Next 11 Ventures

Privacy Policy — Next 11 Ventures Ltd

Version 2 · Last updated: 29 July 2026

This privacy policy sets out how Next 11 Ventures Ltd (CRN: NI732482) uses and protects your personal data.

1. Important information and who we are

This privacy policy gives you information about how Next 11 Ventures Ltd (CRN: NI732482) collects and uses your personal data through your use of our website and through your dealings with us in connection with our investment and venture-building activities (together, our "Services").

Next 11 Ventures Ltd is a private limited company registered in Northern Ireland under company number NI732482, whose registered office is at The Mount Business & Conference Centre, 2 Woodstock Link, Belfast, County Down, Northern Ireland, BT6 8DD. We are a venture and development capital company.

We comply with the UK GDPR, the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, and the Privacy and Electronic Communications Regulations 2003 (PECR).

Our Services are aimed at businesses and business professionals. They are not intended for children, our website is not directed at children and we do not knowingly collect data relating to children. If we become aware that we hold personal data relating to a child, we will delete it.

Next 11 Ventures Ltd is the controller and is responsible for your personal data (referred to as "Next 11", "we", "us" or "our" in this privacy policy). As a controller established in the United Kingdom, we are subject to the UK data protection regime and regulated by the Information Commissioner's Office.

This policy applies to you if you are:

  • a founder, director or employee of a company that approaches us, or that we approach, in connection with a possible investment;
  • a director, employee or beneficial owner of a company in which we hold or have held an interest;
  • an investor, prospective investor, co-investor or adviser;
  • a supplier, contractor or professional adviser, or an individual working for one; or
  • a visitor to our website or a recipient of our communications.

We are not required to appoint a data protection officer. The person responsible for overseeing questions about this privacy policy is Steve Pugh, Chief Executive Officer, who can be contacted using the details in paragraph 10.

If you have any questions about this privacy policy, if you wish to exercise your legal rights (paragraph 9) or if you wish to complain about how we have handled your personal data (paragraph 11), please contact us.

2. The types of personal data we collect about you

Personal data means any information about an individual from which that person can be identified.

We may collect, use, store and transfer different kinds of personal data about you, which we have grouped together as follows:

  • Identity Data includes first name, last name, any previous names, username or similar identifier, title, date of birth, nationality and, where we are required to verify your identity, copies of identity documents.
  • Contact Data includes business and billing address, email address and telephone numbers.
  • Professional Data includes your job title, role, employer, directorships, shareholdings, professional background, career history and other information contained in a pitch deck, business plan, CV or similar material you provide to us.
  • Financial Data includes bank account and payment details, and information about your source of funds or source of wealth where we are required to obtain it.
  • Transaction Data includes details of payments to and from you, investments made, distributions and details of services provided to or by you.
  • Due Diligence Data includes information obtained in connection with anti-money laundering, sanctions, politically exposed person and adverse media checks, and information gathered when we assess a possible investment.
  • Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access our website.
  • Profile Data includes your username and password, your interests, preferences, feedback and survey responses.
  • Usage Data includes information about how you interact with and use our website and our communications.
  • Marketing and Communications Data includes your preferences in receiving marketing from us and your communication preferences.

We also collect, use and share aggregated data such as statistical or demographic data which is not personal data, as it does not directly or indirectly reveal your identity. For example, we may aggregate Usage Data to analyse general trends in how people interact with our website.

We do not routinely collect any special categories of personal data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Where a due diligence, sanctions or adverse media check returns information of this kind, or information about criminal convictions and offences, we will only process it where the law permits us to do so, and we will keep it separate, limit access to it and retain it for no longer than necessary.

3. How is your personal data collected?

We use different methods to collect data from and about you, including through:

Your interactions with us. You may give us your personal data by filling in forms on our website, by submitting a pitch or business plan, or by corresponding with us by post, phone, email or otherwise. This includes personal data you provide when you:

  • approach us, or respond to us, about a possible investment or partnership;
  • enter into or negotiate an investment, shareholders' agreement or commercial contract with us;
  • subscribe to our updates or request marketing to be sent to you;
  • attend an event, meeting or pitch session; or
  • give us feedback or contact us.

Automated technologies or interactions. As you interact with our website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data using cookies, server logs and similar technologies. Please see paragraph 4 and our cookie policy for further details.

Third parties or publicly available sources. We may receive personal data about you from various third parties and public sources, as set out below:

  • Technical Data from analytics providers such as Google, and from advertising networks and search information providers;
  • Contact, Financial and Transaction Data from providers of technical, payment and banking services;
  • Identity, Contact and Professional Data from data brokers, aggregators, business information providers and professional networking sites;
  • Identity, Contact, Professional and Due Diligence Data from publicly available sources such as Companies House, the Insolvency Register, the Electoral Register, sanctions lists, court records and press and media reports;
  • Identity, Professional and Due Diligence Data from identity verification, credit reference and screening providers; and
  • Identity, Contact and Professional Data from co-investors, introducers, brokers, advisers and other business contacts who refer you to us.

