Privacy Policy
How enquiries and controlled access are handled.
This notice describes the receipt and use of information submitted through the private introduction and service-request forms, together with the limited personal and technical information processed when individual access to the Private Salon is issued, verified and administered.
The forms covered by this notice
This notice covers the Private Introduction form and the Request Consideration forms appearing across the public mandate pages. All such forms submit to the same controlled consideration process and are handled by the same present contracting and controlling entity.
Each form collects a name, a stated role, an email address, an optional telephone number, a country or jurisdiction, the nature of the matter, a preferred form of reply, and a written description of the matter. A technical record of the market and language selected, the page from which the enquiry was written, and a one-way hash of the submitting network address and browser identification is retained to prevent abuse. Sensitive documentation must not be submitted through these forms.
What is collected and why
Enquiries submitted through the private introduction form are received by the House. The information submitted — name, contact details, and a short written context — is used solely to consider whether the House is the appropriate recipient of the matter, and to reply.
Personal data is processed on the basis of the enquirer's request, in order to take steps prior to a possible engagement (Art. 6(1)(b) GDPR), and, where applicable, on the basis of the legitimate interest of the controlling entity in receiving and evaluating principal enquiries (Art. 6(1)(f) GDPR).
Data is not disclosed to third parties for any purpose other than the matter itself, save for the technical service providers who host this site and the enquiry register.
Private Salon access and security
Access to the Private Salon is granted individually following introduction and qualification. Where an invitation is issued, DGF & Co Capital Services GmbH records a recipient label, the relevant mandate reference, the permitted scope of access, the issue and expiry dates, revocation status and the applicable use count or use limit.
The access credential itself is not stored in readable form. Only a cryptographic hash of the credential is retained for server-side verification.
Successful verification creates a limited session associated with the relevant invitation, mandate and permission scope. The session is subject to idle and absolute expiry and becomes unusable following logout, expiry or invalidation. The related browser cookie is encrypted, HttpOnly, Secure, SameSite and short-lived.
Access attempts may be rate-limited using a one-way hash of the submitting network address. Repeated unsuccessful attempts may result in temporary restriction or lockout. A limited security record is maintained to protect the Private Salon and investigate suspected misuse.
This information is processed to authenticate approved recipients, restrict access to the appropriate mandate and materials, protect confidential residence information, prevent misuse, investigate attempted unauthorised access and preserve an appropriate security record for the Private Salon.
Depending on the relationship and stage of the matter, this processing is undertaken to take steps at the request of the recipient before a possible engagement or in connection with an existing mandate under Article 6(1)(b) GDPR, and on the basis of the legitimate interests of DGF & Co Capital Services GmbH in maintaining controlled access, confidentiality, information security and abuse prevention under Article 6(1)(f) GDPR.
Transmission and delivery
Enquiries and Private Salon access records are transmitted over encrypted connections and maintained on infrastructure operated on behalf of DGF & Co Capital Services GmbH by technical service providers engaged for that purpose. Access to the information is limited according to operational need and the relevant mandate.
Private Salon materials are made available only to the recipient and for the mandate and permission scope for which access has been granted. Appointment of a professional adviser or execution provider does not automatically grant that party access to the Salon or to another recipient’s records.
Hosting-platform visitor measurement
This website is published on the Lovable platform. The platform injects its own visitor-measurement script, served from the path /~flock.js, which transmits measurement data to the platform endpoint /~api/analytics. This script is added by the publishing platform and is not part of the editorial content of the website.
To the extent verified, the information transmitted is technical and relates to the page requested, the referring page, and standard technical characteristics of the request such as the browser identification and network address made available to the platform. The purpose is aggregate measurement of website usage.
This measurement is a setting of the publishing platform and can be switched off there. Where it is switched off, the script and the endpoint are no longer served and this section is withdrawn. No retention period or international-transfer arrangement is stated here, because none has been verified by DGF & Co Capital Services GmbH.
Retention and deletion
An enquiry is retained for as long as the matter is under consideration and for such further period as is necessary to answer it or to comply with legal obligations. Where the House is not the appropriate recipient, the enquiry is deleted once the reply has been made and any applicable retention obligation has expired. Deletion may be requested at any time in writing.
Invitation information is retained while access remains valid. An invitation becomes unusable upon its stated expiry date, upon revocation or upon exhaustion of any applicable use limit. A session becomes unusable following logout, expiry or invalidation.
Security and access records are retained only for so long as is necessary to protect the Private Salon, investigate suspected misuse, administer the relevant mandate and comply with applicable legal obligations. When those purposes and obligations have ended, the records are deleted or irreversibly anonymised. Hashed network addresses are treated as pseudonymous security information.
Controlling entity and rights
DGF Private Office is a service identity of DGF & Co Capital Services GmbH, a limited liability company registered in Berlin (HRB 219323 B). Accepted mandates are entered into by DGF & Co Capital Services GmbH, as identified in the engagement letter and legal notice. The controlling entity for this processing is DGF & Co Capital Services GmbH, with its registered office at Anton-Wilhelm-Amo-Straße 45, 10117 Berlin-Mitte, Germany.
The contact of record for data-protection matters is David Shlomo Aric Goldenberg, Director, at the registered office address.
Data subjects have the right to request access to, rectification of, or erasure of their personal data, to request restriction of or object to processing, to data portability where applicable, and to lodge a complaint with a supervisory authority. Such requests may be made in writing to the contact of record.