PRIVACY POLICY
Applicable to the Phasegrowth platform, website and related services
Privacy summary. Phasegrowth processes professional account, organisation-profile, usage and communication data to verify users, create and maintain profiles, provide EU funding and partner matchmaking, secure the Platform and meet legal obligations. Phasegrowth does not sell personal data. Users may contact contact@phasegrowth.com to exercise their rights.
Contents
Phasegrowth OÜ is the controller of personal data processed through the Phasegrowth platform, unless a specific service notice states otherwise.
Phasegrowth OÜ
Registry code: 16014205
Registered address: Narva mnt 5, 10117 Tallinn, Estonia
Privacy contact: contact@phasegrowth.com
Phasegrowth has not designated a separate Data Protection Officer. Privacy enquiries and requests should therefore be sent to the privacy contact above. Phasegrowth will designate and register a Data Protection Officer if this becomes legally required.
This Policy explains how Phasegrowth collects, uses, discloses, retains and protects personal data when an individual visits the website, creates or uses an account, acts for an organisation, receives a matchmaking suggestion, communicates through the Platform, contacts Phasegrowth or otherwise interacts with the services.
The Platform is designed for professional and organisational use. Information about a legal entity is not personal data as such, but information connected with identifiable employees, representatives, researchers, experts, founders or other natural persons is personal data and is covered by this Policy.
Phasegrowth processes personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”), the Estonian Personal Data Protection Act and other applicable Estonian and European Union legislation, including rules governing electronic communications, cookies, direct marketing, accounting and information-society services.
Where this Policy and mandatory law differ, mandatory law prevails.
Account and identity data
Information collected: Name, professional email address, organisation, role, account identifier, verification status and administrator/member role.
Source: Provided by the user; inferred from the professional email domain; confirmed by an organisation administrator.
Organisation-profile data
Information collected: Professional biography, expertise, technologies, sectors, project roles, organisational affiliations and public professional contact details.
Source: Provided or corrected by the user; obtained from CORDIS, organisational websites and other public professional sources.
EU funding and project data
Information collected: Participation in projects, project roles, programme, project titles, scientific classifications and related professional history.
Source: CORDIS and other official or public European Union sources.
Matchmaking and preference data
Information collected: Areas of interest, sought partners, calls, collaboration preferences, tags, match feedback and saved or dismissed results.
Source: Provided by the user or generated from organisation-profile information.
Communication data
Information collected: Messages, invitations, support requests, reports, feedback and correspondence with Phasegrowth or other users.
Source: Provided by the sender and recipients through the Platform or email.
Technical and security data
Information collected: IP address, device and browser data, timestamps, authentication events, logs, session identifiers, security alerts and cookie choices.
Source: Collected automatically when the website or Platform is used.
Subscription and transaction data
Information collected: Plan, billing contact, invoices, payment status and transaction references. Phasegrowth should not store full payment-card details where payment is handled by an external provider.
Source: Provided by the customer or received from payment and accounting providers.
Public-source provenance data
Information collected: Source URL, access date and indicators used to associate public information with an organisation.
Source: Public websites, directories and official datasets.
Create, authenticate and manage accounts; verify control of a professional email address; administer team access.
Personal data used: Account, identity, technical and security data.
Legal basis: Performance of the Platform agreement or steps requested before entering it (Article 6(1)(b)); legitimate interests in preventing impersonation and unauthorised access (Article 6(1)(f)).
Build, display and maintain organisation profiles.
Personal data used: Account, organisation-profile, public-source and project data.
Legal basis: Performance of the Platform agreement (Article 6(1)(b)); legitimate interests in providing accurate B2B discovery and reducing registration burden (Article 6(1)(f)).
Match organisations with funding calls and potential partners and explain suggested matches.
Personal data used: Organisation-profile, project, preference and feedback data.
Legal basis: Performance of the Platform agreement (Article 6(1)(b)); legitimate interests in improving relevance and service quality (Article 6(1)(f)).
Provide verification indicators, route uncertain profiles for review and prevent misleading claims.
Personal data used: Account, domain, public-source, project and security data.
Legal basis: Legitimate interests in platform integrity, fraud prevention and user trust (Article 6(1)(f)).
Enable communications, invitations, support and reports.
Personal data used: Account and communication data.
