PRIVACY POLICY

Last updated: 19 August 2026

1. About Mercurius OS

Mercurius OS is a trade name of Incapital B.V., a company incorporated under the laws of the Netherlands.

Mercurius OS develops technology and services designed to connect data, systems, artificial intelligence, workflows and human decision-making within an intelligent operating environment.

For the purposes of this Privacy Policy, references to “Mercurius OS”, “we”, “us” or “our” mean Incapital B.V., unless otherwise stated.

Incapital B.V.
Keizersgracht 391 A
1016 EJ Amsterdam
The Netherlands

Email: info@mercuriusos.com

Mercurius OS operates internationally and may work with customers, partners, technology providers and other parties in different countries.

Our website may refer to our global network, including Amsterdam, Bengaluru and Silicon Valley. These references describe our international business network and do not imply that separate Mercurius OS legal entities operate in each of these locations.


2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, store and protect personal data when you:

  • visit the Mercurius OS website;
  • contact us;
  • submit information through a form;
  • communicate with us about our technology or services;
  • become, or consider becoming, a customer, partner or supplier;
  • otherwise interact with Mercurius OS in a business context.

Where Mercurius OS processes personal data on behalf of a customer as part of services provided to that customer, the customer may act as the data controller and Incapital B.V. may act as a data processor.

Such processing will be governed by the applicable customer agreement and, where required, a Data Processing Agreement.


3. Personal Data We May Collect

Depending on how you interact with us, we may collect personal data including:

Contact information
Such as your name, business email address, telephone number, job title, company and country.

Communication information
Information contained in emails, contact forms, meeting requests and other communications with us.

Business information
Information about your organisation, role, business requirements, technology environment and potential interest in Mercurius OS.

Website and technical information
Such as IP address, browser type, device information, pages visited, referral information and technical information relating to your use of our website.

Customer and supplier information
Information necessary to establish and manage a commercial relationship, enter into agreements, provide services, administer accounts and meet legal or financial obligations.

We aim to collect only the personal data that is relevant and necessary for the purpose for which it is processed.


4. How We Collect Personal Data

We may obtain personal data:

  • directly from you;
  • when you contact us or submit a form;
  • during meetings and business communications;
  • through our website and associated technologies;
  • from your organisation;
  • from business partners or service providers;
  • from professional networks and publicly available business sources where permitted by law.

When personal data is obtained from third-party or publicly available sources, we process that information in accordance with applicable data protection law.


5. How We Use Personal Data

We may use personal data to:

  • respond to enquiries;
  • communicate with customers, prospects, partners and suppliers;
  • evaluate business requirements and potential applications of Mercurius OS;
  • arrange meetings and demonstrations;
  • prepare proposals and agreements;
  • provide and support our services;
  • manage customer and supplier relationships;
  • improve our website, technology and services;
  • maintain the security and integrity of our systems;
  • operate and develop our business;
  • communicate relevant information about Mercurius OS;
  • comply with legal and regulatory requirements;
  • establish, exercise or defend legal claims.

We do not use personal data for purposes that are incompatible with the purpose for which the information was collected unless permitted by law.


6. Legal Bases for Processing

Where the General Data Protection Regulation (GDPR) applies, we process personal data only where we have a lawful basis.

Depending on the circumstances, this may include:

Contract
Where processing is necessary to enter into or perform an agreement.

Legitimate interests
Where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. This may include responding to business enquiries, managing professional relationships, improving our services, protecting our systems and conducting appropriate business-to-business communications.

Legal obligation
Where processing is necessary to comply with applicable law.

Consent
Where we specifically ask for your consent, for example for certain cookies or communications where consent is legally required.

Where processing is based on consent, you may withdraw that consent at any time.

These are among the recognised legal bases under the GDPR.


7. AI and Mercurius OS Technology

Artificial intelligence is central to the technology and services developed by Mercurius OS.

The use of AI does not remove the need for responsible data governance.

Where our services involve the processing of personal data, the applicable role of Incapital B.V. — as controller or processor — will depend on the specific service, contractual relationship and processing activity.

Where we process personal data on behalf of a customer, we will process such data in accordance with the applicable agreement, documented instructions and data protection requirements.

