Deal Scout handles two very different kinds of information: the personal data of people who visit this site or hold an account, and the confidential deal and investor records our customers put into the platform. This notice explains both, who else sees them, and what you can ask us to do.
Last updated 21 August 2026
This notice is a working draft. What it says about how the platform works is drawn from the software itself, but the document has not been reviewed by a qualified adviser, and the items marked to confirm are not yet settled. If you need a definitive position before then, email contact@dealscout.financial.
Deal Scout is a private-markets software platform operated by [to confirm: full legal entity name], a company registered in [to confirm: country of incorporation] under company number [to confirm: company registration number], with its registered office at [to confirm: registered office address]. In this notice “we” and “Deal Scout” mean that company.
Questions about this notice, or any request about your data, go to contact@dealscout.financial. Our data protection contact is [to confirm: DPO or privacy contact, if one is appointed].
Whether we are a controller or a processor depends on which data is in question, and it changes what you should ask us versus what you should ask the fund.
For that second category the fund or firm that uploaded it is the controller and decides what happens to it. If you are an investor, portfolio-company officer or counterparty and you want your data corrected or removed, the fund is the right party to ask. Contact us and we will pass the request on, but we cannot act on their records unilaterally — that is what being a processor means.
We do not buy personal data, we do not enrich your record from data brokers, and we do not run advertising or behavioural profiling of any kind.
Deal Scout sets four first-party cookies and no others. All four are strictly necessary to operate the service, which is why you are not asked to consent to them — there is nothing optional to consent to.
| Recipient | Purpose | Data it receives |
|---|---|---|
| sb-… | Authentication session issued by our database provider | A signed session token. Required to stay logged in. |
| ds_csrf | Cross-site request forgery protection | A random token compared against a request header on every write. |
| dealscout_current_fund_id | Remembers which fund you were last looking at | A fund identifier. A convenience only; clearing it just resets the selection. |
| SSO state | Protects the single sign-on handshake | A short-lived random value, deleted the moment sign-in completes. |
There are no analytics cookies, no advertising cookies, no social-media pixels and no third-party tags on this site. If that ever changes, this clause changes first and consent will be asked for properly.
We use the following providers to run the service. Each is bound to process data only on our instructions. This list is maintained from the application itself rather than from memory, and the two rows that matter most to a customer assessment are Anthropic — because document content genuinely leaves our systems — and our database provider, which holds everything.
| Recipient | Purpose | Data it receives |
|---|---|---|
| Supabase | Database, authentication and document storage | All account data, all customer content, all audit records. Hosting region stated below. |
| Railway | Application hosting | Data in transit through the application, plus application logs. |
| Anthropic | AI document extraction | The contents of documents you submit for extraction. See clause 06. |
| Upstash | Rate limiting and abuse prevention | Organisation identifiers and request counters. No document content and no personal data. |
| Open Exchange Rates | Foreign exchange rates | None. We request published rates; we send no customer data. |
| Sentry | Error monitoring, when enabled | Diagnostic context attached to an error. Enabled only where an endpoint is configured. |
| Email delivery | Transactional email — invitations, notices, contact enquiries | Recipient address and message content. |
| QuickBooks / Xero | Accounting integration | Only if you connect it, and only the ledger data the integration is scoped to. |
| Malware scanning | Scanning uploads for malicious files | The uploaded file, where a scanning service is configured. |
Hosting and data-residency regions: [to confirm: Supabase project region and Railway region]. Our email provider is [to confirm: which SMTP provider is configured in production]. Whether an e-signature provider is engaged depends on configuration; by default Deal Scout uses its own click-wrap and no third party is involved.
We do not sell personal data, and we do not share it with anyone not listed above except where we are legally required to.
Deal Scout uses Anthropic’s Claude models to read the documents you upload and propose structured figures from them. This means the content of those documents — which for our customers routinely includes commercially sensitive and personal information — is transmitted to Anthropic to be processed.
Two things about how that is built are worth knowing, because they are properties of the system rather than promises:
Our contractual position with Anthropic on retention and on training is [to confirm: confirm the commercial terms: retention period and whether inputs are excluded from training]. That is the question a customer’s information-security review will ask first, so it should be answered here precisely rather than in general terms.
We do not use your documents or your data to train our own models, and we do not use one customer’s data to serve another. Tenant isolation is enforced in the database itself, not only in application code.
Account records are kept while your account is active. Customer content is kept for as long as the customer’s agreement runs, and on termination is dealt with as set out in the Terms. Specific retention periods: [to confirm: agree a retention schedule per data category].
Deal Scout’s audit log is append-only and enforced as such in the database: updates and deletes are rejected outright, including by our own administrators. That is a deliberate fiduciary control — an audit trail that can be quietly edited is not an audit trail, and fund administration is an activity where someone may later need to prove who approved what.
The honest consequence is that a request to erase personal data cannot remove the fact that a named person approved a particular action at a particular time. We consider that record necessary for compliance with our customers’ legal obligations and for establishing and defending legal claims, which is a recognised limit on the right to erasure. We can restrict further processing of it, and we will explain exactly what remains and why. The precise legal basis to rely on here should be settled with counsel: [to confirm: confirm the erasure-exemption position for audit records].
Where we act as controller we rely on: performance of a contract, for operating your account; our legitimate interests, for securing the platform, preventing abuse and responding to enquiries; compliance with a legal obligation, where one applies; and consent where we ask for it, which you can withdraw at any time. The definitive mapping of basis to purpose is [to confirm: confirm legal bases with counsel].
Some of the providers in clause 05 operate outside the United Kingdom and the European Economic Area. Where personal data is transferred outside those areas we rely on the transfer mechanisms named here: [to confirm: confirm transfer mechanism — UK IDTA, EU SCCs or adequacy — per provider].
Security is described below, as implemented rather than aspired to:
No system is immune. If a breach affects your personal data we will notify the relevant supervisory authority and affected people as required by law.
Subject to the limits in clause 07, you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. You can also withdraw consent where consent is what we relied on.
Ask by emailing contact@dealscout.financial. We will respond within one month. There is no charge unless a request is excessive, and we will say so before charging anything.
If your data sits inside a customer’s workspace rather than in your own account, see clause 02 — the fund is the party who can act on it, and we will forward your request to them.
If you are unhappy with how we have handled a request you can complain to your data protection regulator. In the UK that is the Information Commissioner’s Office at ico.org.uk. We would rather you raised it with us first.
When we change this notice we update the date at the top. If a change materially affects how we handle your personal data we will tell account holders directly rather than relying on you to re-read the page.