Introduction
This Privacy Policy explains how MB Lady Christina ("MBLC", "we", "us", or "our") collects, uses, stores, and protects personal data in connection with your visits to www.mblc.lt, use of our partner portal, app-based or web-based account features, survey and application forms, any communication you send us, or any services you request.
MBLC operates strictly as an On-Demand Hedge Fund Materials Provider and a Request-Only Hedge Fund Consultant. Our business model is built exclusively on explicit mutual agreement. We are not a marketing firm, we do not conduct mass marketing campaigns, we do not solicit clients or investors, and we do not provide investment advice, brokerage, asset management, or any regulated financial services. All services are provided solely within a narrow, specialized niche of technical and operational consulting, and materials support for institutional clients and professional counterparties who have specifically granted permission for such engagement.
For the purposes of the General Data Protection Regulation (GDPR), MBLC is the data controller for personal data that we determine the purpose and means of processing for. We are committed to transparent processing in line with the GDPR and other applicable laws in the European Union and the Republic of Lithuania.
Scope of This Policy
This Policy applies to any personal data that MBLC collects, processes, or otherwise controls, including data obtained through our website, partner portal, account authentication workflows, dashboards, application and survey forms, uploaded documents, email communications, contact forms, or any other interaction where you voluntarily provide information to us.
It covers all individuals who interact with MBLC, whether as website visitors, enquirers, or institutional clients. The Policy does not apply to personal data processed by third-party websites or services linked from our site, nor to any data collected by our institutional clients in their own operations.
Processing of personal data is carried out only where we have a lawful basis, including legitimate interest, contractual necessity, steps taken at your request before entering into an engagement, legal obligation, or consent where required.
Personal Data We Collect
We collect and process only the minimum personal data that is strictly necessary to respond to your explicit requests and to deliver the requested services. We do not collect data proactively or for any speculative purposes.
The categories of personal data we may collect include:
- Your full name
- Email address
- Company or organisation name
- Job title or professional role
- Business contact details (telephone, postal address)
- Content of communications or enquiries submitted through our forms or email
- Account and authentication data, including email address, user ID, account status, registration metadata, password reset events, login timestamps, and login IP records
- Partner portal profile and access-control data, including display name, company name, role, permissions, onboarding status, portal settings, preferences, and security/session records
- Application and survey data that you submit, including professional background, business contact information, fund or strategy information, assets under management, performance and risk metrics, operational details, regulatory information, and other due-diligence materials you choose to provide
- Files or documents uploaded through our services, such as factsheets, presentations, contracts, return files, or other business documents supplied for review
- Portal records generated when you use available features, such as contacts, notes, tasks, links, calendar records, workbook records, document access records, and user preferences
- Technical website, app, and portal usage data, including IP address, browser type and version, operating system, referral source, pages visited, timestamps, user agent, device or session identifiers, error logs, and security events
- Local device/browser data used for functionality, such as theme preference and session timing values stored in local storage
We may receive limited professional contact information from authorised institutional representatives, introducers, or counterparties where they ask us to contact or invite you in a professional capacity. We ask that such parties provide only business contact data that they are lawfully permitted to share.
We do not intentionally collect special category data as defined under GDPR Article 9, such as health, biometric, religious, political, or trade-union information. Please do not provide such information unless we specifically request it and a valid legal basis applies. If special category data is submitted unintentionally and is not required, we may delete it.
You may visit and browse our website without actively submitting contact information. However, like most websites and apps, we may process limited technical data such as IP address, device/browser information, and timestamps for security, fraud prevention, diagnostics, and functionality. No cookies or tracking technologies are used for marketing or profiling purposes.
