Data Processing Agreement
Effective May 9, 2026
1. Parties
This Data Processing Agreement ("DPA") forms part of the Terms of Service between FounderDive ("Data Processor") and you ("Data Controller" or "you"). By using FounderDive as a business customer, you act as the Data Controller for personal data of your users.
Data Processor: FounderDive, operated by FounderDive Inc., United States.
Data Protection Officer: [email protected]
GDPR Representative (EU): Available at [email protected]
2. Scope & Purpose
This DPA governs the processing of Personal Data by FounderDive on behalf of the Customer in connection with the FounderDive Service. FounderDive processes Personal Data only for the following purposes:
- Providing AI-powered market research and analysis
- Delivering AI cofounder chat with persistent memory
- Managing user accounts, authentication, and billing
- Sending transactional communications
- Monitoring and improving Service reliability and performance
3. Categories of Personal Data
We process the following categories of personal data:
- Account Data: Name, email address, account ID
- Business Data: Business name, description, industry, stage, goals
- Usage Data: Chat messages, Deep Dive requests, sprint task completions, commitment statuses
- Financial Data: Subscription plan, billing records (payment handled by Lemon Squeezy — we do not store card data)
4. Sub-processors
FounderDive engages the following sub-processors. You authorize us to engage new sub-processors with 30 days' notice:
Supabase
Purpose: Database, authentication, and storage
Location: United States / EU
Lemon Squeezy
Purpose: Subscription and payment processing
Location: United States
OpenRouter
Purpose: AI model routing (DeepSeek, Qwen, LLaMA)
Location: United States
Perplexity AI
Purpose: Web search for market research
Location: United States
xAI / Grok
Purpose: X/Twitter social listening
Location: United States
Reddit / PRAW
Purpose: Public Reddit community sentiment analysis
Location: United States
Resend
Purpose: Transactional email delivery
Location: United States
Sentry (Functional Software)
Purpose: Error monitoring and crash reporting
Location: United States
Groq
Purpose: Voice transcription processing
Location: United States
Vercel
Purpose: Frontend deployment and edge network
Location: United States
Railway
Purpose: Backend hosting
Location: United States
5. Processing Principles
FounderDive processes personal data in accordance with GDPR Article 5 principles:
- Lawfulness: Processing is based on contractual necessity or legitimate interests
- Purpose Limitation: Data is used only for defined, explicit purposes
- Data Minimisation: We collect only what is necessary for each purpose
- Accuracy: Personal data is kept accurate and up to date
- Storage Limitation: Data is retained as described in our Privacy Policy and deleted on request
- Security: All data is encrypted in transit (HTTPS) and at rest (Supabase encryption)
6. Data Subject Rights
As Data Controller, you are responsible for responding to data subject requests. We will assist you as required under GDPR Article 28:
- Provide mechanism to access, correct, or delete data via [email protected]
- Support data portability in JSON/CSV format
- Delete all personal data within 30 days of account deletion request
7. Security Measures
We implement technical and organizational security measures including: AES-256 encryption at rest, TLS 1.2+ in transit, Row-Level Security in Supabase, encrypted backups, access controls, and regular security monitoring via Sentry.
8. Breach Notification
In the event of a personal data breach that is likely to result in risk to individuals, we will notify you within 72 hours of becoming aware. Notifications are sent to the email address associated with your account.
9. Contact
For DPA requests, data incident reports, or sub-processor questions:
Email: [email protected]
Subject line: Include "DPA Request" or "Data Incident"