This privacy statement was last updated March 2022
Your privacy is of utmost importance to us. To help you understand what we do and how we process your data, we have created this statement. If you have any questions or concerns after reading this statement, please do not hesitate to contact us at [email protected]
What we do
Dealroom.co offers an online platform. The purpose of the platform is to map the start-up, scale-up, and corporate landscape around the world and to provide transparency on financing, ownership, and backgrounds on those involved. Dealroom.co does this by collecting and presenting this data about the corporate landscape on its platform in an orderly fashion.
For the sole purpose to provide transparency of the start-up and scale-up market and to accelerate entrepreneurship & innovation through this data transparency, we gather, analyze and publish information on start-ups, scale-ups, corporates, investors, ownership, and backgrounds on those involved we:
- Gather personal data of individuals related to start-ups, scale-ups, corporates, and investors (from the individuals themselves and/or from third party sources);
- Enrich the data with data from other sources to make profiles as complete as possible;
- Add a “Dealroom.co score” showing our subjective opinion (if applicable) and
- Publish the personal data within the platform.
For the avoidance of doubt: ‘automated decision-making’ is not part of our processing activities.
What personal data we collect
We collect the following personal data either directly from you as a registered user, indirectly from you using our website, or from third-party sources. We will more specifically explain our processing of your data below. We distinguish three types of data subjects involved in our processing below.
As a registered user, you will enter the following information about yourselves while registering. We need this information to create a secure account for you. To secure your account we use an authentication application called Auth0. The personal data we collect during this process are your:
- email address
- IP address
- job title
- company name
- telephone number
- profile photo
- login count
- last login date/time
When you register through a sign-on application (such as Facebook facilitates), the data we additionally collect during this process are your:
- marital status
- profile picture
- photos and comments
Visitor of our website:
As a user of the website (unregistered) we collect some data from you while visiting our website. This data concerns your:
- IP address
- behaviour on our website, preferences, etc
Subject of our platform:
Finally, we make it our business to collect information on start-ups, scale-ups and corporates, and investors all over the world including information on data subjects such as directors, managers, angel investors, team members, and other persons. The information we collect, show, and share on our platform may hold the following personal data:
- Function (management)
- Company (management)
- Previous companies (management)
- Portfolio/previous investments (investors)
- News articles content
- Gender (with consent, or if publicly available)
- Ethnicity (with consent)
- LinkedIn URL
- Facebook URL
- Twitter URL
- Whether users (investors) searched for your company
What Legal Ground justifies our processing?
We may only process your data subject to one of the limited legal grounds specified in the GDPR. In the below overview, we specify which legal ground we have for the various types of data and data processing that are part of our services.
Performance of the agreement
When you provide us with personal data to create a user account for our website and service we may process such personal data on the ground of ‘performance of the agreement’. Without the information we cannot control and manage the account and access you wish to receive.
For the legal basis of legitimate interest an assessment is made by Dealroom.co of the interests of Dealroom.co on one hand and your interests, fundamental rights, and freedoms as the data subject on the other. This balancing test assesses if your interests should override ours. To this extent, we had carefully assessed every data point processed and concluded that the impact on your interests, rights, and freedoms is mainly low as the information provided is publicly known. As your interests, therefore, do not override ours, we believe we have a legitimate interest to process your data. This assessment is however subjective. If you feel that your interests should be weighed out otherwise or have not been treated correctly in this assessment, you may at any time address your concerns or objection. We will promptly register your objection and cease using any data which is based on the legitimate interest ground which your objection concerns. This may influence your use of our website. You can find additional information concerning the legitimate interest assessment in our Legitimate Interest Statement.
