Privacy Notice
Mondriot · Version 1.0 · 31 May 2026
1. About this notice
This Privacy Notice explains how 93 Management and Advisory Ltd ("Mondriot", "we", "our", or "us") collects, uses, and protects personal data when you use the Mondriot platform at mondriot.com (the "Platform").
Mondriot is a compensation intelligence platform for non-investment professionals working in alternative investments. We provide benchmark reports drawn from a cohort built of verified records contributed by professionals like you and synthetic records modelled by us from market intelligence.
This Notice applies to:
(a) candidates — individuals who create a candidate account to benchmark their own compensation;
(b) clients — fund managers and other firms whose authorised representatives access the Platform under a separate Client Data Sharing Agreement; and
(c) visitors to mondriot.com who have not signed in.
If you are an employee whose compensation data has been uploaded to Mondriot by your employer under a Client Data Sharing Agreement, please refer to section 7 (Client-uploaded data) and to your employer's privacy notice for information about how your employer determines the purposes and means of processing your data.
We are the controller of personal data described in this Notice unless we state otherwise.
2. Who we are and how to contact us
Controller. 93 Management and Advisory Ltd, a company registered in England and Wales under company number 16123706, with registered office at Worthy House, 14 Winchester Road, Basingstoke, Hampshire RG21 8UQ.
VAT registration. 483 5134 84
Data protection contact. Contact us through the Platform or at the support address shown in your account.
We are not required to appoint a Data Protection Officer under Article 37 UK GDPR. We have nonetheless designated a named privacy contact responsible for data protection matters.
3. The personal data we process
We process the following categories of personal data:
3.1 Account data
When you create a candidate or client representative account, or apply for access to the Platform, we collect:
- name;
- work email address;
- employer / firm name;
- access-application details, including your stated reason for interest, message to us, and where you heard about Mondriot where provided;
- job title;
- magic-link authentication tokens;
- candidate preauthorisation and allowlist-check outcomes;
- sign-in history and timestamps; and
- account preferences and settings.
3.2 Compensation submissions (candidates)
When you submit your compensation to generate a benchmark, we collect:
- role title and function;
- corporate band;
- investment strategy;
- industry / sector;
- location (city);
- compensation paid as of date (month and year);
- base salary;
- bonus amount;
- annualised carried interest;
- total carry in play (optional);
- other long-term incentive plan ("LTIP") value (optional);
- employer / firm name; and
- an uploaded job specification PDF (optional).
3.3 Benchmark history (candidates)
A record of every benchmark you have generated, including the cohort filters applied, the percentile result, and the date of generation.
3.4 Client-uploaded data (where applicable)
When a client firm uploads a CSV of roles for bulk benchmarking, the CSV typically contains the categories listed in section 3.2 above relating to the firm's employees. The lawful basis on which the client firm shares this data with us is set out in section 5 and in the Client Data Sharing Agreement entered into between the client firm and us.
3.5 Payment data
When you purchase tokens or a subscription, our payment processor Stripe Payments UK Ltd ("Stripe") collects card or other payment details directly from you. We receive limited transaction metadata (transaction reference, amount, status, last four digits of card) but not your full card number, expiry, or CVV.
3.6 Communications data
Records of any correspondence with us, including access applications, technical feedback submitted through the Platform, support requests, and customer support exchanges.
3.7 Technical and usage data
When you use the Platform we automatically collect:
- IP address;
- browser type and version, operating system, and device identifiers;
- pages viewed and features used;
- referring URL; and
- date and time of access.
This data is collected by cookies, pixels and similar technologies. See section 12 and our Cookie Notice for details.
3.8 Marketing data
If you opt in to marketing communications, we record your subscription preferences and engagement (opens, clicks).
3.9 Special category data
We do not knowingly collect special category personal data within the meaning of Article 9 UK GDPR (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation). You should not submit such data to the Platform.
4. Where we collect personal data from
We collect personal data:
(a) directly from you when you create an account, apply for access, submit compensation data, generate a benchmark, contact us, or otherwise use the Platform;
(b) from your employer where you are an employee of a client firm and your employer has uploaded data to the Platform under a Client Data Sharing Agreement;
(c) from LinkedIn where you authenticate using LinkedIn's OAuth integration (limited to the profile fields you have authorised LinkedIn to share, which are described at the point of authentication);
(d) from Stripe in respect of transaction metadata;
(e) from 93 Management and Advisory Ltd's affiliated recruitment practice where you have separately consented to us using compensation data shared in the course of that engagement to inform the Mondriot cohort; and
(f) from candidate preauthorisation and domain allowlists maintained by us for access-control purposes; and
(g) automatically through your use of the Platform, as described in section 3.7.
