Privacy Policy

Home / Primary Privacy Policy

Primary Privacy Policy

Effective Date: 25 August 2026

At GM FINANCIAL GROUP LTD (the “Company”, “we”, “our”, or “us”), we are committed to protecting the privacy and personal data of individuals who access our website, communicate with us, submit information, or otherwise interact with our advisory services.

This Primary Privacy Policy explains how the Company collects, uses, stores, discloses, and protects personal data in connection with the website gmfinancialgroup.gr, preliminary communications, enquiries, submissions, assessments, and other interactions with the Company.

This Policy applies where GM FINANCIAL GROUP LTD determines the purposes and means of processing personal data and therefore acts as a data controller under applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR where applicable.

Scope clarification

Personal data may also be processed in connection with a specific advisory engagement, mandate, contractual relationship, project assessment, financing process, or other professional engagement.

In such circumstances, the processing of personal data may also be subject to the terms of the relevant written agreement, confidentiality obligations, data protection provisions, and other applicable legal or regulatory requirements.

Depending on the circumstances and the nature of the relevant processing activity, the Company may act as a data controller, joint controller, or processor, as applicable under relevant data protection law.

Where the Company processes personal data on behalf of a client or other party under a specific written agreement, the respective responsibilities of the parties shall be determined by that agreement and applicable data protection law.

Nothing in any contractual arrangement shall exclude, restrict, or replace any obligation, right, or protection arising under applicable data protection law.

1. Data Controller

For the purposes of applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR where applicable, GM FINANCIAL GROUP LTD acts as the data controller in relation to personal data processed for its own business, website, communication, assessment, administrative, compliance, and advisory purposes.

The Company determines the purposes and means of such processing and is responsible for ensuring that personal data is handled in accordance with applicable data protection requirements.

Where the Company processes personal data solely on behalf of a client or other party under a specific written agreement, the Company may act as a processor rather than a controller, depending on the nature of the processing and the applicable legal framework.

Privacy and data protection enquiries may be directed to:

Privacy Contact
GM FINANCIAL GROUP LTD
3 Cardinal Point, Park Road
Rickmansworth, England, WD3 1RE

Email: dpo[at]gmfinancialgroup[dot]gr

The use of the above email address does not, by itself, imply that the Company has appointed a statutory Data Protection Officer unless such appointment is required or has been formally made under applicable law.

2. Personal Data We Collect

We collect and process personal data only to the extent reasonably necessary for legitimate business, advisory, communication, compliance, security, and operational purposes.

The categories of personal data we may collect depend on the nature of your interaction with the Company and may include:

Identification and Contact Information
Name, professional title, company or organisation name, business address, email address, telephone number, and other contact details.

Professional and Corporate Information
Information relating to your role, authority, employer, business activities, company structure, directorships, shareholdings, beneficial ownership, professional relationships, or representation of another person or entity.

Advisory, Project and Financing Information
Business, financial, commercial, transaction, project, financing, ownership, management, or other information provided in connection with an enquiry, preliminary assessment, mandate, engagement, or financing process.

Compliance and Verification Information
Where necessary and lawful, information required for identity verification, authority checks, compliance, due diligence, fraud prevention, sanctions screening, anti-money laundering procedures, or other legal and regulatory purposes.

Correspondence and Communications
Information contained in emails, website forms, documents, enquiries, submissions, meeting notes, and other communications with the Company.

Technical and Usage Data
When you access the website, we may automatically collect limited technical information such as:

  • IP address,
  • browser type and version,
  • device type and operating system,
  • date and time of access,
  • pages viewed and interactions with the website,
  • referring URLs,
  • security and diagnostic information.

Such technical data may be used for website operation, security, fraud prevention, analytics, performance monitoring, and improvement of the website and related services.

Personal Data Obtained from Third Parties

Where permitted by applicable law, we may receive personal data from clients, authorised representatives, introducers, professional advisers, business partners, counterparties, service providers, publicly available sources, regulatory or compliance databases, and other lawful sources relevant to the Company’s advisory or business activities.

The Company does not seek to collect personal data that is unnecessary for the relevant purpose and may request that information not relevant to a particular enquiry, assessment, engagement, or process is not provided.

3. Legal Bases and Purposes of Processing

We process personal data only where a valid legal basis applies under applicable data protection law.

