Privacy policy

Last updated: Sep 2, 2026

This policy explains how SubsidySignal ("we", "us") processes personal data when you visit this website or use the SubsidySignal service. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

Controller

The data controller is:

[TO BE COMPLETED BY OPERATOR — legal entity name, address, country]

Contact for privacy matters: [TO BE COMPLETED BY OPERATOR — privacy contact email]

What data we process, and why

Account data

When you create an account we process your email address, your name (if provided), your password (stored only as a salted hash by our authentication provider) and your interface language preference.

  • Purpose: providing the service you signed up for — authentication, your dashboard, your signal reports.
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Retention: for the life of your account. When you delete your account, account data is deleted; residual copies in encrypted backups expire within 35 days.

Organization and vendor profile data

To match funding signals to your business, you (or colleagues in your organization) provide information about your company: name, website, what you sell, target industries, countries served, and report recipient email addresses.

  • Purpose: generating and delivering relevant funding signals; this is the core function of the service.
  • Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Retention: for the life of the organization account. Report recipients can unsubscribe from every email; unsubscribed addresses are suppressed, not re-added.

Billing data

Paid subscriptions are processed by Stripe. We store your plan, subscription status and a Stripe customer reference. Full payment card details are handled by Stripe and never reach our servers.

  • Legal basis: performance of a contract and legal obligations (tax and accounting law).
  • Retention: as required by applicable tax and commercial law (typically up to 10 years for invoices).

Usage analytics (first-party)

We record a small number of first-party, cookieless product events (for example "landing page visited", "signup completed") to understand aggregate funnel performance. These events are not tied to advertising identifiers and are not shared with advertising networks. We do not use third-party analytics or tracking pixels.

  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving our own service.
  • Retention: aggregate event data is retained for up to 24 months.

Server logs

Our hosting infrastructure records technical request logs (IP address, user agent, timestamp) for security and error diagnosis.

  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in operating a secure service.
  • Retention: short-lived, per our hosting providers' standard log retention (typically ≤ 30 days).

Data about funding recipients

The funding database shown on this site contains organization-level information from official public sources (CORDIS, the Financial Transparency System, TED). We exclude natural-person beneficiaries at ingestion and follow the source publishers' retention rules. If you believe a record on this site identifies a natural person, contact us and we will review and remove it where required.

Processors and recipients

We use the following processors under Art. 28 GDPR data processing agreements:

Processor Purpose Location
Supabase Database, authentication, storage EU region hosting
Stripe Payment processing and billing EU/US — EU SCCs and Data Privacy Framework
Resend Transactional and report email delivery EU/US — SCCs
Netlify Web hosting and content delivery EU/US — SCCs
Anthropic AI analysis of public funding records US — SCCs. Only public funding-record text is sent; no customer account data.

Payments are processed by Stripe; we receive only the billing status and the last digits of the payment method, never full card data. Cancellation and refund terms are set out in our Terms of service.

We do not sell personal data and we do not share it with advertisers.

International transfers

Where a processor processes data outside the EU/EEA, transfers rely on adequacy decisions (including the EU–US Data Privacy Framework where certified) and/or Standard Contractual Clauses.

Your rights

Under the GDPR you have the right to access, rectify, and erase your personal data; the right to restrict or object to processing; the right to data portability; and the right to withdraw consent at any time where processing is based on consent. You can exercise most of these directly in your account settings (data export, account deletion) or by contacting us at the address above.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or workplace.

Automated decision-making

Purchase predictions concern organizations that received public funding, not our users, and produce no legal or similarly significant effects on any natural person. We do not perform automated decision-making within the meaning of Art. 22 GDPR on our users.

Changes

We will update this policy when our processing changes and indicate the date of the last revision above. Material changes are announced to account holders by email.