Konsiteo
Scrupulous Since 1985
Magnificentia
Privacy Notice—Konsiteo Ltd
Effective date: 10 July 2026
Konsiteo Ltd is a company registered in England and Wales, with its registered office at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ (company number 9835328, VAT number GB226792289, ICO registration ZA150392, and Croatian tax identification HR99353656457). Alen Karlović, Founder and Director, may be contacted by email at alen@konsiteo.com—OpenPGP-encrypted correspondence is encouraged, using the public key published at konsiteo.com, fingerprint 74E5 1E59 C219 E13C A611 4E4A 2966 8E19 C842 C2E3—or by end-to-end encrypted Signal communication. These contact details constitute the formal address for all data-related communications and enquiries addressed to the controller. This notice satisfies the transparency obligations set out in Articles 12, 13, and 14 of the UK General Data Protection Regulation and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. Where personal data is transmitted to this practice by individuals located within the European Union, processing is conducted in equal compliance with Regulation (EU) 2016/679 (EU GDPR). It is written not because the law requires words, but because this practice is constituted around a disposition that predates any regulatory framework: the refusal to hold anything—including another person's information—without accountability to a standard higher than what is merely permitted. What follows is that account, given plainly and completely.
What this website does not do
This website is hosted on servers located within the European Union in Amsterdam, The Netherlands. As is standard with all web hosting, the hosting infrastructure may generate server access logs—recording technical data such as IP addresses, timestamps, URLs of pages requested, HTTP status codes, data volumes transferred, referrer addresses, and user-agent strings (which may indicate the browser and operating system in use)—as a routine function of delivering web pages. This technical logging is an inherent function of internet infrastructure, is not used by this practice for any analytical or commercial purpose, and is governed by the hosting provider's own data processing terms. This practice does not access, analyse, or use data collected in this way for any purpose relating to individual visitors. That it could is not a reason to do so—it is precisely the kind of question this practice holds itself answerable to. This website collects no tracking data, deploys no analytics platform, and sets no cookies of any kind—not functional, not analytical, not marketing, not statistical. This website does not load any third-party scripts, stylesheets, or external resources during page render. All fonts are self-hosted and served locally from our website server. No requests are made to external typography providers, content delivery networks, or any other third party as a result of visiting this site, and accordingly no technical data (such as your IP address or browser headers) is transmitted to third parties in connection with font delivery. No device fingerprinting is performed. No pixel, tag, beacon, or link-decoration technique is used to observe, record, or transmit your behaviour, your identity, or your device characteristics to any party, including to Konsiteo itself. You arrive here, you read, and you leave—without leaving a trace that this practice has authored or permitted. The absence of cookies and tracking is not a compliance posture. It is the simplest expression of a practice organised around one principle: that what cannot be defended before a genuinely sovereign faculty has no place here—not in counsel, and not in the infrastructure through which counsel is offered.
What personal data is collected, and how
The only personal data processed by Konsiteo is information that you choose, freely and deliberately, to transmit directly to Alen Karlović: your name, your email address—together with the technical metadata inherent in the transmission, such as timestamps and mail server headers—and the substance of your communication, whether delivered by email to alen@konsiteo.com or by encrypted Signal message. No web form, submission engine, session token, or behavioural tracking mechanism captures visitor information. The data that reaches this practice arrives because you sent it—and only because you sent it. When, following assessment, an individual is accorded placement upon the private register, the personal data transmitted in the course of that approach is retained and held as described in the retention section of this notice. Placement upon the private register is itself a form of active data holding: the individual's details are maintained by this practice in connection with a continuing consideration, and they are processed accordingly under the terms described here. Where a covenantal advisory relationship is entered into, this practice additionally collects a copy of the client's valid passport or national identity document, together with a written declaration of the source of funds intended for the engagement and any supporting documentation the client provides in connection with that declaration. This category of personal data is collected at the points described in the engagement itself—before the initiation fee, and again before the commitment fee where a material period has passed or the capital presented has changed—and plays no part in any correspondence preceding those stages. End-to-end encrypted Signal communication is the preferred channel for all correspondence with this practice. Email transmitted without OpenPGP encryption travels over standard SMTP infrastructure and is not end-to-end encrypted in transit; this practice therefore publishes the necessary public key, precisely because unencrypted email is not a channel worthy of the confidence this practice asks its correspondents to place in it. Signal messages, like email, constitute a deliberate transmission of personal data to this practice and are processed under the same terms described in this notice. These measures are not offered as features—they are the natural expression of a practice that treats the privacy of those who approach it as a responsibility that runs prior to and independent of any legal obligation.
