Privacy Policy
Last updated August 24, 2026.
1. Who is responsible for your personal data?
Until Capital 4U AG is incorporated and entered in the Commercial Register, this website is operated by Richard Debrot, acting for the formation project Capital 4U AG (in formation). He is responsible for the personal data processed through this website.
Upon incorporation, Capital 4U AG will assume operation of the website and will become the controller for processing carried out from that point onward, subject to applicable law.
Contact address: Capital 4U AG (in formation), Aegeristrasse 8, 6300 Zug, Switzerland. Privacy enquiries and requests may be submitted through the contact form. Please state “Data Protection” in the subject line.
2. Scope of this Privacy Policy
This Privacy Policy explains how personal data are processed when you visit www.c4uag.com, use the contact form, correspond with C4U or communicate with us in connection with a proposed business relationship, partnership, transaction or investment opportunity. Separate notices or contractual provisions may apply to due diligence, onboarding, transactions, employment applications or other specific relationships.
3. Personal data we collect
3.1 Information you provide
When you use the contact form or communicate with us, we may receive your name, email address, subject, message, organisation, role, contact details and any other information that you choose to provide. If discussions progress, we may also receive business, project, counterparty, transaction and due-diligence information through appropriate channels.
Please do not submit passwords, payment-card information, copies of identity documents or other highly confidential material through the public contact form. We will provide a more suitable transmission method if such information is required.
3.2 Technical and usage data
When the website is accessed, the web server and security components may process technical data such as your IP address, date and time of access, requested page or file, referrer URL, browser type and version, operating system, device information, language, response status, transferred data volume and security events. These data are needed to deliver, protect and troubleshoot the website.
3.3 Anti-spam data
The contact form uses honeypot fields and related technical signals to distinguish genuine submissions from automated spam. These controls may process form timing, field interaction and technical connection data. They are used only for security and spam prevention.
4. Why we process personal data
We process personal data to operate, secure and maintain the website; respond to enquiries; assess potential business relationships and opportunities; take steps requested before entering into an agreement; administer existing relationships; conduct proportionate due diligence and compliance checks where required; protect our systems, rights and legitimate business interests; comply with legal obligations; and establish, exercise or defend legal claims.
Under Swiss data protection law, we process personal data in accordance with the principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and data security. Where the EU or UK GDPR applies, processing is based, as appropriate, on steps taken at your request before a contract, performance of a contract, compliance with legal obligations, our legitimate interests in operating and protecting the business and evaluating genuine enquiries, or consent where consent is legally required. Consent may be withdrawn for future processing at any time.
5. Website systems, cookies and similar technologies
5.1 Website platform
The website is built and operated using WordPress, the Astra theme, Elementor/Pro Elements and a Honeypot anti-spam component. These components run within the website and hosting environment and process the technical and form data required to display the site, receive enquiries and prevent abuse.
5.2 Hosting and email
Our hosting provider processes website content, connection data, server logs, security information and backups on our behalf. Contact-form submissions are transmitted to and handled through our hosting and business-email environment. Hosting, email, backup and IT-support providers may therefore process personal data as service providers subject to contractual and confidentiality obligations.
5.3 Google Fonts
The website currently loads typefaces from Google Fonts. When a page is displayed, your browser may connect directly to fonts.googleapis.com and fonts.gstatic.com. Google may receive technical connection data, including your IP address, browser information and the page request. Google may process such data outside Switzerland, including in the United States. C4U does not use Google Fonts to identify visitors, but does not control Google’s independent processing. Further information is available in Google’s privacy information.
5.4 Cookies, analytics and advertising
In an ordinary public visit, the website does not currently intentionally use analytics, advertising cookies or behavioural profiling technologies. Strictly necessary cookies or comparable storage may be used if required for security, form operation, load balancing or an administrator session. You can restrict cookies through your browser, although necessary functions may then be affected. If non-essential analytics, advertising or embedded services are introduced, this Privacy Policy and any required consent controls will be updated before use.
