Grant Fund
Trust & legal

Privacy Policy

Last revised August 12, 2026Version 3.0

1. Introduction

1.1. This Privacy Policy explains how Grant Fund LLC ("Grant Fund", "we", "us", or "our") collects, uses, stores, discloses, and otherwise processes personal data in connection with the Grant Fund website, application, Passport workflow, grant eligibility screening, AI-assisted funding analysis, readiness reports, negative-match memos, weekly radar updates, exports, support, billing, KYC/KYB, compliance, and related services.

1.2. This Policy is intended for publication on the Grant Fund website and inside the application. It should be read together with the Terms and Conditions / Terms of Service, Cookie Policy, Data Processing Addendum, Subprocessor List, AI Processing Notice, Data Retention Summary, KYC/KYB Privacy Notice, and other applicable legal documents.

1.3. The Service is intended primarily for Business Users. Individuals may nevertheless have rights as data subjects under applicable data-protection law regardless of whether their company account is used for business purposes.

2. Controller identity and contact details

2.1. Controller: Grant Fund LLC.

2.2. Jurisdiction: Delaware, United States.

2.3. Registered address: 16192 Coastal Highway, Lewes, DE 19958, USA.

2.4. Delaware file number: ХХХХХ3115.

2.5. EIN: ХХ-ХХХ7314.

2.6. EU VAT (non-Union OSS): ХХХХХ6151.

2.7. Legal and privacy email: privacy@grant.fund.

2.8. Grant Fund is established outside the European Economic Area. Our representative for the purposes of Article 27 of the GDPR is Ivan Petrakov. Where a Data Protection Officer or a UK or Swiss representative is appointed, the relevant contact details are published at the foot of every page in this legal section.

3. Role of Grant Fund

3.1. Grant Fund generally acts as an independent controller for account administration, website operation, billing, tax, compliance, KYC/KYB, fraud prevention, security, product analytics, communications, support, legal defence, service administration, and business operations.

3.2. Grant Fund may act as a processor where a Business User, grant consultant, accelerator, investor, or company submits personal data about founders, employees, contractors, advisors, clients, portfolio companies, consortium partners, customers, or other third parties into the Service and determines the purposes and means of processing that data. Where Grant Fund acts as processor, the Data Processing Addendum applies to the extent required by applicable law.

3.3. Users who submit personal data about other individuals are responsible for providing required privacy notices, identifying a lawful basis, obtaining required consents or authorisations, and ensuring that such data may lawfully be processed through the Service.

4. Categories of personal data

4.1. Account data: name, business email, password credentials or authentication data, organisation name, role, user ID, account settings, plan information, user permissions, and login metadata.

4.2. Contact and communication data: email address, telephone number where provided, message content, support requests, feedback, survey responses, call notes, and other communications.

4.3. Billing and payment data: plan, subscription status, invoices, VAT and other tax identification data, billing address, transaction identifiers, payment method metadata, tax status, refund data, chargeback data, payment-risk signals, and payment processor records. Grant Fund does not need to store full card numbers where payment processors handle them directly.

4.4. Passport data: company name, jurisdiction, incorporation status, legal entity type, founding date, headcount, revenue, balance sheet, SME indicators, ownership indicators, UBO information, sector, technology readiness level, IP status, prior funding, funding history, planned consortium structure, partner commitments, customer letters, regulatory status, compliance status, and related company or founder profile data.

4.5. Company and founder data: names of founders, directors, officers, employees, contractors, advisors, team members, shareholders, beneficial owners, investors, board members, client representatives, portfolio company contacts, and other business contacts; roles; professional profiles; CV information; work history; relevant expertise; and public-source references.

4.6. KYC/KYB and compliance data: identity information, business registration data, ownership and control information, UBO data, sanctions screening results, restricted-party indicators, PEP indicators, adverse media indicators, source-of-funds information, geography, sector, compliance responses, fraud indicators, risk flags, verification status, and records of compliance decisions.