Legal basis: Performance of the Platform agreement (Article 6(1)(b)); legitimate interests in customer support and dispute resolution (Article 6(1)(f)).
Operate, secure, troubleshoot and improve the Platform.
Personal data used: Technical, security, usage, feedback and limited account data.
Legal basis: Legitimate interests in security, service availability, quality assurance and product development (Article 6(1)(f)); legal obligations where applicable (Article 6(1)(c)).
Send service messages, including verification codes, invitations, security alerts and material service notices.
Personal data used: Account and communication data.
Legal basis: Performance of the Platform agreement (Article 6(1)(b)); legal obligation where a notice is required (Article 6(1)(c)).
Send optional newsletters or promotional communications.
Personal data used: Name, professional email address and communication preferences.
Legal basis: Consent (Article 6(1)(a)) where required; otherwise a legally permitted legitimate-interest basis for relevant B2B communications, with an immediate right to object and unsubscribe (Article 6(1)(f)).
Manage subscriptions, payments, accounting, taxation and legal claims.
Personal data used: Account, transaction, correspondence and contractual data.
Legal basis: Performance of contract (Article 6(1)(b)); compliance with legal obligations (Article 6(1)(c)); legitimate interests in establishing, exercising or defending legal claims (Article 6(1)(f)).
Comply with lawful requests and prevent or investigate illegal use.
Personal data used: Relevant account, communication, transaction and security data.
Legal basis: Legal obligation (Article 6(1)(c)); legitimate interests in protecting Phasegrowth, users and third parties (Article 6(1)(f)).
Phasegrowth may obtain professional information indirectly from CORDIS, European Union funding sources, an organisation’s own website, public professional directories and similar lawful sources. This permits the Platform to prepare a draft profile rather than require users to enter all information manually.
Where personal data have not been obtained directly from the individual, Phasegrowth will provide the information required by Article 14 GDPR within the applicable period, normally through the profile, an account notice, an email or this Policy, unless an applicable exception applies. Phasegrowth will identify the relevant data categories and source where reasonably practicable.
Individuals may ask Phasegrowth to correct, supplement, restrict or remove public-source personal data. Removal from the Platform does not remove information from the original public source.
The Platform uses automated classification, similarity analysis, embeddings and language-processing tools to create suggested tags, draft profile text, confidence indicators and rankings of potentially relevant calls or organisations.
These outputs are recommendations. They do not determine eligibility for funding, award funding, conclude a contract, establish professional competence or produce a legal or similarly significant effect for an individual. Phasegrowth does not intend to make decisions falling within Article 22(1) GDPR solely by automated means.
Users can review and correct profile information, change interests and tags, provide feedback and request human review where an automated association or profile activation appears incorrect.
The Platform is not designed for special-category personal data, criminal-conviction data, national identification numbers, personal financial information, medical information or other highly sensitive personal data. Users must not submit such information unless Phasegrowth has expressly introduced a function for that purpose and has confirmed an appropriate legal basis and safeguards.
Users must not upload confidential proposal material, trade secrets or personal data concerning third parties unless they are authorised to do so and the relevant Platform function is suitable for that information.
Phasegrowth may disclose personal data only where necessary to operate the Platform or meet legal obligations. Recipient categories may include hosting and database providers, authentication and email-delivery providers, analytics and security providers, artificial-intelligence and language-processing providers, payment and accounting providers, professional advisers, competent public authorities and other Platform users where the user chooses to publish a profile or communicate.
Processors act under contractual data-processing terms and may process personal data only on documented instructions from Phasegrowth, subject to confidentiality and security obligations. Phasegrowth does not sell or rent personal data to data brokers or advertisers.
Organisation-profile information marked as public or visible to matched organisations may be disclosed to other users. Users should review the profile before publication and avoid placing personal contact details in public fields unless they want them to be visible.
Phasegrowth seeks to use providers processing data within the European Economic Area where reasonably practicable. Some providers or their support operations may be located outside the European Economic Area.
Where personal data are transferred to a country not recognised by the European Commission as providing an adequate level of protection, Phasegrowth will use an applicable transfer mechanism, such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where required. Information about the applicable safeguards may be requested at contact@phasegrowth.com.
Active account and profile data
For the duration of the account. Following closure, core account and profile records are normally deleted or anonymised within 90 days, except where longer retention is justified below.
