Sommaire

Information notice

Makers fund – Digital Platform — Version 2.0 – May 2026 — pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR)

I. Introduction

This Policy governs the processing, including the collection, use, storage, disclosure, and protection (hereinafter "processing") of your personal data (hereinafter "Personal Data") that is processed by MIMCO Asset Management S.A.S. (hereinafter "MIMCO") when you visit the Platform, when you create or use your account, when you subscribe to the Makers fund, or in the context of any relationship with Makers fund.

Personal Data refers to any information relating to an identified or identifiable natural person. It does not include anonymized or aggregated data that does not allow for the identification of an individual.

MIMCO places great importance on the protection of personal data and is committed to processing it in accordance with the GDPR and applicable regulations.

II. Data controller

Personal data collected via the Platform is processed by:

MIMCO Asset Management S.A.S.
Simplified joint-stock company (S.A.S.) under French law
62 Rue Miromesnil, 75008 Paris, France
RCS number: 898 003 124
Email: office@mimco-am.com

MIMCO, in its capacity as data controller, implements all necessary technical and organizational measures to protect Personal Data against unauthorized access, modification, disclosure, or destruction.

III. Data collected

In the course of using the Platform and subscribing to the Fund, MIMCO may collect and process the following categories of data:

1. Identification data

Last name, first name, preferred name, date and place of birth, nationality(ies), gender, postal address, email address, phone number, copy of identity document, identity document number and expiry date.

2. Personal and family situation data

Marital status, matrimonial regime, number of dependents, country of tax residence, tax identification number (TIN), and tax status.

3. Professional data

Profession, employer, industry, professional status, and primary source of income.

4. Financial and wealth data

Annual income, estimated net worth, asset allocation, source of funds, investment capacity, IBAN and banking information, and history of investments made via the Platform.

5. Suitability and product knowledge data

In accordance with applicable regulatory obligations: investment objectives, investment horizon, risk tolerance, investment experience, knowledge of financial instruments, responses to suitability questionnaires, and risk understanding attestations.

6. Regulatory data (AML-CFT / KYC)

Information regarding beneficial owners, politically exposed persons (PEPs), declarations of source of funds, additional supporting documents required by regulation, and results of checks performed as part of legal obligations.

7. Supporting documents

Depending on the user profile (individual, legal entity, partner, etc.): company bylaws, business registration extracts or equivalent, identification documents for directors, meeting minutes, powers of attorney, and any documents required under regulatory obligations.

8. Technical and connection data

IP address, connection logs, timestamps, technical identifiers, browsing data, and data from cookies (in accordance with the Cookie Policy).

9. Partner data

For partner access to the Platform: professional identification information, data relating to accreditation or regulatory status, and verification documents (KYD).

IV. Purposes and legal bases

Data is processed for the following purposes:

  • a) Creation and management of the user account and profile Legal basis: contractual performance.
  • b) Processing of subscription requests for the Fund — Legal basis: contractual performance.
  • c) Compliance with regulatory obligations (KYC, AML-CFT, FATCA, CRS) — Legal basis: legal obligation.
  • d) Management of redemption requests — Legal basis: contractual performance.
  • e) Security and integrity of the Platform — Legal basis: legitimate interest.
  • f) Communication of information relating to the Fund (reporting, NAV, distributions) — Legal basis: contractual performance.
  • g) Management of partner and financial advisor relationships — Legal basis: contractual performance or legitimate interest.
  • h) Commercial prospecting — Legal basis: consent.

V. Data recipients

Personal data may be transmitted to the following recipients, strictly within the scope of their duties:

  • Fundcraft Services S.à r.l., in its capacity as the Fund's administrative agent and Transfer Agent, responsible for maintaining the register of shares, KYC validation, and processing subscriptions and redemptions;
  • Ascender, in its capacity as the Fund's AIFM, in accordance with its regulatory obligations;
  • EFG Bank (Luxembourg) S.A., in its capacity as the Fund's depositary;
  • Wizards, the technical service provider responsible for the development and maintenance of the Platform;
  • distributor partners and financial advisors (CGP), within the framework of the client relationship they maintain with their own investors;
  • competent authorities (tax authorities, financial regulators, judicial authorities) when required by regulation.

Each recipient is required to process personal data solely on the instructions of MIMCO, in accordance with this Policy and by applying appropriate security and confidentiality measures.

VI. Subcontractors

MIMCO may use subcontractors for the development and technical maintenance of the Platform, data hosting, and fund administration. These subcontractors are carefully selected and bound by contractual obligations in compliance with the GDPR.

Data is hosted within the European Union.

VII. Transfers outside the European Union

MIMCO strives to keep personal data within the European Union. In the event that a transfer outside the EU becomes necessary, particularly in the context of FATCA or CRS regulatory obligations, MIMCO ensures that appropriate safeguards are in place in accordance with the GDPR (standard contractual clauses, European Commission adequacy decisions).

VIII. Retention periods

Personal data is kept for the time strictly necessary for the purposes for which it is collected, and at a minimum for the periods required by applicable regulations.

For information: KYC and AML-CFT data are kept for a minimum period of 5 years after the end of the business relationship, in accordance with applicable AML-CFT regulations; accounting and financial data are kept in accordance with applicable legal obligations; connection data is kept for a maximum period of 12 months.

IX. Security

MIMCO implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data and to protect it against loss, alteration, unauthorized disclosure, or unlawful access. These measures are regularly reviewed and updated.

X. Data subject rights

Within the limits of applicable personal data protection laws, you have the following rights:

  • Right of access : to obtain confirmation that your data is being processed and to receive a copy of it;
  • Right to rectification : to have inaccurate or incomplete data corrected;
  • Right to erasure : request the deletion of your data, subject to legal retention obligations;
  • Right to restriction of processing : request the temporary suspension of the processing of your data;
  • Right to object : object to the processing of your data based on legitimate interest or for direct marketing purposes;
  • Right to data portability : receive your data in a structured, commonly used, and machine-readable format, and transmit it to another controller;
  • Right to withdraw your consent : at any time, for processing based on your consent (notably for direct marketing), without affecting the lawfulness of processing carried out prior to such withdrawal.

These rights may be exercised by contacting the Data Protection Officer (DPO) at the following address: office@mimco-am.com

A response will be provided within one month of receiving your request; this period may be extended by two additional months for complex or multiple requests.

XI. Complaints to the Competent Authority

If you believe that the processing of your Personal Data by MIMCO violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority.

For users residing in France, the competent authority is:

Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy – TSA 80715 – 75334 Paris Cedex 07
www.cnil.fr

For users residing in another EEA member state, complaints may be filed with the data protection authority in your country of habitual residence.

XII. Updating Your Personal Data

You are responsible for keeping your Personal Data up to date and informing MIMCO of any changes, particularly regarding your tax, professional, or financial situation, insofar as this information is necessary for the fulfillment of your regulatory or contractual obligations.

XIII. Policy Modifications

MIMCO reserves the right to modify this Policy at any time, particularly to reflect changes in applicable regulations or processing practices. The version currently in effect will always be available on the Platform. In the event of a material change, users will be notified by any appropriate means.