4.7. Public-source enrichment data: data from company registries, official portals, public websites, grant databases, Official Sources, press releases, public business profiles, public funding records, and other publicly available materials used to enrich, validate, compare, or warn about Passport data.

4.8. Grant-search and report data: search parameters, screening history, programme matches, fit or not-fit classifications, readiness gaps, negative-match memos, weekly radar updates, report contents, source references, export files, and user actions relating to reports.

4.9. Uploaded files and user content: documents, PDFs, spreadsheets, pitch decks, financial models, screenshots, technical summaries, support attachments, prompts, comments, responses, and other files or text submitted by or for the User.

4.10. AI logs and audit logs: prompts, source excerpts, model inputs, model outputs, confidence metadata, review logs, trace metadata, system traces, classification records, quality-control records, and audit records where retained for safety, security, debugging, auditability, legal defence, quality control, abuse prevention, compliance, or product improvement.

4.11. Usage and technical data: IP address, device identifiers, browser type, operating system, language, time zone, pages visited, features used, clicks, session duration, referral data, approximate location derived from IP address, authentication logs, error logs, performance logs, cookies, and similar technologies.

4.12. Security and abuse-prevention data: access logs, security logs, device fingerprints where lawful, fraud signals, bot detection data, abuse reports, account-integrity signals, rate-limit data, and incident records.

4.13. Special-category personal data: the Service is not designed to collect special-category personal data, criminal-offence data, children's data, biometric data, health data, or highly regulated personal data. Users must not submit such data unless expressly necessary for the permitted use of the Service, lawful, and authorised.

5. Purposes of processing

5.1. To provide, operate, maintain, and secure the Service.

5.2. To create, maintain, and update Accounts and Passports.

5.3. To screen company and project data against Funding Programs and Official Sources.

5.4. To generate reports, readiness gaps, negative-match memos, radar updates, exports, alerts, source references, and other Outputs.

5.5. To process subscriptions, payments, taxes, invoices, VAT receipts, refunds, chargebacks, and billing disputes.

5.6. To provide support, respond to requests, process feedback, and communicate with Users.

5.7. To perform KYC/KYB, sanctions, export-control, UBO, AML, fraud-prevention, abuse-prevention, and compliance checks.

5.8. To detect, prevent, investigate, and respond to security incidents, misuse, unauthorised access, scraping, payment fraud, policy violations, and legal risks.

5.9. To improve, test, debug, monitor, and develop the Service, including quality control, product analytics, system reliability, AI safety, source quality, and database quality.

5.10. To comply with legal, tax, accounting, audit, regulatory, sanctions, payment, and reporting obligations.

5.11. To establish, exercise, or defend legal claims and enforce the Terms and related agreements.

5.12. To send service, security, billing, legal, product, and administrative notices.

5.13. To send marketing communications where permitted by law and subject to any required consent or opt-out rights.

6. Legal bases under GDPR

6.1. Contract performance: where processing is necessary to provide the Service, manage Accounts, deliver paid features, generate Outputs, provide exports, process support, and administer subscriptions.

6.2. Legitimate interests: where processing is necessary for service security, fraud prevention, abuse prevention, product improvement, analytics, AI safety, database quality, customer support, business operations, legal defence, direct marketing to business contacts where permitted, and enforcement of rights, provided those interests are not overridden by the rights and freedoms of data subjects.

6.3. Legal obligation: where processing is necessary for tax, accounting, VAT, invoicing, payment, sanctions, AML/KYC/KYB, regulatory, consumer-law, court, law-enforcement, or other legal obligations.

6.4. Consent: where required for non-essential cookies, analytics, marketing communications, optional data collection, or other consent-based processing.

6.5. Vital interests or public interest: only where legally applicable and exceptional.

6.6. Processor processing: where Grant Fund acts as processor, the lawful basis is determined by the User acting as controller, and Grant Fund processes personal data under documented instructions subject to the DPA.

7. Automated processing and AI-assisted Outputs

7.1. Grant Fund uses automation and AI-assisted systems to classify, extract, summarise, source-match, screen, and generate Outputs in connection with grant eligibility and workflow support.

