PRIVACY

Privacy notice.

TF DebtInvest aims to process personal data transparently and proportionately. This notice describes how personal data may be processed when you use this website or communicate with us.

Last updated: September 2026

01

Controller and contact

CapIQ Payments EES OÜ, trading as TF DebtInvest, is the controller of personal data processed through this website and direct business communications where the company determines the purposes and means of processing.

Questions about personal data and requests to exercise data-protection rights may be sent to contact@tfdebtinvest.com.

02

Personal data we may process

  • Name, role, company and professional contact information.
  • Email address, telephone number and the content of messages you send us.
  • Information submitted through contact forms or other business communications.
  • Technical information such as language preference, timestamps and limited server logs needed for security and operation.
  • Business-related information required for due diligence, counterparty checks or a potential transaction where a lawful basis exists.
03

Purposes and legal bases

Personal data is processed only for defined purposes and on a lawful basis under applicable data-protection law.

  • To respond to enquiries and manage business communications.
  • To assess or prepare a possible contract or transaction.
  • To comply with legal obligations, for example documentation, AML/KYC or other compliance requirements where applicable.
  • For legitimate interests such as IT security, documenting business contacts and protecting legal claims, where those interests are not overridden by the rights of the individual.
  • Where processing relies on consent, that consent may be withdrawn for future processing.
04

Recipients and processors

Personal data may be made available to service providers that support hosting, IT operations, email, legal, accounting, compliance or other professional services, but only to the extent necessary.

Where a provider processes personal data on our behalf, the relationship should be governed in a manner that provides appropriate protection for the data.

05

Transfers outside the EU/EEA

Where personal data needs to be transferred to a country outside the EU/EEA, an authorised transfer mechanism and appropriate safeguards should be used where required by applicable law.

The service providers actually used should be documented internally and this notice updated if the technical setup of the website changes.

06

Retention

Personal data is not retained for longer than necessary for the relevant purpose. Contact enquiries may be retained while there is a relevant business need, an active matter or a need to document communications.

Data that must be retained by law may be kept for longer. When data is no longer required it should be deleted or appropriately anonymised.

07

Your rights

Depending on the circumstances and legal basis, you may have rights to information, access, rectification, erasure, restriction, objection and data portability.

Where processing is based on consent, you may withdraw consent without affecting the lawfulness of processing carried out before withdrawal.

  • Right to information and access.
  • Right to rectification of inaccurate data.
  • Right to erasure in certain circumstances.
  • Right to restriction and objection in certain circumstances.
  • Right to data portability where the conditions are met.
  • Right to lodge a complaint with the competent data-protection authority.
08

Security and automated decisions

We aim to use proportionate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure.

The website contact forms are not themselves used to make decisions based solely on automated processing that produce legal or similarly significant effects for a visitor.

NEXT STEP

Have a portfolio, servicing matter or potential transaction to discuss?