
Privacy Policy
1. Controller
The PE CFO Circle is operated by:
Skill Equity GmbH
Opernplatz 14
60313 Frankfurt am Main
Germany
Email: contact@skillequitypartners.com
Phone: +49 69 153 201 400
Skill Equity GmbH is the controller responsible for the processing of personal data described in this
Privacy Policy.
2. Visiting Our Website
When you visit this website, certain technical information may be processed automatically. This may include:
• IP address;
• date and time of access;
• page or file requested;
• referrer URL;
• browser type and version;
• operating system;
• device information;
• information concerning successful or unsuccessful page delivery.
We process this information to provide the website, maintain its stability and security, identify technical errors and protect the website against misuse.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and technically functional operation of the website.
Technical and security information is retained only for as long as required for website operation, error analysis, security and the investigation of potential misuse. The precise technical retention periods may be determined by the website platform and its security configuration.
3. Website Hosting and Wix Platform
We use Wix to host and operate this website, including:
• website hosting;
• forms and form submissions;
• the protected member area;
• member accounts and authentication;
• event-registration functions;
• website security and related technical services.
The provider is:
Wix.com Ltd.
5 Yunitsman Street
Tel Aviv
Israel
Depending on the website function concerned, Wix may process technical usage information, form submissions, contact information, member-account information and event-registration data on our behalf.
Wix and its service providers may process personal data in Israel, the European Union and other countries. Where data is transferred outside the European Economic Area, the transfer is based on an applicable adequacy decision or appropriate safeguards where required.
Wix provides a binding Data Processing Agreement governing the processing it performs for website operators. Its current privacy information identifies 5 Yunitsman Street, Tel Aviv, as its contact address.
Legal bases: Article 6(1)(b) GDPR where processing is necessary to provide a requested membership, account or event function, and Article 6(1)(f) GDPR for the secure and effective operation of the website.
4. Cookies and Similar Technologies
This website uses cookies and similar technologies.
Some technologies are strictly necessary to:
• display and operate the website;
• maintain website and account security;
• enable login and authentication;
• provide the protected member area;
• remember necessary website settings;
• provide functions expressly requested by the user.
Technologies that are strictly necessary for a digital service expressly requested by the user may be used without consent under § 25(2) TDDDG. Related personal-data processing is based on Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the relevant function.
Optional technologies, including analytics or marketing technologies where used, are activated only after the user has provided consent. The legal bases are § 25(1) TDDDG and Article 6(1)(a) GDPR.
Users can grant, refuse or withdraw consent through the website’s cookie settings. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Further details concerning the cookies and technologies currently used, including their provider, purpose and duration, are available through the cookie-management tool.
5. Contact and Membership Enquiries
When you contact us through the website or by email, we process the information you provide.
Depending on the form or enquiry concerned, this may include:
• first and last name;
• business email address;
• telephone number;
• current role;
• company name;
• industry or sector;
• company revenue;
• company shareholder or ownership information;
• reason for contacting us;
• membership interest;
• message content;
• related correspondence.
Company revenue and shareholder information are used to understand the professional and ownership context of the company and assess its relevance to the PE CFO Circle.
We use the information to:
• review and respond to enquiries;
• assess expressions of interest in membership;
• understand the applicant’s professional background and company context;
• communicate concerning possible membership;
• answer event-related questions;
• process speaking or contribution enquiries;
• administer the relationship arising from the request.
Submitting an enquiry does not automatically result in membership. Membership enquiries are reviewed personally by authorised representatives of Skill Equity GmbH.
Legal bases: Article 6(1)(b) GDPR where processing relates to requested membership, event participation or another requested relationship. Article 6(1)(f) GDPR also applies to our legitimate interests in reviewing the relevance and professional fit of applicants and efficiently administering business enquiries.
Form submissions and related correspondence are generally retained for 12 months after the enquiry has been completed or the last relevant communication has taken place. They may be retained for longer where required by law or necessary for the establishment, exercise or defence of legal claims.
Unsuccessful membership enquiries are generally deleted 12 months after the final decision or last communication.
6. Recommendations and Invitations
Members or other professional contacts may recommend individuals who may be relevant to the PE CFO Circle.
In this context, we may receive:
• name;
• current role;
• company;
• professional contact details;
• information about the person’s professional background;
• the reason for the recommendation.
We use this information to assess whether the person may be relevant to the Circle and, where appropriate, to contact them concerning possible participation or membership.
Legal basis: Article 6(1)(f) GDPR. Our legitimate interests are the careful development of a relevant professional community and the consideration of suitable recommendations.
Where we contact an individual based on a recommendation, we will provide the information required under applicable data-protection law.
Recommendation information is generally deleted within 12 months where no membership or ongoing relationship is established.
7. Membership and Member Accounts
The website includes a protected member area.
