Privacy Controls
Privacy & Cookie Policy
Last updated 1 August 2026
This page is maintained by Aegis US Capital Gateway to explain, in plain terms, what personal data we collect through this site and the private application process, why we collect it, how long we keep it, and how you exercise your rights under the EU/UK General Data Protection Regulation. It describes our own practices; it is not a certification or an independent audit.
1. Who is responsible for your data
Aegis US Capital Gateway (Private Client Division) acts as the data controller for information submitted through this website. Privacy questions, rights requests, and complaints can be sent to ankur@burnsfunding.com, which is monitored by our executive team.
2. What we collect and why
We only collect what the mandate review requires. We do not buy personal data from third parties, and we do not sell or rent your data to anyone.
| Data | Purpose | Lawful basis |
|---|---|---|
| Principal details (name, entity, country of residence, email, phone) | Reviewing your application, verifying eligibility, and contacting you about your mandate. | Steps taken at your request prior to entering a contract (Art. 6(1)(b)). |
| Mandate profile (currencies, allocation range, primary focus) | Assessing suitability and preparing the private consultation. | Steps taken at your request prior to contract (Art. 6(1)(b)). |
| Identity documents (passport, proof of address — optional) | Know-your-client checks and onboarding readiness. Uploads are optional at application stage. | Your explicit consent when you choose to upload, and our legal obligations once onboarding begins (Art. 6(1)(a) and 6(1)(c)). |
| Abuse-prevention signals (salted, hashed IP fingerprint, form timing, security-challenge records) | Blocking automated spam, rate-limiting submissions, and protecting the intake channel. | Our legitimate interest in securing the service (Art. 6(1)(f)). |
| Email delivery records (address, message type, delivery/bounce status) | Making sure confirmations and follow-ups actually reach you, and retrying failures. | Contractual/pre-contractual necessity and legitimate interest in reliable delivery. |
| Analytics events (page views, aggregate usage) — only with consent | Understanding which parts of the site are useful so we can improve them. | Your consent (Art. 6(1)(a)), withdrawable at any time. |
We do not use your data for automated decision-making or profiling that produces legal effects. Every mandate is reviewed manually.
4. How long we keep it
We keep personal data only as long as the purpose requires, then delete it. Our current schedule:
| Record | Retention | Then |
|---|---|---|
| Applications that do not proceed | 24 months from last contact | Deleted from the application database. |
| Applications that become engagements | Duration of the engagement, plus the period required by applicable tax, AML, and corporate record-keeping rules | Deleted or archived in restricted storage once the obligation lapses. |
| Uploaded identity documents | 12 months if no engagement begins | Erased from the private encrypted vault. |
| Abuse-prevention fingerprints (hashed IPs) | 24 hours | Automatically pruned; they are never stored in raw form. |
| Email delivery and bounce logs | 90 days | Purged from the notification outbox. |
| Analytics data (consented) | As configured in our analytics provider, no longer than 14 months | Aggregated or deleted. |
6. How we protect it
Applications travel over TLS and are stored in an access-controlled database with row-level security; documents live in a private vault that is never publicly addressable. Uploads are size-capped, type-checked against their actual file signature, and scanned before storage. The intake form is protected by rate limits, a single-use security challenge, and honeypot and timing checks. Access to applicant records is limited to the executive review team.
7. Your rights and how to exercise them
If you are in the EEA or UK, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw any consent you have given. Withdrawing consent does not affect processing carried out before withdrawal.
The fastest route is our data rights portal, where you can export or erase the consent record held for your browser immediately, or lodge an access or erasure request covering your mandate application, documents and correspondence.
You may also email ankur@burnsfunding.com with the subject line “Data Rights Request” and the email address you used to apply. We respond within 30 days and may ask for proof of identity before releasing or deleting records — this protects you from someone else making a request in your name. There is no charge unless a request is manifestly unfounded or excessive.
For analytics specifically, the fastest route is the . If you are unhappy with our response, you may lodge a complaint with your local supervisory authority (for example, your national data protection authority in the EU or the ICO in the UK).
8. Children
This service is offered to business principals and is not directed at anyone under 18. We do not knowingly collect data from children; if we learn that we have, we delete it.
9. Changes to this policy
We update this page when our practices change and revise the date at the top. Material changes affecting existing applicants are communicated by email to the address on file.