Privacy Policy
Fundlinx is a capital-raising system of record for fund managers. To do its job it holds two very different kinds of data: information about you and your firm, and information about limited partners built from public disclosures. This policy explains both, because they carry different rights and different obligations.
We have written this against what the software actually does. Where a practice is a deliberate limit — read-only scopes, no advertising trackers, credentials encrypted at rest — we say so, and you can hold us to it.
1Who we are
Fundlinx (“Fundlinx”, “we”, “us”) operates the service at fundlinx.ai. The controller for the data described here is Alphaquest Innovate LLP, registered at My Home Bhooja, Raidurg, Hyderabad, Telangana 500032, India.
For data about you and your firm, we are the controller. For personal data about third parties that you import — your contacts, your CRM records, your calendar attendees — you are the controller and we act as your processor, handling it only to provide the service to you.
2Data you give us
- Account: name, work email, firm, role and fund status. Your password is stored only as a bcrypt hash — we never hold it in a readable form and cannot recover it.
- Fund profile: strategy, stage, target size, cheque range, geography, thesis, prior fund performance and portfolio companies. This is what computes your Fit score.
- Work product: the LPs you target, pipeline stages, notes, touchpoints, drafted outreach and compliance acknowledgements.
We use this to operate the service, compute matching, and support you. We do not sell it, and we do not use one firm’s work product to advantage another. Fit scores and pipelines are isolated per firm.
3Data from sources you connect
The Launchpad lets you connect sources so Fundlinx can find warm paths to LPs. Every connection is optional, initiated by you, and can be disconnected at any time. We request the narrowest scopes that do the job:
| Source | Scopes requested | Access |
|---|---|---|
openid, profile, email, calendar.readonly, contacts.readonly, contacts.other.readonly | Read-only | |
| Microsoft | User.Read, Calendars.Read, Contacts.Read, People.Read | Read-only |
| HubSpot | crm.objects.contacts.read, companies.read, deals.read | Read-only |
| Salesforce | api, refresh_token, openid | Read-only use |
| Pipedrive | contacts:read, deals:read | Read-only |
openid, profile, email — sign-in only | See §4 |
Mailbox scopes are opt-in and never bundled. The default connect asks for calendar and contacts, which carry most of the relationship signal at a fraction of the sensitivity. Reading mail content is a separate, explicitly labelled choice you have to make.
From these sources we derive and store: the people you know, the organisations they belong to, how strong the connection looks (degree, mutual count, recency), and which target LPs each person unlocks. We do not store your calendar events or message bodies as a corpus — we extract the relationship signal and keep that.
OAuth tokens are encrypted at rest using envelope encryption. A database dump alone is not enough to act as you. Disconnecting a source deletes its tokens and the connection records derived from it.
Google user data — what we access and how it is used
Fundlinx’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, when you connect a Google account:
- What we access.
calendar.readonly— for events in the last 18 months we read only the attendee list and the event start time. We do not read event titles, descriptions, locations or attachments.contacts.readonlyandcontacts.other.readonly— names, email addresses, organisation, job title and photo URL.openid,emailandprofile— to show you which Google account is connected. - Why. To identify people you already know, resolve their employers against our limited-partner database, and show you which LPs you can reach through a warm introduction rather than a cold approach. That is the entire purpose.
- What we store. The derived relationship record only — person, organisation, how you are connected, and when you last interacted. We do not retain a copy of your calendar or your Google contacts as a corpus.
- What we never do. We do not sell or transfer Google user data. We do not use it for advertising, and we serve no advertising. We do not use it to train, fine-tune or otherwise improve any generalised AI or machine-learning model — neither ours nor a third party’s. No human at Fundlinx reads your Google data except with your explicit permission for a support request you have raised, or where required by law.
- Who it reaches. Google user data is processed on our own infrastructure. It is not sent to the AI subprocessors in §8 — those operate on public limited-partner information, not on your contacts or calendar.
- How to revoke. Disconnect Google in the Launchpad, which deletes the stored tokens and the records derived from that source. You can also revoke access independently at myaccount.google.com/permissions. To have the derived records deleted as well, email support@fundlinx.ai — we action deletion within 30 days.
The same limits apply to Microsoft Graph data, which we treat identically.