7.2. Outputs are informational and decision-support materials only. They are not official Grantor decisions and are not legal, tax, accounting, financial, investment, immigration, procurement, compliance, state-aid, sanctions, export-control, patent, intellectual-property, or regulated professional advice.

7.3. The Service is not designed to make automated decisions about individuals that produce legal effects or similarly significant effects. Users must not use the Service for high-risk automated decisions about individuals unless they have independently ensured full legal compliance and obtained Grant Fund's prior written consent where required.

7.4. AI-assisted Outputs may be inaccurate, incomplete, outdated, non-exhaustive, misclassified, or unsuitable. Users must independently verify Outputs against Official Sources and obtain professional advice where appropriate.

8. AI providers and model training

8.1. Grant Fund may use OpenAI, Anthropic, Mistral, self-hosted models, proprietary models, third-party AI vendors, infrastructure providers, retrieval providers, monitoring providers, and other AI or infrastructure providers.

8.2. Grant Fund does not share User Passport data with external AI providers unless disclosed in this Privacy Policy, the DPA, or the Subprocessor List.

8.3. User Data is not used to train third-party foundation models unless expressly disclosed and legally permitted.

8.4. Grant Fund may use User Data, AI logs, source excerpts, model inputs, model outputs, and audit records for safety, security, debugging, auditability, legal defence, quality control, abuse prevention, compliance, and product improvement, subject to applicable law and contractual restrictions.

9. Recipients and subprocessors

9.1. Grant Fund may disclose personal data to employees, contractors, founders, officers, advisors, counsel, auditors, accountants, service providers, subprocessors, payment providers, tax/VAT processors, hosting providers, cloud infrastructure providers, AI providers, analytics providers, monitoring providers, customer support providers, compliance providers, KYC/KYB providers, fraud-prevention providers, communication providers, and other vendors involved in operating the Service.

9.2. Grant Fund may disclose personal data to banks, payment processors, card networks, tax authorities, courts, regulators, law-enforcement bodies, public authorities, sanctions authorities, Grantors, or other third parties where required or permitted by law, necessary for compliance, or necessary to protect rights, security, or legitimate interests.

9.3. Grant Fund may publish and update a Subprocessor List. Subprocessors may change over time subject to the DPA and applicable law.

9.4. Third-party services may process personal data under their own terms and privacy policies where they act as independent controllers, including payment processors and certain compliance providers.

10. International transfers

10.1. Grant Fund is based in Delaware, United States and hosts the Service in the EU/EEA through Hetzner or other reputable EU/EEA infrastructure providers. Because Grant Fund is itself established outside the EEA, access to personal data by Grant Fund is a transfer out of the EEA even though the data is stored within it. Some service providers, support personnel, AI providers, payment providers, compliance providers, or other recipients are also located outside the EEA.

10.2. Where personal data is transferred to third-party recipients outside the EEA, the United Kingdom, Switzerland, or other relevant jurisdictions, Grant Fund relies on lawful transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, transfer-impact assessments, supplementary measures, derogations, or other lawful mechanisms. The safeguard covering Grant Fund's own access described in §10.1 is being put in place with counsel and this Section will be updated once it is; until then, that access remains protected by the measures described in the Security Statement, and the GDPR continues to apply to it in full under Article 3(2).

10.3. Copies of applicable transfer mechanisms may be made available where required by law, subject to confidentiality, security, and commercial limitations.

11. Data retention

11.1. Grant Fund retains personal data only for as long as necessary for the purposes described in this Privacy Policy, unless longer retention is required or permitted for legal, tax, accounting, security, audit, dispute, compliance, anti-fraud, backup, legitimate business, or legal-defence reasons.

11.2. Grant Fund provides an archive at the point of Account closure, where technically and legally possible. The User is prompted to download it before the Account is closed, and a copy is sent to the registered email address. Access to the Service ends immediately on closure.