|Data Category||Source||Legal Ground||If applicable, Legitimate Interest and impact|
|First and last name, email address, job title, company name, telephone number (registered user data), photo||Data Subject||Performance of the agreement – access to the website subject to registration||n.a.|
|Interests, job title, company name, marital status, profile picture, photos, search history and comments (when registering through a sign-on functionality)||Data Subject||Consent||n.a|
|Various information categories added by the user to its account (such as the tagline)||Data Subject||Consent||n.a|
|Name and job title (Company Team)||Publicly available information||Legitimate Interest||Employers are important for assessment of a company, high importance from a commercial perspective for Dealroom. Impact low, publicly available information|
|Name and address (angel investors)||Publicly available information||Legitimate Interest||Identities and decisions of investors play a large role in identifying promising companies. High importance from a commercial perspective for Dealroom. Impact low, if names of persons are concerned those are publicly known. Home addresses are processed as limited as possible.|
|Financial Information (angel investors)||Publicly available information||Legitimate Interest||Past investments can tell a lot about the viability of a (new) company. High importance from a commercial perspective for Dealroom. Impact low, if names of persons are concerned those names and the financial information are publicly known|
|Name, education, work experience (founders)||Publicly available information||Legitimate Interest||The success of a company, especially with a start- or scale-up, largely depends on the skills and knowledge of the founder. High importance from a commercial perspective for Dealroom. Impact low, no sensitive data is processed, and the data is already publicly available.|
|Educational information and historical successes (company names)- Inferred data (Founder)||Publicly available information||Legitimate Interest||The history and education of the founder are important to assess the success of a company. The impact is medium as the information is publicly known but results in profiling.|
|Names, job titles, company names (Investor team)||Publicly available information||Legitimate Interest||Which people are employed by an investor is an important factor when assessing the value of their decisions. High importance from a commercial perspective for Dealroom. Impact low, no sensitive data is processed, and the data is already publicly available.|
|Name, if part of the used URL (angel investors)||Publicly available information||Legitimate Interest||It is important that both investor and investee can fact verify information on each other. Dealroom provides URLs to social media to this extent. The impact is low, only if angel investors are concerned, and if, only their names.|
|Name and filed of industry (investors)||Publicly available information||Legitimate Interest||Information about the funding rounds is important when making decisions concerning investments. High importance from a commercial perspective for Dealroom. Impact low, no sensitive data is processed, and the data is already publicly available|
|ID, name, profile, angellist, Facebook URL, Twitter URL, Linkedin URL, logo picture, address (city only), latitude, longitude, HQ Region, HQ Country HQ City, companies, founded companies (People)||Publicly available information||Legitimate Interest||The goal of Dealroom.co is to provide accurate and up-to-date information while trying to prevent damage caused by mistakes, errors, and fraud. To reach this goal, it is important to get all information that could reasonably be relevant. The impact is low. The data processed is not sensitive data and the data is already publicly available.|
|Financial and educational information portfolio (People)||Publicly available information||Legitimate Interest||In the decision-making process it is important that both investor and investee know with whom they are dealing. Two important factors in that process are education and their portfolio (investors). The impact is low. High importance from a commercial perspective for Dealroom. The data processed is not sensitive data and the data is already publicly available.|
|University name (founder – user)||Publicly available information||Legitimate Interest||The skills and knowledge of the founder are of importance when making investing decisions. High importance from a commercial perspective for Dealroom. The data processed is not sensitive data and the data is already publicly available.|
|University name (founder)||Publicly available information||Legitimate Interest||The skills and knowledge of the founder are of importance when making investing decisions. High importance from a commercial perspective for Dealroom. The data processed is not analysis data and the data is already publicly available.|
|Gender (founders, team members, angel investor, people)||Data Subject or
Publicly available information
|Legitimate Interest (when publicly available – inferred data)||Dealroom does not show individual information about someone’s gender but uses this data to generate statistics and blogs for the promotion of equal treatment of and equal opportunities for all genders. The impact on the data subject is medium, because of the importance of this topic in today’s society.|
|Ethnicity (founders, angel investors, people)||Data Subject||Consent
(Dealroom does not proactively ask for users to provide their ethnicity, and this is not inferred either)
To what purpose do we use your data?
We use all of the personal data mentioned in the above overview for the sole purpose of gathering, analyzing, and publishing information on start-ups, scale-ups, corporates, and investors and to provide transparency on financing, ownership, and backgrounds on those involved.
More specifically we
- Provide you with services and products that you request from us,
- Inform you about platform and service updates, content, offers, and advertisements that may be of interest to you,
- Contact you as required to perform our services,
- Send you an invoice for our products or services,
- Provide customer service and follow-up to sales or support requests,
- Improve your customer experience on our platform,
- Develop customized and personalized content, offers, products and services,
- Store your preferences for future interactions with us or our platform,
- Create external research and marketing reports,
- Prevent illegal activities, suspected fraud and potential threats to our platform,
- Analyse the characteristics of our customers and their use of our platform to understand customer and market needs and improve our product as well as business development
- Share data showing the search behaviour of investors (subject to their consent).
What are the applicable retention periods?
How long do we store the data we collect directly from you?
The personal data we collect is the information you provide when creating an account or a company on the Dealroom.co platform. We store the information mentioned here until you remove it from your account or until you delete your account.
All (personal) data on invoices remain part of our accounting system. We are required by law to keep our accounting files available for seven years. Afterward, all invoices are deleted.
How long do we store data we collect from your use of our platform?
How long do we store data we collect from other sources?
