nei.io
Home The Liquidity Gap Our Approach The Platform Legal FAQ About Us
Log in Request Access
Home The Liquidity Gap Our Approach The Platform Legal FAQ About Us Log in
Legal/NEI Privacy Policy

NEI Privacy Policy

Version: 1.0 · Effective September 16, 2026

Last updated: September 16, 2026

This document may be updated from time to time; see its Changes section.

NEI ("we", "us") operates the NEI platform at app.nei.io and the website nei.io. This policy explains what personal data we process, why, for how long, and what rights you have. It is subject to change as described in Section 12.

Controller: New Era Ventures ApS (CVR 42329843), c/o Rasmus Secher Schultz, Holsteinsgade 50, 1. th, 2100 Copenhagen Ø, Denmark. Contact: contact@nei.io.

1. Who this policy covers

  • Platform users - individuals with an invited account on the NEI platform (buyers, sellers, advisors, and their teams).
  • Business contacts - market participants (advisors, brokers, investors) whose professional details we hold in our contact database and correspond with about transactions.
  • Website visitors and inquirers - people who visit nei.io or use the contact form.

2. What we collect and why

At a glance (detail and legal bases follow below):

Data Purpose
Account data (name, email, employer, phone, role) Operate your account; identify you to counterparties
Credentials (one-way hash only) Sign-in verification
Login security codes (stored hashed, expire within minutes) Two-step sign-in verification
Content you submit (deals, quotes, documents, notes, messages) Facilitate and document transactions
Activity records Transaction audit trail; evidence of agreements
Mandate and platform activity Deal alerts and service communications; matching
Usage patterns and content Internal service improvement and development
Business-contact data Originate and execute transactions; market relationships
KYC/AML information Counterparty screening via our broker-dealer
Contact-form submissions Answer your inquiry
Technical logs (IP addresses, ~30 days) Security, abuse prevention, rate limiting

Platform users

Some of this data you provide directly (account details, content you submit); activity records and technical logs are generated by your use of the Platform.

  • Account data (name, email, employer, phone, role): to operate your account and identify you to transaction counterparties. Legal basis: performance of contract. Accounts are created by invitation only - we collect this data from you or from the organization that nominated you.
  • Credentials: we never store your password itself. Sign-in is verified against a salted one-way hash (bcrypt), from which the password cannot be recovered.
  • Content you submit (deal information, documents, notes, messages, comments, sign-offs): to facilitate and document transactions. Legal basis: performance of contract. Where content you upload contains personal data of third parties, the NEI Data Processing Addendum applies (see Section 10).
  • Activity records (actions on deals, changes to records, acceptance of terms): to maintain an accurate transaction audit trail and evidence agreements. Legal basis: legitimate interest in the integrity and enforceability of transactions.
  • Service communications and deal alerts: we use your account data, mandate, and platform activity to send you what the service is for - deals matching your mandate, new and changed listings, and platform updates - on the platform and by email. Legal basis: performance of contract / legitimate interest in operating the deal network. Digest-type emails carry an unsubscribe or preference option; essential service, security, and terms notices do not require one and may always be sent.
  • Service improvement and development: we use platform data - usage patterns, activity records, and content - to maintain, secure, improve and develop the Platform and our services, for NEI's internal purposes only. This data is never shared externally for these purposes (see Section 4 for the only external data sharing we do). Legal basis: legitimate interest in developing and improving our services; you may object (Section 8).

Business contacts

  • Professional contact data (name, business email/phone/address, employer, title, regulatory identifiers, investment mandate, interaction notes): to originate and execute transactions and maintain market relationships. Legal basis: legitimate interest in conducting our business with professional market participants. Where we did not collect your data from you directly, we obtained it from our business partners, from publicly available professional sources (such as firm websites and professional registers), or through referrals from mutual business contacts.
  • Correspondence: emails exchanged with us about transactions are retained as part of the transaction record (see Section 5).

Website visitors

  • Contact-form submissions (name, email, phone, company, message): to respond to your inquiry. Legal basis: steps prior to entering a contract / legitimate interest. Submissions are delivered to our mailbox and are not stored in a website database.
  • Technical logs: our infrastructure (Google Cloud) logs HTTP requests including IP addresses for security, abuse prevention and rate limiting. Legal basis: legitimate interest in securing our services. Logs are retained ~30 days.
  • Cookies: nei.io sets no cookies; the platform sets only strictly necessary session cookies. Full details in the NEI Cookie & Advertising Policy.

3. What we do NOT do

We do not sell personal data. We do not use advertising trackers. We do not profile you for advertising or share data for advertising. We do match your stated mandate and platform activity to relevant deals - that is the service you signed up for, not advertising. We do not make automated decisions with legal effect about you.