Where membership is confirmed and a member account is created, we may process:
• name;
• email address;
• login and authentication information;
• current role and company;
• company context provided during the application process;
• membership status;
• account and access status;
• event activity associated with the account;
• communications relating to membership;
• technical security and login information.
We process this information to:
• establish and administer membership;
• provide access to restricted content;
• authenticate members;
• administer accounts and permissions;
• maintain the security of the member area;
• prevent unauthorised account use;
• communicate with members concerning the Circle and its events.
Legal basis: Article 6(1)(b) GDPR for the establishment and administration of membership and Article 6(1)(f) GDPR for account security, access management and the prevention of misuse.
Member-account information is retained while the membership or account remains active.
Following account closure or the end of membership, account and membership information is generally retained for up to 12 months and is then deleted or anonymised, unless continued retention is required by law or necessary for legal claims.
Members may request the closure of their account by contacting us.
8. Event Requests and Registrations
Members may request or register for participation in events through the website.
Depending on the event and registration process, we may process:
• name;
• email address;
• company and current role;
• the event concerned;
• registration or request date;
• attendance and confirmation status;
• waiting-list information;
• cancellation information;
• correspondence concerning the event;
• information voluntarily provided by the participant.
We use this information to:
• review event requests;
• manage event capacity;
• confirm or decline participation;
• maintain waiting lists;
• communicate practical event information;
• administer attendance;
• respond to cancellations;
• conduct necessary event follow-up.
Submitting an event request does not necessarily guarantee participation. Event requests and confirmations are reviewed and administered personally.
Legal basis: Article 6(1)(b) GDPR where processing is necessary to administer requested participation and Article 6(1)(f) GDPR for effective event planning, capacity management and participant communication.
Event-registration and attendance information is generally retained for 12 months following the relevant event. Information may be retained for longer where required for accounting, legal, security or documentation purposes.
9. Automated Website Workflows and Email Delivery via Twilio SendGrid
We use Twilio SendGrid, a service of the Twilio group, to support automated workflows between the website and Skill Equity GmbH.
SendGrid is used for automated processes including:
• notifying Skill Equity GmbH when a membership enquiry is submitted;
• notifying Skill Equity GmbH when an event-registration request is submitted;
• notifying Skill Equity GmbH of general contact or speaking enquiries;
• sending automated acknowledgement emails;
• sending membership and account invitations;
• sending password-reset emails;
• sending event-registration confirmations;
• sending event reminders and updates;
• sending other service-related communications.
When a form is submitted, the relevant information is transmitted through the automated workflow so
that an email notification can be generated and delivered.
Depending on the workflow concerned, SendGrid may process:
• the information entered into a website form;
• name and email address;
• telephone number;
• current role and company;
• company revenue and shareholder information;
• selected event or type of request;
• message content;
• sender and recipient email addresses;
• subject line and email content;
• date and time of transmission;
• technical delivery information;
• delivery status, including whether an email was processed, delivered, rejected or returned.
SendGrid acts as a technical transmission and email-delivery provider. It does not determine whether an individual becomes a member, whether an application is accepted or whether an event place is confirmed. These decisions are made personally by authorised representatives of Skill Equity GmbH.
Legal bases: Article 6(1)(b) GDPR where the automated process is necessary to administer membership, an event request, a member account or another requested service. Article 6(1)(f) GDPR also applies to our legitimate interest in the secure, reliable and efficient receipt and administration of website submissions and communications.
Twilio group companies and subprocessors may process personal data inside and outside the European Economic Area. Where cross-border transfers require additional safeguards, Twilio’s contractual framework provides for recognised transfer mechanisms, including Standard Contractual Clauses. Twilio’s published SendGrid documentation explains that EU data residency is available only where the account and relevant subusers have been specifically configured for it.
According to Twilio’s currently published retention schedule for SendGrid:
• email message bodies are normally retained only as long as needed for delivery, for up to 72 hours;
• random content samples used for security and troubleshooting may be retained for seven days;
• most recipient, message-activity and metadata information is retained for approximately 30 days, with
deletion completed within up to 37 days;
• certain email-event information may be retained for up to one year for security, fraud prevention, abuse
detection and network protection.
Copies of form notifications received and retained by Skill Equity GmbH are subject to the purpose-
specific twelve-month periods described in this Privacy Policy.
10. Photographs and Recordings at Events
Photographs or recordings may be made at selected PE CFO Circle events.
Selected photographs may be published:
• on the PE CFO Circle website;
• on LinkedIn;
• in communications relating to the PE CFO Circle.
Participants will be informed before or during the relevant event where photographs or recordings are planned.
Depending on the nature of the photograph, the circumstances of the event and the intended publication, processing may be based on:
• consent under Article 6(1)(a) GDPR; or
• our legitimate interests under Article 6(1)(f) GDPR in documenting events and communicating the
activities of the PE CFO Circle.
