Privacy Policy
Last updated: 16 August 2026 · Pilot version
Who we are
ivi ("we") provides audit-grade extraction and portfolio intelligence for limited partners. The data controller for this service is the operator identified in the Imprint. Contact: michael@ivi.vc.
What we process, and why
- Account data (name, email, authentication records) — to operate your account. Legal basis: contract performance (Art. 6(1)(b) GDPR).
- Fund documents you upload (capital account statements, fund reports, capital call notices) and the financial figures extracted from them — to provide the service you signed up for. Legal basis: contract performance.
- Technical logs (access times, errors, processing events) — to keep the service secure and reliable. Legal basis: legitimate interest (Art. 6(1)(f)).
- Billing data — processed by Stripe when a paid subscription is active. Legal basis: contract performance.
Your documents and figures are never used to train AI models, and never shown to any other customer. Access is isolated per team at the database and API layer.
Where your data lives
Documents, extracted figures, and account data are stored with Supabase in London, United Kingdom (AWS eu-west-2 — a jurisdiction holding an EU adequacy decision). Application servers run on NetCup in Germany. Processing that leaves this perimeter — extraction, remote OCR, job orchestration — is named under International transfers below.
Subprocessors
We use the following providers to deliver the service. Each entry states the role and where the provider is established — the third-country ones are covered under International transfers below.
- Supabase — database, authentication, file storage (data stored in London, UK — AWS eu-west-2; provider established in the United States)
- NetCup GmbH — application hosting, including the self-hosted mailbox that receives forwarded fund documents (Germany, EU)
- Railway — hosts our remote Docling OCR service, used for CPU-heavy document types (provider established in the United States; deployment region not published by the provider)
- Mistral AI SAS — OCR escalation for low-coverage pages (France, EU — this leg stays inside the EEA)
- OpenAI, via the Vercel AI Gateway (Vercel Inc.) — text extraction from documents; no training on your data (both established in the United States)
- Inngest — background job processing (email-forwarding poll, async pipeline steps) (provider established in the United States)
- emailit — outbound e-mail delivery: the sign-in, password-reset and other authentication mail for your account, plus extraction-complete notifications (region not published by the provider)
- Stripe — payment processing (when billing is active)
International transfers
Part of the pipeline leaves the EEA, and we say so plainly. Every extraction request is routed through the Vercel AI Gateway (Vercel Inc., United States) to OpenAI (United States), so the text of your documents is processed there. Our remote Docling OCR service runs on Railway (United States), background job orchestration runs on Inngest (United States), and Supabase, although it stores your data in London, is a US-established company whose staff may access it in support.
For those transfers we rely on the EU–US Data Privacy Framework where the provider holds a current certification under it, and on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) where it does not. Certification status is public and can be checked in the Data Privacy Framework register.
The remaining legs stay inside the EEA / adequacy perimeter: OCR escalation goes to Mistral AI SAS, established in France (EU); application servers and the inbound mailbox run on NetCup in Germany; and storage sits in London, United Kingdom, which holds an EU adequacy decision.
Retention and deletion
We retain your documents and figures for as long as your account is active. Account and data deletion is a manual, operator-run process, not an automated pipeline: request it by contacting us (write to michael@ivi.vc) and you may export your portfolio and documents at the same time. On a verified request, your login and personal data are removed immediately. Your extracted fund figures are then re-keyed to an anonymous token (no longer linkable to you) and retained in that anonymized form to meet AML record-keeping obligations (5 years by default, pending final confirmation with counsel for the applicable jurisdiction), after which they are permanently deleted. The full retention and erasure policy is published below and at /legal/terms; deletion is handled by contacting us (support@ivi.vc) — the manual path that exists today.
Your rights
Under the GDPR you have the right to access, rectify, export, and erase your personal data, to restrict or object to processing, and to lodge a complaint with a supervisory authority. Write to michael@ivi.vc — we respond within one business day during the pilot.
Data processing agreement
A data-processing agreement (Art. 28 GDPR) covering the processing described above, including the subprocessor list, is available at /legal/dpa and is executed per-customer on signature for pilot customers.