Skip to content
Preflightby Flying Aries

Legal

Privacy policy

Last updated 26 September 2026

1. Controller

The controller responsible for processing your personal data is Suriyaa Sundararuban, Flying Aries, [Street and number], [Postcode] [City], Germany, email [contact email].

2. What we process and why

  • Account and investor profile (name, email, address, entity details, tax ID, investor type and self-declared investor status): to provide the service, know our clients and issue correct invoices. Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) GDPR (tax and commercial law).
  • Order materials (intake answers, pitch decks and other documents you upload, data room links): solely to prepare the report you ordered. We do not use your materials for any other client, for marketing, or to train AI models. Legal basis: Art. 6(1)(b) GDPR.
  • Payment data: payments are processed by Stripe. We receive the payment status, amounts, tax details and invoices, never your full card details. Legal basis: Art. 6(1)(b) and (c) GDPR.
  • Security and audit records (sign-ins, document access, approvals, records of AI prompts and responses for your order): to protect your data, prevent misuse and document how each report was produced. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and quality assurance).

3. AI-assisted research

Research drafts are prepared with the help of an AI model provided by Anthropic, PBC (United States). For your order, the model receives your intake answers and the documents you uploaded, and searches the public web. Anthropic acts as our processor under a data processing agreement; transfers to the United States are based on the EU Standard Contractual Clauses. Every report is reviewed and approved by a human analyst; no decision about you is made by automated means within the meaning of Art. 22 GDPR.

4. Processors and hosting

  • Supabase, Inc.: database, authentication and file storage. Your data is hosted in the EU (Frankfurt, Germany).
  • Vercel Inc.: website hosting and aggregate page-view analytics. Server functions run in the Frankfurt region.
  • Stripe Payments Europe, Limited (Ireland): payments, tax calculation and invoicing.
  • Anthropic, PBC: AI research assistance (see section 3).
  • Resend (Plus Five Five, Inc.): delivery of account and order emails, such as sign-in links and confirmations. Emails are processed in the United States; the transfer is safeguarded by the EU Standard Contractual Clauses.

Where a processor may access data from outside the EU/EEA, transfers are safeguarded by the EU Standard Contractual Clauses or an adequacy decision, such as the EU-U.S. Data Privacy Framework where the recipient is certified.

5. Cookies, local storage and analytics

We use a session cookie to keep you signed in, a cookie that remembers an invitation code for 30 days when you follow an invitation link, and a local browser setting for your light or dark theme. We do not use advertising cookies.

We measure aggregate page views with Vercel Web Analytics, provided by Vercel Inc. We configure it so that page addresses are recorded without query parameters, identifiers such as order numbers and invitation codes are replaced by placeholders, and the staff console is never recorded. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in understanding how the website is used). [Counsel to confirm whether consent under § 25 TDDDG is required for this configuration.]

6. How long we keep data

We keep your account and order materials for as long as your account is active, or until you ask us to delete them. Invoices and accounting records are kept for the periods required by German tax and commercial law (currently up to ten years). Audit records are kept for [retention period] and then deleted.

7. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15 to 21 GDPR). You can export your data and request deletion at any time in the client portal under Privacy, or by email to [contact email]. You also have the right to lodge a complaint with a data protection supervisory authority, for example [competent supervisory authority].

8. Security

Documents are stored in private storage and accessed only through short-lived signed links. Access is role-based, staff access requires multi-factor authentication, and all access to documents is logged.