Legal
Privacy policy
Last updated 27 September 2026
Draft for legal review. Text in [square brackets] is a placeholder to be completed before launch.
1. Controller
The controller responsible for processing personal data on this website and in Runway is Suriyaa Sundararuban, Flying Aries, [Street and number], [Postcode] [City], Germany, email [contact email].
2. What we process about founders, and why
- Account and order data (name, email address, whether you buy as a business or as a private person, the package, payment status and invoices): to provide the service you bought and to keep accounting records. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (tax and commercial law).
- Your materials (intake answers, your pitch deck and the files you upload to your data room checklist): only to prepare your deliverables. We do not use them for any other founder, for marketing, or to train AI models. Legal basis: Art. 6(1)(b) GDPR.
- Payment data: payments are processed by Stripe. We receive the payment status, amounts, tax details and invoices, never your full card details. Legal basis: Art. 6(1)(b) and (c) GDPR.
- Investment opt-in (optional and off unless you tick it): “Share my company profile with Flying Aries for possible investment”. If you tick it, Flying Aries may review your company profile (intake answers and deck) as a potential investor and may contact you about it. We record when you gave or withdrew consent and the wording you saw. Legal basis: Art. 6(1)(a) GDPR (consent). You can withdraw at any time in your portal under Privacy and data; withdrawal does not affect processing before it (Art. 7(3) GDPR). Your choice has no effect on your package.
- Security and audit records (sign-ins, file access, approvals, and the prompts and responses of the AI drafts for your order): to protect your data, prevent misuse and document how each deliverable was produced. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and quality assurance).
3. AI-assisted drafts
First drafts are prepared with an AI model provided by Anthropic, PBC (United States). For your order, the model receives your intake answers and your pitch deck; for investor matching it receives the business facts of the matched investors. Anthropic acts as our processor under a data processing agreement; transfers to the United States are based on the EU Standard Contractual Clauses [counsel to confirm the agreement in place]. Your advisor reviews, edits and approves every deliverable; no decision about you is made by automated means within the meaning of Art. 22 GDPR.
4. Processors and hosting
- Supabase, Inc.: database, sign-in and file storage. Your data is hosted in the EU (Frankfurt, Germany).
- Vercel Inc.: website hosting. Server functions run in the Frankfurt region.
- Stripe Payments Europe, Limited (Ireland): payments, tax calculation and invoicing.
- Anthropic, PBC: AI drafting (see section 3).
- Resend (Plus Five Five, Inc.): delivery of sign-in links and order emails. [Counsel to confirm the processing region and transfer safeguards.]
Where a processor may access data from outside the EU/EEA, transfers are safeguarded by the EU Standard Contractual Clauses or an adequacy decision, such as the EU-U.S. Data Privacy Framework where the recipient is certified.
5. Cookies and local storage
We use a session cookie to keep you signed in, an access cookie for a shared deck you confirmed your email for (see section 7), and a local browser setting for your light or dark theme. These are necessary for the service or your settings (§ 25(2) no. 2 TDDDG). We do not use advertising or analytics cookies.
6. Information for investors in our database (Art. 14 GDPR)
To match founders with suitable investors, we keep a database of investors and investment firms. If you are an individual investor (for example a business angel) in this database, this section informs you about it.
- What we hold: your name and firm, the stages, sectors and regions you invest in, typical cheque sizes, publicly announced portfolio companies, and a business contact route (for example a firm website form or a business email address). We do not hold private contact details and do not scrape LinkedIn or other websites against their terms.
- Sources: information you or your firm published for founders (such as a firm website or public investment criteria), or that you gave us directly. The source is recorded for every entry.
- Purpose and legal basis: to recommend you to founders whose rounds match your stated criteria, so they can approach you in a professional capacity. Legal basis: Art. 6(1)(f) GDPR (our and founders' legitimate interest in efficient, relevant introductions, which you can reasonably expect when you publish investment criteria), or your consent under Art. 6(1)(a) GDPR where you gave it. [Counsel to confirm the legitimate interests assessment.]
- Recipients: founders who bought an investor list receive your name, firm, investment focus, typical cheque size and business contact route, with a short reason why you match. Our processors in section 4 host the data.
- Retention: as long as the information is accurate and relevant; entries are reviewed regularly and removed when outdated.
- Your rights: access, rectification, erasure, restriction and objection (Art. 15 to 21 GDPR). If you object, we stop recommending you immediately, delete your contact details and keep only your name and firm so that you are not added again. Write to [contact email].
7. Information for people who view a shared deck
Founders can share their pitch deck through a private Runway link. If you open such a link, this section applies to you.
- What we process: the work email address you enter, a one-time code (stored only as a hash and valid for 10 minutes), when you open the deck, how long each page is on your screen (only while the page is visible and you are active), whether you download the PDF, and your browser type. We do not store your IP address for this purpose.
- Why: to let only people the founder intended open the deck, and to show the founder who viewed it and how long each page was read. The founder decides whom to share the deck with and sees this information for their links.
- Legal basis: Art. 6(1)(f) GDPR: the founder's and our legitimate interest in keeping confidential fundraising materials under control and in understanding investor interest. You are informed before you continue, and you can simply not open the deck. [Counsel to confirm the allocation of roles between the founder and us.]
- Cookie: after you confirm your email, a strictly necessary cookie keeps you signed in to that one link for up to 30 days.
- Retention: until the founder deletes the link or their account data; then your email and viewing data for that link are deleted.
- Your rights: the rights in section 9 apply. Write to [contact email] and we will act on your request, informing the founder where needed.
8. How long we keep data
We keep your account and order materials while your account is active or until you ask us to delete them. Invoices and accounting records are kept for the periods required by German tax and commercial law (currently up to ten years). Consent records and audit records are kept for [retention period] to document compliance.
9. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR). In your portal under Privacy and data you can download your data and request deletion at any time; deletion removes your decks, intake answers, deliverables, data room files and AI prompts, and anonymises your account. You also have the right to lodge a complaint with a data protection supervisory authority, for example [competent supervisory authority].
10. Security
Decks, data room files and reports are stored in private storage in the EU and are accessed only through links that expire after 60 seconds. Access is role-based and enforced in the database, advisor access requires two-factor authentication, and file access is logged.