Data Processing Addendum
Last updated July 27, 2026
If you are using StartupFlow AI on behalf of a company and someone has asked you for a DPA, this is it. It forms part of our Terms of Service and it applies automatically from the moment you use the service. You do not need to sign anything or wait for us to counter-sign, though if your process requires a signed copy, email privacy@startupflowai.com and we will send one.
Everything below uses the GDPR’s definitions of controller, processor, personal data and processing.
1. Which of us is which
For most of what happens on StartupFlow AI, we are the controller: your account, your startup profile, the matching, the recommendations. We decide what to collect and why, and the privacy policy governs it.
For content you put into the platform that contains other people’s personal data (a cap table with your co-founders’ details, a team slide, a document you upload to your Data Room, an investor you share a link with), you are the controller and we are your processor. This addendum covers that part.
2. What we process for you
- Subject matter: hosting and making available the content you put into your Data Room and your application materials.
- Duration: as long as your account is active, plus the deletion window in section 8.
- Nature and purpose: storage, retrieval, sharing at your instruction, and AI-assisted drafting where you ask for it.
- Types of personal data: whatever you upload. Typically names, roles, email addresses and equity holdings of founders, employees and shareholders.
- Categories of data subject: your team, your shareholders, and anyone you send a share link to.
- Special categories: none are expected, and you should not upload any.
3. Our obligations
We will:
- process your content only on your documented instructions (using the product is the instruction), except where the law requires otherwise, in which case we will tell you first unless the law forbids that too;
- make sure anyone with access is bound by confidentiality and needs the access to do their job;
- apply the security measures in section 5;
- help you respond to requests from data subjects, and with your own obligations under Articles 32 to 36, taking into account what we can actually see;
- tell you without undue delay if we become aware of a breach affecting your content, with what we know at the time;
- delete or return your content when the contract ends, as described in section 8;
- give you the information you need to show compliance, and allow an audit as described in section 7.
4. Your obligations
You are responsible for having a lawful basis to put other people’s personal data into the platform in the first place, and for telling those people about it where the law requires. In practice: do not upload a document about someone who would be surprised to learn you had.
5. Security
We apply the measures listed on the trust page. In summary: HTTPS in transit; a private object-storage bucket with time-limited signed links; AES-256-GCM encryption at rest for tax identifiers; Argon2 password hashing; token hashing at rest; per- user query scoping enforced in the service layer; logged admin access; and nightly encrypted backups.
6. Sub-processors
You give us general written authorisation to use the sub-processors listed on the sub-processors page. We will tell you before we add or replace one if you have asked to be on the notice list, and you will have 30 days to object on reasonable data-protection grounds. If we cannot resolve an objection, you may terminate the affected part of the service and we will refund any prepaid, unused fees.
Each sub-processor is bound by terms no less protective than these, and we remain liable to you for what they do.
7. Audit
We will provide the information reasonably needed to demonstrate compliance with this addendum. Given our size, an on-site audit is not practical; a documented question-and-answer process is. If your own regulator requires more, tell us and we will work out what is achievable rather than pretend otherwise.
8. Deletion and return
Your content is available for export from Settings at any time, as JSON or as a readable document, so “return” needs no request from you.
On deletion: until you delete your account, then 30 days. Nothing is touched during that window and it can be cancelled with one click. After it, the account row and everything cascading from it (including the objects in storage) are permanently removed. What survives is a hashed tombstone with no readable personal data in it, kept so we can prove the erasure happened.
Backups are the honest exception. Encrypted nightly snapshots may hold deleted content until they rotate out; we do not restore from backup to resurrect deleted accounts, and the snapshot expires on its own schedule.
9. International transfers
Processing happens in the United States and our team accesses it from Pakistan. Where your content is transferred out of the EEA or the UK, we rely on the Standard Contractual Clauses: the 2021 EU SCCs, module three (processor to processor) where we are your processor, with the UK International Data Transfer Addendum where UK data is involved. Those clauses are incorporated into this addendum by reference. The detail is in the privacy policy.
10. Order of precedence
Where this addendum conflicts with the Terms of Service, this addendum wins for anything concerning the processing of personal data. Everything else stays as the Terms say.
Questions
Send them to privacy@startupflowai.com. If your legal team needs a specific clause added, ask. We would rather have the conversation than lose you to a template mismatch.