4LinkedIn, specifically
LinkedIn has no official API that returns a member’s own connection list. Fundlinx therefore offers two routes, and they carry different risk:
- Consented data export (recommended). You request your connections archive from LinkedIn and upload it. This is your data, exported through LinkedIn’s own supported mechanism.
- Direct session connect. You supply credentials and Fundlinx maintains a logged-in session to read your own network. This is outside LinkedIn’s Terms of Service and the risk sits with the account owner. The product labels this clearly before you choose it.
A connected seat reads your own network only. Fundlinx does not send messages, connection invitations or any other action from your LinkedIn account. Session state is encrypted at rest on the same basis as OAuth tokens.
5LP records and public data
The LP database is built from public disclosures — regulatory filings, pension and endowment reports, charity and company registries, and published press. Depending on jurisdiction these include SEC Form D and ADV, IRS 990-PF, DOL 5500, APRA portfolio holdings disclosures, NPS commitment disclosures, LGPS reports, Companies House, ACRA, MAS and SEBI registers, among others.
Where disclosure is thin, coverage is research-led: entity resolution from registries, press and public rosters, scored for confidence. Every claim carries its citation, and inferred data is never presented as filed fact. Records about individuals at LP institutions are limited to professional, role-based information.
We process this under legitimate interests — providing market intelligence to professional investors about entities that publicly disclose their investment activity. If you are named in a record, see §12.
6Documents and the data room
Documents you upload are stored on our server, not in a third-party file service. We extract text from them so they can be searched and matched. Data room access is gated per LP, documents can be watermarked, and views are logged so you can see engagement. Those access logs are your work product and are visible to you, not to other customers.
7Cookies and analytics
Fundlinx sets one cookie: fundlinx_session, which keeps you signed in. It is HttpOnly, Secure, SameSite=Lax, scoped to this host, and expires after 30 days.
There are no advertising trackers, no analytics pixels and no third-party cookies on this site. Nothing to opt out of, because there is nothing there.
8Subprocessors
These providers process data on our behalf:
| Provider | Purpose | Note |
|---|---|---|
| Anthropic (Claude) | Drafting outreach, summarising evidence, entity resolution | Not used to train models |
| OpenAI | Text embedding and extraction for LP matching | API tier, not used for training |
| Perplexity | Research-led enrichment where public disclosure is thin | On-demand only |
| Exa | Semantic web search for LP evidence | On-demand only |
| Serper | Web search results for LP evidence | On-demand only |
| X (Twitter) API | Public post signals on LP activity | Public data only |
| Hostinger | Server hosting and database (EU) | Infrastructure |
| Residential proxy provider | Egress for LinkedIn sessions you explicitly connect | Only if you connect a seat |
Enrichment providers are metered and are called on demand — when you open a profile or request intelligence — not as a background sweep across the database.
9Security
- All traffic is served over TLS, with HSTS enabled.
- Passwords are bcrypt-hashed; we cannot read them.
- OAuth refresh tokens and LinkedIn session state are encrypted at rest with envelope encryption.
- Each firm’s pipeline, targets, notes and documents are isolated per tenant.
No system is perfectly secure. If you find a vulnerability, email support@fundlinx.ai and we will respond.
10Retention and deletion
- Account and work product: kept while your account is active.
- Connected-source data: deleted when you disconnect that source.
- On account closure: your account, fund profile, pipeline, notes, documents and connection graph are deleted within 30 days, except where we must retain records to meet a legal obligation.
- LP records from public sources are not specific to your account and remain in the database after you leave.
11Your rights
Depending on where you live, you may have rights to access, correct, export, delete or restrict processing of your personal data, and to object to processing based on legitimate interests. Email support@fundlinx.ai and we will respond within 30 days. You also have the right to complain to your local data protection authority.
12If you are an LP in our database
If you are named in an LP record and want to see what we hold, correct it, or have it removed, email support@fundlinx.ai with enough detail to identify the record. We will tell you what we hold and the source it came from, correct anything inaccurate, and honour removal requests for personal data where we do not have an overriding obligation to retain it.
13International transfers
Our servers are in the EU. Some subprocessors listed in §8 operate outside the EEA, including in the United States. Where we transfer personal data internationally we rely on Standard Contractual Clauses or an equivalent lawful transfer mechanism.
14Changes and contact
If we make a material change we will update the date at the top of this page and notify account holders by email before it takes effect. Questions go to support@fundlinx.ai.