Privacy Policy
How we collect, use, share, and protect your personal data, and the rights you have under UK data-protection law.
Draft for review. This document is a carefully researched template that still requires sign-off by a qualified solicitor and completion of any [bracketed] fields before it is relied upon. It is provided for transparency, not as legal advice.
01Who is responsible for your data
FreshGeo Ltd(“SeedPilot”, “we”) is the data controller for the personal data described in this policy. We are registered in England and Wales (company number [COMPANY NUMBER]) and registered with the UK Information Commissioner’s Office under registration number [ICO REGISTRATION NUMBER]. For any privacy matter, contact privacy@getseedpilot.com.
02Scope
This policy applies to personal data we process when you visit getseedpilot.com, create an account, or use the Platform as a founder or investor. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
03What we collect
You give us
- Account & identity: name, email, role, password (hashed), and any details from Google/LinkedIn sign-in.
- Founder briefing: company, sector, stage, raise amount, traction, team, and your answers to the AI assessment.
- Investor mandate: thesis, stages, sectors, cheque range, deployment, and calibration choices.
- Deal materials: decks, data-room documents, diligence responses, and messages you exchange with counterparties.
- Support & demo requests: the contents of forms and emails you send us.
We collect automatically
- Technical & usage data: IP address, device and browser type, pages viewed, and actions taken, via essential cookies and server logs. See our Cookie Policy.
We obtain from third parties
- Public records: company and director data from official UK public registers and other public sources, used to build and verify investor profiles and to check founder companies.
04How and why we use it (lawful bases)
We rely on the following lawful bases under UK GDPR:
- Contract: to create your account, run the assessment, generate matches and briefs, operate deal rooms, and provide the service you ask for.
- Legitimate interests: to secure and improve the Platform, prevent fraud and abuse, build investor profiles from public records, and send service-related communications. We balance these against your rights.
- Consent: for non-essential cookies/analytics and any marketing email, which you can withdraw at any time.
- Legal obligation: to comply with law, accounting, and lawful requests.
05AI processing
We send briefing and profile content to our AI sub-processor (Anthropic) to generate scores, briefs, and matches. This is automated processing that informs, but does not solely determine, outcomes that produce legal or similarly significant effects; a match is a suggestion, and humans make all contact and investment decisions. You can ask us about the logic involved and request human review of any assessment by emailing privacy@getseedpilot.com.
07International transfers
Some sub-processors (for example, Anthropic and Resend) are located outside the UK. Where data is transferred internationally, we rely on the UK’s adequacy regulations or the International Data Transfer Agreement / UK Addendum to the EU Standard Contractual Clauses, together with appropriate safeguards.
08How long we keep it
We keep personal data only as long as needed for the purposes above: for the life of your account, plus a reasonable period afterwards for legal, security, dispute-resolution, and backup purposes (typically up to 6 years for records with a legal or accounting dimension). Public-record investor data is retained while a profile remains listed. You can ask us to delete your data sooner; see your rights below.
09Your rights
Under UK GDPR you have the right to access, rectify, erase, restrict, or object to processing of your personal data; to data portability; and to withdraw consent at any time. To exercise any right, email privacy@getseedpilot.com. We respond within one month.
If you are an individual whose data appears in an investor/director profile sourced from public records, you can ask us to update or remove it using the same address.
You also have the right to complain to the Information Commissioner’s Office (ICO) at ico.org.uk, though we’d appreciate the chance to resolve it first.
10Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, scoped database permissions (row-level security), signed links for shared documents, and audit logging. No system is perfectly secure; report any concern to security@getseedpilot.com.
11Children
The Platform is for business users aged 18 and over. We do not knowingly collect data from children.
12Changes to this policy
We may update this policy from time to time. We will revise the “last updated” date and, for material changes, notify you by email or in-product notice.