Privacy Policy
Version dated 29 May 2026
At Stone Bridge Capital (MFO) Ltd (referred to in this Policy as "we", "us", "our" or "SBC"), we are committed to protecting the privacy of information and personal data entrusted to us. We handle personal information in an open and transparent manner, in compliance with the European General Data Protection Regulation (GDPR) and applicable Cypriot data protection law.
This Privacy Policy applies to personal data processed by Stone Bridge Capital (MFO) Ltd, registered in the Republic of Cyprus under registration number HE371697, with registered office at Limassol, Eptanisou 28. It explains what personal data we collect, why and how we use it, to whom we disclose it, how we protect it, and what rights you have in relation to that data.
1. Scope of this Policy
This Policy describes how we collect, handle, store and protect personal information about you when:
-
we provide services to you or to our clients;
-
you use our website at www.sbc.cy ("our Website");
-
we perform any other activities that form part of the operation of our business.
We may refer to information that identifies you, may identify you, or otherwise relates to you as "personal data" or "personal information". We may also collectively refer to collecting, handling, using, protecting and storing your personal information as "processing" such personal information.
2. What information we collect
In the course of providing services — or discussing possible services as part of a prospective client engagement — we may collect or obtain personal data about you. We also collect personal data when you use our Website.
We may collect data because you provide it to us (for example through a contact form on our Website or through our client onboarding procedures), because other persons provide it to us (such as your adviser or a service provider), or because it is publicly available.
We may also collect personal data because we observe or infer it from how you interact with our Website — for example through cookies and similar tracking technologies. See our Cookie Policy for further detail.
The personal data we collect may include, without limitation:
-
your name, age, date of birth, identification document details;
-
your email address, postal address, country of residence;
-
your family circumstances (for example, marital status, number of dependants);
-
your employment, business activity and education details;
-
financial and tax-related information (for example, source of wealth, tax residency, asset information);
-
your IP address, browser type and language, and access times when using the Website;
-
any other information you provide to us in correspondence or in the course of our engagement.
In some circumstances, the personal data we collect may include sensitive or special categories of data — such as health information or ethnic origin — where this is required by the nature of the services or by legal obligations applicable to us. Where the processing of sensitive personal data requires it, we will obtain your explicit consent.
Where we have no direct contractual relationship with you but obtain personal data about you from our client, we take reasonable steps to ensure that the client has complied with applicable data protection requirements, including providing you with relevant notices and obtaining any necessary consents.
Our Website and services are not designed for, or intentionally targeted at, children. It is not our policy to intentionally collect or store information about individuals under the age of fourteen.
3. How we use your personal data
We process personal data only where the law permits us to do so. The most common situations are as follows.
A. Performance of a contract
Where we need to perform a contract entered into with you, or to take steps prior to entering into such a contract. We use your personal data to provide the agreed services and in the course of related correspondence — with you, with trusted third parties engaged on a mandate-by-mandate basis (such as lawyers, accountants, banking specialists), or with competent authorities. We also use personal data to conduct client due diligence checks. If you do not provide the personal data we request, we may be unable to offer or continue offering our services.
B. Compliance with legal obligations
We are required to comply with various legal and regulatory obligations and applicable industry standards. This may include carrying out identity verification and "know-your-client" procedures, conducting anti-money laundering checks, complying with tax reporting and disclosure obligations, and providing information to public bodies or law enforcement agencies when required by law.
C. Legitimate interests
In some cases, we process personal data to pursue our legitimate business interests or those of third parties, provided your interests and fundamental rights do not override those interests. This includes:
-
maintaining our accounts and records;
-
enhancing the security of our network and information systems;
-
identifying, preventing and investigating fraud and other unlawful activities;
-
managing our infrastructure, business operations and internal policies and procedures;
-
financial accounting, invoicing and risk analysis;
-
improving our services and the operation of our Website;
-
defending, investigating or prosecuting legal claims;
-
business development and obtaining professional advice from our own advisers.