Why that data is processed and on what legal basis
The personal data you choose to transmit is processed for one purpose only: to consider your correspondence and, where appropriate, to respond to it within the terms this practice has described. The lawful basis for this processing is the legitimate interest of both parties in conducting a private and substantive enquiry. The legitimate interest relied upon is the mutual interest of the person writing to this practice and of Konsiteo in exchanging substantive, private correspondence in connection with a potential or ongoing advisory engagement. This interest is not overridden by the data subject's rights, given the absence of any profiling or third-party sharing, the minimal scope of data involved, and the reasonable expectation of anyone who initiates direct contact that their correspondence will be read and considered—an interest that, given the nature of this practice and the deliberate choice made by anyone who writes to it, clearly outweighs any privacy intrusion. Where a covenantal advisory relationship is entered into, the additional processing required to perform that contract is conducted on the basis of contractual necessity, and that processing will be described in the engagement documentation provided at that stage. The engagement documentation will itself satisfy the transparency requirements of Article 13 of the applicable regulation in respect of that additional processing, and will stand as a complete disclosure for the purposes of the advisory relationship. Identification documents and source-of-funds information are collected and processed on the basis of legal obligation, in accordance with anti-money laundering legislation applicable to those who provide advisory and wealth management of the kind this practice offers. Fees are settled exclusively by bank transfer; the payment details transmitted in that process are processed on the basis of contractual necessity and retained in accordance with applicable financial record-keeping obligations.
How long personal data is retained
Correspondence is retained for as long as the relationship that it documents remains active and, thereafter, for such period as is necessary to protect the legitimate interests of both parties in the event of any subsequent enquiry or dispute—a period not exceeding seven (7) years from the conclusion of the relevant engagement or correspondence. Where no advisory relationship follows from an initial approach, correspondence is retained for no longer than is reasonably necessary to conclude the exchange and, in any event, for no more than two (2) years. Where an individual has been accorded placement upon the private register, personal data is retained for the duration of that placement. Where that placement does not result in an invitation to the private waiting list, personal data is retained for no longer than two (2) years from the date of the most recent correspondence, following which it is deleted without further notice. Where placement upon the private register is followed by an invitation to the private waiting list, the retention terms applicable to the private waiting list apply from the date of that invitation. Where an individual has been placed on the private waiting list (by correspondence transmitted through the channels described above), personal data is retained for the duration of that placement and for a period not exceeding seven (7) years thereafter, in accordance with the same terms as apply to an active engagement. Identification documents and source-of-funds records are retained for the period required under applicable anti-money laundering law, being not less than five (5) years from the conclusion of the engagement to which they relate, and are not retained beyond the point at which that legal obligation ceases to apply. Identification documents, source-of-funds declarations, supporting financial documentation, and instruments of engagement are held in encrypted storage, accessible only to the person to whom this practice belongs, and are not stored on shared, third-party, or general-purpose systems. No personal data is retained beyond these periods without a renewed purpose that can be independently justified.
With whom personal data is shared
Personal data transmitted to this practice is not shared with any third party for any purpose. It is not sold, licensed, or otherwise transferred to data brokers, marketing platforms, analytics providers, or any entity whose purpose is the secondary use of personal information. Where legal obligations or regulatory requirements compel disclosure—for instance, to a regulator, a court, a data protection authority in the jurisdiction of the client, or a financial institution in the course of meeting applicable compliance obligations—disclosure will be made to the minimum extent required and will not be treated as a routine matter. Where Konsiteo is required to conduct client due diligence or meet anti-money laundering obligations under applicable law, personal data may be processed for that purpose on the basis of legal obligation. Identification and source-of-funds records are not shared beyond what is strictly required to meet that legal obligation, and are never used for any purpose beyond it. Where a client signs the instrument of engagement electronically, the Qualified Trust Service Provider used to issue the signature processes the personal data necessary to verify identity and issue the signature, under its own privacy notice and as an independent controller for that purpose. The legal counsel and banking relationships engaged by Konsiteo in the ordinary course of its operations are bound by confidentiality obligations that reflect the standards this practice holds in every dimension of its conduct.
