Privacy policy
Privacy policy
Mosaic Group collects only what is needed to understand an enquiry and respond to it. This policy sets out what is collected, why, who sees it, how long it is kept and the choices you have.
Last updated 1 October 2026
01
Who is responsible for your information
Mosaic Group LLC is the controller of the personal data described in this policy. It is a limited liability company organised under the laws of [state of formation], with its registered office at [registered office address].
Your point of contact for privacy matters is admin@mosaic-group.co. Mosaic Group [has / has not] appointed a data protection officer; where one is appointed, the contact details will be published here.
02
What this policy covers
This policy explains how Mosaic Group collects, uses and protects personal data when you use this website, and when you correspond with the Mosaic Group team after an enquiry. It does not cover third-party websites, including the LinkedIn pages linked from the team section.
The website is a business-to-business introduction channel. It is not intended for consumers and is not designed for people under 18; Mosaic Group does not knowingly collect data from children.
03
What Mosaic Group collects
From the enquiry form, which you fill in:
full name, work email address, company or organisation, and country of operation
which category you selected: investor or capital partner, origination partner, company seeking financing, or other
if you are an investor: your investor type and the record that you confirmed you are an accredited, professional or institutional investor under the rules of your jurisdiction
if you are an origination partner or a company seeking financing: asset type, the facility size you are seeking, and the currency of your assets, where you gave it
any message you added, the date and time of submission, the record that you agreed to this policy, and the internal routing status of your enquiry
During and after contact:
correspondence you send by email, telephone, video call or in person, and Mosaic Group’s notes of those discussions
information needed to assess a potential mandate, such as company structure, asset data, financial information and source documents, where you choose to share it
identity, ownership and sanctions information, where a program proceeds to onboarding
Automatically, from technical operation of the website:
server and security logs, including IP address, browser and device type, pages requested, referring page and timestamps, used to keep the site running and secure
04
Where information comes from
Most information is given directly by you. Mosaic Group may also receive details about you from a mutual contact, from an introducer, or from publicly available sources such as company registers and your organisation’s website, where that is appropriate for assessing a business relationship.
Where Mosaic Group obtains your personal data other than directly from you, it will tell you within one month, and provide the information in this policy that applies.
06
How and why Mosaic Group uses personal data
Mosaic Group uses personal data only for the purposes below, and processes it only where there is a lawful basis.
Responding to your enquiry and, where appropriate, putting you in touch with the relevant partners. Steps taken at your request, or a contract with you, and Mosaic Group’s legitimate interest in operating an enquiry channel.
Assessing and documenting a potential program, including underwriting, structuring and approval records. Legitimate interest in evaluating and managing business relationships; contract, where a mandate proceeds.
Meeting legal and regulatory duties, including know your customer, anti money laundering, sanctions screening, tax reporting, record keeping and audit. Compliance with legal obligations.
Keeping records to manage risks, resolve disputes and establish, exercise or defend legal claims. Legitimate interest in the proper administration of the business and legal compliance.
Sending occasional updates about programs to people who have asked to hear from Mosaic Group. Consent, or legitimate interest in continuing an existing business relationship, with an opt-out in every message.
Mosaic Group does not sell personal data, and does not use it for automated decision-making or profiling that produces legal or similarly significant effects.
07
Enquiries for facilities below US$10 million
Mosaic Group’s programs currently start at US$10 million. Where a sender indicates a smaller facility, the enquiry is recorded so that Mosaic Group can respond and can contact the sender if the minimum changes, and it is not routed to capital partners or origination partners.
Those details are held for the period in Retention and can be deleted on request at any time.
08
Who Mosaic Group shares information with
Personal data is shared only where needed, and under confidentiality or data processing terms:
Mosaic Group partners, employees and contractors who need it to respond to your enquiry or run a program
the relevant capital partners, origination partners or financing counterparties, where sharing your details is necessary to progress the opportunity you have raised
service providers that host the website and database, deliver email, store documents and support communications
professional advisers, including lawyers, auditors and tax advisers, under duty of confidence
regulators, tax authorities, courts or law enforcement, where Mosaic Group is required or permitted by law, and prospective buyers in a corporate reorganisation, subject to confidentiality
The sub-processors used for this website are listed in Sub-processors and Mosaic Group will tell you when that list changes.
