Privacy notice
What FundDaddy knows, why it has it, and what you can ask us to do.
FundDaddy handles two different groups of personal data: information provided by account users, and professional information about people in the investor and startup ecosystem that may come from public sources.
Updated 31 August 2026
Draft status. A review draft: not indexed, and not final until checked by qualified counsel.
01
Who is responsible for the data?
The controller is Entro314 Labs SINGLE MEMBER P.C. (Entro314 Labs), a single-member private company (Ι.Κ.Ε.) registered in Greece, seat Cheimarras 3, 13561 Agioi Anargyroi, Attica, Greece, Γ.Ε.ΜΗ. 193782603000. Full registration details are in the legal notice.
Because the controller is established in Greece, the lead supervisory authority is the Hellenic Data Protection Authority, and a complaint may also be made to the authority in your own country of residence. No data protection officer is appointed; the appointment criteria in Article 37 are among the assessments still outstanding.
Privacy requests go to hello@funddaddy.co or, for anything about a directory record, the removal form, which collects the detail a request has to contain.
02
What do you collect from account users?
- Account identifier, email address, name and profile image supplied through Clerk.
- Saved lists, saved searches, pipeline stages, notes, contact activity and tasks.
- Private portfolio entries, profile claims, edits, contributions and connect requests.
- Notification state, record views and security or operational logs.
- Removal requests, including the reply address and explanation provided.
03
What do you hold about people who did not create an account?
The professional directory may hold a person’s name, role, employer or affiliation, professional profile links, photo source, business contact details and evidence about the source or verification of those fields. Sources can include public company sites, public professional profiles, public registers and structured datasets.
Personal contact details are not published on open directory pages. A person can object, request access or correction, or ask for erasure without creating an account.
04
Why is the data used?
- To provide accounts, search, saved research and fundraising workflow tools.
- To maintain and improve the professional investor directory.
- To verify claims, corrections, contributions and removal requests.
- To protect the service, prevent misuse and investigate failures.
- To relay a connect request when that feature and email delivery are configured.
05
Which legal bases are intended to apply?
Account and requested service processing is expected to rely on performance of the user contract. Directory research and service security are expected to rely on legitimate interests, subject to a documented necessity and balancing assessment. Consent applies only where a person is given a real choice, such as opting a personal profile into the public directory. Legal obligations may require limited retention.
The legitimate-interest assessment and full record of processing have not been supplied. Those are approval blockers for the final notice.
07
How long is information kept?
A complete retention schedule is not implemented or documented in this repository. Some account-owned records are deleted when the account row is deleted, while certain edit, verification and erasure evidence is designed to remain for accountability. Exact periods and backup deletion behavior must be defined before this notice is final.
08
Can I export or delete my data?
Signed-in users can export selected investors or a saved list as CSV, and the account settings page provides a JSON export of the account row, saved lists and activity, saved views, private portfolio records, profile claims and edits, connect requests, record-view history and notifications. It excludes authentication secrets and session details held by Clerk. No export or switching charge is made.
A verified person can erase supported personal-profile fields and associated media, and deleting the Clerk account removes the account identity and cascades account-owned records. A complete deletion map covering every table, log, provider and backup has not been compiled, so deletion is not described here as comprehensive.
09
Is personal information sold or shared?
The application contains no advertising network, cross-context behavioural tracking or Global Privacy Control handler. Whether signed-in access to professional contact records falls within a US state-law definition of sale or sharing has not been assessed, and no exemption is claimed here.
10
What can I ask for?
Depending on the processing and your location, you may request access, correction, erasure, restriction, portability or object to processing. You may withdraw consent where consent is the basis, and complain to the Hellenic Data Protection Authority or another competent supervisory authority.
For a directory record, use the removal form. Every other rights request goes to hello@funddaddy.co. What is still missing is the written identity-verification procedure — how a requester is confirmed to be who they say they are before personal data is disclosed or erased — which is one of the records this notice remains a draft for.