4. How we use your personal data

Legal basis

The law requires us to have a legal basis for collecting and using your personal data. We rely on one or more of the following:

Performance of a contract with you: where we need to perform a contract we are about to enter into or have entered into with you.

Legitimate interests: where it is necessary to conduct our business and pursue our legitimate interests, for example to assess investment opportunities, to manage our portfolio, to carry out direct marketing, to transmit personal data within our group for internal administrative purposes, to keep our networks and systems secure and to prevent fraud. We consider and balance any potential impact on you and your rights, both positive and negative, before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted by law. You may ask us for a copy of the relevant legitimate interests assessment at any time.

Recognised legitimate interests: in limited cases we may rely on the separate lawful basis of recognised legitimate interests under Article 6(1)(ea) and Annex 1 of the UK GDPR, which does not require a balancing test. For us this is most likely to apply where we detect, investigate or prevent crime, including fraud and money laundering, or where we disclose personal data to a public authority carrying out a public task.

Legal obligation: where it is necessary for compliance with a legal obligation we are subject to. We will identify the relevant legal obligation when we rely on this basis.

Consent: we rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose.

Where we intend to use your personal data for a new purpose, we will only do so where the new purpose is compatible with the purpose for which we originally collected it, where you have consented, or where we are otherwise permitted to do so by law. We will let you know before we do so where we are required to.

Purposes for which we will use your personal data

Purpose / UseType of dataLegal basis
To register you as a new contact and set up your record on our systems(a) Identity (b) Contact (c) ProfessionalNecessary for our legitimate interests (to manage our contacts and run our business)
To assess, negotiate and complete a possible investment, including reviewing pitch materials, carrying out due diligence and preparing transaction documents(a) Identity (b) Contact (c) Professional (d) Financial (e) Due Diligence(a) Performance of a contract with you (b) Necessary for our legitimate interests (to evaluate and complete investment opportunities)
To carry out anti-money laundering, sanctions, politically exposed person and other regulatory or background checks(a) Identity (b) Contact (c) Financial (d) Due Diligence(a) Necessary to comply with a legal obligation (b) Recognised legitimate interest (detecting, investigating or preventing crime)
To manage our investments and our relationship with portfolio companies, including monitoring performance, exercising our rights as a shareholder and appointing directors or observers(a) Identity (b) Contact (c) Professional (d) Transaction(a) Performance of a contract with you (b) Necessary for our legitimate interests (to protect and manage our investments)
To manage payments, fees, charges and distributions, and to collect and recover money owed to us(a) Identity (b) Contact (c) Financial (d) Transaction(a) Performance of a contract with you (b) Necessary for our legitimate interests (to recover debts due to us)
To manage our relationship with you, including notifying you about changes to our terms or this privacy policy and dealing with your requests, complaints and queries(a) Identity (b) Contact (c) Profile (d) Marketing and Communications(a) Performance of a contract with you (b) Necessary to comply with a legal obligation (c) Necessary for our legitimate interests (to keep our records updated and manage our relationship with you)
To administer and protect our business and our website, including troubleshooting, data analysis, testing, system maintenance, support, reporting, hosting of data and network and information security(a) Identity (b) Contact (c) Technical(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network and information security, to prevent fraud and in the context of a business reorganisation or group restructuring) (b) Necessary to comply with a legal obligation
To deliver our Services and relevant content to you(a) Identity (b) Contact (c) Profile (d) Usage (e) Marketing and Communications (f) Technical(a) Performance of a contract with you (b) Necessary for our legitimate interests (to study how people use our Services, to develop them, to grow our business and to inform our strategy)
To use data analytics to improve our website, our Services and our relationships, and to measure the effectiveness of our communications(a) Technical (b) UsageNecessary for our legitimate interests (to keep our website and Services updated and relevant, to develop our business and to inform our strategy)
To send you relevant updates, marketing and other communications and to make personalised suggestions and recommendations to you(a) Identity (b) Contact (c) Technical (d) Usage (e) Profile (f) Marketing and Communications(a) Necessary for our legitimate interests (direct marketing, developing our Services and growing our business) (b) Consent, having obtained your prior consent to receiving direct marketing communications
To establish, exercise or defend legal claims and to obtain professional advice(a) Identity (b) Contact (c) Professional (d) Financial (e) Transaction (f) Due Diligence(a) Necessary for our legitimate interests (to protect our legal position) (b) Necessary to comply with a legal obligation
To carry out market research through your voluntary participation in surveys(a) Identity (b) Contact (c) ProfileNecessary for our legitimate interests (to understand our market and to help us improve and develop our Services)

Automated decision-making

We do not currently make decisions about you based solely on automated processing that produce legal effects concerning you or that similarly significantly affect you.

