Legal

Privacy Policy

How Founder1st collects, uses, stores and protects information belonging to clients, prospective clients and portal users.
PlaceholderThis document describes Founder1st's actual data practices but is not legal advice and has not yet been reviewed by counsel. Requires Founder1st legal review before production use.

1. Information we collect

  • Contact and identity information provided by a client principal or authorised contact, including name, business email, telephone number and business address.
  • Company information provided during onboarding, including entity details, registration identifiers, financial baselines, client and pipeline information, team structure and strategic objectives.
  • Documents uploaded to the client portal by a client organisation.
  • Technical records generated by use of the portal, including authentication events, access records, IP address and browser user agent.

2. Why we collect it

  • To perform the advisory engagement contracted between Founder1st and the client organisation.
  • To produce diagnostics, strategic plans and deliverables for that organisation.
  • To administer, secure and audit access to the client portal.
  • To meet record-keeping obligations relating to signed agreements.

3. Data minimisation

  • Onboarding does not require date of birth, personal financial information or personal tax identifiers unless a specific legal or regulatory requirement applies to the engagement.
  • Sensitive commercial fields are optional and can be declined without preventing onboarding.
  • Passwords are never collected in onboarding or held in Founder1st application tables. Authentication credentials are handled solely by the authentication provider.

4. Access and confidentiality

  • Client information is segregated by organisation and enforced at the database layer, not only in the interface.
  • Founder1st personnel access a client record only where their role and assignment permit it.
  • Documents are held in private storage and served only through short-lived authorised links. Access is recorded.

5. Retention

  • Retention periods vary by category of information and are published on the data retention page.
  • Records subject to a legal or contractual retention requirement are flagged and retained rather than deleted.

6. Your rights

  • A client organisation may request an export of its structured record or the deletion of information not subject to a retention requirement, through the client portal or its engagement lead.
  • Requests are reviewed, actioned by an authorised person and recorded.

7. Third parties

  • Founder1st uses infrastructure providers for hosting, database, storage, authentication and email delivery. These providers process information on Founder1st's instruction.
  • Founder1st does not sell client information.

8. Contact

  • Questions about this policy should be directed to your Founder1st engagement lead.