D. Consent
Where we wish to provide marketing communications to you regarding our services that we think might be of interest to you, we will only do so on the basis of your consent. You may withdraw your consent at any time by writing to solutions@sbc.cy or by using the unsubscribe function in any marketing communication we send.
4. Legal grounds for processing sensitive personal data
Where we process sensitive personal data, we do so on one of the following grounds: (a) you have given your explicit consent; (b) the processing is necessary to carry out our obligations under employment, social security or social protection law; (c) the processing is necessary for the establishment, exercise or defence of legal claims; or (d) you have made the data manifestly public.
5. To whom we disclose your personal data
In connection with one or more of the purposes outlined in this Policy, we may disclose your personal data to:
-
trusted third parties engaged on a mandate-by-mandate basis to support the services — including lawyers, tax advisers, accountants, auditors, corporate service providers and banking specialists;
-
competent authorities (including courts and authorities regulating us);
-
your employer, your advisers, or your designated representatives;
-
credit reference agencies and similar organisations that help us make business decisions and mitigate the risk of fraud and misconduct;
-
third parties involved in a potential or actual sale of all or part of our business or assets;
-
other third parties that reasonably require access to personal data relating to you for one or more of the purposes outlined in this Policy.
Some of the recipients of your personal data may be based in countries outside the European Economic Area. Where this is the case, we put in place adequate safeguards in accordance with applicable law to ensure that your personal data continues to receive an equivalent level of protection. In cases where no adequacy mechanism is in place, we may request your specific consent before such transfer.
We may share non-personal, de-identified and aggregated information for research and statistical purposes.
6. How we protect your personal data
We use a range of physical, electronic and managerial measures to keep your personal data secure, accurate and up to date. These measures include:
-
staff training on data protection obligations;
-
administrative and technical controls restricting access to personal data on a "need-to-know" basis;
-
technological security measures including firewalls, encryption and anti-virus software;
-
physical security measures protecting our premises and equipment.
7. How long we keep your personal data
We retain your personal data for the longest of the following periods:
-
as long as is necessary for the relevant activity or services;
-
any retention period required by law;
-
the end of the period in which litigation or investigations might arise in respect of the services;
-
any retention period set out in our internal data retention policy.
8. Your rights
Under the GDPR and applicable Cypriot data protection law, you have a number of rights in relation to your personal data. You may:
A. Access
Request a copy of the personal data we hold about you and verify that we are processing it lawfully.
B. Rectification
Request that any incomplete or inaccurate data we hold about you be completed or corrected.
C. Erasure
Request the deletion of your personal data where there is no good reason for us to continue processing it (the "right to be forgotten").
D. Objection
Object to the processing of your personal data where we rely on a legitimate interest, or where we process your data for direct marketing purposes. If you object to processing for direct marketing purposes, we will stop such processing.
E. Restriction
Request that we suspend the processing of your personal data — for example, where the data is not accurate, where it has been used unlawfully but you do not want it deleted, or where you have objected and we are verifying our grounds for processing.
F. Portability
Request to receive a copy of your personal data in a structured, commonly used format, and to transfer that data to another organisation.
G. Withdrawal of consent
Withdraw consent at any time where we rely on consent as the legal basis for processing. The lawfulness of processing prior to withdrawal is not affected.
To exercise any of these rights, or for any other question about our use of your personal data, please write to solutions@sbc.cy or by post to Stone Bridge Capital (MFO) Ltd, Eptanisou 28, Nicolaou & Zavos Center, Office 402, Agios Nicolaos, 3100 Limassol, Cyprus.
9. Right to complain
If you are not satisfied with the way we have handled your personal data or any privacy query, you have the right to complain to the Office of the Commissioner for Personal Data Protection in Cyprus. We are happy to provide direction to that office on request.
10. Changes to this Policy
We may modify or update this Policy from time to time. When we do, we will amend the version date at the top of the document. We encourage you to review this Policy periodically to remain informed about how we protect your personal data.
11. Contact
If you have any questions about this Privacy Policy or about how we process personal data, please write to us at:
Stone Bridge Capital (MFO) Ltd
Limassol, Eptanisou 28
Email: solutions@sbc.cy