11.3. Ninety (90) days after closure, User Data is deleted or anonymised unless longer retention is required or permitted for legal, tax, accounting, security, audit, dispute, compliance, anti-fraud, backup, legitimate business, or legal-defence reasons.

11.4. Backup copies may persist for a limited period after deletion in accordance with Grant Fund's backup and disaster-recovery practices.

11.5. Security logs, audit logs, payment records, tax records, compliance records, KYC/KYB records, abuse-prevention records, AI logs, and legal-defence records may be retained for longer where required or permitted by law.

12. Data subject rights

12.1. Subject to applicable law, data subjects may have rights to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and not to be subject to solely automated decisions that produce legal or similarly significant effects.

12.2. Rights requests may be sent to privacy@grant.fund. Grant Fund may need to verify identity and authority before responding.

12.3. Some rights may be limited by legal, tax, accounting, security, audit, compliance, anti-fraud, dispute, legal-defence, confidentiality, or third-party-rights reasons.

12.4. Where Grant Fund acts as processor, it may refer the request to the relevant User acting as controller or assist that User in responding to the request in accordance with the DPA.

13. Right to complain

13.1. Data subjects in the European Economic Area have the right to lodge a complaint with the supervisory authority of their country of residence, their place of work, or the place of the alleged infringement. Grant Fund is established outside the Union and therefore has no single lead supervisory authority; the competent authority is the one local to the data subject.

13.2. The list of national supervisory authorities is published by the European Data Protection Board at www.edpb.europa.eu. In the United Kingdom the competent authority is the Information Commissioner's Office (www.ico.org.uk); in Switzerland, the Federal Data Protection and Information Commissioner (www.edoeb.admin.ch).

13.3. Data subjects may also contact Grant Fund first at privacy@grant.fund so that Grant Fund can attempt to address the issue directly. Doing so does not affect the right to complain to a supervisory authority.

14. Security summary

14.1. Grant Fund uses technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction.

14.2. Measures may include access controls, authentication controls, encryption in transit where appropriate, network security, logging, monitoring, backup procedures, least-privilege permissions, vendor controls, confidentiality obligations, incident response procedures, and internal access restrictions.

14.3. No online service can guarantee absolute security. Users are responsible for maintaining secure credentials, managing internal access, controlling uploads, and notifying Grant Fund of suspected compromise.

14.4. Grant Fund does not claim ISO 27001, SOC 2, or similar certification unless expressly stated as certified in a current published security document.

15. Use by consultants, accelerators, investors, and client representatives

15.1. Grant consultants, accelerators, investors, advisors, venture studios, and similar professional users may submit data about clients, portfolio companies, founders, employees, or third parties only where they have lawful authority and a valid legal basis to do so.

15.2. Such users remain responsible for providing required notices, obtaining required consents, respecting confidentiality obligations, complying with controller obligations, and ensuring that submitted data is accurate, lawful, current, and authorised.

15.3. Grant Fund may require such users to enter into a DPA or provide evidence of authority where appropriate.

16. Cookies and similar technologies

16.1. Grant Fund uses cookies and similar technologies as described in the Cookie Policy.

16.2. Non-essential cookies will be used only where permitted by applicable law and, where required, after consent.

17. Changes to this policy

17.1. Grant Fund may update this Privacy Policy from time to time.

17.2. Material changes may be notified by email, dashboard notice, website notice, or other reasonable means.

17.3. Continued use of the Service after an updated Policy becomes effective is subject to the updated Policy, without prejudice to mandatory data-subject rights.

18. Contact

18.1. Controller: Grant Fund LLC.

18.2. Registered address: 16192 Coastal Highway, Lewes, DE 19958, USA.

18.3. Privacy email: privacy@grant.fund.

Questions about your data?

For any privacy request or question, contact us at privacy@grant.fund.

Data Protection Officer / EU representative: Ivan Petrakov

Cookie preferences

We use strictly necessary cookies to run the site, and — only with your consent — analytics and marketing cookies. You can change your choice anytime.