Privacy Controls

Privacy & Cookie Policy

Last updated 1 August 2026

This page is maintained by Aegis US Capital Gateway to explain, in plain terms, what personal data we collect through this site and the private application process, why we collect it, how long we keep it, and how you exercise your rights under the EU/UK General Data Protection Regulation. It describes our own practices; it is not a certification or an independent audit.

1. Who is responsible for your data

Aegis US Capital Gateway (Private Client Division) acts as the data controller for information submitted through this website. Privacy questions, rights requests, and complaints can be sent to ankur@burnsfunding.com, which is monitored by our executive team.

2. What we collect and why

We only collect what the mandate review requires. We do not buy personal data from third parties, and we do not sell or rent your data to anyone.

DataPurposeLawful basis
Principal details (name, entity, country of residence, email, phone)Reviewing your application, verifying eligibility, and contacting you about your mandate.Steps taken at your request prior to entering a contract (Art. 6(1)(b)).
Mandate profile (currencies, allocation range, primary focus)Assessing suitability and preparing the private consultation.Steps taken at your request prior to contract (Art. 6(1)(b)).
Identity documents (passport, proof of address — optional)Know-your-client checks and onboarding readiness. Uploads are optional at application stage.Your explicit consent when you choose to upload, and our legal obligations once onboarding begins (Art. 6(1)(a) and 6(1)(c)).
Abuse-prevention signals (salted, hashed IP fingerprint, form timing, security-challenge records)Blocking automated spam, rate-limiting submissions, and protecting the intake channel.Our legitimate interest in securing the service (Art. 6(1)(f)).
Email delivery records (address, message type, delivery/bounce status)Making sure confirmations and follow-ups actually reach you, and retrying failures.Contractual/pre-contractual necessity and legitimate interest in reliable delivery.
Analytics events (page views, aggregate usage) — only with consentUnderstanding which parts of the site are useful so we can improve them.Your consent (Art. 6(1)(a)), withdrawable at any time.

We do not use your data for automated decision-making or profiling that produces legal effects. Every mandate is reviewed manually.

3. Cookies and similar technologies

Strictly necessary storage keeps the site working — it records your cookie choice and supports security controls on the application form. It cannot be switched off, and it is not used for advertising.

Analytics cookies load only after you accept them in the consent banner. Nothing is set before you choose, and rejecting analytics does not limit any part of the service. We do not run advertising or cross-site tracking cookies.

You can review or change your choice at any time: . Withdrawing consent stops future analytics collection immediately.

4. How long we keep it

We keep personal data only as long as the purpose requires, then delete it. Our current schedule:

RecordRetentionThen
Applications that do not proceed24 months from last contactDeleted from the application database.
Applications that become engagementsDuration of the engagement, plus the period required by applicable tax, AML, and corporate record-keeping rulesDeleted or archived in restricted storage once the obligation lapses.
Uploaded identity documents12 months if no engagement beginsErased from the private encrypted vault.
Abuse-prevention fingerprints (hashed IPs)24 hoursAutomatically pruned; they are never stored in raw form.
Email delivery and bounce logs90 daysPurged from the notification outbox.
Analytics data (consented)As configured in our analytics provider, no longer than 14 monthsAggregated or deleted.

5. Who processes data on our behalf

We use a small number of vetted processors, each bound by a data processing agreement and permitted to act only on our instructions:

  • Hosting and application platform — serves this site and runs the application backend.
  • Managed database and encrypted file storage — stores application records and identity documents in a private, non-public bucket.
  • Transactional email provider — delivers confirmations, status links, and follow-up messages from our own sending domain.
  • Analytics provider — only active if you accept analytics cookies.

Because we establish U.S. corporate structures, some processing takes place in the United States. Transfers out of the EEA/UK rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable) together with encryption in transit and at rest. We also disclose data to professional advisers or authorities where a legal obligation requires it.

6. How we protect it

Applications travel over TLS and are stored in an access-controlled database with row-level security; documents live in a private vault that is never publicly addressable. Uploads are size-capped, type-checked against their actual file signature, and scanned before storage. The intake form is protected by rate limits, a single-use security challenge, and honeypot and timing checks. Access to applicant records is limited to the executive review team.

7. Your rights and how to exercise them

If you are in the EEA or UK, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw any consent you have given. Withdrawing consent does not affect processing carried out before withdrawal.

The fastest route is our data rights portal, where you can export or erase the consent record held for your browser immediately, or lodge an access or erasure request covering your mandate application, documents and correspondence.

You may also email ankur@burnsfunding.com with the subject line “Data Rights Request” and the email address you used to apply. We respond within 30 days and may ask for proof of identity before releasing or deleting records — this protects you from someone else making a request in your name. There is no charge unless a request is manifestly unfounded or excessive.

For analytics specifically, the fastest route is the . If you are unhappy with our response, you may lodge a complaint with your local supervisory authority (for example, your national data protection authority in the EU or the ICO in the UK).

8. Children

This service is offered to business principals and is not directed at anyone under 18. We do not knowingly collect data from children; if we learn that we have, we delete it.

9. Changes to this policy

We update this page when our practices change and revise the date at the top. Material changes affecting existing applicants are communicated by email to the address on file.