Who is responsible
Musubi is a startup and investor workspace operated from Athens, Greece. The registered legal entity and postal address have not yet been supplied for this draft. The current project contact is hello@musubi.vc; confirmation of the responsible controller and privacy contact is required.
This notice covers personal information processed to operate Musubi. Organizations using their workspaces may independently determine how they use information about team members, founders, applicants, and investment contacts. Any processing carried out solely on an organization’s instructions requires an appropriate data processing agreement and a clear allocation of responsibilities.
Information in the platform
Account records include name, work email, password hash, organization membership, account type, approval status, and session records such as IP address, user agent, and expiry. We also process security and operational logs.
Profiles can contain company and fund descriptions, sectors, geography, websites, professional links, team information, investment preferences, and contact details. Workspace records include funding opportunities, applications and reviews, funding history, commitments, cap-table or equity assumptions, revenue and other KPIs, milestones, notifications, follows, and updates.
Assessments may include founder scenario responses, derived scores, company assessments, reviewer feedback, and challenges. Where legacy recruitment features are used, records can also include professional candidate profiles, experience, skills, saved candidates, and job-related preferences. These features are distinct from the current funding-focused homepage.
Billing records include Stripe customer and subscription identifiers, plan status, transaction-related events, and checkout references. Payment card details are collected through Stripe’s payment interface. Contact inquiries contain the name, email, and message you submit and are sent to our configured business mailbox.
Information comes from you, your organization’s members, counterparties who review or respond to your activity, administrators, and service providers such as Stripe. Do not upload health information, government identifiers, criminal records, or other sensitive personal information into free-text fields unless a specific lawful and supported process has been agreed.
Purposes and legal bases
We use account and workspace information to provide requested services and respond to pre-contract inquiries. The contractual basis applies where the individual is a party to the contract; for representatives of organizations, our proposed basis is legitimate interests in operating the organization’s account and communicating with its representatives.
Security, abuse prevention, service maintenance, relevant matching, and ordinary business communications rely on legitimate interests, subject to necessity and balancing against individual rights. Accounting and legally required disclosures rely on legal obligations. Optional preference cookies rely on consent. Any future marketing or additional processing needs its own appropriate basis and notice.
Required account and application fields are needed to deliver the relevant feature. If you do not provide them, that feature may not be available. Optional fields are voluntary. Providing a third party’s personal information requires authority and an appropriate legal basis; that person must also receive the applicable privacy information.
Visibility and recipients
Profile fields exposed by public company and investor pages can be accessed by visitors and potentially indexed by search engines. Other workspace records are made available according to the feature, membership, sharing choices, and applicable permissions. Applications and investment requests are shared with the relevant counterparty; authorized reviewers and administrators may access records needed for their work.
Infrastructure, database, email, security, and payment providers process information needed to supply their services. The code integrates Stripe for billing and Cloudflare Turnstile for bot checks. Turnstile processes technical browser and network signals under Cloudflare’s applicable privacy terms. The production hosting, email provider, processing locations, and contractual roles still need to be confirmed.
Information may be disclosed where legally required or necessary to address fraud, security incidents, or legal claims. This draft does not promise that all information remains in the EU. Any transfer outside the EEA must be reviewed for a valid transfer mechanism, such as an adequacy decision or appropriate contractual safeguards, and information about those safeguards must be available on request.
Matching and assessments
Musubi calculates fit and assessment indicators from supplied profiles, funding requirements, milestones, and assessment responses. These indicators can help prioritize or evaluate opportunities and may constitute profiling where they relate to an identifiable person.
Scores are not guarantees of investment, suitability, or performance. Founder Signal results include a sharing choice for investors. Ask us to correct inaccurate source information or explain and review a result that concerns you. The current scoring features support human review; they are not described here as a system for making legally significant decisions solely by automation. Any such use requires a separate legal assessment and safeguards.
Cookies and browser storage
Essential session cookies support sign-in and security. The musubi_cookie_consent cookie records privacy choices for 180 days. Optional preference cookies can be declined or changed through Cookie settings without losing core access.
The sidebar also stores its collapsed or expanded state in local browser storage. This is separate from cookies. The current consent configuration contains essential and preference categories; it does not enable an advertising category. Cloudflare’s bot checks may process technical information when an authentication challenge runs. A production storage inventory must confirm each deployed technology and whether consent or an exemption applies.
Retention and security
Account and workspace data is retained while needed to provide the service and manage the relevant business relationship. Retention after closure depends on outstanding transactions, legal obligations, dispute periods, security needs, and backup arrangements. Inquiry emails also depend on the business mailbox’s retention settings. Specific periods and deletion procedures are not yet confirmed; this draft does not promise automated deletion after a fixed period.
Passwords are stored as hashes, and access is controlled through accounts, memberships, permissions, and administrative checks. Production transport protection, backup controls, provider contracts, and incident procedures must be verified before launch. No service can guarantee absolute security. If a personal-data breach occurs, applicable GDPR assessment and notification duties apply.
Your rights and contact
Depending on the processing, you may request access, correction, erasure, restriction, or portability, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. Some rights are limited by legal obligations or the rights of other people.
Send requests to the confirmed privacy contact; until then, use hello@musubi.vc. We may need proportionate identity verification. GDPR requests are normally answered within one month; permitted extensions require an explanation. You may complain to a supervisory authority where you live or work or where an alleged infringement occurred. In Greece this is the Hellenic Data Protection Authority (www.dpa.gr).
Musubi is designed for adult professional users, not children. Material changes to processing require updated information before the new processing begins. The draft date above identifies this version.
Contact: hello@musubi.vc