Skip to content

Datenschutz · GDPR

Privacy Policy

NMA Venture Capital GmbH · Hamburg

This policy applies to every website and product operated by NMA Venture Capital GmbH ("NMA", "we"): nma.vc, startupgrid.ai (GRID, including app.startupgrid.ai and grid.nma.vc) and tectic.ai (the Tectic platform, including app.tectic.ai and api.tectic.ai), together "the Services". Sections 1–10 apply everywhere. Section 11 adds what is specific to each product; if you only use one of them, that is the part to read after the basics.

We wrote this in plain language on purpose. Where the GDPR requires a legal basis we name the article; where it does not, we do not pad.

1. Who is responsible

NMA Venture Capital GmbH
Am Sandtorkai 27
20457 Hamburg, Germany

Managing directors: Nico Lumma, Christoph Hüning
Commercial register: Amtsgericht Hamburg, HRB 136790
VAT ID: DE300254362

Email: [email protected] · Phone: +49 178 4497585

We have not appointed a data protection officer, as we are not required to; the contact above reaches the people who make the decisions in this document.

2. The short version

  • Visiting a site: we see the technical data your browser sends (Section 4) and count page views with an analytics tool we host ourselves, without cookies (Section 5). Nothing is sold, nothing is shared with advertising networks, and no tracking follows you off our sites.
  • Using a product: we process what you give us to provide it — your account, what you type, files and accounts you connect — on servers in Frankfurt, Germany, with AI models that run in the EU (Section 6). Your content is not used to train models.
  • Your rights are in Section 9. Writing to [email protected] is enough to exercise any of them.

3. Where your data lives

All our servers are rented from UpCloud Ltd (Helsinki, Finland). The application and database servers are in Frankfurt am Main, Germany; the analytics server is in Copenhagen, Denmark. Databases, uploaded files, media and backups stay in the EU:

What

Provider

Location

Application servers and databases

UpCloud Ltd

Frankfurt, Germany

Analytics (self-hosted PostHog) and build systems

UpCloud Ltd

Copenhagen, Denmark

Uploaded files and media

UpCloud Object Storage

EU

Encrypted database backups

Cloudflare R2, EU jurisdiction bucket

EU

DNS, TLS termination and DDoS protection in front of every site

Cloudflare, Inc.

EU edge locations; see Section 8 for the transfer safeguard

grid.nma.vc (one static marketing page)

Vercel Inc.

see Section 8

4. Visiting our sites: technical data

When you open any page, your browser transmits the address of the page, the time, your IP address, browser and operating system, and the page you came from. Our servers and Cloudflare's edge record this in access logs so that the sites work, stay secure and can be repaired when something breaks.

  • Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in running a stable and secure service.
  • Retention: server access logs are kept for 14 days and then deleted, unless an entry has to be preserved as evidence of an attack.
  • TLS: every connection is encrypted. Our certificates are issued by Let's Encrypt; issuing them involves no personal data of yours.

5. Analytics — self-hosted, no cookies, no consent banner

On our public marketing pages (currently nma.vc and startupgrid.ai) we count page views with PostHog, an open-source analytics tool that we run on our own server in Copenhagen, Denmark. No data goes to PostHog Inc. or any other third party.

We configured it deliberately narrowly:

  • No cookies and no local storage. The script keeps its state in memory only; when you close the tab, nothing remains in your browser. Because nothing is stored on your device, the consent requirement of § 25 TTDSG does not apply and we do not show a cookie banner.
  • Page views only. No click tracking, no session recording, no heat maps, no surveys, no cross-site tracking, no fingerprinting.
  • Do Not Track is honoured. If your browser sends DNT, the script does not run at all.
  • IP addresses are discarded on arrival; only a coarse location (country/city) derived from them is kept with an event.

We use these numbers to see which pages are read and whether a site is broken. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding whether our sites serve their purpose, weighed against an intervention we have reduced to the minimum. You can opt out by enabling Do Not Track in your browser.

Where our product applications (the parts behind a login) measure whether features work, they use the same self-hosted PostHog, equally without cookies. There, events can be tied to your account so that we can help you when something goes wrong.