09
International transfers
Mosaic Group operates across the United States, United Kingdom, Europe, the Middle East and Asia, and its main hosting, database and email providers operate data centres in the United States and elsewhere. Your information may therefore be processed outside your own country, including in the United States.
Where a transfer from the European Economic Area or the United Kingdom is not covered by an adequacy decision, Mosaic Group relies on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or certification under a recognised framework, together with a transfer risk assessment and technical safeguards. You can request a copy of the safeguards by writing to the address in Contact.
10
How long information is kept
Mosaic Group keeps personal data only as long as needed for the purposes above, applying these default periods:
Enquiries that Mosaic Group is pursuing: for three years from the last substantive contact, then reviewed and deleted or anonymised.
Enquiries below the US$10m minimum: for twelve months, then deleted or anonymised, unless you have asked to remain on file.
Correspondence and meeting notes: for three years from the last contact.
Onboarding, know your customer and sanctions records: for the period required by the applicable anti money laundering regime, currently [five] years after the relationship ends.
Server and security logs: for [30] days, unless a security incident requires a longer hold.
Accounting and tax records: for the period required by applicable tax law, currently [six] years.
11
How Mosaic Group protects information
Mosaic Group applies technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit, access controls on a least-need basis, row-level security in the database so that enquiry data cannot be read without authorisation, logging of administrative access, multi-factor authentication for staff accounts, supplier due diligence, and a documented response process for suspected incidents.
No method of transmission or storage is completely secure. If a personal data breach affects you and Mosaic Group is required to notify you or a regulator, it will do so without undue delay.
12
Your rights
Where applicable law gives you these rights, you can ask Mosaic Group to:
confirm whether it holds your personal data and provide a copy of it
correct inaccurate data, or complete data that is incomplete
delete data that is no longer needed, or that you have withdrawn consent for
restrict or object to processing, including processing for direct marketing
provide your data in a structured, commonly used format so you can move it
withdraw consent at any time, where consent is the basis for processing
Requests can be made to admin@mosaic-group.co. Mosaic Group will verify your identity where there is a risk of disclosing information about someone else, will respond within one month, and will not charge a fee except where a request is manifestly unfounded or excessive.
You can also complain to a supervisory authority in the country where you live or work, for example the Information Commissioner’s Office in the United Kingdom or the competent data protection authority in your EU or EEA member state. Other jurisdictions, including some US states, provide additional rights; [confirm whether any state-law notice, do-not-sell link or additional disclosure is required].
13
Sub-processors
Providers used in connection with this website, as at the date of this policy:
Website hosting and delivery: [provider name, country]. Serves the website and stores static assets.
Database and application backend: [provider name, country]. Stores enquiry records; access is restricted by role and row-level security.
Transactional email delivery: [provider name, country]. Sends the enquiry confirmation and internal notifications from notify.mosaic-group.co.
Document storage and sharing: [provider name, country]. Holds diligence documents where a mandate proceeds.
Communications and scheduling: [provider name, country]. Video calls and calendar bookings, where used.
14
Third-party websites
Links from this website, including the LinkedIn profiles of individual partners, lead to pages controlled by others. Their use of your data is governed by their own policies, and Mosaic Group is not responsible for them.
15
Changes to this policy
Mosaic Group may update this policy. The version and date at the top of the page show when it last changed, and material changes will be announced on the website and, where Mosaic Group holds your contact details and a continuing relationship with you, notified directly.
16
Contact and complaints
Write to Mosaic Group LLC at [postal address for privacy correspondence], or email admin@mosaic-group.co with “Privacy” in the subject line.
Mosaic Group aims to acknowledge a privacy concern within 2 business days and to respond substantively within [number of days, for example 15 or 30 calendar days].
Questions about this page
Write to Mosaic Group at admin@mosaic-group.co, or use the contact form.