4. Who we share data with

  • Transaction counterparties: platform content is visible to the parties of a transaction according to the platform's role- and stage-based document access rules.
  • Market-data partner (MSCI): NEI shares transaction and market data originating from NEI's own deal activity with MSCI. A data point is NEI's own once NEI has added information to it - NEI enriched a vendor quote with NEI-observed information, or NEI added value to the deal (sourced, intermediated, verified, priced, matched). What is shared is the resulting market data point (price, size, instrument, transaction terms) - never contributed content, documents, client identities, or the identity of the listing organisation.
  • Processors: Google Cloud Platform (hosting, storage, logging; United States) and Google Workspace (email). Processors act under Art. 28 agreements.
  • Broker-dealer: information needed for counterparty screening (KYC, AML, sanctions) and, when a transaction is executed, the transaction information and documents needed to execute it, are shared with the broker-dealer through which securities transactions are conducted, which processes them under its own regulatory obligations.
  • Business transactions: if NEI is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, under confidentiality; we will provide notice before personal data becomes subject to a different privacy policy.
  • No third-party data sales, no ad networks.
  • Legal and law enforcement: where required by law, regulation, valid law-enforcement request, or defense of legal claims.

5. How long we keep data (retention overview)

Full internal schedule available on request. Summary:

Data Retention
Account and profile data (login profile) Life of account + 90 days after closure, then anonymized. Your identity within deal and transaction records is kept per the transaction-record period below
Login security codes Single-use: deleted on use; expire after 10 minutes; residual records swept within a day
Terms acceptances Relationship + 5 years (evidence of agreement)
Business-contact records While the relationship is active; reviewed every 24 months of inactivity
Transaction correspondence 3 years after last message
Deal and transaction records, documents Life of deal + 7 years (transaction records)
Audit logs (platform activity) 5 years
Infrastructure/security logs (IP addresses) ~30 days
Database backups Rolling 7 days
Contact-form inquiries 12 months

Deleted platform documents may persist in versioned backup storage for up to 5 years before final erasure. Erasure requests propagate to rolling backups within 7 days.

These are our normal periods. Retention can extend beyond them where a legal obligation or our legal position requires it - for example a legal hold, preservation order, or valid law-enforcement request; tax and bookkeeping requirements; fraud or security investigations; or the pursuit or defense of legal claims, including regulatory investigations. In those cases we retain only the data needed for that purpose, for as long as that purpose lasts.

6. International transfers

Data is hosted and processed on Google Cloud in the United States, and may also be processed in Google Cloud data centres in the European Union. Where data is transferred outside the EEA/UK, we rely on Google's certification under the EU-US Data Privacy Framework and its data-processing terms, and/or Standard Contractual Clauses with our processors. A copy of the applicable safeguards is available on request via contact@nei.io.

7. Security

Invitation-only access, role- and stage-based document permissions, bcrypt password hashing, encryption of stored email-integration tokens, TLS in transit, least-privilege database roles, and cloud-provider encryption at rest. See the NEI Security Measures page for the full description.

8. Your rights and choices

Your choices: you may object to the service-improvement use of your data, unsubscribe from digest-type emails (Section 2), and object to outreach as a business contact - and you can exercise the rights below at any time.

Under the GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Contact contact@nei.io. We respond within one month. You may lodge a complaint with Datatilsynet, the Danish Data Protection Agency (www.datatilsynet.dk), or with the supervisory authority where you live or work in the EU/EEA.

Note for business contacts: if you object to outreach, we retain your name and email on a suppression list solely to honor the objection.

9. Where your data comes from (Art. 14)

For business contacts not collected directly: sources are our business partners, publicly available professional sources (firm websites and public regulatory registers such as FINRA BrokerCheck), and referrals from mutual business contacts. Categories: professional contact and role data as in Section 2.

10. Data you upload about others

If you upload documents or contact details containing third parties' personal data, you are responsible for having the right to do so. Our processing of that data on your behalf is governed by the NEI Data Processing Addendum.

11. Sites and services operated by others

Our sites link to external sites and services (for example LinkedIn, or resources referenced in our guides). Those are operated by others under their own privacy practices, which this policy does not cover.

12. Changes to this Privacy Policy

We version this policy. Material changes are announced on the platform and by updating the dates shown on this page before they take effect; superseded versions remain available on request and, once they exist, on this site. Continued use after notice constitutes acceptance of the updated notice.

13. California residents (CCPA/CPRA)

Categories collected: identifiers, professional information, communications (Section 2). We do not sell or share personal information for cross-context behavioral advertising, and have not in the preceding 12 months. Rights: know, delete, correct, non-discrimination - exercise via contact@nei.io. Authorized agents may act with written permission.

nei.io The Private Markets deal network
FAQ Contact us Resources Terms DPA Disclosures Privacy Cookies Security Legal LinkedIn