Legal

Privacy Policy

Last updated 1 September 2026

Foundsy is the data controller for the personal data described here. This policy explains what we collect, why, how long we keep it, and the rights you have under UK GDPR.

What we collect

  • Account data — name, email, role (creator or investor), and sign-in identifiers from Google or Apple if you use them.
  • Profile and pitch content — everything you publish: bio, track record, project detail, images and documents.
  • Verification data — identity documents, date of birth, address, and company registration details checked against Companies House.
  • Activity data — introduction requests, messages, NDA signatures, data room access logs, saved projects and mandate preferences.
  • Technical data — IP address, device and browser information, and error logs.

Why we use it, and our lawful basis

  • Contract — running your account, matching, introductions, messaging, NDAs and data rooms.
  • Legitimate interests — fraud prevention, rate limiting, audit logging, platform security and product improvement.
  • Legal obligation — identity and company checks, and retaining records of agreements.
  • Consent — optional marketing email, which you can withdraw at any time.

Who sees what

Your public profile and published pitch content are visible to anyone. Confidential documents in a data room are visible only to investors whose request you approved, for the period you set, and every view is logged. Verification documents are never shown to other users — only to our trust team.

We share data with processors who run the platform for us: our cloud hosting and database provider, our transactional email provider, and Companies House for company lookups. We do not sell personal data.

How long we keep it

  • Account and profile data — while your account is open, then 30 days.
  • Identity verification documents — 12 months after a decision, then deleted.
  • Signed NDAs and their audit trail — 6 years, as contract records.
  • Data room access logs — 6 years, as evidence of controlled disclosure.
  • Messages and introduction history — while your account is open, then 12 months.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, or ask us to transfer it. Email us and we will respond within one month. Deletion requests are honoured except where we must retain records — signed NDAs, access logs and verification decisions — for the periods above.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk.

Security

Data is encrypted in transit and at rest. Confidential documents live in a private store and are only ever served through short-lived, expiring links. Access to the database is restricted by row-level security so users can only read their own records.

International transfers

Our infrastructure is hosted in the UK and EU. Where a processor operates outside the UK, transfers are covered by UK adequacy regulations or the International Data Transfer Addendum.

Questions about this page? Contact the Foundsy team.