6. Who may receive personal data?
Access is limited to persons and organisations that need the data for the relevant purpose. Recipients may include C4U’s founders, directors, employees and authorised representatives; website hosting, email, backup, cybersecurity and IT-support providers; Google in connection with Google Fonts; professional advisers such as legal, tax, audit and compliance specialists; competent authorities where disclosure is required or permitted by law; and, only where necessary for a specific enquiry or transaction, relevant banks, custodians, regulated service providers, project entities, counterparties or due-diligence providers.
Submitting the contact form does not by itself cause your information to be circulated to transaction parties. Any broader disclosure will be limited to what is necessary, legally permitted and appropriate to the stage of the relationship. We do not sell personal data.
7. International data transfers
Recipients and service providers may be located in Switzerland, the European Economic Area, the United Kingdom, the United States or other countries involved in a relationship or transaction. Some countries may not provide a level of data protection recognised as adequate under Swiss law.
Where required, we rely on an adequacy decision, approved standard contractual clauses adapted for Swiss law, another legally recognised safeguard or a statutory exception. We may also apply technical and organisational measures such as access restrictions, encryption and data minimisation. Information about relevant transfer safeguards may be requested through the contact details above, subject to legal and confidentiality restrictions.
8. How long we retain personal data
We retain personal data only for as long as necessary for the stated purpose, applicable legal duties, legitimate documentation needs and the establishment, exercise or defence of claims. Our ordinary retention periods are:
Data category | Ordinary retention period |
Contact enquiries and correspondence | Up to 24 months after the last substantive contact, unless the matter becomes contractual, legally relevant or is closed sooner. |
Business, due-diligence and transaction records | For the relationship or transaction and thereafter for the period needed for legal, compliance and claims purposes; ordinarily no longer than 10 years unless a longer period is required. |
Accounting and statutory business records | Up to 10 years where Swiss law requires retention. |
Ordinary server and security logs | Up to 12 months, unless a security incident, investigation or legal obligation requires longer retention. |
Rejected spam and honeypot information | Up to 90 days, unless longer retention is necessary to address persistent abuse. |
Backups | Until overwritten or deleted under the documented backup cycle; data are not restored for ordinary use after the primary retention period except where technically or legally necessary. |
We may anonymise data instead of deleting it. Retention may be shortened where data are no longer needed or extended where required by law, a preservation duty, an investigation, a dispute or a documented legitimate need.
9. Data security
We use proportionate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure, access or misuse. Measures may include encrypted transmission, access controls, authentication, backups, system updates, anti-spam controls and service-provider commitments. No internet transmission or storage system can be guaranteed to be completely secure.
10. Your rights
Subject to applicable law and any permitted limitations, you may request information about whether and how we process your personal data; access to your personal data; correction of inaccurate data; deletion or destruction of data; restriction of processing; delivery or transfer of data in a commonly used electronic format where data portability applies; and review of an automated individual decision, if one were used. Where processing is based on consent, you may withdraw that consent for the future. Where the GDPR applies, you may also object to processing based on legitimate interests and exercise the additional rights provided by that law.
To exercise a right, use the contact details in section 1 and provide enough information to identify the relevant processing. We may verify your identity and may restrict or refuse a request where permitted by law or necessary to protect third-party rights. You may also raise a concern with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, the competent data protection authority in your country.
11. Automated decisions and profiling
The website does not make automated individual decisions with legal or similarly significant effects and does not create behavioural or investment profiles of website visitors.
12. Third-party websites
The website may link to third-party websites. Their operators determine their own processing activities. This Privacy Policy does not apply to those websites, and you should review their privacy information before providing personal data.
13. Changes to this Privacy Policy
We may update this Privacy Policy when our processing, systems, services or legal obligations change. The version published on the website applies from the “Last updated” date shown above. Material changes will be highlighted where appropriate.