Privacy policy
Last updated: Sep 2, 2026
This policy explains how SubsidySignal ("we", "us") processes personal data when you visit this website or use the SubsidySignal service. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
Controller
The data controller is:
[TO BE COMPLETED BY OPERATOR — legal entity name, address, country]
Contact for privacy matters: [TO BE COMPLETED BY OPERATOR — privacy contact email]
What data we process, and why
Account data
When you create an account we process your email address, your name (if provided), your password (stored only as a salted hash by our authentication provider) and your interface language preference.
- Purpose: providing the service you signed up for — authentication, your dashboard, your signal reports.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Retention: for the life of your account. When you delete your account, account data is deleted; residual copies in encrypted backups expire within 35 days.
Organization and vendor profile data
To match funding signals to your business, you (or colleagues in your organization) provide information about your company: name, website, what you sell, target industries, countries served, and report recipient email addresses.
- Purpose: generating and delivering relevant funding signals; this is the core function of the service.
- Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Retention: for the life of the organization account. Report recipients can unsubscribe from every email; unsubscribed addresses are suppressed, not re-added.
Billing data
Paid subscriptions are processed by Stripe. We store your plan, subscription status and a Stripe customer reference. Full payment card details are handled by Stripe and never reach our servers.
- Legal basis: performance of a contract and legal obligations (tax and accounting law).
- Retention: as required by applicable tax and commercial law (typically up to 10 years for invoices).
Usage analytics (first-party)
We record a small number of first-party, cookieless product events (for example "landing page visited", "signup completed") to understand aggregate funnel performance. These events are not tied to advertising identifiers and are not shared with advertising networks. We do not use third-party analytics or tracking pixels.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving our own service.
- Retention: aggregate event data is retained for up to 24 months.
Server logs
Our hosting infrastructure records technical request logs (IP address, user agent, timestamp) for security and error diagnosis.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating a secure service.
- Retention: short-lived, per our hosting providers' standard log retention (typically ≤ 30 days).
Data about funding recipients
The funding database shown on this site contains organization-level information from official public sources (CORDIS, the Financial Transparency System, TED). We exclude natural-person beneficiaries at ingestion and follow the source publishers' retention rules. If you believe a record on this site identifies a natural person, contact us and we will review and remove it where required.
Processors and recipients
We use the following processors under Art. 28 GDPR data processing agreements:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | EU region hosting |
| Stripe | Payment processing and billing | EU/US — EU SCCs and Data Privacy Framework |
| Resend | Transactional and report email delivery | EU/US — SCCs |
| Netlify | Web hosting and content delivery | EU/US — SCCs |
| Anthropic | AI analysis of public funding records | US — SCCs. Only public funding-record text is sent; no customer account data. |
Payments are processed by Stripe; we receive only the billing status and the last digits of the payment method, never full card data. Cancellation and refund terms are set out in our Terms of service.
We do not sell personal data and we do not share it with advertisers.
International transfers
Where a processor processes data outside the EU/EEA, transfers rely on adequacy decisions (including the EU–US Data Privacy Framework where certified) and/or Standard Contractual Clauses.
Your rights
Under the GDPR you have the right to access, rectify, and erase your personal data; the right to restrict or object to processing; the right to data portability; and the right to withdraw consent at any time where processing is based on consent. You can exercise most of these directly in your account settings (data export, account deletion) or by contacting us at the address above.
You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or workplace.
Automated decision-making
Purchase predictions concern organizations that received public funding, not our users, and produce no legal or similarly significant effects on any natural person. We do not perform automated decision-making within the meaning of Art. 22 GDPR on our users.
Changes
We will update this policy when our processing changes and indicate the date of the last revision above. Material changes are announced to account holders by email.