Who is responsible
The data controller is Ventures.eu Unipessoal Lda, Rua Rodrigues Sampaio 31, 4º Dto., 1150-278 Lisboa, Portugal. For any privacy question or to exercise your rights, contact grantcompass@dealflow.eu.
What we collect
- Account details — your first name, last name and email address, provided when you create an account.
- Company details — your company name and company website/domain, plus any profile information you choose to add (sector, stage, country, team size, description) and your matching preferences (funding type, ticket size, consortium readiness, technology readiness level).
- Usage data — a limited, first-party record of key actions in the app (for example: which grants you open, searches you run, and when you request a call) tied to a random per-browser identifier and, once you sign in, your account. This record sets no cookie and is not shared with anyone.
- Session recordings and heatmaps — only if you accept them. See "Cookies and session recording" below. We do not use advertising cookies, and we do not track you across other websites.
How we use it, and the legal basis
- To run the matching service (contract, Art. 6(1)(b)) — we use your profile and preferences to rank open EU funding calls for you and to generate eligibility assessments.
- To triage and qualify leads (legitimate interest, Art. 6(1)(f)) — we match your company domain against our own business records (our HubSpot CRM and public EU Cordis grant-winner data) to understand whether your company is a known contact, a past EU grant winner, or new to us, so our grant team can follow up appropriately. We read these sources; we never sell your data.
- To improve the product (legitimate interest, Art. 6(1)(f)) — aggregated, first-party usage analytics. This is the cookie-free record described above.
- To see where the site confuses people (consent, Art. 6(1)(a)) — the Microsoft Clarity session recordings, and only after you accept them. You can withdraw at any time, and withdrawing is as easy as accepting.
- To contact you about your account, a call you requested, or matching grants you asked to be alerted about.
Sources we match against
To triage your account we compare your company domain against (a) our own CRM records and (b) the European Commission's public Cordis dataset of funded projects and their participating organisations. Cordis is public, open EU data. We do not add you to any external database as a result of your signup without a lawful basis.
Cookies and session recording
The Service sets no cookie of its own. It does store two things in your browser's local storage that are needed for it to work at all: your signed-in session, and the random per-browser identifier behind the usage data above. Neither is shared with a third party, and neither follows you to other websites.
Separately, and only if you accept, we load Microsoft Clarity. Clarity records how visitors move through the site — clicks, scrolling, mouse movement, the pages visited, and your browser, device and approximate location derived from your IP address — and turns it into session replays and heatmaps we use to find the places where the site is confusing. It sets two cookies, _clck and _clsk, which distinguish your browser and group your page views into one session.
Clarity does not run until you accept it. If you reject it, or ignore the banner, no Clarity script is loaded and no Clarity cookie is set. You can change your mind at any time using Cookie settings in the footer of every page; rejecting after having accepted stops the recording immediately and deletes the two cookies.
What is hidden from the recordings. We mask the parts of the app that contain your own or someone else's data, so they never reach Microsoft: your profile and company details, your saved grants and match scores, eligibility assessments, your conversations with the AI assistant, everything you type into the booking and contact forms, the sign-in and signup forms, and the whole internal admin console. Masked content is replaced in the browser before anything is sent — we see that a field was filled in and where you clicked, not what it said.
Who we share it with
We use a small number of processors to run the Service — our cloud database and hosting provider (Supabase); Microsoft, for the Clarity recordings, but only where you have accepted them; and, where you request a call or eligibility assessment, tools our grant team uses to respond. Microsoft may process Clarity data outside the EU under the standard contractual clauses in its data-protection terms. Processors act on our instructions under data-processing terms. We do not sell personal data.
How long we keep it
We keep your account data while your account is active and for as long as needed to provide the Service and meet legal obligations. Usage-analytics records are retained for a limited period and then aggregated or deleted. Session recordings are held by Microsoft under Clarity's own retention periods, which we do not control: playback data (the replay itself) for 30 days, click and heatmap data for 9 months, and any session we label or favourite for 9 months. Microsoft deletes it from its servers and backups after that. You can ask us to delete your account at any time.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing based on legitimate interest. To exercise any of these, email grantcompass@dealflow.eu. You also have the right to lodge a complaint with your local data-protection authority.
Changes
We may update this policy; the "last updated" date above always reflects the current version. Material changes will be communicated in-app or by email.