Legal
Privacy Policy
Effective date: 25 July 2026
This policy explains how Caroloom collects and uses personal data when you visit caroloom.com or contact us. It applies to Caroloom itself; our portfolio companies maintain their own privacy practices.
1. Who we are
Caroloom is the data controller for the personal data described in this policy.
Caroloom
Copenhagen, Denmark
support@caroloom.com
2. The personal data we collect
We may collect:
- Information you send us. If you contact us by email, we receive your name, email address, organisation, message, and any other information or attachments you choose to provide.
- Technical information. When you visit our website, our hosting provider may process information such as your IP address, request date and time, requested page, referring page, and browser or device information. This information is used to deliver, secure, and maintain the website.
We do not offer user accounts, payments, or a contact form on this website. We do not use advertising cookies or cross-site tracking.
3. Why we use personal data
We process personal data to:
- respond to enquiries and communicate about potential investments, acquisitions, partnerships, or other business matters;
- take steps you request before entering into a contract;
- operate, protect, troubleshoot, and improve this website;
- prevent misuse and establish, exercise, or defend legal claims; and
- comply with legal and regulatory obligations.
Our legal bases under the GDPR are our legitimate interests in running and protecting our business and communicating with relevant contacts (Article 6(1)(f)); steps taken at your request before a contract or performance of a contract (Article 6(1)(b)); and compliance with legal obligations (Article 6(1)(c)).
Where we rely on legitimate interests, we consider whether those interests are proportionate and whether your rights and interests override them.
4. When we share personal data
We may share personal data with:
- service providers that support our hosting, email, security, and business operations, including Vercel, which hosts this website;
- professional advisers, such as lawyers, accountants, and consultants, where necessary;
- a Caroloom portfolio company or transaction counterparty where this is relevant to your enquiry and lawful; and
- public authorities or other parties when required by law or necessary to protect legal rights.
We do not sell personal data. Service providers may process personal data only for the services they provide to us and under appropriate contractual obligations.
5. International transfers
Some service providers may process data outside Denmark or the European Economic Area. Where required, we use an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate. You may contact us for more information about the safeguards relevant to your data.
6. How long we keep personal data
We keep personal data only for as long as it is needed:
- general enquiries are normally deleted or anonymised within 24 months after the last meaningful contact;
- information connected with an active business relationship, transaction, or contract may be kept for its duration and afterwards for applicable accounting, legal, and limitation periods; and
- technical logs are retained according to our provider settings and only as long as reasonably necessary for security, reliability, and troubleshooting.
We may keep information longer where required by law or where necessary for a legal claim.
7. Your rights
Depending on the circumstances, you may have the right to request access to, correction of, deletion of, or restriction of your personal data; to receive certain data in a portable format; and to object to processing based on legitimate interests.
To exercise a right, email support@caroloom.com. We may need to verify your identity. These rights are not absolute, and exemptions may apply.
You may also lodge a complaint with the Danish Data Protection Agency. We encourage you to contact us first so we can try to resolve your concern.
8. Cookies and analytics
This website does not currently use non-essential cookies or an analytics service. Essential technical storage may be used by our hosting platform where necessary to provide security or core functionality. If we introduce analytics, advertising, or other non-essential technologies, we will update this policy and, where required, ask for consent before using them.
9. Security
We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful loss, misuse, alteration, or unauthorised access. No internet transmission or storage system can be guaranteed to be completely secure.
10. Other websites
Our website links to portfolio companies and third-party services. Their privacy practices are governed by their own policies. Caroloom is not responsible for the privacy practices of external websites.
11. Automated decisions and children
We do not use personal data collected through this website for automated decision-making that produces legal or similarly significant effects. This corporate website is not directed to children.
12. Changes to this policy
We may update this policy when our practices or legal obligations change. The latest version will always be published on this page, with its effective date shown above.