Privacy Policy
This Privacy Policy explains how we collect, use, disclose, and protect your personal information. By using our Service, you agree to the collection and use of information as described in this policy.
Welcome to our fundraising platform ("Platform", "Service"). This Privacy Policy explains how we, as a company registered in the United Arab Emirates ("we", "us", or "our"), collect, use, disclose, and protect your personal information. By using our Service, you agree to the collection and use of information as described in this policy. We are committed to protecting your privacy and handling your personal data transparently and securely.
2. Information We Collect
We collect various types of information from you during account creation, onboarding, and use of our Platform:
- Personal Identification Information: Name, email address, phone number, and password (for account registration and login).
- Profile and Company Information: Details you provide during onboarding such as your location, company name, industry/sector, company size, and any preferences.
- Payment Information: If you subscribe, we collect billing details but not your full credit card numbers. Payment transactions are handled by Stripe. Your credit card information is transmitted directly to Stripe and is not stored on our servers.
- Usage Data: Information about how you use the Platform, e.g. the investors you view or shortlist, status updates you assign, and when you use features like AI email drafting.
- Communication Data: If you draft or send communications through our Platform, we may process the content of those messages and the recipient details.
- Cookies and Tracking Technologies: We use cookies or similar technologies to provide essential functionality and to analyze usage of our Service.
- Investor and Third-Party Data: As part of operating the Platform, we process personal data relating to investors ("Investor Data"). Investor Data typically includes professional information such as name, firm affiliation, professional title, business email address, geographic location, investment preferences, and professional biography. We do not collect or publish sensitive personal data about listed investors. See Section 2A below.
2A. Sources of Information and Legal Basis for Processing
Under applicable data protection law, including UAE PDPL and GDPR, we are required to identify the sources of personal data we process and the legal basis on which we rely.
2A.1. Sources of Personal Data
- Directly from you (users): Account registration details, profile and company information, content you submit, payment information, and any communications you send to us or through the Platform.
- Publicly available sources: For Investor Data, we compile from investor and firm websites, public filings, professional networking profiles, press releases, and industry publications.
- Third-party data providers: We obtain certain Investor Data from commercial data providers with contractual relationships.
- User contributions and corrections: Users may submit corrections or updates to Investor Data.
- Automated collection: Usage data, log data, device and browser information, and cookie-based data.
2A.2. Legal Basis for Processing
- Performance of a contract: For user data, we process your personal data as necessary to provide the Platform and perform our obligations under our Terms of Service.
- Legitimate interests: For Investor Data, we rely on our legitimate interests in operating a fundraising facilitation platform.
- Consent: Where required by applicable law, we rely on your freely given consent, for example for non-essential cookies and marketing communications.
- Legal obligation: We process certain personal data to comply with our legal and regulatory obligations.
2A.3. Automated Decision-Making and AI Processing
We use artificial intelligence to assist users in drafting outreach emails and to rank or filter investor profiles. These are decision-support features, not automated decisions that produce legal effects. All final decisions are made by the user.
3. How We Use Your Information
We use the collected information for the following purposes:
- Providing and Improving the Service: To operate the Platform and personalize your experience.
- Account Management: To create and maintain your user account, authenticate you, and communicate account-related information.
- Subscription Processing: To process subscription payments and manage billing through Stripe.
- Communication Features: To enable you to draft and send emails to investors, including AI email drafting.
- Email Delivery: To send emails on your behalf using SendGrid as our email delivery service provider.
- Customer Support: To respond to your inquiries and provide customer support.
- Service Announcements and Updates: To inform you of important updates, changes to terms, or new features.
- Marketing (with Consent): If you explicitly agree, we may send newsletters or promotional communications.
- Legal Compliance and Protection: To comply with applicable laws, enforce our Terms of Service, and prevent fraud.
