← Back to home

Privacy Policy

Last updated: July 2026

Fynton is a product of FjordPoint Capital GmbH, Im Prüfling 2, 60389 Frankfurt am Main, Germany (“we”, “us”). When you use fynton.ai, you are contracting with and providing your data to FjordPoint Capital GmbH. This Privacy Policy informs you pursuant to Art. 13 and Art. 14 GDPR about the nature, scope, and purpose of the processing of personal data when using Fynton (hereinafter “Service” or “Platform”).

The Service is intended exclusively for professionals and businesses. We do not knowingly collect or process data from individuals under 18 years of age.

1. Controller

The controller within the meaning of the GDPR is:

FjordPoint Capital GmbH
Im Prüfling 2
60389 Frankfurt am Main
Germany
Phone: +49 1709444213
Email: fynton@fjordpoint-capital.com
Managing Director: Elliot Alexander Nordstrom
Commercial register: HRB 140804, Amtsgericht Frankfurt am Main

2. Data protection officer

We are not legally required to appoint a data protection officer under § 38 BDSG. For privacy questions, you may contact us at any time at fynton@fjordpoint-capital.com.

3. Definitions

We use the terms in this Privacy Policy in the sense of the definitions in Art. 4 GDPR (“personal data”, “processing”, “controller”, “processor”, etc.).

4. Categories of data processed

4.1 Master data (account)

When you register, we process: email address, name (optional), password hash (not stored in plain text). When signing in via Google OAuth, we receive your email address, name, and profile picture URL from Google.

4.2 Usage data

To provide the Service, we process: your agent configurations (target groups, industries, regions, search criteria), generated and stored company records (company name, website, phone, email, publicly researched information about companies), status changes, team assignments, comments, and notes.

4.3 Billing and contract data

For subscription billing, we process: billing address, subscription status, payment history (via Stripe). Your credit card and bank details are processed exclusively by our payment provider Stripe; we only store the Stripe customer ID.

4.4 Technical access data (server logs)

When you visit our website, our servers automatically collect: IP address, time of access, URL accessed, HTTP status code, amount of data transferred, referrer URL, user agent (browser/operating system). This data is used for technical provision, IT security, and error analysis. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation). Logs are deleted or anonymized after no more than 30 days.

4.5 Interaction and behavioural data

When you use the investor matching function, we process data about your interactions with investor profiles: which profiles you accept, decline, or mark as known; the relationship status you assign (e.g. “Committed”, “In dialogue”); and any notes you add. This data is used to (a) provide and personalise your matching agent and (b) in aggregated and anonymised form, to improve matching quality across the platform.

Legal basis: Art. 6(1)(b) GDPR for personalisation of your individual agent; Art. 6(1)(f) GDPR (legitimate interest in improving the service) for aggregate model improvement. You will always make your own decisions — automated outputs are for support only (see Section 12 on automated decision-making).

4.6 Google Workspace integration (optional)

If you connect Gmail and Google Calendar, we process email metadata (sender, recipients, date, subject line) and, for business-relevant messages, email body text (cleaned and encrypted at rest). We also process calendar event metadata (attendees, date/time). This data powers relationship strength scores, contact personas, and an optional inbox Q&A feature in the People tab. Email body content is used solely to generate investor relationship intelligence for your own account; it is not shared with other users and is not used to train shared models. Bodies are retained for up to 12 months and deleted when you disconnect Google or upon expiry. The legal basis is Art. 6(1)(a) GDPR (consent). You can disconnect and delete this data at any time in Settings.

4.7 Third-party data (publicly sourced company contacts)

As part of AI-assisted research, the Service processes personal data of third parties (e.g. managing directors or company contacts) obtained from publicly accessible sources (websites, legal notice details, publicly available business directories). The legal basis is Art. 6(1)(f) GDPR (legitimate interest in initiating business contacts in the B2B sector). Data subjects may object at any time (see Section 10).

For investor profile data maintained in our proprietary database, see Section 4.8.

4.8 Proprietary investor database and conference data

FjordPoint Capital maintains a proprietary database of investor profiles, including names, firm affiliations, mandate characteristics, commitment histories, and conference attendance records. This database has been compiled from (a) publicly available sources including company websites, public filings, press releases, and published conference attendee/speaker lists (SuperReturn, IPEM, and similar events), and (b) relationship-sourced data from private markets professionals, provided with appropriate authorisation.

Data subjects in this database are third parties (investors, allocators, and their representatives) who have not directly provided their data to us. We process this data on the basis of Art. 6(1)(f) GDPR — our legitimate interest, and that of our users, in enabling efficient and targeted capital-raising in the B2B private markets context, consistent with investors' reasonable professional expectations.

