Privacy Policy
Effective Date: 13 June 2026
1. Introduction and Controller Identity
1.1 Fundable Oy (“Fundable”, “we”, “us”, or “our”) respects your privacy and is committed to processing personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), the Finnish Data Protection Act (1050/2018), and other applicable data protection laws.
1.2 For the purposes of the GDPR, Fundable Oy is the data controller in respect of the personal data described in this Privacy Policy, except where Fundable acts as a data processor on behalf of an Investor User (see Section 9). Contact: privacy@fundable.app.
2. Scope
2.1 This Privacy Policy describes how Fundable collects, uses, discloses, retains, and protects information in connection with (a) the no-login founder audit service, and (b) the integrated investor inbound feature (the “Investor Feature”).
3. Data We Collect
3.1 Founder Submissions (No-Login). When a founder uses the Service without creating an account, we transiently process: (i) the textual content or PDF pitch deck submitted; (ii) basic technical metadata necessary for service delivery (IP address, user-agent, timestamp); and (iii) any optional email address provided to receive a copy of the Audit Output.
3.2 Investor Feature Data. When an Investor User activates the Investor Feature, we process: (i) email metadata associated with inbound submissions (sender address, subject line, timestamp, recipient mailbox identifier); (ii) email body content and attached pitch materials; and (iii) the Investor User’s account credentials and configuration settings.
3.3 Account Data (Registered Users). For registered users, we process name, email address, organisation, authentication credentials (in hashed form), and audit history.
3.4 Usage and Diagnostic Data. Aggregated and anonymised usage statistics, error logs, and performance telemetry that do not identify individuals.
4. Legal Bases for Processing
4.1 We process personal data on the following legal bases under Article 6(1) GDPR:
- (a) Performance of a contract — to deliver the Service you request (Art. 6(1)(b)).
- (b) Legitimate interests — to secure, maintain, and improve the Service in a manner consistent with our zero-retention and no-training commitments (Art. 6(1)(f)).
- (c) Legal obligation — to comply with applicable law (Art. 6(1)(c)).
- (d) Consent — where you have expressly opted in, such as to receive a copy of your Audit Output by email (Art. 6(1)(a)).
5. Zero-Retention and Ephemerality
5.1 Strict Deletion Protocol. For non-registered founder users, all submitted pitch materials, file contents, and extracted text are deleted from Fundable’s processing systems immediately upon completion of the analysis and delivery of the Audit Output. No copy, mirror, backup, or derivative artefact of the submitted content is retained on Fundable’s production or backup infrastructure beyond the transient processing window required to generate the Audit Output.
5.2 Transient processing buffers used by the Service are flushed automatically as part of the analysis lifecycle, and in any event within a period not exceeding the time strictly necessary to deliver the Audit Output.
5.3 For Investor Users, materials processed through the Investor Feature are retained only for as long as required to populate and display the investor dashboard, and are subject to the Investor User’s configured retention period (which the Investor User may set to immediate deletion).
5.4 Where you have provided an email address to receive your Audit Output, we retain that email address solely for delivery of the requested message and, where you have consented, for limited follow-up communications until you withdraw consent.
6. AI Training Policy — Strict Prohibition
6.1 No Training, Ever. Fundable shall NOT use, and contractually prohibits its subprocessors from using, any User Content, pitch deck, document, text, attachment, or other material submitted by founders or forwarded through the Investor Feature for the purpose of training, fine-tuning, retraining, evaluating, benchmarking, or otherwise improving any artificial-intelligence model, large language model, machine-learning system, or algorithm, whether proprietary to Fundable or operated by a third party.
6.2 Where Fundable relies on third-party model providers to generate the Audit Output, Fundable transmits content exclusively under contractual terms (such as zero-data-retention or no-training enterprise endpoints) that prohibit such providers from logging, retaining, or using the content for model improvement.
6.3 This prohibition is a core, non-negotiable commitment of the Service and may be relied upon as a material representation.
7. Data Security
7.1 Fundable implements appropriate technical and organisational measures to safeguard personal data, including: (a) Transport Layer Security (TLS 1.2 or higher) for all data in transit; (b) AES-256 encryption for any data at rest within the transient processing window; (c) strict role-based access controls and the principle of least privilege; (d) network segmentation and hardened production infrastructure; (e) logging, monitoring, and intrusion detection; and (f) regular review of security practices.
7.2 No method of transmission or storage is completely secure; however, Fundable maintains a security programme designed to protect personal data against unauthorised access, alteration, disclosure, or destruction.
8. Sharing and Disclosure
8.1 Fundable does not sell personal data. We disclose personal data only to: (a) vetted subprocessors who provide infrastructure, hosting, or model-inference services under contractual terms consistent with this Privacy Policy and the GDPR; (b) competent authorities where required by law; and (c) successors in interest in connection with a merger, acquisition, or sale of assets.
8.2 International transfers outside the European Economic Area, if any, are carried out on the basis of Standard Contractual Clauses adopted by the European Commission or another lawful transfer mechanism.
9. Role in the Investor Feature
9.1 When Fundable processes personal data contained in inbound pitch materials on behalf of an Investor User, Fundable acts as a data processor and the Investor User acts as data controller. Such processing is governed by a Data Processing Agreement entered into between the parties pursuant to Article 28 GDPR.
10. Your Rights under the GDPR
10.1 Subject to the conditions set out in the GDPR, you have the right to:
- (a) Access — obtain confirmation as to whether personal data concerning you is being processed and obtain a copy thereof (Art. 15).
- (b) Rectification — request correction of inaccurate or incomplete personal data (Art. 16).
- (c) Erasure — request deletion of your personal data, the “right to be forgotten” (Art. 17).
- (d) Restriction — request restriction of processing (Art. 18).
- (e) Data portability — receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller (Art. 20).
- (f) Object — object to processing based on legitimate interests (Art. 21).
- (g) Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal (Art. 7(3)).
- (h) Lodge a complaint — with the Finnish Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) or another competent supervisory authority (Art. 77).
10.2 Requests may be addressed to privacy@fundable.app. We respond within one (1) month, extendable by two (2) further months where necessary under Article 12(3) GDPR.
10.3 Given the zero-retention nature of the Service, for non-registered founder users there is typically no personal data remaining for Fundable to access, rectify, or erase following the completion of the analysis.
11. Retention
11.1 Personal data is retained only for as long as necessary for the purposes for which it was collected, as further described in Section 5, and in any event in accordance with applicable legal retention obligations.
12. Cookies and Similar Technologies
12.1 The Service uses only strictly necessary cookies for session and security purposes. Any non-essential cookies are deployed solely on the basis of your prior consent, which may be withdrawn at any time.
13. Children
13.1 The Service is not directed to persons under the age of eighteen (18), and we do not knowingly process personal data of children.
14. Changes to this Privacy Policy
14.1 Fundable may update this Privacy Policy from time to time. Material changes will be communicated through the Service or by email. The “Effective Date” at the top of this document indicates the date of the latest revision.
15. Contact
15.1 For any question, request, or complaint regarding this Privacy Policy or our data-processing practices, please contact: privacy@fundable.app.