5. Why we use your personal data and our lawful basis
We process personal data for the purposes set out below, relying on the lawful basis identified for each purpose under Article 6(1) UK GDPR.
5.1 To provide the Platform and the benchmark service
| Purpose | Lawful basis |
|---|---|
| Creating and authenticating your account; allowing you to submit compensation data and generate benchmark reports; making your benchmark history available to you; allowing client firms to upload data and access bulk benchmarks. | Performance of a contract to which you are a party (Article 6(1)(b)) — namely, our Terms of Service. |
5.2 To build, maintain and improve the benchmark cohort
| Purpose | Lawful basis |
|---|---|
| Where you consent, contributing your compensation submission, in de-identified form, to the cohort used to generate benchmarks for other users; refining benchmark methodology; combining your record with synthetic records and records contributed by other users to produce more accurate cohort statistics over time. | Consent (Article 6(1)(a)) for candidate compensation submissions contributed to the cohort. Candidate benchmark generation requires this consent. You can withdraw consent for future processing at any time by deleting your account or requesting erasure under section 9. Records contributing to the cohort are de-identified before contribution, and we operate technical controls (rate limits and capped allowances) that prevent any user from extracting an outsized share of the dataset and frustrate triangulation. |
5.3 To take payment and operate subscriptions
| Purpose | Lawful basis |
|---|---|
| Taking and recording payment for tokens and subscriptions; managing renewals; issuing receipts; refunds; tax compliance. | Performance of a contract (Article 6(1)(b)) for the elements necessary to deliver the purchased service; legal obligation (Article 6(1)(c)) for tax and accounting record-keeping. |
5.4 To communicate with you about the service
| Purpose | Lawful basis |
|---|---|
| Sending account-related communications (sign-in links, security alerts, receipts, service notifications, changes to these terms or this Notice); reviewing access applications; responding to your enquiries and support requests. | Performance of a contract (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) in operating a functioning service. |
5.5 To send you marketing communications
| Purpose | Lawful basis |
|---|---|
| Sending you marketing emails about Mondriot features, content and offers, where you have opted in to receive them. | Consent (Article 6(1)(a)). You can withdraw consent at any time by clicking the unsubscribe link in any marketing email or by contacting us through the Platform. |
5.6 To secure the Platform and prevent abuse
| Purpose | Lawful basis |
|---|---|
| Detecting and preventing fraud, abuse, scraping, and other misuse; checking candidate access against preauthorised email and domain lists; monitoring access patterns; enforcing the rate limits and acceptable use policy in our Terms of Service. | Legitimate interests (Article 6(1)(f)) in operating a secure platform that protects all users and the integrity of the cohort. |
5.7 To comply with legal obligations
| Purpose | Lawful basis |
|---|---|
| Responding to lawful requests from regulators, law enforcement and courts; meeting our tax, accounting and other statutory obligations. | Legal obligation (Article 6(1)(c)). |
5.8 Automated decision-making and the benchmark insight
The Platform generates a written benchmark insight paragraph that is produced algorithmically from your submission and the cohort statistics. This is a form of automated processing under Article 22 UK GDPR (as amended by the Data (Use and Access) Act 2025).
The insight is provided to you as informational analysis, not as a decision that produces legal effects concerning you or that similarly significantly affects you. It does not determine your eligibility for any benefit or service, does not affect your status as a user, and does not change the compensation you are paid or have been offered. We provide the analysis on the basis of your contract with us (Article 6(1)(b)). You can ignore, act on, or seek a second view on the insight as you choose.
Where you would prefer not to receive an automated insight and would like to view only the underlying statistics, contact us through the Platform and we will configure your account accordingly. You retain the right to obtain human review of the analysis by contacting us.
6. The cohort: how we de-identify your data before contribution
This section explains in detail how your compensation record is treated once it has been submitted.
When you submit a compensation record, the original record is stored in your account in identifiable form so that you can access it, edit it, and delete it. Before that record contributes to the cohort that benchmarks other users, we generate a separate contribution record which:
(a) does not contain your name or email address;
(b) does not contain your employer's name (your employer is standardised internally to a peer-grouping category but the firm name itself is not exposed in the contribution record);
(c) retains a unique identifier linking the contribution record to your underlying account record so that we can (i) remove the contribution record from the cohort if you exercise your right to erasure, (ii) audit the data quality of the cohort, and (iii) respond to data subject rights requests.