Art. 14 GDPR applies: if you are an investor whose data appears in our database and you wish to access, correct, or delete that data, or to object to its processing, please contact us at fynton@fjordpoint-capital.com. We will respond within one month.

Important: commitment history data is used exclusively to generate aggregated, anonymised match quality signals. We do not directly disclose specific non-public investor-to-fund commitment relationships to users.

4.9 Analytics

We use PostHog (EU-hosted instance — no data transfer outside the EU/EEA) to understand how users interact with the platform and to improve our product. PostHog receives usage events including a pseudonymous user identifier, session duration, and in-product actions (e.g. login, swipe events, conversion events). Legal basis: Art. 6(1)(a) GDPR (consent via Cookiebot). DPA concluded with PostHog. Analytics cookies and local storage entries are set only after you accept statistics cookies in the Cookiebot banner (see Section 8).

5. Purposes of processing

  • Provision, operation, and technical maintenance of the Platform
  • Authentication and session management
  • AI-assisted investor matching, research, and enrichment
  • Personalisation of matching agents based on your interaction data
  • Billing and contract management
  • Communication within the contractual relationship (transactional emails, support)
  • Product analytics and improvement (with consent where required)
  • Protection against abuse, fraud prevention, IT security
  • Compliance with statutory retention obligations (e.g. German Commercial Code, Tax Code)

6. Legal bases for processing

  • Art. 6(1)(b) GDPR — performance of a contract (provision of the Service)
  • Art. 6(1)(c) GDPR — legal obligations (e.g. tax retention)
  • Art. 6(1)(f) GDPR — legitimate interests (IT security, abuse prevention, B2B company research, product improvement)
  • Art. 6(1)(a) GDPR — consent (where required, e.g. optional integrations)

7. Processors and external service providers

To provide our Service, we use carefully selected processors (Art. 28 GDPR) and third-party services. We have concluded appropriate data processing agreements (DPAs) with all processors. Where data is transferred to third countries outside the EU/EEA, this is based on EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and/or an adequacy decision (e.g. EU-US Data Privacy Framework).

7.1 Supabase (database & authentication)

Provider: Supabase Inc., 970 Toa Payoh North #07-04, Singapore 318992 / Supabase, Inc., Delaware, USA. We use Supabase to store all user and company data and for authentication. The session token (JWT) to maintain your login is stored exclusively in your browser’s local storage; we do not set cookies for this purpose. Our Supabase instance is hosted in the EU (AWS region Frankfurt). Legal basis: Art. 6(1)(b), (f) GDPR; DPA concluded; for US access, Standard Contractual Clauses and DPF certification.
More information: https://supabase.com/privacy · DPA

7.2 Render (hosting)

Provider: Render Services, Inc., 525 Brannan Street, San Francisco, CA 94107, USA. The application (backend API and frontend delivery) runs on Render in the Frankfurt region (EU). Legal basis: Art. 6(1)(b), (f) GDPR; DPA concluded, Standard Contractual Clauses, DPF.
More information: https://render.com/privacy · DPA

7.3 Stripe (payment processing)

Provider (EU): Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Parent company: Stripe, Inc., USA. Stripe processes all payments and handles your payment data (card/SEPA data) as an independent controller. We only receive metadata from Stripe (customer ID, subscription status, invoice amounts). Legal basis: Art. 6(1)(b) GDPR; DPF certified.
More information: https://stripe.com/privacy

7.4 OpenAI (AI processing)

Provider: OpenAI, L.L.C., 3180 18th Street, San Francisco, CA 94110, USA (or OpenAI Ireland Ltd. for EU customers). We use OpenAI APIs (e.g. GPT models) for AI-assisted company research, enrichment, and classification. Search criteria and publicly available company data are transmitted to OpenAI. Under OpenAI API terms, this data is not used to train models and is deleted by default after a maximum of 30 days. Legal basis: Art. 6(1)(b), (f) GDPR; DPA (Business Terms) concluded; Standard Contractual Clauses.
More information: https://openai.com/policies/privacy-policy · DPA

7.5 Google (OAuth login, Gmail & Calendar integration)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When you sign in with Google, Google transmits your email address and name to us. If you optionally connect Gmail and Google Calendar, we access email metadata (sender, recipients, date, subject) and, for business-relevant messages, email body text (cleaned and encrypted at rest), as well as calendar event metadata (attendees, date/time). Where enabled, we also use the Google Custom Search API to support research. Legal basis: Art. 6(1)(a) GDPR (login/integration by your choice) or Art. 6(1)(f) GDPR (search).
More information: https://policies.google.com/privacy

