Deal Scout
Sign inRequest a demo

Privacy notice

Deal Scout handles two very different kinds of information: the personal data of people who visit this site or hold an account, and the confidential deal and investor records our customers put into the platform. This notice explains both, who else sees them, and what you can ask us to do.

Last updated 21 August 2026

Draft — pending legal review

This notice is a working draft. What it says about how the platform works is drawn from the software itself, but the document has not been reviewed by a qualified adviser, and the items marked to confirm are not yet settled. If you need a definitive position before then, email contact@dealscout.financial.

01Who this notice is from

Deal Scout is a private-markets software platform operated by [to confirm: full legal entity name], a company registered in [to confirm: country of incorporation] under company number [to confirm: company registration number], with its registered office at [to confirm: registered office address]. In this notice “we” and “Deal Scout” mean that company.

Questions about this notice, or any request about your data, go to contact@dealscout.financial. Our data protection contact is [to confirm: DPO or privacy contact, if one is appointed].

02The distinction that governs everything below

Whether we are a controller or a processor depends on which data is in question, and it changes what you should ask us versus what you should ask the fund.

We are the controller for

  • People who visit this website or contact us — your name, work email, firm and message.
  • People who hold a Deal Scout login — the account record itself: name, email, role, organisation, and multi-factor enrolment.
  • Our own billing and business records.

We are a processor for

  • Everything a customer puts into the platform: deal documents, financial statements, cap tables, investor registers, bank and beneficiary details, valuations and correspondence.
  • That content may contain personal data about people who never signed up with us — company directors named in accounts, individual limited partners, counterparty contacts.

For that second category the fund or firm that uploaded it is the controller and decides what happens to it. If you are an investor, portfolio-company officer or counterparty and you want your data corrected or removed, the fund is the right party to ask. Contact us and we will pass the request on, but we cannot act on their records unilaterally — that is what being a processor means.

03What we collect, and where it comes from

Account and identity

  • Name, work email address, role and organisation, held to create and authorise your login.
  • Multi-factor authentication enrolment. MFA is mandatory for privileged roles and a second step-up is required before financial writes, so this data is not optional to the service.
  • For customers using single sign-on, the identifiers their identity provider returns.

Activity and audit

  • An append-only audit record of consequential actions: who approved a valuation, who released a wire, who confirmed an extraction, and when. See clause 07 — this record is deliberately immutable.
  • Application and security logs, including request metadata.

Customer content

  • Documents you upload and the structured records derived from them. We do not choose what goes in; you do.

Website and technical

  • Your IP address, used transiently as a rate-limiting key to stop abuse. It is not stored against your account or used to profile you.
  • On the public landing page only, anonymous counts of how far visitors scroll and which button they press. No cookie, no identifier, no third-party script, and nothing that can be traced to a person.

We do not buy personal data, we do not enrich your record from data brokers, and we do not run advertising or behavioural profiling of any kind.

04Cookies

Deal Scout sets four first-party cookies and no others. All four are strictly necessary to operate the service, which is why you are not asked to consent to them — there is nothing optional to consent to.

RecipientPurposeData it receives
sb-…Authentication session issued by our database providerA signed session token. Required to stay logged in.
ds_csrfCross-site request forgery protectionA random token compared against a request header on every write.
dealscout_current_fund_idRemembers which fund you were last looking atA fund identifier. A convenience only; clearing it just resets the selection.
SSO stateProtects the single sign-on handshakeA short-lived random value, deleted the moment sign-in completes.

There are no analytics cookies, no advertising cookies, no social-media pixels and no third-party tags on this site. If that ever changes, this clause changes first and consent will be asked for properly.

05Who else processes your data

We use the following providers to run the service. Each is bound to process data only on our instructions. This list is maintained from the application itself rather than from memory, and the two rows that matter most to a customer assessment are Anthropic — because document content genuinely leaves our systems — and our database provider, which holds everything.

RecipientPurposeData it receives
SupabaseDatabase, authentication and document storageAll account data, all customer content, all audit records. Hosting region stated below.
RailwayApplication hostingData in transit through the application, plus application logs.
AnthropicAI document extractionThe contents of documents you submit for extraction. See clause 06.
UpstashRate limiting and abuse preventionOrganisation identifiers and request counters. No document content and no personal data.
Open Exchange RatesForeign exchange ratesNone. We request published rates; we send no customer data.
SentryError monitoring, when enabledDiagnostic context attached to an error. Enabled only where an endpoint is configured.
Email deliveryTransactional email — invitations, notices, contact enquiriesRecipient address and message content.
QuickBooks / XeroAccounting integrationOnly if you connect it, and only the ledger data the integration is scoped to.
Malware scanningScanning uploads for malicious filesThe uploaded file, where a scanning service is configured.