We may use third-party technology and AI providers as part of our technology infrastructure. Where such providers process personal data on our behalf, appropriate contractual and data protection arrangements will be implemented as required.


8. Automated Decision-Making

We do not currently use personal data collected through this website to make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.

If this changes, we will provide appropriate information and safeguards as required by applicable law.


9. Cookies and Website Technologies

Our website may use cookies and similar technologies required for the website to function and, where applicable, to understand how the website is used.

Essential cookies may be used where necessary for the operation and security of the website.

Analytics, advertising or other non-essential cookies will only be used in accordance with applicable requirements, including obtaining consent where required.

You can manage applicable cookie preferences through the cookie settings provided on our website.

Where consent is required, continuing to browse the website will not by itself be treated as consent.

That laatste is belangrijk: de Autoriteit Persoonsgegevens bevestigt expliciet dat scrollen of doorgaan met een website geen geldige actieve toestemming voor trackingcookies vormt.


10. Sharing Personal Data

We do not sell personal data.

We may share personal data where necessary with:

  • technology and cloud service providers;
  • website, hosting and IT providers;
  • professional advisers;
  • payment, accounting and administrative service providers;
  • business partners involved in providing agreed services;
  • competent authorities where required by law;
  • other service providers acting on our behalf.

We require service providers that process personal data on our behalf to handle that information appropriately and in accordance with applicable data protection requirements.


11. International Data Transfers

Mercurius OS operates in an international technology environment and may use service providers or work with organisations located outside the European Economic Area (EEA).

This does not mean that personal data is automatically transferred to every country in which Mercurius OS has business relationships or network activities.

Where personal data is transferred outside the EEA, we take appropriate measures to ensure that the transfer complies with applicable data protection law.

Depending on the circumstances, these measures may include:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses approved by the European Commission; or
  • another legally recognised transfer mechanism.

The GDPR requires safeguards when personal data is transferred outside the EEA; SCCs are one of the mechanisms available for this purpose.


12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected.

Retention periods may depend on:

  • the nature of our relationship with you;
  • the purpose for which the data is processed;
  • contractual requirements;
  • legal and regulatory obligations;
  • the need to establish, exercise or defend legal claims.

When personal data is no longer required, we will delete or anonymise it where appropriate.

This reflects the GDPR principle that personal data should not be retained longer than necessary and that organisations should establish appropriate retention or review periods.


13. Data Security

We take appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

These measures are reviewed and developed in accordance with the nature of our operations, the information involved and evolving technology and security risks.

No internet transmission or information system can, however, be guaranteed to be completely secure.


14. Your Rights

Where the GDPR applies, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to certain processing;
  • receive certain personal data in a portable format;
  • withdraw consent where processing is based on consent;
  • object to direct marketing;
  • exercise applicable rights concerning automated decision-making.

These rights are subject to the conditions and limitations provided by applicable law.

To exercise your rights, contact:

info@mercuriusos.com

We may request information necessary to verify your identity before processing a request.


15. Marketing Communications

We may contact existing and prospective business relationships about Mercurius OS where permitted by applicable law.

Where required, we will obtain consent before sending marketing communications.

You may opt out of marketing communications at any time by using the unsubscribe option provided in the communication or by contacting us at:

info@mercuriusos.com

We may continue to send non-marketing communications where necessary for an existing business or contractual relationship.


16. Third-Party Websites and Services

Our website may contain links to websites or services operated by third parties.

We are not responsible for the privacy practices, security or content of third-party websites or services.

We recommend reviewing the privacy information of the relevant third party before providing personal data.


17. Children

Mercurius OS provides business technology and services and is not directed at children.

We do not knowingly collect personal data from children through our website for commercial purposes.


18. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our website, technology, services, business operations or applicable law.

The most recent version will be published on this website together with the date of the latest update.


19. Contact

Questions about this Privacy Policy or the way we process personal data can be directed to:

Mercurius OS
a trade name of Incapital B.V.

Keizersgracht 391 A
1016 EJ Amsterdam
The Netherlands

Email: info@mercuriusos.com


20. Supervisory Authority

If you believe that your personal data has been processed in violation of applicable data protection law, you have the right to lodge a complaint with a competent supervisory authority.

For Incapital B.V. in the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).

You may also have the right to contact the supervisory authority in the EU/EEA country where you live or work.