Where consent is relied upon, it may be withdrawn at any time with effect for the future.
Where processing is based on legitimate interests, individuals may object for reasons arising from their particular situation.
Close-up portraits or prominently featured photographs intended for external promotional use should be handled through appropriate event-specific information and, where required, consent.
When a photograph is published on LinkedIn, LinkedIn may process the information under its own responsibility and in accordance with its own privacy terms.
Photographs are retained for as long as they remain relevant for the stated purpose. They will be removed where consent is validly withdrawn, a justified objection applies or continued publication is no longer necessary, subject to any overriding legal grounds.
11. Recipients of Personal Data
Personal data may be accessed by authorised representatives and employees of Skill Equity GmbH where necessary for the purposes described in this Privacy Policy.
It may also be disclosed to service providers and other recipients, including:
• Wix as website and platform provider;
• Twilio SendGrid as workflow and email-delivery provider;
• IT and technical-support providers;
• email and communications providers;
• event venues and event-service providers;
• photographers or media providers where applicable;
• LinkedIn where event photographs or related content are published;
• professional advisers;
• public authorities where disclosure is required by law.
Service providers acting as processors are required to process personal data in accordance with applicable contractual instructions and data-protection requirements.
Personal data is not provided to investors, other members or external organisations merely because an individual submitted a membership or event enquiry.
12. International Data Transfers
Some service providers may process personal data outside the European Economic Area.
Where the European Commission has issued an adequacy decision for the relevant country, transfers may be based on that decision.
In other cases, appropriate safeguards are used where required. These may include:
• the European Commission’s Standard Contractual Clauses;
• approved Binding Corporate Rules where applicable;
• supplementary technical and organisational safeguards.
Information concerning safeguards applicable to a particular transfer may be requested using the
contact details above.
13. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected.
Unless a more specific period is stated elsewhere in this Privacy Policy, the following periods generally apply:
• website contact and membership form submissions: 12 months after completion of the enquiry or last
relevant communication;
• unsuccessful membership enquiries: 12 months after the final decision or last communication;
• recommendation information where no relationship is established: 12 months;
• event registrations and attendance records: 12 months following the relevant event;
• active member accounts: for the duration of the active membership;
• closed member accounts: up to 12 months after closure;
• internal copies of automated email notifications: in accordance with the corresponding enquiry,
membership or event retention period.
Information may be retained for longer where:
• statutory retention obligations apply;
• continued retention is required for security purposes;
• legal claims are pending or reasonably anticipated;
• the individual has consented to longer processing for a specific purpose.
Provider-managed technical information may be deleted according to the provider’s own technical
retention schedule.
14. Data Security
We use appropriate technical and organisational measures designed to protect personal data against:
• accidental or unlawful loss;
• destruction;
• alteration;
• unauthorised disclosure;
• unauthorised access;
• misuse.
Website communications are encrypted using SSL/TLS technology.
Access to membership, enquiry and event information is restricted to authorised persons who require access for the relevant purpose.
15. Your Data-Protection Rights
Subject to the applicable legal requirements, you may have the right to:
• obtain information about personal data processed concerning you;
• receive a copy of your personal data;
• request the correction of inaccurate or incomplete information;
• request deletion;
• request restriction of processing;
• receive certain information in a structured, commonly used and machine-readable format;
• object to processing based on legitimate interests;
• withdraw consent with effect for the future;
• lodge a complaint with a competent supervisory authority.
Where processing is based on Article 6(1)(f) GDPR, you may object for reasons arising from your particular situation.
Where processing is based on consent, withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Requests may be directed to:
Skill Equity GmbH
Email: contact@skillequitypartners.com
You also have the right to lodge a complaint with a competent supervisory authority.
The supervisory authority normally responsible for a controller based in Frankfurt am Main is:
The Hessian Commissioner for Data Protection and Freedom of Information
Wilhelmstraße 7
65185 Wiesbaden
Germany
The authority has used this address since 16 March 2026.
16. Mandatory Information
Fields marked as mandatory are required to process the relevant enquiry, assess a membership request, administer event participation or provide a member account.
If mandatory information is not provided, we may be unable to:
• process the enquiry;
• assess the membership request;
• administer an event request;
• create or maintain a member account;
• provide the requested website function.
Optional information may be omitted.
17. Automated Decision-Making
We do not use solely automated decision-making, including profiling, that produces legal effects or similarly significant effects.
Membership enquiries and event requests are reviewed personally.
Twilio SendGrid automates the technical transmission of information and emails but does not make decisions concerning membership, event participation or access to the PE CFO Circle.
18. Amendments to This Privacy Policy
We may update this Privacy Policy where necessary to reflect:
• changes to the website;
• changes to membership or event processes;
• new or amended website functions;
• changes to the service providers used;
• changes to applicable legal requirements.
The current version is published on this page.
​
​
Last updated: 28 July 2026
