Legal information
Privacy Policy
Last updated 28/08/2026.
This page is maintained internally and, until a lawyer has reviewed it, shouldn't be treated
as final legal copy. Bracketed items ([ ... ]) mark facts that still need
confirming.
Who this applies to
This policy covers personal data processed by Funding Monitor when you or your organization use the Service. The data controller is [ECECT — registered address to be confirmed], established in the Republic of Cyprus. Because the Service and its data controller are based in Cyprus, an EU member state, this processing is governed directly by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) together with Cyprus's own national law implementing it (the Protection of Natural Persons against the Processing of Personal Data Law of 2018, Law 125(I)/2018 [citation to be verified by a lawyer]).
What we collect, and why
| Data | Why |
|---|---|
| Account email, name, hashed password | To create and secure your account, and to let your team log in. |
| Organization profile details you provide (sector, description, past projects, preferences), and any document you upload (e.g. a Partner Identification Form) | To draft and run the matching that's the whole point of the Service — this is the data an AI model reads to score funding calls against your organization. |
| Login session data: an IP address and browser identifier at login time, and when you were last active | Security — detecting suspicious logins, letting you (or an admin) see and revoke active sessions, enforcing an optional idle-timeout. |
| Page-view usage data (which pages you visited, when) | Usage analytics for your own organization and, platform-wide, for the people running the Service — kept for 90 days, then automatically deleted. |
| Notes, flags, and match-status you set on a funding call | Shared within your own organization's account so your team can track what you're working on — never shown to other organizations. |
AI processing
Extracting call details and scoring matches uses an AI model. Depending on which provider is configured, this is either a self-hosted model running on infrastructure we control (no data leaves our systems) or a cloud AI provider (currently supported: Claude/Anthropic, OpenAI, DeepSeek, Mistral, or a gateway routing to one of these). If a cloud provider is active, the text being processed — funding-call content and, when scoring a match, a summary of your organization's profile — is sent to that provider under their own terms. Mistral is EU-headquartered; the others are not — worth knowing if EU data residency matters to your organization. We don't use AI-processed content to train any provider's models beyond what that provider's own default terms already state.
Artificial intelligence and the EU AI Act
The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) applies to AI systems placed on the market or put into use within the EU, with its obligations phasing in across 2025-2027. Funding Monitor's AI use — reading public funding-call text to extract structured details, and computing a Matching% relevance score against your own organization's profile — doesn't decide credit, employment, biometric identification, law enforcement, or any other outcome listed in the Act's Annex III as “high-risk.” We treat it instead as a limited-risk AI system subject to the Act's Article 50 transparency duty: every score or extracted detail is clearly presented as AI-generated, and the Disclaimer explains its real, known limitations in plain language. [A qualified lawyer should confirm this risk classification before it's relied on.]
Cookies
We use only the cookies needed to keep you logged in: a session cookie, and — if you tick “Remember me” at login — a longer-lived cookie so you don't have to log in again for up to 30 days. We don't use advertising or third-party tracking cookies.
Who else sees your data
Within the Service, an organization's own data (profile, matches, notes) is visible only to users assigned to that organization, plus platform administrators who operate the Service. We don't sell personal data, and we don't share it with third parties except: the AI provider processing a request (see above), and, if configured, an outbound email provider used solely to send password-reset emails.
How long we keep it
Account and organization data is kept for as long as your account is active. Page-view usage data is automatically deleted after 90 days. A login session is deleted when you log out, when it's idle past any configured timeout, or if it's evicted by a concurrent-login limit.
Your rights
Depending on where you're located, you may have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. Ask your organization's Platform Admin — accounts and organization profiles can both be deleted on request — or contact us directly at [privacy contact email to be added]. If you believe we haven't handled your data properly, you also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection — Cyprus's national supervisory authority (dataprotection.gov.cy) — or with the supervisory authority in your own EU member state if different.
Changes to this policy
We may update this policy as the Service changes. Material changes will be communicated through the Service.