HomeFounda21

Data Policy

Last updated 19 July 2026

1. What we collect

From founders:

  • Account details: name, email, phone number, password (stored hashed by our authentication provider).
  • Venture information and checkpoint submissions: text, documents, and links you submit for scoring.
  • Eligibility and outcome data: B-BBEE ownership percentages, entity type, turnover band, and self-reported outcomes (capital raised, headcount, revenue), captured for funder reporting purposes only.

We deliberately don't ask for a government ID or passport number. Phone number is what we use to keep one account per person; we'd rather collect less sensitive data even if it means a lighter check for now. If a stronger identity check becomes necessary later, this policy will be updated before it's introduced, not after.

From funders (institutions):

  • Organisation name, funder type, contact name and email.
  • Cohort and passcode configuration you create.

2. How we use it

Checkpoint submissions are sent to a third-party AI model for scoring. Eligibility and outcome data is never sent to the scoring model, it is used only to generate funder-facing reports and cohort-level M&E summaries. We use account data to operate logins, cohort membership, and email notifications about your account activity.

3. Who can see your data

A founder's checkpoint results and profile are visible to every funder whose cohort that founder has joined. Founda21 accounts are portable, joining a second funder's cohort shares your existing progress with that funder too. We do not sell personal data to third parties.

4. Data storage and security

Data is stored with our infrastructure providers (Supabase for authentication and file storage, a managed PostgreSQL database for application data). We apply reasonable technical safeguards, but no system is 100% secure.

5. Your rights

You can request access to, correction of, or deletion of your personal data at any time, either through your funder or account admin, or by emailing foundarsa@gmail.com. Deleting a founder account removes that founder's data from Founda21, subject to any records a funder is legally required to retain for reporting purposes.

6. Cookies

We use strictly necessary cookies to keep you logged in. We don't use third-party advertising or tracking cookies.

7. Contact

Questions about this policy can be sent to foundarsa@gmail.com.

This is a plain-language description of what we actually do, written to be honest and easy to read rather than formal legal drafting. It isn't a substitute for a lawyer's review (including for POPIA/GDPR compliance), which is worth getting as Founda21 scales, but it accurately reflects our current practice.