4. How We Share and Disclose Information
We do not sell your personal data to any third parties. We only share your information in the following circumstances:
- Service Providers: We share data with trusted third-party providers including Stripe (payment processing), SendGrid (email delivery), cloud hosting services (Render & AWS), and AI service providers. We contractually require all service providers to protect your data.
- Business Transfers: If we undergo a merger, acquisition, or sale, your personal data may be transferred as part of that transaction.
- Legal Obligations: We may disclose your information if required by law or in response to valid legal requests.
- Protection of Rights and Safety: We may share information to enforce our Terms of Service, protect rights, or prevent fraud.
- With Your Consent: In cases where you explicitly authorize it.
5. Data Security
We prioritize the security of your personal data with technical and organizational measures:
- Encryption: All data transmission is secured via HTTPS. Databases utilize encryption at rest.
- Access Controls: We limit access to personal data to authorized personnel with confidentiality obligations.
- Secure Hosting: Our Platform runs on reputable cloud infrastructure (Render and AWS) with high security standards.
- Payment Security: All payment transactions are processed via Stripe, which is PCI-DSS compliant.
- Monitoring and Testing: We monitor systems for suspicious activity and periodically test security.
- Data Backups: Regular encrypted backups are performed.
Despite our efforts, no method of transmission or storage is 100% secure. In the event of a data breach, we will notify you and relevant authorities as required by law.
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Policy or as required by law.
- Account Information: Active account data is retained while the account is active plus up to 90 days after closure, after which personal data is deleted or anonymized.
- Investor Data: Retained as long as the investor remains professionally active. We conduct periodic reviews (at least annually). Verified removal requests are processed within 30 days.
- Subscription and Transaction Data: Invoices and tax records are retained for a minimum of 5 years from the date of the transaction.
- Communications: Support correspondence and outreach drafts retained for up to 24 months. Email delivery metadata retained per SendGrid's policies, typically no more than 90 days.
- Usage Logs: Application and security logs retained for up to 12 months.
- Future Modules Data: Data from future modules will have their own retention practices clarified at launch.
7. Your Rights and Choices
You have rights regarding your personal data under applicable data protection laws:
- Access and Portability: You have the right to request a copy of the personal data we hold about you.
- Rectification (Correction): If any information is inaccurate or outdated, you have the right to correct or update it.
- Erasure: You may request that we delete your personal data under certain circumstances.
- Restriction of Processing: You can ask us to restrict processing of your data in certain situations.
- Objection to Processing: You have the right to object to certain types of processing, such as direct marketing.
- Withdraw Consent: You have the right to withdraw consent at any time.
- Data Portability: Where applicable, you may request to receive your data in a machine-readable format.
- Non-Discrimination: We will not discriminate against you for exercising your data rights.
To exercise any of these rights, contact us at support@venturestrat.ai. We may verify your identity before processing your request. We will respond within a reasonable timeframe.
7A. Rights of Listed Investors and Other Data Subjects
If you are an investor whose data is on the Platform but you are not a user, you have the following rights:
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure (removal) — within 30 days of verification
- Right to object
- Right to restrict processing
- Right to lodge a complaint with a supervisory authority
To exercise any of these rights, contact privacy@venturestrat.ai. We will respond within 30 days.
8. Cross-Border Data Transfers
Our servers may be located outside the UAE. We ensure appropriate safeguards are in place including contractual safeguards and standard contractual clauses.
9. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from anyone under 18.
10. Future Features and Modules
We plan to introduce additional modules in the future. This Privacy Policy will be updated to reflect any changes in data practices.
11. Updates to This Privacy Policy
We may modify this Privacy Policy from time to time. If we make material changes, we will notify you by email or by placing a prominent notice on our website.
12. Contact Us
If you have any questions about this Privacy Policy:
- Email: ibrahim@venturestrat.co
- Privacy and Data Protection Inquiries: privacy@venturestrat.ai
- Address: Al Thanyah Road, Dubai, United Arab Emirates
We will be happy to answer your questions. Your privacy is important to us.