Depending on the circumstances, the legal bases on which we may rely include:

  • performance of a contract or taking steps at the request of an individual before entering into a contract,
  • legitimate interests, where necessary for the operation, administration, security, development, and protection of the Company’s business and Services, provided that such interests are not overridden by the rights and freedoms of the individual concerned,
  • compliance with legal or regulatory obligations applicable to the Company,
  • consent, where consent is required under applicable law.

Personal data may be processed for purposes including:

  • responding to enquiries, requests, submissions, and communications,
  • assessing whether a matter, project, business, or financing request falls within the scope of the Company’s services,
  • conducting preliminary assessments, capital-readiness reviews, and related advisory analysis,
  • preparing, structuring, organising, or managing information and documentation in connection with a potential or existing professional engagement,
  • communicating with clients, prospective clients, introducers, authorised representatives, professional advisers, lenders, funds, investors, institutions, service providers, and other relevant counterparties,
  • supporting due diligence, compliance, verification, fraud prevention, sanctions screening, anti-money laundering, or other lawful risk-management procedures where applicable,
  • administering mandates, engagements, contracts, fees, records, and business relationships,
  • complying with legal, regulatory, accounting, tax, audit, record-keeping, or enforcement obligations,
  • protecting the security, integrity, availability, and lawful operation of the website, communications, systems, and business infrastructure,
  • analysing website usage and performance and improving the Company’s website and services,
  • establishing, exercising, or defending the Company’s legal rights.

Where processing is based on legitimate interests, the Company will consider the nature of the data, the purpose of processing, the reasonable expectations of the individual, and the potential impact on that individual before relying on that legal basis.

The legal basis applicable to a particular processing activity may vary depending on the nature of the relationship, the information involved, and the relevant legal or regulatory requirements.

4. Disclosure of Personal Data

The Company does not sell personal data.

Personal data may be disclosed only where such disclosure is lawful, necessary, proportionate, and relevant to the purpose for which the data is processed.

Depending on the circumstances, personal data may be disclosed to:

Service Providers and Processors
Third-party providers supporting hosting, IT infrastructure, cybersecurity, communications, analytics, document management, professional administration, or other operational functions. Where such providers act as processors on behalf of the Company, appropriate contractual and data protection safeguards will be used as required by applicable law.

Professional Advisers and Service Providers
Lawyers, accountants, auditors, consultants, compliance specialists, technical advisers, valuation professionals, and other professional service providers where their involvement is necessary for the relevant business, advisory, compliance, or legal purpose.

Funding and Transaction Counterparties
Where relevant to a legitimate advisory engagement, assessment, mandate, financing process, or transaction, personal data may be disclosed to independent third-party lenders, banks, funds, investors, institutions, advisers, service providers, or other counterparties involved in reviewing, assessing, structuring, progressing, or completing the relevant matter.

Any such disclosure will be limited to the information reasonably necessary for the relevant purpose and will be subject to applicable law, confidentiality obligations, contractual arrangements, and any other safeguards considered appropriate.

Legal, Regulatory, and Public Authorities
Personal data may be disclosed where required or permitted by law, regulation, court order, lawful request, regulatory obligation, enforcement process, or where necessary to protect the legal rights, property, security, or legitimate interests of the Company or another party.

Corporate Transactions
Personal data may be disclosed in connection with an actual or proposed merger, acquisition, restructuring, financing, sale of assets, transfer of business, or similar corporate transaction, subject to appropriate confidentiality and data protection safeguards.

Affiliated or Related Entities
Where legally permitted and operationally necessary, personal data may be shared with entities under common ownership or control, or other related entities, solely for purposes consistent with this Policy and subject to appropriate safeguards.

A recipient of personal data may act as a processor, joint controller, or independent controller depending on the nature of the relationship and the relevant processing activity.

The Company does not assume that every third party receiving personal data acts as a processor and does not represent that a Data Processing Agreement applies in circumstances where the relevant recipient acts independently as a controller under applicable law.

5. Data Retention

The Company retains personal data only for as long as reasonably necessary for the purposes for which it was collected or otherwise processed, taking into account applicable legal, regulatory, contractual, accounting, tax, compliance, operational, security, and risk-management requirements.

The applicable retention period may vary depending on the nature of the personal data, the purpose of processing, the type of relationship with the individual or organisation concerned, and any legal or contractual obligations requiring the Company to retain records for a specific period.