6. Using our products

The Services behind a login process what you give them. What follows applies to every product; product-specific details are in Section 11.

6.1 Account and login

To create an account we store your email address, a display name if you set one, a password hash (never the password) or the identifier of the sign-in provider you chose, the time of sign-up and of your last login. We set a strictly necessary session cookie after login; it exists only to keep you logged in and requires no consent (§ 25(2) TTDSG).

If you choose Sign in with Google, Google Ireland Ltd tells us your email address, name and profile picture and confirms that the address is yours. We do not receive your Google password and Google does not learn what you do inside our product. Google's own policy applies to what happens on Google's side: policies.google.com/privacy.

Legal basis: Art. 6(1)(b) GDPR — the contract you enter into by creating an account.

6.2 Your content

Text you enter, documents you upload, results you generate and settings you save are stored so that the product can do its job and show you your work again. They are visible to you and to the colleagues you share them with inside your organisation; they are not visible to other customers and not to us, except where you ask us for support or the law obliges us.

Legal basis: Art. 6(1)(b) GDPR.

6.3 AI processing — in the EU, not for training

Our products use large language models to summarise, draft, extract and classify. Every model call goes through Cortecs GmbH (Vienna, Austria), an EU provider that routes to open models (such as Mistral) hosted by European inference providers (for example Mistral, OVHcloud and Scaleway). Your prompts and content are transmitted only to compute the answer; Cortecs processes them in memory, deletes them when the request completes, and binds its upstream providers not to train on them — your content is not used to train any model. No prompt is ever sent to OpenAI, Anthropic, Google or any other non-EU model provider.

Legal basis: Art. 6(1)(b) GDPR (it is the service you asked for); Art. 28 GDPR for the processor relationship with Cortecs.

6.4 Accounts you connect (Google Workspace, Microsoft 365, HubSpot, Slack, Notion, Google Sheets)

Some products can read from accounts you own elsewhere — a mailbox, a calendar, a CRM, a document store — after you explicitly authorise the connection with that provider's OAuth consent screen. We then store an access token (encrypted at rest) and read only the data types you approved, only to provide the feature you enabled. You can revoke a connection at any time in the product or in the provider's own security settings; we delete the token immediately and stop reading.

For Google and Microsoft accounts the connection is brokered by Composio Inc. (USA), whose verified OAuth application handles the authorisation handshake; the data you approved flows to our servers in Frankfurt. See Section 8 for the transfer safeguard.

Google API Services User Data Policy. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely: Google user data is used only to provide the feature you enabled, is never sold, is never used for advertising, and is never read by a person except with your explicit consent for support, for security purposes, or where the law requires it.

Legal basis: Art. 6(1)(b) GDPR for the feature you enabled; the OAuth consent is the authorisation towards the provider, not a GDPR consent, and revoking it ends the processing.

6.5 Payments

Where a product is paid, payments are handled by Mollie B.V. (Amsterdam, Netherlands). Mollie receives what is needed to process the payment (amount, your payment method details, name, email); we receive a confirmation, the payment method type and the last digits of a card — never full card numbers. Mollie is an independent controller for the payment itself; its policy: mollie.com/privacy.

We keep invoices and payment records for 10 years because German commercial and tax law requires it (§ 257 HGB, § 147 AO). Legal basis: Art. 6(1)(b) and (c) GDPR.

6.6 Emails we send you

Transactional email — sign-in links, verification codes, invoices, notifications you enabled — is delivered through AhaSend B.V. (Amsterdam, Netherlands; sending servers in Germany and Finland). The sign-in emails of the Tectic platform (tectic.ai) are delivered by Resend, Inc. (USA). Both receive your address and the message content only to deliver it. We do not send newsletters without your consent, and every optional email has an unsubscribe link that works.

Legal basis: Art. 6(1)(b) GDPR for emails the service needs; Art. 6(1)(a) GDPR for anything optional.

6.7 Support and contact

If you write to [email protected] or use a contact form, we store your message and address to answer it and keep the thread for two years after the last exchange, so that we can follow up. Legal basis: Art. 6(1)(f) GDPR, or (b) where the request concerns a contract.