7.6 PostHog (analytics)

Provider: PostHog, Inc., 965 Mission St, San Francisco, CA 94103, USA / PostHog EU cloud. We use PostHog to analyse platform usage for product improvement purposes. EU-hosted instance — data processed in the EU; no international transfer for analytics events routed via our EU instance. DPA concluded.
More information: https://posthog.com/privacy

7.7 Cookiebot (consent management)

Provider: Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark. Cookiebot displays the cookie consent banner and stores your consent choices (see Section 8). When the banner loads, your IP address (truncated), browser information, and consent state are processed to document consent. Legal basis: Art. 6(1)(c) GDPR (proof of consent obligations) and Art. 6(1)(f) GDPR. Data processed in the EU.
More information: https://www.cookiebot.com/en/privacy-policy/

8. Cookies and local storage

We use technically necessary entries in your browser’s local storage or session storage that are required to carry out electronic communication or to provide certain functions you explicitly request (e.g. login session). This storage is permitted without consent under § 25(2) no. 2 TDDDG.

Specifically, we store the following in your browser:

  • Supabase Auth Session (local storage) — JWT token to maintain your login. Removed on logout.
  • Language (local storage, key locale) — stores your selected interface language.
  • UI preferences (session storage) — short-lived flags indicating whether you have dismissed certain notices (e.g. upgrade or quota notices) in the current browser session. Automatically deleted when you close the browser tab.
  • Cookie consent preference (cookie CookieConsent, set by Cookiebot) — stores your consent choices for this website. Required to remember your decision. Provider: Usercentrics A/S (Cookiebot), Havnegade 39, 1058 Copenhagen, Denmark. Legal basis: Art. 6(1)(c) GDPR in conjunction with § 25(2) TDDDG (proof of consent).

Consent management (Cookiebot): We use the consent management platform Cookiebot by Usercentrics to obtain and document your consent choices. The Cookiebot banner is shown on your first visit; non-essential cookies and identifiers are set only after you consent.

Analytics cookies (consent required): If you accept statistics cookies in the consent banner, PostHog may set cookies and use local storage to measure platform usage, maintain session continuity, and improve the product (see Sections 4.9 and 7.6). Legal basis: Art. 6(1)(a) GDPR (consent). You may change or withdraw your consent at any time via the “Cookie settings” link in the footer. If you decline analytics, PostHog operates in a cookieless mode that does not store identifiers in your browser.

We do not use marketing or advertising cookies. Google Analytics is not used on the Platform.

Note: When you visit external payment pages of our payment provider Stripe (e.g. checkout.stripe.com, billing.stripe.com), Stripe may set cookies on its own responsibility. Details are in Stripe’s privacy policy (see Section 7.3).

9. Storage period

We store personal data only as long as necessary to provide the Service or as required by statutory retention obligations (e.g. 6 or 10 years under German commercial and tax law for tax-relevant records). After you cancel your account, personal data is deleted within 30 days unless retention obligations apply. Server logs are deleted or anonymized after no more than 30 days.

10. Your rights as a data subject

Under the GDPR, you have the following rights:

  • Access (Art. 15 GDPR) — to data we store about you
  • Rectification (Art. 16 GDPR) — of inaccurate data
  • Erasure (Art. 17 GDPR) — “right to be forgotten”
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) — in a common, machine-readable format
  • Objection (Art. 21 GDPR) to processing based on Art. 6(1)(f) GDPR
  • Withdrawal of consent (Art. 7(3) GDPR), at any time with effect for the future

To exercise these rights, send an informal email to fynton@fjordpoint-capital.com. Exercising these rights is free of charge for you.

11. Right to lodge a complaint with a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority about our processing of your personal data (Art. 77 GDPR). The authority responsible for us is:

The Hessian Commissioner for Data Protection and Freedom of Information
Postfach 3163
65021 Wiesbaden
Germany
Phone: +49 611 1408 - 0
https://datenschutz.hessen.de

12. Automated processing and profiling

Fynton uses automated processing to generate investor match recommendations based on your mandate, agent configuration, and interaction history. This constitutes profiling within the meaning of Art. 4(4) GDPR. However, it does not produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR: all outputs are recommendations for support only, and every decision remains yours (“human in the loop”). You may request human review of any automated output by contacting us at fynton@fjordpoint-capital.com.

13. Data security

We implement appropriate technical and organizational measures (Art. 32 GDPR), including: TLS encryption in transit, encrypted storage of sensitive data (e.g. integration API keys via Fernet), row-level security in the database, role-based access control, minimized service account principle, regular backups, and monitoring.

14. Minors

Our Service is intended exclusively for business users and adults. We do not knowingly process data of persons under 18 years of age.

15. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy so that it always meets current legal requirements or to reflect changes to our services. The updated version applies on your next visit.

Legal notice / Imprint · Privacy · Terms · Disclaimer · DPA ·