All policies

Data Governance Policy

How data is classified, who may access it, where it lives, and when it is destroyed.

Draft — pending legal reviewVersion 0.1.0Updated 8 August 2026

Draft — pending legal review.This document describes our intended practice but has not completed legal review, and is not yet in force. Please don't rely on it as a binding agreement until it is marked active with an effective date.

How we classify data

Different data warrants different handling, so we classify it and apply controls by class rather than treating everything identically.

  • Restricted: credentials, authentication tokens, and payment identifiers. Never logged, never exported in plain text.
  • Confidential: your venture content, documents, and decisions. Access limited to you and those you grant it to.
  • Internal: aggregate operational metrics with no personal detail.
  • Public: marketing content and these policy documents.

Who can access your data

Within your workspace, access follows the roles you assign. Row-level security enforces those boundaries in the database itself, so permissions do not depend on the application getting every check right.

Our staff do not browse customer content. Access to production data requires a specific operational reason such as a support request you raised or an active incident, is limited to the minimum needed, and is logged.

Where your data lives

Data is stored with our infrastructure providers in the regions stated in your account settings. Where processing requires an international transfer, we rely on appropriate safeguards such as standard contractual clauses.

Retention and destruction

We keep data only as long as it serves a purpose, and destroy it on a defined schedule rather than leaving it to accumulate.

  • Active venture content: retained while your account is open.
  • Deleted items: purged from live systems immediately and from backups within 30 days.
  • Closed accounts: content deleted within 30 days, subject to legal retention duties.
  • Activity records: retained 12 months, then deleted.
  • Backups: retained 35 days on a rolling basis.

Subprocessors

We use a small set of subprocessors for hosting, database, authentication, and email. Each is contractually bound to equivalent protection standards, and we maintain a current list available on request.

Exercising your rights

Requests to access, export, correct, or delete data can be made in Settings or by writing to privacy@founderos.app. We respond within 30 days and will tell you if we need longer and why.