Privacy Policy
1. Data protection at a glance
General information
The following gives a simple overview of what happens to your personal data when you visit this website. Personal data is any data that can be used to personally identify you. More detailed information follows in the sections below.
A) Who is responsible for data processing on this website?
Data processing is carried out by the website operator. Contact details are given in the legal notice and below in Section 2.
B) How do we collect your data?
We collect data in two ways. First, when you actively provide it — for example, by sending us an email or submitting a pitch via our external Typeform. Second, technical data is collected automatically by our hosting provider when you visit the site (e.g. IP address, browser, operating system, page requested, time of request).
C) What do we use your data for?
Technical data is used to deliver the website and keep it secure. With your explicit consent (via the cookie banner), we additionally collect anonymous, aggregated usage statistics to understand which pages are visited.
D) What rights do you have regarding your data?
You have the right, at any time and free of charge, to information about the origin, recipients and purpose of your stored personal data. You also have the right to request correction, restriction or deletion of this data, to object to processing based on legitimate interests, to withdraw any consent given, and to data portability. For these requests and any other data-protection questions, you can contact us at the address given in the legal notice. You also have the right to lodge a complaint with the competent supervisory authority.
2. General information and mandatory disclosures
Data privacy
The operators of this website take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy. Please note that data transmission over the internet can have security vulnerabilities; complete protection of your data from access by third parties is not possible.
Controller
The controller responsible for data processing on this website is:
heal.capital Management GmbH
Rosenthaler Str. 49
10178 Berlin, Germany
Email: info@healcapital.com
The controller is the natural or legal person who, alone or jointly with others, decides on the purposes and means of processing personal data.
Withdrawal of your consent
Where processing is based on your consent, you can withdraw that consent at any time with effect for the future. An informal email to info@healcapital.com is sufficient. The lawfulness of processing carried out before withdrawal remains unaffected.
Right to lodge a complaint
If you believe that the processing of your personal data infringes data protection law, you have the right to lodge a complaint with the competent supervisory authority. For our registered office, this is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
Right to data portability
You have the right to receive data that we process automatically on the basis of your consent or in fulfilment of a contract in a commonly used, machine-readable format. If you request direct transfer of the data to another controller, this will only be done where technically feasible.
Information, correction, deletion
Within the framework of applicable legal provisions, you have the right at any time to receive free information about your stored personal data, its origin and recipients, and the purpose of processing, and where applicable a right to rectification or deletion. You can contact us at any time at the address given above.
3. Data collection on our website
Cookies and local storage
This website does not set tracking cookies before you give consent. The only data we store in your browser by default is a single entry in local storage (`cookie-consent`) that records whether you accepted or declined the cookie banner. This entry contains no personal data and is used solely to remember your choice so the banner is not shown again.
If you accept the banner, we additionally load Vercel Analytics (see Section 4), which by design does not use cookies. If you decline, no analytics are loaded.
You can clear the consent entry at any time via your browser settings; the banner will reappear on your next visit.
Server log files
Our hosting provider Vercel Inc. ("Vercel") automatically collects and stores information that your browser transmits when accessing the site. This typically includes:
• IP address (anonymised or truncated in logs)
• Date and time of the request
• Requested URL and HTTP method
• HTTP status code and bytes transferred
• Referrer URL (if any)
• Browser user agent (browser name, version, operating system)
This data is processed for the purpose of delivering the website, ensuring its stability and security, and investigating abuse. It is not combined with other data sources and is not used to identify individual visitors. The legal basis is Article 6(1)(f) GDPR (legitimate interest in operating a secure website).
4. Analytics
Vercel Analytics
When (and only when) you accept the cookie banner, we load Vercel Analytics, a privacy-friendly, aggregated analytics service provided by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA.
Vercel Analytics does not use cookies, does not track users across sites, does not collect IP addresses in identifiable form, and does not build user profiles. It records anonymous, aggregated events such as page views and referrers, which we use to understand which pages of our website are of interest to visitors.
Legal basis: your consent under Article 6(1)(a) GDPR. You can withdraw consent at any time by clearing the `cookie-consent` entry in your browser's local storage; on your next visit the banner will reappear and no analytics will be loaded unless you accept again.
For further information, see Vercel's privacy documentation at https://vercel.com/legal/privacy-policy.
No other analytics, advertising, or profiling tools are used on this website. In particular, we do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, Hotjar, or similar.
5. External services and embedded resources
To deliver this website we use a small number of external services. Each of these receives your IP address and request metadata when your browser fetches a resource from them. No additional personal data is transmitted unless you actively submit it.
Vercel (hosting and content delivery)
Provider: Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. Vercel hosts this website and delivers its pages and static assets via its global edge network. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reliable website delivery). A data processing agreement is in place.
Fontshare (font delivery)
Provider: Indian Type Foundry ("Fontshare"), loaded from api.fontshare.com, for the "Satoshi" typeface used on this website. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a consistent visual presentation).
unpkg (CSS delivery for the interactive map)
Provider: Cloudflare Inc., via unpkg.com, used to deliver the stylesheet for the Leaflet map library. Legal basis: Art. 6(1)(f) GDPR.
CARTO (map tiles, /ecosystem page only)
Provider: CARTO, loaded from basemaps.cartocdn.com. Used only on the /ecosystem page to render dark-mode map tiles. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in presenting the ecosystem map).
Typeform (pitch submission form)
Provider: TYPEFORM S.L., C/ Bac de Roda 163, 08018 Barcelona, Spain. Our "Submit a Pitch" link opens a form hosted by Typeform; data entered there is processed under Typeform's own privacy policy. No data is sent to Typeform unless you click through and submit the form. Legal basis: Art. 6(1)(b) GDPR (steps prior to entering a contract).
External links
Elsewhere the website links to external services (Substack, LinkedIn, portfolio company websites, etc.). These are plain hyperlinks — nothing is embedded from those services and no data is transmitted to them unless you click the link.
Fonts and assets loaded by the browser are not combined with any user account and are not used to build a profile. We do not transfer personal data outside the EU/EEA except as described above for services with US parent companies; in each case, appropriate transfer mechanisms (e.g. the EU–US Data Privacy Framework, Standard Contractual Clauses) apply.
Last updated: 22/04/2026