Data Processing Agreement

Effective May 9, 2026

1. Parties

This Data Processing Agreement ("DPA") forms part of the Terms of Service between FounderDive ("Data Processor") and you ("Data Controller" or "you"). By using FounderDive as a business customer, you act as the Data Controller for personal data of your users.

Data Processor: FounderDive, operated by FounderDive Inc., United States.
Data Protection Officer: [email protected]
GDPR Representative (EU): Available at [email protected]

2. Scope & Purpose

This DPA governs the processing of Personal Data by FounderDive on behalf of the Customer in connection with the FounderDive Service. FounderDive processes Personal Data only for the following purposes:

  • Providing AI-powered market research and analysis
  • Delivering AI cofounder chat with persistent memory
  • Managing user accounts, authentication, and billing
  • Sending transactional communications
  • Monitoring and improving Service reliability and performance

3. Categories of Personal Data

We process the following categories of personal data:

  • Account Data: Name, email address, account ID
  • Business Data: Business name, description, industry, stage, goals
  • Usage Data: Chat messages, Deep Dive requests, sprint task completions, commitment statuses
  • Financial Data: Subscription plan, billing records (payment handled by Lemon Squeezy — we do not store card data)

4. Sub-processors

FounderDive engages the following sub-processors. You authorize us to engage new sub-processors with 30 days' notice:

Supabase

Purpose: Database, authentication, and storage

Location: United States / EU

Lemon Squeezy

Purpose: Subscription and payment processing

Location: United States

OpenRouter

Purpose: AI model routing (DeepSeek, Qwen, LLaMA)

Location: United States

Perplexity AI

Purpose: Web search for market research

Location: United States

xAI / Grok

Purpose: X/Twitter social listening

Location: United States

Reddit / PRAW

Purpose: Public Reddit community sentiment analysis

Location: United States

Resend

Purpose: Transactional email delivery

Location: United States

Sentry (Functional Software)

Purpose: Error monitoring and crash reporting

Location: United States

Groq

Purpose: Voice transcription processing

Location: United States

Vercel

Purpose: Frontend deployment and edge network

Location: United States

Railway

Purpose: Backend hosting

Location: United States

5. Processing Principles

FounderDive processes personal data in accordance with GDPR Article 5 principles:

  • Lawfulness: Processing is based on contractual necessity or legitimate interests
  • Purpose Limitation: Data is used only for defined, explicit purposes
  • Data Minimisation: We collect only what is necessary for each purpose
  • Accuracy: Personal data is kept accurate and up to date
  • Storage Limitation: Data is retained as described in our Privacy Policy and deleted on request
  • Security: All data is encrypted in transit (HTTPS) and at rest (Supabase encryption)

6. Data Subject Rights

As Data Controller, you are responsible for responding to data subject requests. We will assist you as required under GDPR Article 28:

  • Provide mechanism to access, correct, or delete data via [email protected]
  • Support data portability in JSON/CSV format
  • Delete all personal data within 30 days of account deletion request

7. Security Measures

We implement technical and organizational security measures including: AES-256 encryption at rest, TLS 1.2+ in transit, Row-Level Security in Supabase, encrypted backups, access controls, and regular security monitoring via Sentry.

8. Breach Notification

In the event of a personal data breach that is likely to result in risk to individuals, we will notify you within 72 hours of becoming aware. Notifications are sent to the email address associated with your account.

9. Contact

For DPA requests, data incident reports, or sub-processor questions:

Email: [email protected]

Subject line: Include "DPA Request" or "Data Incident"