In determining appropriate retention periods, the Company may consider:

  • the duration of any enquiry, assessment, mandate, engagement, transaction, or business relationship,
  • the need to maintain records for legal, regulatory, tax, accounting, audit, compliance, or evidential purposes,
  • applicable limitation periods for legal claims,
  • the sensitivity, volume, and nature of the personal data,
  • the potential risks associated with continued retention,
  • the need to protect the Company’s legal rights, legitimate interests, systems, and business operations.

Where personal data is no longer required for the purpose for which it was collected and there is no lawful basis for continued retention, the Company will take reasonable steps to delete, anonymise, securely destroy, or restrict access to the relevant data, as appropriate.

Personal data contained in backup, archive, security, audit, or disaster-recovery systems may remain for a limited additional period where immediate deletion is not technically feasible, provided that such data remains subject to appropriate safeguards and is not used for unrelated purposes.

Where personal data is processed in connection with a specific written engagement or contractual relationship, any applicable retention provisions contained in the relevant agreement may also apply, subject always to applicable data protection law.

6. Your Rights

Subject to the conditions, limitations, and exemptions provided by applicable data protection law, you may have the following rights in relation to your personal data:

  • right of access – to request confirmation as to whether your personal data is being processed and, where applicable, access to that data and related information,
  • right to rectification – to request correction of inaccurate or incomplete personal data,
  • right to erasure – to request deletion of personal data where the applicable legal conditions are met,
  • right to restriction of processing – to request that the processing of your personal data be restricted in certain circumstances,
  • right to data portability – to receive certain personal data in a structured, commonly used, and machine-readable format and, where applicable, request its transmission to another controller,
  • right to object – to object to certain processing based on legitimate interests or other applicable legal grounds,
  • right to withdraw consent – where processing is based on consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal,
  • rights relating to direct marketing – to object at any time to the processing of personal data for direct marketing purposes,
  • rights relating to automated decision-making – where applicable, to exercise rights in relation to decisions based solely on automated processing that produce legal or similarly significant effects.

Requests to exercise privacy rights may be submitted to:

Privacy Contact
dpo[at]gmfinancialgroup[dot]gr

The Company may request reasonable information necessary to verify the identity and authority of the person making the request before acting on it.

The Company will respond within the time limits required by applicable law. In certain circumstances, those time limits may be extended where legally permitted, including where a request is complex or multiple requests have been received.

Certain rights are not absolute and may be restricted or refused where permitted by applicable law, including where processing is required for legal obligations, the establishment, exercise or defence of legal claims, protection of the rights of others, or other lawful reasons.

Supervisory Authorities

You also have the right to lodge a complaint with a competent data protection supervisory authority where you consider that the processing of your personal data infringes applicable data protection law.

Greece
Hellenic Data Protection Authority
www.dpa.gr

United Kingdom
Information Commissioner’s Office (ICO)
www.ico.org.uk

7. Children

The Company’s website and professional advisory services are not directed to individuals under the age of 18.

The Company does not knowingly collect or process personal data relating to children in connection with the use of the website or the provision of its professional services, except where such processing is lawful, necessary, and relevant to a legitimate business, legal, compliance, or contractual purpose.

If personal data relating to a person under the age of 18 is provided to the Company by a client, authorised representative, professional adviser, or other third party in connection with a legitimate matter, the person providing that information is responsible for ensuring that the disclosure is lawful and appropriately authorised.

Where the Company becomes aware that personal data relating to a child has been collected or provided without an appropriate lawful basis, it may take reasonable steps to delete, restrict, or otherwise cease processing that data, subject to any legal or regulatory obligation requiring its retention.

8. Security Measures

The Company implements appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful access, disclosure, alteration, loss, destruction, misuse, or accidental damage.

Such measures may include, where appropriate:

  • access controls and authentication measures,
  • role-based or need-to-know access restrictions,
  • encryption and secure transmission methods,
  • secure hosting and infrastructure controls,
  • system monitoring, logging, and security reviews,
  • malware protection, backups, and recovery procedures,
  • internal confidentiality and information-handling controls,
  • appropriate safeguards in relation to third-party service providers and processors.

The specific measures applied may vary depending on the nature, sensitivity, volume, and context of the personal data involved, the purpose of processing, the systems used, and the level of risk identified.

The Company regularly reviews its security arrangements and may update them to reflect changes in technology, operational requirements, legal obligations, and identified risks.