Hosting and data-residency regions: [to confirm: Supabase project region and Railway region]. Our email provider is [to confirm: which SMTP provider is configured in production]. Whether an e-signature provider is engaged depends on configuration; by default Deal Scout uses its own click-wrap and no third party is involved.

We do not sell personal data, and we do not share it with anyone not listed above except where we are legally required to.

06AI processing, stated plainly

Deal Scout uses Anthropic’s Claude models to read the documents you upload and propose structured figures from them. This means the content of those documents — which for our customers routinely includes commercially sensitive and personal information — is transmitted to Anthropic to be processed.

Two things about how that is built are worth knowing, because they are properties of the system rather than promises:

  • Nothing an AI model proposes is written to your records until a person approves it. Extraction produces a reviewable draft citing the page each figure came from; the confirmation step is human and it is not optional. The models do not write to your books.
  • Every figure carries its provenance — the document, the page, the quoted text — so any number in the platform can be traced back to the source it was read from.

Our contractual position with Anthropic on retention and on training is [to confirm: confirm the commercial terms: retention period and whether inputs are excluded from training]. That is the question a customer’s information-security review will ask first, so it should be answered here precisely rather than in general terms.

We do not use your documents or your data to train our own models, and we do not use one customer’s data to serve another. Tenant isolation is enforced in the database itself, not only in application code.

07How long we keep things — including what we cannot delete

Account records are kept while your account is active. Customer content is kept for as long as the customer’s agreement runs, and on termination is dealt with as set out in the Terms. Specific retention periods: [to confirm: agree a retention schedule per data category].

The audit trail is immutable, by design

Deal Scout’s audit log is append-only and enforced as such in the database: updates and deletes are rejected outright, including by our own administrators. That is a deliberate fiduciary control — an audit trail that can be quietly edited is not an audit trail, and fund administration is an activity where someone may later need to prove who approved what.

The honest consequence is that a request to erase personal data cannot remove the fact that a named person approved a particular action at a particular time. We consider that record necessary for compliance with our customers’ legal obligations and for establishing and defending legal claims, which is a recognised limit on the right to erasure. We can restrict further processing of it, and we will explain exactly what remains and why. The precise legal basis to rely on here should be settled with counsel: [to confirm: confirm the erasure-exemption position for audit records].

08Why we are allowed to process it

Where we act as controller we rely on: performance of a contract, for operating your account; our legitimate interests, for securing the platform, preventing abuse and responding to enquiries; compliance with a legal obligation, where one applies; and consent where we ask for it, which you can withdraw at any time. The definitive mapping of basis to purpose is [to confirm: confirm legal bases with counsel].

09Where your data goes

Some of the providers in clause 05 operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside those areas we rely on the transfer mechanisms named here: [to confirm: confirm transfer mechanism — UK IDTA, EU SCCs or adequacy — per provider].

10How it is protected

Security is described below, as implemented rather than aspired to:

  • Multi-factor authentication is enforced, and privileged financial actions require a fresh step-up rather than an existing session.
  • Tenant isolation is enforced by row-level security in the database, so one organisation cannot read another’s rows even if application code is wrong.
  • Irreversible actions — releasing a wire, changing a beneficiary, approving a valuation, settling a trade — require two different people. The person who prepares can never be the person who approves.
  • Beneficiary names are screened before a wire can be transmitted.
  • Uploads are size-checked and, where a scanner is configured, scanned for malware.
  • Data is encrypted in transit. Encryption at rest is provided by our database and storage provider.
  • The audit trail cannot be altered after the fact — see clause 07.

No system is immune. If a breach affects your personal data we will notify the relevant supervisory authority and affected people as required by law.

11Your rights

Subject to the limits in clause 07, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also withdraw consent where consent is what we relied on.

Ask by emailing contact@dealscout.financial. We will respond within one month. There is no charge unless a request is excessive, and we will say so before charging anything.

If your data sits inside a customer’s workspace rather than in your own account, see clause 02 — the fund is the party who can act on it, and we will forward your request to them.

If you are unhappy with how we have handled a request you can complain to your data protection regulator. In the UK that is the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first.

12Changes to this notice

When we change this notice we update the date at the top. If a change materially affects how we handle your personal data we will tell account holders directly rather than relying on you to re-read the page.

Terms of serviceData processing agreementHome →