Under UK GDPR Article 4(5), this is pseudonymisation, not anonymisation. The contribution record is still personal data because re-identification remains possible by joining it to the underlying account record, but the linking identifier is accessible only to authorised Mondriot personnel for the purposes set out above. Other users of the Platform never see your name, your employer, or any field of your record that could re-identify you.
In addition to verified records contributed by users, the cohort contains synthetic records that we model from market intelligence available to 93 Management and Advisory Ltd's recruitment practice. Synthetic records are not personal data and are flagged in the cohort as such. Each benchmark report indicates the proportion of verified versus synthetic records behind it through the cohort provenance footer.
7. Client-uploaded data
Where a client firm uploads compensation data relating to its employees (the "Client Data"), that processing is governed by a separate Client Data Sharing Agreement between us and the client firm. In summary:
(a) the client firm is the controller of the Client Data in its capacity as employer, prior to upload;
(b) on upload to Mondriot, we and the client firm act as joint controllers within the meaning of Article 26 UK GDPR in relation to the Client Data: the client firm determines the purpose for which the data is uploaded (benchmarking the firm's roles), and we determine the technical means by which benchmarks are produced and the contribution of Client Data, in de-identified form, to the cohort;
(c) the client firm is responsible for ensuring it has a lawful basis under Article 6 (and where applicable Article 9) UK GDPR to share Client Data with us, and for informing its employees that their compensation data may be shared with a compensation benchmarking provider;
(d) we apply the same de-identification step described in section 6 to any Client Data that contributes to the cross-client cohort.
The full allocation of responsibility between us and client firms is set out in the Client Data Sharing Agreement. If you are an employee of a client firm and would like a copy of the relevant arrangement, please contact your employer.
8. Who we share your personal data with
We share personal data with the following categories of recipients:
8.1 Service providers acting as our processors
We use the following third parties to process personal data on our behalf, under written data processing agreements that meet the requirements of Article 28 UK GDPR:
- Hosting and database — Supabase Inc. (United States), hosting the Platform's database and authentication infrastructure;
- Front-end hosting — Vercel Inc. (United States), hosting the Platform's web application;
- Payment processing — Stripe Payments UK Ltd (United Kingdom) and Stripe Inc. (United States);
- Email delivery — Resend, Inc.;
- Authentication — LinkedIn (where you sign in via LinkedIn OAuth);
Where you have signed in via LinkedIn, LinkedIn is an independent controller for the data it processes about its own users; we receive a limited subset of your LinkedIn profile data via the OAuth integration, which you authorise at the point of sign-in.
8.2 Professional advisers and regulators
Our legal, accounting and tax advisers; regulators (including the Information Commissioner's Office); law enforcement and courts where we are required to disclose information by law or are required to do so to establish, exercise or defend legal claims.
8.3 Corporate transactions
Prospective buyers and their advisers in connection with any sale of, or investment in, 93 Management and Advisory Ltd or the Mondriot business, in each case subject to confidentiality obligations.
8.4 Other users
Other Platform users see your data only in de-identified, aggregated form as part of the cohort statistics underlying their benchmark reports. They do not see your name, employer, or any other field that re-identifies you to them.
We do not sell your personal data.
9. International transfers
Some of our processors are located in the United States or other countries outside the United Kingdom. Where this is the case, we ensure an appropriate safeguard is in place to protect your personal data:
(a) where the transfer is to a US-based recipient certified under the EU-US Data Privacy Framework with the UK Extension, the transfer relies on the UK Extension to the EU-US Data Privacy Framework, which was recognised as providing adequate protection under UK GDPR by the Data Protection (Adequacy) (United States of America) Regulations 2023;
(b) where the transfer is to a recipient not certified under the UK Extension, we use the UK International Data Transfer Agreement ("IDTA") or the UK Addendum to the EU Standard Contractual Clauses, and have completed a transfer risk assessment;
(c) where the transfer is to a country in respect of which the United Kingdom has made adequacy regulations (currently including, among others, the European Economic Area, Switzerland, the Channel Islands and South Korea), we rely on those adequacy regulations.
A list of our processors and the safeguard in force for each is available on request.