If this changes, we will tell you before the decision is made. You will have the right to make representations about the decision, to obtain human intervention and to contest the decision, and we will provide you with information about the decision as required by Articles 22A to 22D of the UK GDPR. We will not make such decisions using special category data unless you have given your explicit consent or the processing is necessary for reasons of substantial public interest.

Direct marketing

When your personal data is collected you may be asked to indicate your preferences for receiving direct marketing communications from us. Otherwise, you will receive marketing communications from us if you have requested information from us, dealt with us in a business capacity or have otherwise not opted out of receiving them.

We may also analyse your Identity, Contact, Professional, Technical, Usage and Profile Data to form a view on which of our activities may be of interest to you, so that we can send you relevant communications.

Third-party marketing

We will get your express consent before we share your personal data with any third party for that third party's own direct marketing purposes.

Opting out of marketing

You can ask us to stop sending you marketing communications at any time by following the opt-out links within any marketing communication sent to you, or by contacting us.

If you opt out of receiving marketing communications, you will still receive communications that are essential for administrative, transactional or contractual purposes.

Cookies and similar technologies

Our website uses cookies and similar storage and access technologies. Under PECR as amended by the Data (Use and Access) Act 2025, some of these require your consent and some do not.

We do not need your consent where the technology is used solely for one of the following purposes:

  • to transmit a communication over an electronic communications network;
  • because it is strictly necessary to provide a service you have requested;
  • to collect information for statistical purposes about how our website is used, with a view to making improvements, where that information is not used to identify you and is not combined with advertising data;
  • to enable you to change the appearance or function of our website, for example remembering your display or language preferences; or
  • to locate you, or enable you to be located, in an emergency.

Where we rely on one of these exceptions, we tell you about it in our cookie policy and you can object at any time using the controls described there. We will stop using the technology for that purpose if you object.

For all other cookies and similar technologies, including anything used for advertising, cross-site tracking or profiling, we will ask for your consent before we set them and you can withdraw that consent at any time.

For more information about the technologies we use and how to change your preferences, please see our cookie policy.

5. Disclosures of your personal data

We may share your personal data, where necessary, with the parties set out below for the purposes set out in the table above:

  • companies within our group, and companies in which we hold or are considering an interest;
  • co-investors, syndicate members, prospective investors and their advisers;
  • professional advisers including lawyers, accountants, tax advisers, auditors, insurers and corporate finance advisers;
  • service providers who provide IT, cloud hosting, communications, document management, identity verification, screening, banking and payment services;
  • HM Revenue & Customs, regulators, law enforcement and other authorities who require reporting of processing activities in certain circumstances; and
  • third parties to whom we may choose to sell, transfer or merge parts of our business or our assets, or whose business we may seek to acquire or merge with. If a change happens to our business, the new owners may use your personal data in the same way as set out in this privacy policy.

We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and we only permit them to process your personal data for specified purposes and in accordance with our instructions, under a written contract.

6. International transfers

Some of our service providers and business contacts are based outside the UK, so processing your personal data may involve a transfer of data outside the UK.

Under the Data (Use and Access) Act 2025, personal data may be transferred out of the UK where the standard of protection in the destination country is not materially lower than the standard under UK data protection law. This is known as the data protection test.

Whenever we transfer your personal data out of the UK, we ensure that at least one of the following applies:

  • the destination country is covered by UK regulations recognising that it provides an appropriate standard of protection, sometimes called adequacy regulations or a data bridge; or
  • we put in place appropriate safeguards, normally the International Data Transfer Agreement or the International Data Transfer Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment carried out on a reasonable and proportionate basis to satisfy ourselves that the data protection test is met; or
  • a specific exception in UK data protection law applies, for example where the transfer is necessary for the performance of a contract with you or for the establishment, exercise or defence of legal claims.

To obtain a copy of the safeguards we use, please contact us.

7. Data security

We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. These include access controls, encryption in transit, multi-factor authentication on our core systems, backups and supplier due diligence. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach. We will report a notifiable breach to the ICO within 72 hours of becoming aware of it and will notify you where the breach is likely to result in a high risk to your rights and freedoms.

8. Data retention

How long will you use my personal data for?

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint, or if we reasonably believe there is a prospect of litigation in respect of our relationship with you.