International transfers
Konsiteo Ltd's registered office is in England and Wales; the practice is rooted in Rijeka, Croatia, within the European Union (Konsiteo Ltd, Dobriše Cesarića 24, 51000 Rijeka, Croatia, OIB: 99353656457), and operates across jurisdictions. Personal data may therefore move between these two jurisdictions in the ordinary course of correspondence and engagement. The United Kingdom holds an adequacy decision under EU GDPR, renewed in December 2025 and valid until December 2031, meaning that data flowing between Croatia and the UK travels under conditions recognised as providing equivalent protection—without the need for additional transfer safeguards. Where data moves beyond these two jurisdictions, such transfers are conducted in accordance with the requirements of UK GDPR Article 46 and EU GDPR Article 46, under appropriate safeguards, and subject to the same principle of necessity that governs all processing within this practice. Where correspondence is initiated by, or an advisory engagement is entered into with, an individual located outside the United Kingdom and the European Union, the personal data transmitted in the course of that relationship may involve a transfer of data to or from a jurisdiction that does not benefit from an adequacy decision. In such cases, transfers are conducted on one or both of the following bases: where a contract for advisory services is in place or is being formed, the transfer is necessary for the performance of that contract, pursuant to Article 49(1)(b) of EU GDPR and the equivalent UK GDPR provision; and where an engagement letter is issued, it incorporates appropriate transfer safeguards as required by Article 46 of EU GDPR and the ICO's International Data Transfer Agreement under UK GDPR. In all cases, the same principles of minimum data, confidentiality, and purpose limitation that govern this practice's handling of EU and UK personal data apply without modification to data relating to clients and correspondents in any jurisdiction.
Your rights
Under the UK General Data Protection Regulation, the Data Protection Act 2018, and—where applicable—Regulation (EU) 2016/679, you hold rights in relation to the personal data this practice holds about you. These include the right to be informed—which this notice fulfils—the right to access the personal data held, the right to rectify any inaccuracy, the right to erasure where the data is no longer necessary for the purpose for which it was collected, the right to restrict processing in certain circumstances, and the right to object to processing conducted on the basis of legitimate interest. Where processing is conducted on the basis of contractual necessity—as described above in relation to covenantal advisory engagement—you also hold the right to receive the personal data you have provided to this practice in a structured, commonly used, and machine-readable format, and to transmit that data to another controller (the right to data portability). Consent is not relied upon as a lawful basis for any processing within this practice; accordingly, no right to withdraw consent arises in relation to any processing described in this notice. No automated decision-making occurs within this practice. The examination this counsel is built around cannot be delegated to an algorithm—it is conducted by one person, who reads what you write, considers what it means, and responds from a faculty that has itself been examined. To exercise any of these rights, or to raise a concern about the processing of your personal data, please write to alen@konsiteo.com. All data protection complaints will be acknowledged within one calendar month of receipt and investigated without undue delay, with the complainant kept informed of progress throughout. If you remain unsatisfied following the conclusion of that process, you have the right to lodge a complaint with the Information Commissioner's Office. If you are located within the European Union, you also hold the right to lodge a complaint with the data protection supervisory authority of your Member State of habitual residence—including, where that Member State is Croatia, the Croatian Personal Data Protection Agency.
Changes to this notice
This notice reflects the practice as it stands at the effective date shown above. Should the processing activities described here change in any material respect, this notice will be updated and the revised effective date will be shown. The governing logic of this practice—the refusal to hold data beyond what is necessary, the commitment to encrypted communication, and the absence of any tracking or profiling—will not change, because it does not originate in regulation.