10. How long we keep personal data
We keep personal data only as long as we need it for the purposes set out in this Notice. Specifically:
| Category | Retention |
|---|---|
| Account data | For the life of your account, plus 12 months following closure to allow for reactivation, then deleted. |
| Compensation submissions in identifiable form (linked to your account) | For the life of your account; deleted on account closure or request for erasure within 30 days. |
| Contribution records (pseudonymised) | Retained in the cohort for so long as they remain statistically relevant (typically up to 3 years from the snapshot date), then archived in fully anonymised form. |
| Benchmark reports generated by you | For the life of your account; deleted on account closure or request for erasure. |
| Payment metadata | 7 years from the date of the transaction, to meet HMRC record-keeping obligations. |
| Marketing data | For so long as you remain opted in, plus 24 months following withdrawal of consent. |
| Communications and support records | 6 years from the last interaction. |
| Technical / usage logs | 90 days. |
| Backups | Backups are retained for up to 35 days, after which deletions propagate. |
11. Your rights
You have the following rights in relation to your personal data, subject to the limits and conditions set out in UK GDPR:
(a) Right to be informed — you have the right to be informed about how we collect and use your personal data, which is the purpose of this Notice;
(b) Right of access (Article 15) — you can request a copy of the personal data we hold about you, free of charge, and we will respond within one month;
(c) Right to rectification (Article 16) — you can ask us to correct inaccurate personal data or complete incomplete data;
(d) Right to erasure (Article 17) — you can ask us to delete your personal data in the circumstances specified in UK GDPR. Where your record contributes to the cohort, deletion will remove the linkable contribution record within 30 days; aggregate statistics already used in past benchmark reports do not enable re-identification and are retained in archival form;
(e) Right to restriction of processing (Article 18) — you can ask us to suspend processing of your personal data in defined circumstances;
(f) Right to data portability (Article 20) — for the personal data you have provided to us and which we process by automated means on the basis of consent or contract, you can ask us to provide it to you, or to transfer it to another controller you nominate, in a structured, commonly-used and machine-readable format;
(g) Right to object (Article 21) — you can object to processing based on legitimate interests (including the cohort contribution described in section 5.2). We will stop the processing unless we can demonstrate compelling legitimate grounds that override your interests. You can also object to direct marketing at any time;
(h) Rights relating to automated decision-making and profiling (Article 22 as amended by the DUAA) — see section 5.8;
(i) Right to withdraw consent — where we rely on consent, you can withdraw it at any time;
(j) Right to lodge a complaint with the Information Commissioner's Office — see section 17.
You can exercise rights (b) through (g) and (i) by contacting us through the Platform or, for many of them, directly through your account profile (the Download my data and Delete my account controls). We may ask you to verify your identity before responding to a rights request.
12. Cookies and similar technologies
We use cookies and similar technologies on mondriot.com. We currently use strictly necessary cookies and similar technologies only, including Supabase authentication cookies and local storage used to remember that you have acknowledged the Cookie Notice. For the categories of cookies we use, the purposes, the providers, and how to control them, please see our Cookie Notice.
Under the Privacy and Electronic Communications Regulations 2003 ("PECR"), strictly necessary cookies may be set without consent. If we introduce optional analytics, marketing, or other non-essential cookies in future, we will update our Cookie Notice and, where required, ask for your consent before setting them.
13. Children's data
The Platform is intended for adult professionals. We do not knowingly collect personal data from anyone under the age of 18. If you become aware that a person under 18 has provided us with personal data, please contact us through the Platform and we will delete it.
14. How we keep your personal data safe
We have implemented appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, including:
(a) encryption of personal data at rest and in transit;
(b) access controls limiting personal data access to authorised personnel on a need-to-know basis;
(c) pseudonymisation of contribution records as described in section 6;
(d) capped benchmark allowances and rate limits that prevent any single user from extracting an outsized share of the cohort;
(e) regular security reviews and dependency updates;
(f) staff training and confidentiality undertakings;
(g) data breach response procedures, including notification to the Information Commissioner's Office within 72 hours of becoming aware of a notifiable breach.
15. Changes to this Notice
We may amend this Notice from time to time. If we make material changes to how we process personal data, we will notify you in advance by email or by prominent notice on the Platform. The current version is identified by the date at the top of this page; previous versions are available on request.
16. Future demerger to Mondriot Ltd
We currently hold the Mondriot business within 93 Management and Advisory Ltd. We intend in due course to demerge the Mondriot business into a dedicated entity (provisionally "Mondriot Ltd"). If and when this occurs, the new entity will become the controller of your personal data. We will notify you in advance of the transfer date and you will retain all the rights described in section 11.
17. Complaints
If you have a concern about how we have processed your personal data, please contact us first through the Platform so we can try to resolve it.
You also have the right to lodge a complaint with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
SK9 5AF
Tel: 0303 123 1113
ico.org.uk