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, whether we can achieve those purposes by other means and the applicable legal, regulatory, tax, accounting or other requirements.

Our current retention periods are:

CategoryRetention period
Contact, Identity, Financial and Transaction Data relating to customers and counterpartiesSix years after the relationship ends, for tax purposes
Records relating to an investment we holdAt least six years after we dispose of the investment or it is wound up
Pitch materials and correspondence about an opportunity we decide not to pursueUp to 24 months, unless you ask us to delete them sooner
Anti-money laundering and due diligence records, where we are subject to the Money Laundering RegulationsFive years from the end of the business relationship or the completion of the transaction
Marketing and Communications DataUntil you opt out, and for 24 months after your last engagement with us
Website and analytics data14 months

In some circumstances you can ask us to delete your data: see paragraph 9 below.

In some circumstances we will anonymise your personal data, so that it can no longer be associated with you, in which case we may use that information indefinitely without further notice to you.

9. Your legal rights

You have a number of rights under data protection laws in relation to your personal data. You have the right to:

Request access to your personal data (commonly known as a "subject access request"). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it. We will carry out a reasonable and proportionate search for the information you have asked for.

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data corrected, though we may need to verify the accuracy of the new data you provide.

Request erasure of your personal data in certain circumstances. This enables you to ask us to delete or remove personal data where there is no good reason for us to continue processing it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing, where we may have processed your information unlawfully, or where we are required to erase your personal data to comply with local law. Note that we may not always be able to comply with your request for specific legal reasons, which will be notified to you at the time of your request.

Object to processing of your personal data where we are relying on a legitimate interest, or those of a third party, as the legal basis for that particular use of your data, including profiling based on our legitimate interests. In some cases we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.

You also have the absolute right to object at any time to the processing of your personal data for direct marketing purposes.

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. This right only applies to automated information which you initially provided consent for us to use, or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal data (see the table in paragraph 4 for details of when we rely on consent). This will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent we may not be able to provide certain services to you, and we will advise you if that is the case at the time.

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in one of the following scenarios:

  • if you want us to establish the data's accuracy;
  • where our use of the data is unlawful but you do not want us to erase it;
  • where you need us to hold the data even if we no longer require it, as you need it to establish, exercise or defend legal claims; or
  • where you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

Complain to us about how we have handled your personal data, under section 164A of the Data Protection Act 2018, and to complain to the Information Commissioner's Office. See paragraph 11.

If you wish to exercise any of the rights set out above, please contact us.

No fee usually required

You will not have to pay a fee to access your personal data or to exercise any of the other rights. However, we may charge a reasonable fee if your request is manifestly unfounded or manifestly excessive. Alternatively, we could refuse to comply with your request in these circumstances. If we do either of these things we will tell you why, and we will tell you about your right to complain to us and to the ICO.

What we may need from you

We may need to request specific information from you to help us confirm your identity, or to clarify what you are asking for where that is reasonably required for us to respond. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

Time limit to respond

We try to respond to all legitimate requests within one month.

Where we reasonably require confirmation of your identity or clarification of your request in order to respond, the one-month period does not begin, or is paused, until we receive that information from you. Occasionally it could take us longer than a month if your request is particularly complex, or if you have made a number of requests, in which case we may extend the period by up to two further months. We will notify you and keep you updated.

10. Contact details

If you have any questions about this privacy policy or about the use of your personal data, or if you want to exercise your privacy rights, please contact us in the following ways:

Email address: steve.pugh@next11.vc
Postal address: Next 11 Ventures Ltd, The Mount Business & Conference Centre, 2 Woodstock Link, Belfast, County Down, BT6 8DD

Please mark any correspondence about your personal data for the attention of Steve Pugh, Chief Executive Officer.

11. Complaints

Complaining to us

If you are unhappy with how we have handled your personal data you have the right to complain to us. You can do this by email or by post, using the details in paragraph 10, or by any other means by which you normally contact us.

We will:

  • acknowledge your complaint within 30 days of receiving it;
  • make appropriate enquiries into the subject matter of your complaint;
  • keep you informed of progress; and
  • tell you the outcome without undue delay.

Complaining to the regulator

You also have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK regulator for data protection issues, at www.ico.org.uk. We would, however, appreciate the chance to deal with your concerns first, so please contact us in the first instance.

The ICO is in the process of being reconstituted as the Information Commission under the Data (Use and Access) Act 2025. When that change takes effect, references in this policy to the ICO should be read as references to the Information Commission.

12. Changes to the privacy policy and your duty to inform us of changes

We keep our privacy policy under regular review. The date at the top of this policy shows when it was last updated. Where changes are significant we will bring them to your attention directly. Previous versions are available on request.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.

13. Third-party links

Our website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and we are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit or use.