Skip to content
Legal

PRIVACYPOLICY.

How Lengdon collects, uses, and protects your personal data. Last updated 26 August 2026.

Who we are

Lengdon ("we", "us") is operated by Venture Tech LLC, a company under incorporation in the DIFC FinTech Hive, Dubai, United Arab Emirates. We operate closing infrastructure for private capital transactions. We process personal data as a data controller in the course of operating the Lengdon platform. For data protection enquiries: privacy@lengdon.com

What data we collect

We collect and process the following categories of personal data: Identity data: Full name, as provided at account creation and NDA confirmation. Contact data: Email address and, where provided, a telephone number. Transaction data: Actions taken within a transaction room — confirmations, document accesses, signing events, payment confirmations. This data forms part of the append-only audit record. Authentication data: Login events, MFA events, session data. We do not store passwords in plain text. Technical data: IP address, device type, browser type, and access timestamps. Collected for security and fraud prevention purposes. We do not collect payment card data. We do not handle, process, or store financial instruments.

How we use your data

We use personal data for the following purposes: To operate the Lengdon platform: Providing the transaction room infrastructure, enforcing the six-gate closing sequence, and generating the append-only audit record. To comply with legal obligations: Maintaining records as required under applicable law, including data protection law, anti-money laundering regulations, and contract law. To protect the security of the platform: Detecting and preventing fraud, unauthorised access, and abuse. To communicate with you: Responding to enquiries, sending transactional notifications (gate status, signatures required), and, where you have consented, sending product updates. We do not use personal data for advertising. We do not sell personal data to third parties.

Legal basis for processing

We process personal data on the following legal bases: Contract performance (Article 6(1)(b) UK GDPR): Processing necessary to provide the Lengdon service you have contracted for. Legitimate interests (Article 6(1)(f) UK GDPR): Security monitoring, fraud prevention, and platform integrity. We have assessed that these interests are not overridden by your rights. Legal obligation (Article 6(1)(c) UK GDPR): Compliance with applicable laws and regulations. Consent (Article 6(1)(a) UK GDPR): Where you have opted in to receive product communications. Consent can be withdrawn at any time.

The append-only audit record

A core feature of Lengdon is the append-only audit record — a tamper-evident log of every action taken in a transaction room. This record contains personal data (names, roles, timestamps, actions). It cannot be deleted or modified after creation — this is a fundamental design property, not a limitation. Both parties to a transaction receive a copy of the complete audit record at close. This is a contractual commitment, not optional behaviour. Because the audit record is append-only, we cannot fulfil requests to delete personal data contained within it where that data is part of the legally required closing record. We will inform you of this limitation before you enter a transaction room. We retain audit records for a minimum of seven years following close, and for as long as reasonably required by applicable law.

Your rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights: Right of access: You may request a copy of the personal data we hold about you. Right to rectification: You may request correction of inaccurate personal data. Right to erasure: You may request deletion of personal data where we have no legal basis for continued processing. Note: this right does not apply to data contained in the append-only audit record (see above). Right to restrict processing: You may request that we limit our use of your data in certain circumstances. Right to data portability: You may request a machine-readable copy of data you have provided to us. Right to object: You may object to processing based on legitimate interests. To exercise any of these rights, contact: privacy@lengdon.com You also have the right to lodge a complaint with the Information Commissioner's Office (ICO): ico.org.uk

Data transfers

Lengdon operates data residency selection at the transaction room level. When you create a room, you select the jurisdiction (UK, EU, or US) and data for that room is stored accordingly. Account-level data (your profile, authentication records) is stored in the UK. Where we transfer data outside the UK or EEA, we ensure that appropriate safeguards are in place (Standard Contractual Clauses or adequacy decisions).

Cookies

We use strictly necessary cookies to operate the Lengdon platform (session management, authentication state). We do not use advertising cookies, tracking cookies, or third-party analytics cookies. You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies will prevent you from using the platform.

Changes to this policy

We will notify registered users of material changes to this Privacy Policy at least 30 days before they take effect. The current version of this policy is always available at lengdon.com/legal/privacy. This policy was last updated: 26 August 2026.