Privacy Policy

Effective 15 September 2026 · Last updated 15 September 2026

Fundlinx is a capital-raising system of record for fund managers. To do its job it holds two very different kinds of data: information about you and your firm, and information about limited partners built from public disclosures. This policy explains both, because they carry different rights and different obligations.

We have written this against what the software actually does. Where a practice is a deliberate limit — read-only scopes, no advertising trackers, credentials encrypted at rest — we say so, and you can hold us to it.

1Who we are

Fundlinx (“Fundlinx”, “we”, “us”) operates the service at fundlinx.ai. The controller for the data described here is Alphaquest Innovate LLP, registered at My Home Bhooja, Raidurg, Hyderabad, Telangana 500032, India.

For data about you and your firm, we are the controller. For personal data about third parties that you import — your contacts, your CRM records, your calendar attendees — you are the controller and we act as your processor, handling it only to provide the service to you.

2Data you give us

We use this to operate the service, compute matching, and support you. We do not sell it, and we do not use one firm’s work product to advantage another. Fit scores and pipelines are isolated per firm.

3Data from sources you connect

The Launchpad lets you connect sources so Fundlinx can find warm paths to LPs. Every connection is optional, initiated by you, and can be disconnected at any time. We request the narrowest scopes that do the job:

SourceScopes requestedAccess
Googleopenid, profile, email, calendar.readonly, contacts.readonly, contacts.other.readonlyRead-only
MicrosoftUser.Read, Calendars.Read, Contacts.Read, People.ReadRead-only
HubSpotcrm.objects.contacts.read, companies.read, deals.readRead-only
Salesforceapi, refresh_token, openidRead-only use
Pipedrivecontacts:read, deals:readRead-only
LinkedInopenid, profile, email — sign-in onlySee §4

Mailbox scopes are opt-in and never bundled. The default connect asks for calendar and contacts, which carry most of the relationship signal at a fraction of the sensitivity. Reading mail content is a separate, explicitly labelled choice you have to make.

From these sources we derive and store: the people you know, the organisations they belong to, how strong the connection looks (degree, mutual count, recency), and which target LPs each person unlocks. We do not store your calendar events or message bodies as a corpus — we extract the relationship signal and keep that.

OAuth tokens are encrypted at rest using envelope encryption. A database dump alone is not enough to act as you. Disconnecting a source deletes its tokens and the connection records derived from it.

Google user data — what we access and how it is used

Fundlinx’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, when you connect a Google account:

The same limits apply to Microsoft Graph data, which we treat identically.

4LinkedIn, specifically

LinkedIn has no official API that returns a member’s own connection list. Fundlinx therefore offers two routes, and they carry different risk:

A connected seat reads your own network only. Fundlinx does not send messages, connection invitations or any other action from your LinkedIn account. Session state is encrypted at rest on the same basis as OAuth tokens.

5LP records and public data

The LP database is built from public disclosures — regulatory filings, pension and endowment reports, charity and company registries, and published press. Depending on jurisdiction these include SEC Form D and ADV, IRS 990-PF, DOL 5500, APRA portfolio holdings disclosures, NPS commitment disclosures, LGPS reports, Companies House, ACRA, MAS and SEBI registers, among others.

Where disclosure is thin, coverage is research-led: entity resolution from registries, press and public rosters, scored for confidence. Every claim carries its citation, and inferred data is never presented as filed fact. Records about individuals at LP institutions are limited to professional, role-based information.

We process this under legitimate interests — providing market intelligence to professional investors about entities that publicly disclose their investment activity. If you are named in a record, see §12.

6Documents and the data room

Documents you upload are stored on our server, not in a third-party file service. We extract text from them so they can be searched and matched. Data room access is gated per LP, documents can be watermarked, and views are logged so you can see engagement. Those access logs are your work product and are visible to you, not to other customers.

7Cookies and analytics

Fundlinx sets one cookie: fundlinx_session, which keeps you signed in. It is HttpOnly, Secure, SameSite=Lax, scoped to this host, and expires after 30 days.

There are no advertising trackers, no analytics pixels and no third-party cookies on this site. Nothing to opt out of, because there is nothing there.

8Subprocessors

These providers process data on our behalf:

ProviderPurposeNote
Anthropic (Claude)Drafting outreach, summarising evidence, entity resolutionNot used to train models
OpenAIText embedding and extraction for LP matchingAPI tier, not used for training
PerplexityResearch-led enrichment where public disclosure is thinOn-demand only
ExaSemantic web search for LP evidenceOn-demand only
SerperWeb search results for LP evidenceOn-demand only
X (Twitter) APIPublic post signals on LP activityPublic data only
HostingerServer hosting and database (EU)Infrastructure
Residential proxy providerEgress for LinkedIn sessions you explicitly connectOnly if you connect a seat

Enrichment providers are metered and are called on demand — when you open a profile or request intelligence — not as a background sweep across the database.

9Security

No system is perfectly secure. If you find a vulnerability, email support@fundlinx.ai and we will respond.

10Retention and deletion

11Your rights

Depending on where you live, you may have rights to access, correct, export, delete or restrict processing of your personal data, and to object to processing based on legitimate interests. Email support@fundlinx.ai and we will respond within 30 days. You also have the right to complain to your local data protection authority.

12If you are an LP in our database

If you are named in an LP record and want to see what we hold, correct it, or have it removed, email support@fundlinx.ai with enough detail to identify the record. We will tell you what we hold and the source it came from, correct anything inaccurate, and honour removal requests for personal data where we do not have an overriding obligation to retain it.

13International transfers

Our servers are in the EU. Some subprocessors listed in §8 operate outside the EEA, including in the United States. Where we transfer personal data internationally we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.

14Changes and contact

If we make a material change we will update the date at the top of this page and notify account holders by email before it takes effect. Questions go to support@fundlinx.ai.