How We Use Personal Data
We use personal data solely for the following legitimate, narrowly defined purposes:
- To respond to your enquiries and process requests you have explicitly submitted
- To provide the specific information, materials, or consulting services you have requested
- To maintain professional, request-driven communication with existing institutional clients
- To create, authenticate, secure, administer, and support partner portal or app accounts
- To provide role-based access to requested materials, dashboards, files, documents, and portal features
- To review application and survey submissions from professional counterparties and digital asset managers
- To manage uploaded documents, files, due-diligence materials, portal records, contact records, calendar records, workbook records, and account preferences
- To keep accurate records of business communications for legal and compliance purposes
- To ensure the security, functionality, and performance of our website
- To comply with legal and regulatory obligations applicable to MBLC
- To generate anonymised and aggregated website statistics and maintain cybersecurity and system integrity
We do not use personal data for any other purpose, including advertising, behavioural profiling, automated investment decision-making, or any commercial activity outside the strict scope of your explicit request. Our legal bases under GDPR include Article 6(1)(a), 6(1)(b), 6(1)(c), and 6(1)(f), depending on the specific processing activity.
In practical terms, account administration and requested services are processed where necessary for contractual or pre-contractual steps; security logging, fraud prevention, operational support, and limited business communications rely on legitimate interests; legal and accounting records rely on legal obligations; optional consent-based processing is used only where consent is required and may be withdrawn at any time.
No Marketing or Solicitation
MBLC may engage in selective, professional outreach to institutional counterparties and industry partners regarding potential collaborations, partnerships, or service offerings. Such communications are strictly business-to-business in nature and are not directed at retail investors or the general public and should not be considered as Marketing emails.
To ensure absolute clarity and legal certainty, we expressly and irrevocably state the following:
No Investment Advice Disclaimer
MBLC does not provide, and does not purport to provide, any investment advice, financial advice, brokerage services, asset management, portfolio management, or any regulated financial services. Our role is strictly limited to the provision of specialized technical, operational, and materials support within a narrow niche scope for institutional clients who have specifically requested such services.
Any information, documents, software, or materials we supply are of a purely technical or operational nature and must not be interpreted, relied upon, or used as investment advice, a recommendation, an endorsement, or a solicitation to buy, sell, or hold any investment, security, or financial instrument.
Risk Disclosure and Client Responsibility
All institutional clients and recipients of our services remain fully and solely responsible for their own due diligence, independent evaluation of any third-party partner firms, and all investment, operational, or strategic decisions.
MBLC does not verify, guarantee, endorse, assess the suitability of, or accept any liability for any third-party partner firms, materials, software, or services. Any engagement with third parties is undertaken solely at the client's own risk and discretion.
MBLC expressly disclaims any and all liability for losses, damages, or consequences arising from the use of any information, materials, or services provided by us or any third parties.
Disclosure of Personal Data
We do not sell, rent, or otherwise monetize personal data under any circumstances.
Personal data may be shared only when strictly necessary and only with the following categories of recipients, each bound by contractual obligations of confidentiality and data protection where required:
- Technical service providers, including website hosting, secure email delivery systems, authentication, database, file-storage, and infrastructure providers such as Supabase where used to operate the portal, app, database, authentication, and storage services
- Professional advisers (legal counsel or compliance consultants) where required for legitimate business or regulatory purposes
- Public authorities or regulators when required by applicable law or court order
- Professional data storage platforms and secure systems used to manage professional partnerships and business client data.
Where a service provider processes personal data on our behalf, we treat that provider as a processor under GDPR Article 28 and require appropriate confidentiality, security, and data-processing terms. We do not sell personal data and do not share personal data with advertising networks, data brokers, or third parties for cross-site or cross-app behavioural tracking.
International Data Transfers
Our service providers may store or process personal data in the European Union or in other jurisdictions that have been deemed to provide an adequate level of protection under GDPR, or where appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, transfer impact assessments where required, or other valid transfer mechanisms.
We take all reasonable steps to ensure that any international transfer of personal data is carried out in full compliance with applicable data protection laws and that your rights are adequately protected.
Data Security
We implement and maintain appropriate technical and organisational security measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, damage, or disclosure. These measures include, but are not limited to, access controls, encrypted transport, database security controls, authentication safeguards, provider-level security controls, audit review, and confidentiality obligations.
