Privacy Policy

Last updated on 24 Aug 2026

This Privacy Policy is designed to help you understand how we collect, use, disclose and safeguard your personal data when you use this website and when you interact with DCY Fund SCSp (the “Fund”) and its related services.

1. Who we are and scope of this Policy

This Privacy Policy applies to the processing of personal data carried out in the context of:

For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the data controller will typically be:

In this Policy, “we”, “us” or “our” refer to the Fund and, where relevant, its AIFM.

Contact details for privacy matters:

2. Categories of personal data we collect

Depending on your relationship with us (website visitor, prospective investor, investor, representative of a legal entity, counterparty, service provider), we may collect the following categories of personal data:

Identification and contact data

Professional and financial data

Regulatory and compliance data

Technical and website usage data

Communication and interaction data

We generally obtain this data directly from you (or from your advisers), and, where necessary, from public sources or specialised third-party providers (e.g. KYC/AML service providers, banks, distributors).

3. Purposes of processing and legal bases

We process your personal data for the following purposes and on the corresponding legal bases:

Management of your relationship with the Fund and its AIFM

Processing subscription and redemption requests, maintaining the register of investors, communicating with you and your advisers, handling queries.

Legal bases:

Compliance with legal and regulatory obligations

AML/CTF checks, identification and verification of investors, sanctions screening, reporting to competent authorities (including the CSSF), tax reporting (e.g. FATCA/CRS, where applicable), maintenance of statutory records.

Legal bases:

Website operation, security and improvement

Operating and securing the website and troubleshooting it.

Measuring how the website is used. Every page of this website loads Cloudflare Web Analytics, a measurement script served from static.cloudflareinsights.com. It counts page views and records, for each one, the page requested, the referring website if you arrived from one, the country your request comes from, and the class of device and browser you are using. It sets no cookie, stores nothing on your device and derives no identifier from it, so it cannot recognise you on a later visit, build a profile of you, or follow you across other websites. Because nothing is read from or stored on your terminal equipment, we do not ask for your consent for it. The data is processed by Cloudflare, as our processor, and we only ever see aggregate figures.

Protection of our forms against automated abuse. The documentation request form is open to anyone and triggers an email from us. Left unprotected, it could be used to send unwanted messages, in our name and from our domain, to a person who never asked for them. To prevent this, the three product pages that carry the form (BTC Yield, USD Yield and Digital Dynamic) display a Cloudflare Turnstile verification widget, which distinguishes a human visitor from an automated one. The widget is loaded from challenges.cloudflare.com, so on those three pages your IP address and technical signals about your browser and device are transmitted to Cloudflare for that purpose. It sets no cookie, stores nothing on your device, and is not used to track or profile you or to follow you across other websites. No other page of this website loads it.

Legal bases:

Marketing and investor relations

Sending you information about the Fund, newsletters, updates and event invitations that may be relevant to you as a professional or well-informed investor.

Legal bases:

You may opt out of marketing communications at any time by using the unsubscribe link in our emails or by contacting us.

Risk management, fraud prevention and dispute handling

Monitoring, preventing and investigating fraud, unlawful or abusive activities; managing and defending legal claims.

Legal bases:

Where we rely on consent, you may withdraw your consent at any time, without affecting the lawfulness of processing carried out before such withdrawal.

4. Recipients of your personal data

We may share your personal data, on a need-to-know basis, with the following categories of recipients:

One recipient is named here because it is involved every time you open a page:

We do not sell your personal data to third parties.

5. International data transfers

Some of the recipients mentioned above may be located in countries outside the European Economic Area (EEA) which may not provide the same level of data protection as within the EEA.

In such cases, we ensure that appropriate safeguards are implemented in accordance with the GDPR, such as:

This applies in particular to Cloudflare, Inc., named in section 4, which is established in the United States. Cloudflare is certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing an adequate level of protection for personal data transferred to certified US organisations. Where that certification does not apply, the transfer is governed by the Standard Contractual Clauses adopted by the European Commission.

You may contact us at support@dcy.fund for further information on the safeguards applicable to specific transfers.

6. Data retention

We retain your personal data only for as long as necessary to achieve the purposes described in this Policy and to comply with applicable legal and regulatory obligations, in particular:

When data is no longer needed, it is securely deleted or anonymised.

7. Security measures

We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including:

While we strive to protect your personal data, no system can be completely secure and we cannot guarantee absolute security.

8. Your rights under GDPR

Subject to the conditions and limitations set out in the GDPR and applicable law, you have the following rights regarding your personal data:

To exercise your rights, please contact us at:

Please note that we may need to verify your identity before responding to your request, and that legal or regulatory obligations may prevent us from fully complying with certain requests (in particular regarding AML/CTF and statutory record-keeping).

You also have the right to lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD), the Luxembourg data protection authority, or with your local supervisory authority.

9. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities, in applicable law or in guidance from supervisory authorities. Any updates will be published on this website with an updated “last updated” date.

We encourage you to review this Privacy Policy regularly to stay informed about how we process your personal data.