enterprise flow).
  • Communication: System notifications, status alerts, verification emails.
  • Security: Fraud prevention, detection of unauthorised access, compliance auditing.
  • Service improvement: Anonymised usage analysis to improve the platform.
  • Legal obligations: Compliance with applicable anti-money-laundering laws (CIMA, COBAC, etc.).

We process your data on the following legal grounds:

  • Contractual necessity: To provide the services you have subscribed to.
  • Consent: For marketing communications (you may withdraw at any time).
  • Legitimate interests: For platform security and fraud prevention.
  • Legal obligation: To comply with applicable financial regulations.

5. Data Retention

We retain your personal data for the duration of your relationship with LiorLink, plus applicable statutory periods:

  • Account data: Until account deletion + 5 years (accounting obligations).
  • Due diligence files: 10 years minimum (financial regulation).
  • Security logs: 12 months.
  • Non-essential cookies: Maximum 13 months.

Upon expiry, your data is permanently deleted or irreversibly anonymised.

6. Data Sharing

We never sell your personal data. We may share it in the following situations:

  • Operational partners: Hosting providers (secure servers), transactional email services — subject to data processing agreements.
  • Within the platform: A company's due diligence results are visible to authorised, verified NEDs who have received the company's approval.
  • Competent authorities: Where required by law or official request from regulatory authorities.

No data is transferred outside the applicable economic area without appropriate safeguards (standard contractual clauses or adequacy decision).

7. Security

We implement appropriate technical and organisational measures to protect your data:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Passwords hashed with bcrypt — never stored in plain text
  • Role-based access control (RBAC): each user accesses only the data they are authorised to see
  • Two-factor authentication (2FA) available
  • Access and modification logging for audit purposes
  • Regular security testing

8. Your Rights

Under applicable data protection law, you have the following rights:

  • Right of access: Obtain a copy of your personal data we process.
  • Right of rectification: Correct inaccurate or incomplete data.
  • Right to erasure: Request deletion of your data (subject to legal retention obligations).
  • Right to portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interest.
  • Right to withdraw consent: Withdraw your consent at any time for consent-based processing.

To exercise these rights, contact us at: contact@eic-corporation.org. We will respond within 30 days.

9. Cookies

LiorLink uses cookies essential to the proper operation of the platform:

  • Session cookie: Keeps you logged in (Laravel session — deleted on browser close or logout).
  • CSRF cookie: Protects against cross-site request forgery attacks.
  • Interface preferences: Theme (light/dark), selected language — stored in localStorage.

We do not use advertising or third-party tracking cookies. No data is sent to Google Analytics or equivalent services.

10. Policy Changes

We may update this Privacy Policy to reflect legal, technical or operational changes. Any significant change will be notified to you by email and/or by a visible notice on the platform. The "Last updated" date at the top of this page indicates the current version.

By continuing to use LiorLink after notification, you accept the revised policy.

11. Contact & Complaints

For any questions about this policy or to exercise your rights:

If you believe your rights are not being respected, you have the right to contact the competent supervisory authority in your country of residence.