Access to personal data is strictly limited to authorised personnel who require it for legitimate business purposes. Passwords are handled through our authentication provider and are not stored by MBLC in plain text. No internet-based service can be guaranteed to be completely secure, but we take reasonable and proportionate steps to reduce risk and respond to suspected incidents.
Data Retention
We retain personal data only for as long as is necessary to fulfil the purposes for which it was collected, to maintain accurate business records, to protect our services, or to comply with legal and regulatory obligations, including tax, accounting, anti-money laundering, dispute-resolution, and compliance requirements where applicable.
Retention is determined by the nature of the data and the reason it was collected:
- Account, authentication, and portal profile data is retained while the account is active and for a limited period after closure where needed for security, audit, legal, or dispute-resolution purposes.
- Application, survey, uploaded-document, and due-diligence materials are retained while the relevant request, evaluation, partnership, or engagement is active, and then reviewed for deletion, anonymisation, or lawful business-record retention.
- Technical logs, IP records, login records, and security events are retained only for security, fraud-prevention, troubleshooting, audit, and aggregated statistical purposes, and are periodically reviewed.
- Business communications and professional contact records may be retained where needed for ongoing relationship management, legitimate institutional communications, legal compliance, or establishment, exercise, or defence of legal claims.
- Backups and provider logs may persist for a limited period according to technical backup cycles before being overwritten or deleted.
When personal data is no longer required, it is deleted, anonymised, or aggregated in accordance with our data retention policy and applicable law.
External Links
Our website may contain links to third-party websites for your convenience. We are not responsible for the privacy practices, content, or data handling of any external websites. We encourage you to review the privacy policies of any third-party sites you visit.
Your Rights (GDPR)
Under European law, you have the following rights in relation to your personal data (subject to applicable legal limitations):
To exercise any of these rights, please submit a written request to info@mblc.lt. We may ask you to verify your identity before acting on a request. We will respond within one month unless the GDPR permits an extension because of complexity or volume, in which case we will inform you.
If you have a partner portal or app account, you may request account deletion and deletion of associated personal data from inside the app or authenticated portal where that feature is available, or by contacting us if you cannot access your account. Deletion requests cover the authentication account, profile data, and associated portal records unless retention is required by law, security, fraud-prevention, dispute-resolution, or legitimate business-record obligations. Where immediate deletion is not technically possible because of backups, the data will be isolated from ordinary use and removed according to backup deletion cycles.
You also have the right to lodge a complaint with a supervisory authority. In Lithuania, the competent authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), L. Sapiegos str. 17, LT-10312 Vilnius, Lithuania, email ada@ada.lt, website vdai.lrv.lt.
Automated Decision-Making, Tracking & Children
MBLC does not use personal data for automated decision-making that produces legal or similarly significant effects, behavioural advertising, cross-site tracking, or retail profiling. We do not operate advertising pixels or share personal data with advertising networks or data brokers.
Our website, app, portal, and services are intended only for adults acting in a professional or institutional capacity. We do not knowingly collect personal data from children or minors. If we learn that a child has provided personal data, we will delete it unless we are legally required to retain it.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, providers, or applicable law. The date of the most recent version will always be displayed at the top of this page. We encourage you to review this Policy periodically. Where a material change requires notice or consent under applicable law, we will provide it before relying on the changed processing activity.
Contact
For any questions regarding this Privacy Policy, our handling of your personal data, account deletion, or exercise of GDPR rights, please contact us using the details below.
This Privacy Policy is intended to provide clear and transparent information about how MB Lady Christina handles personal data under applicable European data protection law.
Intermediary Non-Interference & Allocator-Only Review Policy
MBLC operates a strictly controlled, request-only partner portal environment designed exclusively for professional institutional allocators and investors.
To preserve independence, regulatory neutrality, and decision integrity, MBLC enforces the following principles: