ONYX Capital Partners ("ONYX", "we", "us") operates this site from New York and London. The short version: the only information we ask for is what you choose to type into our contact form, we never sell it, and these pages set no cookies and run no analytics or tracking scripts of any kind.
1. Who this policy covers
This policy applies to onyxcapital.partners and to the correspondence that follows from it. Our audience is professional rather than consumer: business owners and their representatives, corporate and institutional counterparties, and professional or qualified investors, principally in the United States, the United Kingdom and the wider European Economic Area.
Because the firm operates from two jurisdictions, this policy is written to satisfy both US state privacy law and the UK and EU General Data Protection Regulation. For information covered by the GDPR, ONYX acts as the data controller.
The policy does not govern the confidentiality terms of a live engagement. Once a mandate begins, the engagement letter and any non-disclosure agreement signed alongside it set the standard, and where those terms are stricter, they prevail.
2. Information we collect
What you send us
The contact form asks for your name and email address, and optionally your company, your telephone number and the nature of your inquiry. The message field is yours to fill as you see fit. We also keep the emails, letters and meeting notes that follow a first approach, to the extent they are needed to advise you properly.
Please do not send bank account numbers, government identifiers, health information or other sensitive material through an unencrypted web form. If an engagement requires that kind of detail, we will arrange a secure channel for it.
What our host records
Our hosting provider keeps standard server logs — IP address, browser and device type, the page requested, the time of the request and the referring page — for security, abuse prevention and reliability. These logs are generated by the infrastructure, not by anything we have added to the pages, and we do not use them to build a profile of you.
There is nothing else. The site loads no analytics platform, no advertising or retargeting pixels, no social media widgets and no embedded third-party scripts. Typefaces are served from our own domain rather than a font network, so viewing these pages does not announce your visit to anyone else.
3. How we use your information
We use what you send us in order to:
- reply to your inquiry and arrange a conversation with the right partner;
- assess whether we can act on a mandate, and whether an opportunity is a credible fit for the party asking about it;
- carry out the engagement itself, including the verification and eligibility checks a transaction requires;
- keep the records our legal and professional obligations oblige us to keep; and
- protect the site and the firm against fraud, misuse and security incidents.
Where the GDPR applies, we rely on our legitimate interest in responding to inquiries and running an advisory practice, on the steps taken at your request before entering a contract, on compliance with a legal obligation, and — for any optional update we might send — on your consent, which you may withdraw at any time. We do not make automated decisions about you that produce legal or similarly significant effects, and we do not profile you for advertising.
4. How we share information
We disclose personal information only in these circumstances:
- Service providers. The company that hosts this site, the service that delivers form submissions to us, and our email provider. Each processes information only on our instructions and under a confidentiality obligation.
- Professional advisors. Counsel, accountants and compliance advisors engaged by the firm, where their involvement is necessary to a matter.
- Counterparties, on your instruction. In a live transaction, information reaches a buyer, seller or investor only when the client has directed us to release it, and normally under a signed non-disclosure agreement.
- Legal requirements. Where disclosure is required by law, regulation, court order or a lawful request from a public authority, or where it is necessary to establish or defend legal claims.
- A change to the firm. If ONYX is reorganized or its business transferred, records may pass to the successor entity, which remains bound by this policy.
Because we operate in New York and London, information may move between the United States and the United Kingdom or the EEA. Where it does, the transfer is made under appropriate safeguards, such as standard contractual clauses and the UK addendum to them.
5. We do not sell personal information
We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising as those terms are defined under US state privacy laws. We do not rent, trade or license contact details, and we do not supply them to data brokers. Nothing you send through this site is used for advertising by us or by anyone else.
6. Cookies and tracking technologies
As of the date at the top of this page, this site sets no cookies at all. There is no analytics cookie, no session cookie, no advertising or retargeting pixel, no social plug-in and no third-party tag. Nothing on these pages follows you to another website, and that is why you were not shown a consent banner — there was nothing to consent to.
Your browser may cache images, stylesheets and fonts to make a return visit quicker. That storage is local to your device, is not readable by us, and can be cleared through your browser at any time. If we ever introduce cookies or measurement tools, we will amend this section and the "Last updated" date before they go live, and we will ask for consent where the law requires it.
7. Security
The site is served over an encrypted connection, and its response headers include a content security policy that blocks inline scripts and unapproved third-party resources. Form submissions travel over the same encrypted channel. Access to inquiry records is limited to the partners and staff who need it, and our providers are chosen for their security posture as much as their reliability.
We collect no passwords, no payment card details and no account credentials through this site, so there is no such data to lose. That said, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach ever affects your information, we will notify you and the relevant authorities as required by law.
8. Data retention
An inquiry that does not lead to an engagement is kept for up to twenty-four months so that we can pick up a conversation where it left off, and is then deleted. Records connected to an engagement are kept for the life of the relationship and for as long afterward as law, tax rules and our professional obligations require — generally at least six years from the close of the matter. Server logs are held by our host on a short rolling window, typically no more than ninety days.
When a retention period ends, records are deleted or anonymized. If you ask us to erase your information sooner, we will do so unless we are required to keep it, in which case we will tell you which category applies.
9. Your rights and choices
If you are in the United States
Depending on your state of residence, you may have the right to know what personal information we hold and to obtain a copy of it, to have inaccurate information corrected, to have information deleted, to receive it in a portable format, to opt out of any sale, sharing or targeted advertising — none of which we conduct — and to limit the use of sensitive personal information. You will not be treated differently for exercising any of these rights, and an authorized agent may act on your behalf where state law allows it.
If you are in the United Kingdom or the European Economic Area
You have the right of access to your personal data, and rights to rectification, to erasure, to restriction of processing, to data portability, and to object to processing carried out on the basis of our legitimate interests, including any direct marketing. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand. You may also lodge a complaint with the Information Commissioner's Office in the UK or with the supervisory authority in your country of residence, although we would welcome the chance to resolve the matter first.
Making a request
Write to info@onyxcapital.partners with "Privacy request" in the subject line and tell us what you would like us to do. We respond within thirty days. If a request is unusually complex we will say so within that period and explain how much longer we need. We may ask you to verify your identity, and — where a request is made for a business — that you are authorized to act for it.
10. Children's privacy
It is not directed to anyone under eighteen, and we do not knowingly collect information from children. If we learn that a minor has submitted information through the contact form, we delete it. A parent or guardian who believes a child has contacted us should write to the address in section 12.
11. Changes to this policy
We may revise this policy as the firm, the site or the law changes. The "Last updated" date at the top of the page always reflects the current version. If a change materially affects how we use information you have already given us, we will take reasonable steps to tell you, including by writing to the email address you used to contact us.
12. Contact us
Questions about this policy, or about the information we hold, should go to info@onyxcapital.partners. Privacy matters are handled by the partners of ONYX Capital Partners. You can also reach us through the contact page.
This page is published for information only. It is not legal advice and creates no contractual obligation.