Privacy Notice
Last updated
Introduction
This notice explains how 33Equity B.V. ("33Equity", "we", "us") handles personal data — information that identifies you, or could — when you visit this website, contact us, respond to one of our vacancies, or work with us in the course of an M&A engagement. It also sets out the choices and rights you have over that data.
Our services and this website are aimed at businesses and professionals. The website is not directed at children and we do not knowingly collect data about them.
This version of the notice was last updated in July 2026. We review it periodically; the version published on this page is the one that applies.
Who we are
33Equity B.V. is a private limited liability company incorporated under the laws of the Netherlands, with its registered office at:
33Equity B.V.
Apollolaan 151
1077 AR Amsterdam
The Netherlands
Email: info@33equity.eu
Phone: +31 (0)20 303 5555
For the processing described in this notice, 33Equity B.V. acts as the controller — the party that determines how and why personal data is used. For privacy questions, or to exercise any of the rights described below, contact us at info@33equity.eu.
The data we work with
Contact and identity details
Your name, email address, phone number, employer or company, role, and whatever you choose to include in a message to us — for example through the contact form on this site.
Business and engagement information
Information about you, your organisation and a potential or ongoing transaction that we receive or produce while discussing or delivering our advisory services. This includes the information we need for business acceptance, conflict checks and counterparty due diligence, which in some cases may involve identification documents.
Application details
The CV, motivation and related details you send us when you apply for one of the roles listed on our vacancies page.
Technical data
Log data generated when you use the website, such as your IP address, browser and device characteristics and the pages you view, together with the signals processed by the anti-abuse check on our contact form, which distinguishes genuine visitors from automated traffic.
Aggregated statistics
We may derive statistics from usage of the website. Aggregated data of this kind does not identify anyone and is not personal data.
Where the data comes from
- From you: Directly from you — when you fill in the contact form, email or call us, meet us, or send an application.
- Automatically: From your use of the website — generated automatically by our hosting infrastructure and the anti-abuse check while you browse.
- From third parties: From others — your organisation or colleagues in the context of a transaction, counterparties and their advisers, and public sources such as chamber-of-commerce and company registers.
Why we use it, and on what legal basis
We only process personal data when the GDPR gives us a basis to do so. In practice:
- Responding to your enquiry and corresponding with you — our legitimate interest in answering the people who contact us, or steps taken at your request before entering into an engagement.
- Providing our advisory services — performance of the engagement between us, or with the organisation you represent.
- Business acceptance, conflict and integrity checks — compliance with our legal and professional obligations, and our legitimate interest in taking on work responsibly.
- Handling your application — steps taken at your request with a view to a possible employment relationship.
- Keeping the website and our systems secure — our legitimate interest in preventing abuse, fraud and attacks.
- Administration, accounting and tax — compliance with legal obligations that apply to us.
We do not operate a newsletter and we will not send you marketing you have not asked for. Should we ever introduce marketing communications, they will be strictly opt-in and every message will contain a simple way to unsubscribe.
Where we rely on legitimate interests, we first weigh those interests against your rights and freedoms, and we do not proceed where your interests override ours. We do not use personal data for automated decision-making that produces legal or similarly significant effects about you.
Who we share it with
- Service providers that run parts of our operations under contract with us — website hosting and email delivery, and the anti-abuse service (Cloudflare Turnstile) that protects our contact form. They may only process the data on our instructions and for our purposes.
- Professional advisers — such as lawyers, accountants, auditors and insurers — where their involvement is needed.
- Participants in a transaction — counterparties and their advisers, strictly on a need-to-know basis within the engagement, and normally under confidentiality undertakings.
- Public authorities and regulators — where disclosure is required by law.
We do not sell personal data, and we do not share it with third parties for their own marketing.
International transfers
We work primarily with providers established in the EU or EEA. Where a provider processes data outside the EEA — for example in the United States — we make sure one of the GDPR safeguards applies: an adequacy decision (such as certification under the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses. You can contact us for more detail on the safeguard used in a specific case.
How long we keep it
We keep personal data no longer than the purpose requires, and then delete or anonymise it. In deciding retention periods we look at the nature and sensitivity of the data, why we hold it, and the legal requirements that apply to us. Two rules of thumb:
- Records of engagements, including related business and financial records, are kept for as long as Dutch law requires — for certain records up to seven years.
- Applications for a vacancy are deleted within a reasonable period after the process ends, unless you agree that we may keep your details on file for future openings.
Enquiries that do not lead to an engagement are deleted once it is clear no follow-up is needed.
How we protect it
We apply technical and organisational measures proportionate to the risk: connections to this website are encrypted, access to personal data is limited to those who need it for their work, and we rely on established, security-conscious infrastructure providers. We have procedures for handling a suspected data breach and will inform you and the supervisory authority where the law requires it.
Your rights
Under the GDPR you can, in the circumstances the law describes:
- ask for a copy of the personal data we hold about you (access);
- have inaccurate or incomplete data corrected (rectification);
- have data deleted where there is no good reason for us to keep it (erasure);
- have processing paused while a question about the data is resolved (restriction);
- object to processing based on our legitimate interests — and object at any time, without conditions, to direct marketing;
- receive data you provided to us in a portable, machine-readable format (data portability);
- withdraw consent, where consent is the basis we rely on, without affecting processing that already took place.
To exercise any of these rights, email info@33equity.eu. We may need to verify your identity before acting on a request — this protects your data from being disclosed to someone else. We respond within one month; if a request is complex we may need longer, and will tell you so. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.
You can also lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the opportunity to address your concern directly first.
Third-party websites and embedded services
This website may contain links to external websites, and embeds a small number of third-party services — for example the map showing our office location. When you interact with those services, the third party may process data about you under its own privacy notice, which we encourage you to read. We are not responsible for the privacy practices of external websites.
Changes to this notice
If we change this notice, the updated version will be published on this page and applies from the moment it is posted. Please also let us know if your own details change during our relationship, so that what we hold stays accurate.