We use several technics to collect data from the internet. We store the information mentioned here until new, accurate information is available to replace it. We then remove the old data from our files, unless such data would have historical value and if and for as far you have given your consent for the continued usage of this historical data. In the meantime, as mentioned above under “Your rights”, you may request us to delete any personal information concerning yourself at all times.
Do we share your personal data with others?
We may disclose certain personal data to third parties if needed to provide the services and products on our platform. This sharing of data is subject to your consent. Every consent shall show you upfront what data is concerned. We use third-party services for
- Analytics tracking (with your consent)
- User authentication (with your consent)
- Advertising and promotion (with your consent)
- Content marketing (with your consent)
- Email marketing (with your consent)
- Payment processing: Mollie BV, a Dutch company who services online payments. We share the following data with them: your name and (email) address.
- Search behaviour (with your consent)
If your data is shared with a third party, data processing agreements are in place to safeguard your privacy. These third-party services may access our data solely for the purpose of performing specific tasks on our behalf. We do not give them permission to disclose or use any of our data for any other purpose. We may, from time to time, allow limited access to our data by external consultants and agencies. This access is only permitted for as long as necessary to perform a specific task we asked them to perform. During such tasks non-disclosure conditions (as part of the data processing agreement or otherwise) will be agreed upon prior to receiving access.
We may also disclose your personal data:
- To our affiliates or subsidiaries
- If we are legally entitled or required to do so
- When we believe in good faith that disclosure is necessary to protect our rights, protect your safety, or the safety of others
- If we sell a business or part of a business to another company then the transfer of ownership could include the transfer of your personal data directly related to that business to the purchasing company. We shall require the buyer to treat your personal information in accordance with this privacy statement
- To third parties situated in Armenia, Lebanon, and India subject to your prior consent as well as an agreement safeguarding at least the same level of data protection as described in this policy.
How do we protect your personal data?
The collection, use, and disclosure of personal data collected through our platform are safeguarded by appropriate technological and organizational security measures with the purpose of protecting the data against loss, misuse, and unauthorized access, alteration, disclosure, or destruction. These measures are continually improved in line with tech developments. We will not retain your personal data longer than necessary to fulfil the purposes for which it was collected unless we have to store it for legitimate business, tax, or legal purposes.
- Our website uses SSL (https)
- Our computers are safeguarded by long and complex passwords that are frequently altered.
- Our servers are physically situated in the Netherlands and serviced by a Dutch company.
- Our physical office can only be entered by authorized personnel. Visitors can only enter the building that our office is situated in, after being given access by authorized personnel.
- We have created access profiles for our employees giving them limited access to our systems and (personal) data actually needed to perform their work.
You have certain rights with respect to your personal data, including those set forth below. For more information about these rights, or to submit a request, please email [email protected] Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include personal data, if necessary to verify your identity and the nature of your request.
- Access: You can request more information about the personal data we hold about you and request a copy of such personal data by emailing [email protected]
- Rectification: If you believe that any personal data we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can also correct some of this information directly by emailing [email protected]
- Erasure: You can request that we erase some or all of your personal data from our systems.
- Withdrawal of Consent: If we are processing your personal data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your personal data, if such use or disclosure is necessary to enable you to utilize some or all of our services.
- Portability: You can ask for a copy of your personal data in a machine-readable format. You can also request that we transmit the data to another controller where technically feasible.
- Objection: You can contact us to let us know that you object to the further use or disclosure of your personal data for all data processed on the legal ground of Legitimate Interest, such as for direct marketing purposes.
- Restriction of Processing: You can ask us to restrict further processing of your personal data.
- Right to File Complaint: You have the right to lodge a complaint about Dealroom.co’s practices with respect to your personal data with the supervisory authority of your country or EU Member State.
Other privacy topics
Dealroom.co does not knowingly target children, or collect personal information from children. As a parent/guardian, please contact us if you believe your child under the age of 16 is participating in an activity involving personal information on our website, and you have not received a notification or request for consent. If you are under 16 years old yourself and you wish to use our platform in any way which requires you to submit your personal data, please get your parent or legal guardian to do so on your behalf.
Newsletters and other email communication
When creating an account on Dealroom.co you’ll receive the opportunity to give your consent to receive our newsletter and other email communication via the platform. If you do not wish to receive the newsletter or other email communication any longer, you can use the unsubscribe link in every email or the provided options in your Dealroom.co account settings.
Links to other websites
This privacy statement only covers our own collecting and handling of information. Our platform may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.
Changes to this statement
If you have any questions regarding this privacy statement, please contact the DPO of Dealroom.co at: [email protected]. If you have any complaints about our privacy statement or the way Dealroom.co processes your personal data, you can submit a complaint with the Dutch Data Protection Authority. More information can be found on their website: https://autoriteitpersoonsgegevens.nl