7. Information we collect about people from public sources

Some products build datasets about companies and the people publicly associated with them — founders, investors, public officials — from public sources such as company websites, registers and press releases. Where this concerns you, this is the information Art. 14 GDPR asks us to give:

  • Categories: name, professional role, organisation, publicly stated contact channels, public statements and works.
  • Sources: the public sources listed above; we do not buy personal data from data brokers.
  • Purpose and legal basis: Art. 6(1)(f) GDPR — our customers' legitimate interest in researching the market they operate in, and ours in providing that research. We only compile what is already public, in a professional context, and we do not build profiles of private life.
  • Your rights: you can object at any time (Section 9), and we remove or correct an entry on request unless we have a compelling reason to keep it. Write to [email protected].

8. Recipients and transfers outside the EU

We share personal data only with the processors named in this policy, each bound by a data processing agreement under Art. 28 GDPR, and with authorities where the law compels us. We never sell personal data.

Most processing stays in Germany and the EU. Where a provider is in the USA (Cloudflare, Composio, Resend, Vercel), the transfer rests on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) with supplementary measures. In each case we send the minimum the provider needs for its function.

Provider

Function

Country

Safeguard

UpCloud Ltd

Servers, storage

Finland (servers in Germany)

EU

Cloudflare, Inc.

DNS, TLS, CDN, DDoS protection, backup storage (EU bucket)

USA

DPF / SCCs

Cortecs GmbH

AI model inference

Austria

EU

Mollie B.V.

Payments

Netherlands

EU

AhaSend B.V.

Transactional email

Netherlands (servers in Germany/Finland)

EU

Resend, Inc.

Sign-in emails for tectic.ai

USA

DPF / SCCs

Composio Inc.

OAuth brokering for Google/Microsoft connections

USA

SCCs

Google Ireland Ltd

Sign in with Google (independent controller)

Ireland

EU

Vercel Inc.

Hosting of grid.nma.vc

USA

DPF / SCCs

Linkup SAS

Web search and page retrieval on behalf of agents you run

France

EU

9. Your rights

You can, at any time and free of charge:

  • access the personal data we hold about you (Art. 15),
  • have it corrected (Art. 16) or deleted (Art. 17),
  • have its processing restricted (Art. 18),
  • receive it in a portable format (Art. 20),
  • object to processing based on legitimate interests, including Sections 5 and 7 (Art. 21), and
  • withdraw any consent you gave, with effect for the future (Art. 7(3)).

Write to [email protected]. We answer within one month. If you believe we handle your data unlawfully, you can complain to a supervisory authority; the one responsible for us is Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Str. 22, 20459 Hamburg, datenschutz-hamburg.de.

10. Retention, security, children, changes

Retention. We keep personal data only as long as the purpose requires: account data until you ask us to close the account ([email protected]), which we do within 30 days; content until you delete it; logs 14 days; support threads two years; invoices 10 years by law. Backups are kept for 14 days and then overwritten.

Security. Data is encrypted in transit (TLS) and at rest; secrets and tokens are encrypted with keys held only on our servers; access is limited to the people who operate the service and is logged; production data never leaves the EU for development or testing.

Children. Our Services are for professionals and not directed at anyone under 16. We do not knowingly collect data from children.

Changes. When we change this policy we update the date at the top and, for changes that matter to you, tell account holders by email. Earlier versions are available on request.

11. What is specific to each product

nma.vc — a marketing site only. Section 4 and Section 5 are the whole story; nothing else in this policy applies unless you email us.

GRID (startupgrid.ai, app.startupgrid.ai) — accounts (6.1), your briefs and generated work (6.2), AI processing (6.3), credit purchases through Mollie (6.5), and a dataset of European startups and investors compiled from public sources (Section 7). Optional connections to accounts you own (6.4).

Tectic (tectic.ai, app.tectic.ai, api.tectic.ai) — the platform on which our agents run. Accounts (6.1), agent inputs and outputs (6.2), AI processing (6.3), connected accounts such as Google Workspace, Microsoft 365, HubSpot, Slack, Notion and Google Sheets (6.4). Agents you run may fetch public web pages through Linkup on your instruction. API access is logged per key for billing and abuse prevention.

NMA Venture Capital GmbH, Hamburg. Questions: [email protected].