Privacy.
This policy explains what personal data we collect through this website and the Peliqan platform, why we collect it, how long we keep it and what you can do about it.
Last updated 24 August 2026
Who we are
Peliqan is the trading name of The Secondary Solutions B.V. (KvK 98087363), Herengracht 576a, 1017 CJ Amsterdam. That company is the controller of the personal data described in this policy: we decide what we collect and why. Write to info@peliqan.eu, or to that address, and you reach the people who answer for it.
What we collect
When you send us a message, we receive your name, email address and whatever you write to us. When you subscribe to the newsletter, we receive your email address. When you open an account on the platform, we collect your contact details and the portfolio information and documents you add. When you apply for a service, such as buying or selling a secondary or taking out a NAV loan, we also collect the identity documents we need for know-your-customer (KYC) checks. When you transact, we record the transaction itself: what you bought, sold or borrowed against, with whom, and when. If you accept cookies, Google Analytics also shows us how this website is used: which pages are visited, from what kind of device, and roughly where from. This website does not track you across the web.
Why we collect it
We use your data to answer your message, send you the quarterly newsletter if you asked for it, show your portfolio, arrange the transactions you start, diagnose errors and keep the platform secure. We also process some of it to meet legal obligations such as KYC checks. We do not use it for other purposes, sell it or share it with third parties for marketing. When you start a transaction, we share only the data that transaction requires with the parties involved.
Why we are allowed to
Our lawful basis depends on how we use your data. We run the platform and arrange transactions under our agreement with you, or to prepare that agreement. We carry out KYC checks and keep transaction records because the law requires it. We send the newsletter, load the map and run analytics with your consent, which you can withdraw at any time. We monitor errors and secure the platform based on our legitimate interest in a reliable and safe service, balanced against your privacy.
Where your data goes
Peliqan runs on AWS in Frankfurt: servers, database, document storage, backups and outgoing email all live there, in the European Union. When our software reads your documents, that happens on our own systems and through AWS Bedrock in the EU; your documents never reach an AI vendor's own service. That software reads and extracts; it decides nothing about you on its own. Error monitoring runs on Sentry's EU servers, in Frankfurt too. Our own mailboxes and internal notifications run on Microsoft 365, so when you write to us or sign up, your name and email address land there as well. This website loads two outside services, both from Google and both only with your consent: the map on the contact page, and Google Analytics, which shows us how the website is used. The map also loads if you click it. Google processes those visits partly in the United States, under the EU–US Data Privacy Framework.
How long we keep it
We keep correspondence as long as we have an active conversation or relationship with you, and your account data for as long as your account is open or an agreement with you is still running. Records we must keep by law, such as KYC checks and transaction records, we keep for as long as the law requires, even after you close your account. You can unsubscribe from the newsletter at any time; we then remove your email address from the list.
How we protect it
Access to your data is limited to the people at Peliqan who need it for their work. It is encrypted on the way to us and while we store it on AWS in Frankfurt. No system is perfectly secure. If a data breach affects you, we will tell you and notify the regulator where the law requires it.
Your rights
You can ask us what data we hold about you, have it corrected, or have it deleted. You can also ask for a copy in a form you can take elsewhere, ask us to pause our use of it while we sort something out, and object to any use we base on our own legitimate interest. Where we act on your consent, such as the newsletter or analytics, you can withdraw it whenever you like, and what we did before that stays lawful. One email to info@peliqan.eu is enough for any of it, and we answer within a month. One exception: records we must keep by law, such as KYC checks, we can only delete once the law allows it. If you believe we handled your data incorrectly, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
When this policy changes
We update this policy when our use of your data or the law changes. The date above tells you which version you are reading. If a change affects how we use your data or your rights, we will tell you before it takes effect, by email where we have your address.
Questions
Write to info@peliqan.eu if you want us to clarify anything. A team member will answer you personally.