While the Company takes reasonable steps to protect personal data, no method of transmission over the internet, electronic communication, or data storage system can be guaranteed to be completely secure.

Users and other persons communicating with the Company are responsible for taking reasonable precautions when transmitting confidential, commercially sensitive, or personal information, including ensuring that information is sent through appropriate and authorised channels.

Where the Company becomes aware of a personal data breach, it will assess the incident and take such notification, mitigation, investigation, and remedial steps as may be required under applicable data protection law.

9. International Data Transfers

Personal data may be transferred to, accessed from, or processed in countries outside the European Economic Area (EEA), the United Kingdom, or Switzerland where this is necessary for the Company’s operations, professional services, technology infrastructure, communications, compliance activities, or engagement with relevant third parties.

Where such transfers are subject to applicable data protection restrictions, the Company will take appropriate steps to ensure that the personal data receives a level of protection consistent with applicable law.

Depending on the destination country, the recipient, and the circumstances of the transfer, appropriate safeguards may include:

  • an applicable adequacy decision,
  • Standard Contractual Clauses (SCCs) approved under applicable data protection law,
  • the UK International Data Transfer Addendum or other recognised UK transfer mechanism,
  • binding contractual safeguards,
  • other lawful transfer mechanisms recognised by the relevant supervisory or regulatory authority.

Where required, the Company may also consider supplementary technical, contractual, or organisational measures designed to address risks associated with an international transfer.

The specific transfer mechanism used may vary depending on the countries involved, the status of the recipient, the nature of the personal data, and the legal requirements applicable at the relevant time.

Where a third-party service provider, adviser, lender, fund, investor, institution, or other counterparty independently determines the purposes and means of processing personal data, that party may act as an independent controller and may be subject to its own privacy and international transfer obligations.

Further information about applicable international transfer safeguards may be requested through the Company’s Privacy Contact, subject to any confidentiality, legal, regulatory, or security restrictions.

10. Changes to This Policy

The Company may update this Privacy Policy from time to time to reflect changes in applicable law, regulatory requirements, business activities, services, technology, data processing practices, or operational procedures.

Any updated version will be published on this page and will become effective from the date indicated at the top of the Policy, unless otherwise stated.

Where a material change significantly affects the way personal data is collected, used, disclosed, retained, or otherwise processed, the Company may take additional reasonable steps to bring the change to the attention of affected individuals where required by applicable law.

Users are encouraged to review this Policy periodically to remain informed about how the Company processes and protects personal data.

Continued use of the website after an updated Policy has been published constitutes acknowledgement of the revised Policy, but does not replace any consent or other legal basis that may be required under applicable data protection law.

11. Telephone Call Recording

Telephone calls to GM FINANCIAL GROUP LTD may be recorded for quality assurance, security, record-keeping, and the management of enquiries or client communications. Where call recording is enabled, callers are informed at the beginning of the call.

Recordings may contain personal data and are processed in accordance with applicable data protection law, including the EU General Data Protection Regulation (GDPR) and the UK GDPR where applicable. Access to recordings is restricted to authorised persons and service providers involved in operating or supporting the Company’s communications systems, and recordings are retained only for as long as reasonably necessary for the purposes for which they were collected.

Callers who do not wish to continue with a recorded call may end the call and contact the Company through the alternative communication methods available on the website.

12. Contact

For questions, requests, complaints, or other matters relating to this Privacy Policy or the processing of personal data by the Company, please contact:

Privacy Contact
GM FINANCIAL GROUP LTD
3 Cardinal Point, Park Road
Rickmansworth, England, WD3 1RE

Email: dpo[at]gmfinancialgroup[dot]gr

When contacting the Company in relation to personal data, please provide sufficient information to enable us to identify the relevant matter and respond appropriately.

Where a request concerns the exercise of data protection rights, the Company may request additional information necessary to verify the identity and authority of the person making the request before taking action.

Where the matter relates to personal data processed in connection with a specific client engagement, mandate, transaction, or other contractual relationship, the Company may also refer to the relevant written agreement and any applicable data protection or confidentiality provisions.

Nothing in this section limits your right to contact or lodge a complaint with a competent data protection supervisory authority.

Introduction

Independent advisory focused on capital readiness, structured financing, and institutional alignment for businesses and projects, in cross-border contexts.

All inquiries and information exchanges are reviewed solely through structured written communication via our contact form.

We act as the institutional bridge, guiding the right transaction to the right source of capital.