GA Asset Management

Privacy policy

How we handle personal data

This policy explains what personal data GA Asset Management B.V. processes, why, and what rights you have under the General Data Protection Regulation (GDPR / AVG).

Last updated 26 July 2026 Version 1.0

Controller

GA Asset Management B.V. is the controller for the processing described in this policy.

Address
World Trade Center Schiphol
Schiphol Boulevard 155
1118 BG Schiphol
The Netherlands
Chamber of Commerce
KvK 34301144

We have not appointed a data protection officer, as we are not required to do so. Privacy questions reach us at the address above.

Cookies and tracking

This website sets no cookies. It uses no analytics, advertising, social media plugins, contact forms or tracking of any kind, and it does not build profiles of visitors.

Typefaces are requested from the Google Fonts service when a page loads. Your IP address is therefore visible to Google for the purpose of delivering those files. Google Fonts sets no cookies.

Data we process

Information you send us

If you contact us by email or telephone, we process your name, your contact details and whatever else your message contains.

Technical log data

Our hosting provider records standard server logs when a page is requested: IP address, date and time, the page requested, the referring page and browser and device type. These logs support availability and security and are not used to identify individual visitors.

Investor and counterparty information

If a business relationship develops, we process the data needed to enter into and administer it, including identification documents, tax details, bank details and the information we must collect to comply with anti-money laundering law.

Why we process it

  • To answer your enquiry and maintain contact. Legal basis: our legitimate interest in responding, or the steps preceding a contract.
  • To enter into and perform agreements with investors, service providers and counterparties. Legal basis: performance of a contract.
  • To comply with legal obligations, including the Anti-Money Laundering and Anti-Terrorist Financing Act (Wwft), the Sanctions Act 1977, tax law and obligations under the Wft. Legal basis: compliance with a legal obligation.
  • To keep our website and systems secure and to investigate misuse. Legal basis: our legitimate interest.

We do not use your personal data for automated decision-making or profiling.

Who receives it

We share personal data only where it is necessary, and only with:

  • service providers acting on our instructions, such as our hosting and email providers, IT support and, where applicable, a fund administrator and depositary: Microsoft, AssetCare, InteractiveBrokers;
  • professional advisers, auditors and banks or brokers, where their involvement requires it;
  • supervisory, tax and other authorities, where the law obliges us to provide information.

Processors act under a written agreement and may not use the data for their own purposes. We do not sell personal data.

Transfers outside the EEA

We keep personal data within the European Economic Area where we can. If a provider processes data outside the EEA, we rely on an adequacy decision of the European Commission or on the European Commission's standard contractual clauses, with additional safeguards where these are needed.

The website is hosted on Microsoft resources. The fonts are requested from the Google Fonts service.

How long we keep it

  • Correspondence: for as long as it is relevant to our relationship with you, and then deleted.
  • Client due diligence records under the Wwft: five years after the end of the business relationship or the transaction.
  • Records with a tax or accounting purpose: seven years, as Dutch law requires.
  • Server logs: 30 days.

Security

We take appropriate technical and organisational measures to protect personal data against loss and unlawful processing, including access control, encryption in transit and a limited circle of people who can see the data. If a data breach occurs that presents a risk to you, we notify the Dutch Data Protection Authority and, where required, you.

Your rights

Under the GDPR you may ask us to give you access to your personal data, to correct it, to erase it, to restrict its processing or to transfer it to another party. You may object to processing based on our legitimate interest, and you may withdraw any consent you have given.

Write to office@gaam.nl to exercise a right. We reply within one month and may ask you to confirm your identity first. Where the law requires us to keep certain records, we may not be able to erase them.

Complaints

If you believe we handle your personal data improperly, please tell us first so that we can look into it. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) and to seek a remedy from the courts.

Changes

We update this policy when our processing or the law changes. The version and date at the top of this page show when it was last revised.

Back to home