Skip to content
FoundMatterFoundMatter
Back to FoundMatter
ende

Legal information

  • Legal notice
  • Privacy
  • Terms
  • Withdrawal
  • Cookie policy
  • Accessibility

Privacy notice

How FoundMatter processes personal data.

Updated: 24 August 2026

This notice explains how personal data is processed on the FoundMatter website and web application under the GDPR and Austrian Data Protection Act. The German version is authoritative.

1. Controller

Paul Krügel, sole proprietorship
Stephensongasse 2 / 19, 1210 Vienna, Austria
Email: paul@foundmatter.com

2. Legal bases

  • Consent under Article 6(1)(a) GDPR for voluntary features.
  • Contract and pre-contractual steps under Article 6(1)(b).
  • Legal obligations under Article 6(1)(c).
  • Legitimate interests under Article 6(1)(f), especially secure and reliable operation.

3. Purposes and data categories

Preview, account and authentication

We process the signed preview-access state, language preference, email address, non-readable password representation, full name, workspace type, confirmation state and technical session data.

Investor and startup enquiries

When you use an enquiry form, we process your name, work email, organization or startup, optional website and message, selected need and enquiry source. We use this information only to answer the enquiry and prepare possible pre-contractual steps; submitting the form does not subscribe you to marketing email.

Workspace and product data

Depending on your role, we process organization and profile data, websites, roles, startup and investment criteria, mandates, notes, evaluations, decisions, evidence, release states, matching requests and messages.

Evaluation and AI feedback

We process company information, URLs, materials links, decision questions and results that you provide. Pitch-deck links are technically checked and stored with the result. When you request AI feedback, the required text is sent to OpenAI with store: false.

Operations and security

IP address, time, requested URL, referrer, browser, device and error data may be processed in server and security logs.

4. Recipients and processors

Vercel Inc.
Hosting, content delivery and technical logs.
Supabase Inc.
Authentication and session management and, depending on the deployed environment, database or storage infrastructure.
ALL-INKL.COM – Neue Medien Münnich
Email delivery and receipt, including internal notifications about investor and startup enquiries.
OpenAI Ireland Ltd.
User-requested pitch-readiness critique. API data is not used to train models by default unless the customer explicitly opts in to share it.

5. Cookies

FoundMatter currently uses only technically necessary cookies for preview access, language and authentication. No advertising, analytics, heatmap or session-recording cookies are used. See the cookie policy.

6. International transfers

Where providers process data outside the EU or EEA, transfers rely on an adequacy decision or appropriate safeguards such as EU Standard Contractual Clauses. The specific infrastructure region depends on project configuration.

7. Retention

  • Preview access: up to 7 days; language preference: up to 1 year.
  • Enquiry data: generally up to 12 months after the last substantive contact unless longer retention is required for pre-contractual or legal purposes.
  • Account and workspace data: until account deletion or as required to provide the service.
  • AI critiques: until deleted with the relevant workspace data or account.
  • Business records: for applicable statutory periods, commonly up to 7 years.
  • Technical logs: under the necessary security and retention periods of the hosting provider.

8. Your rights

Subject to the GDPR, you may request access, rectification, erasure, restriction, portability and object to processing, and may withdraw consent for the future. Contact paul@foundmatter.com.

9. Complaint

You may complain to the Austrian Data Protection Authority, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, dsb.gv.at.

10. Automated decisions

FoundMatter provides research, readiness, evaluation and matching guidance. It does not make solely automated decisions under Article 22 GDPR that produce legal or similarly significant effects. Results support, but do not replace, human judgment.

11. Security and changes

Data is transmitted over TLS and access to private workspace data is restricted. We update this notice when law, functions or providers change and will communicate material changes appropriately.

Back to FoundMatter
FoundMatter
  • Legal notice
  • Privacy
  • Terms
  • Withdrawal
  • Cookie policy
  • Accessibility