Security, authentication and system logs
Normally up to 12 months, unless a longer period is necessary to investigate a security event, abuse or legal claim.
Support, reports and ordinary correspondence
Normally three years after the matter is closed, or longer where required for an active dispute or legal obligation.
Match feedback and product analytics
Normally up to 24 months in identifiable form, after which they are deleted or anonymised where still useful for statistical analysis.
Dormant or incomplete registration data
Normally deleted after 12 months of inactivity unless the user completes registration or requests earlier deletion.
Billing, accounting and tax records
Seven years or another period required by applicable Estonian accounting or tax legislation.
Legal claims, fraud and enforcement records
For the applicable limitation period and, where proceedings begin, until final resolution and expiry of any further retention obligation.
Backups
Deleted through the ordinary backup rotation, normally within 90 days after deletion from active systems, unless technically isolated and retained temporarily for disaster recovery.
Retention periods may be shortened or extended where necessary to comply with law, preserve evidence, resolve a dispute, protect users or respond to a lawful authority request. When identifiable data are no longer required, Phasegrowth will delete or irreversibly anonymise them.
Operational messages, such as email-verification codes, invitations, security alerts, match notifications requested through account settings and material changes to the service, are service communications rather than advertising.
Promotional email will be sent only where Phasegrowth has a valid legal basis. Every promotional message will provide an effective means to unsubscribe. An objection to marketing does not prevent Phasegrowth from sending essential service or legal notices.
Phasegrowth applies risk-based technical and organisational measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, role-based permissions, encryption in transit, secure authentication, logging, backups, vulnerability management, processor due diligence and incident-response procedures.
No internet-based service can guarantee absolute security. Users are responsible for protecting their credentials, using secure devices and promptly reporting suspected compromise to contact@phasegrowth.com.
Phasegrowth will assess suspected personal-data breaches and take proportionate containment, remediation and documentation measures. Where required by Article 33 GDPR, Phasegrowth will notify the Estonian Data Protection Inspectorate without undue delay and, where feasible, within 72 hours after becoming aware of the breach. Where Article 34 GDPR applies, affected individuals will also be informed without undue delay.
Subject to the conditions and limitations of the GDPR, an individual may request access to personal data, rectification of inaccurate data, erasure, restriction of processing, portability of data provided to Phasegrowth, and information about recipients. The individual may object at any time to direct marketing and may object, on grounds relating to their particular situation, to processing based on legitimate interests.
Where processing relies on consent, consent may be withdrawn at any time without affecting the lawfulness of processing before withdrawal. Individuals also have the right not to be subject to a solely automated decision producing legal or similarly significant effects, where Article 22 GDPR applies.
Requests should be sent to contact@phasegrowth.com. Phasegrowth may request information necessary to verify identity and authority. Phasegrowth normally responds within one month, subject to the extension permitted by the GDPR for complex or numerous requests. There is normally no fee, but a reasonable fee may be charged or a request refused where it is manifestly unfounded or excessive, as permitted by law.
An organisation administrator may manage access to an organisation account, but this does not replace an individual’s rights under data-protection law. A request concerning personal data may be submitted directly to Phasegrowth even where the individual’s Platform access was created or managed by their employer or another organisation.
Where an organisation provides personal data to Phasegrowth and independently determines why those data are entered, that organisation may have separate controller responsibilities. Users should consult their organisation’s own privacy information where relevant.
Individuals are encouraged to contact Phasegrowth first so that the matter can be investigated and resolved. A complaint may also be lodged with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, email info@aki.ee, or with the supervisory authority in the individual’s habitual residence, place of work or place of the alleged infringement.
Complaints to the Estonian authority may be subject to Estonian procedural and language requirements.
The Platform is intended for professional users aged eighteen or older and is not directed at children. Phasegrowth does not knowingly seek to collect children’s personal data through ordinary Platform registration. Suspected child accounts should be reported to contact@phasegrowth.com.
Phasegrowth may amend this Policy to reflect changes in law, technology, Platform functionality or processing operations. Material changes will be communicated through the Platform, by email or by another appropriate method before they take effect where required. The effective date at the beginning of the Policy identifies the current version.
Questions, requests and concerns concerning personal data should be sent to:
Phasegrowth OÜ
Narva mnt 5, 10117 Tallinn, Estonia
Email: contact@phasegrowth.com
Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation).
Estonian Personal Data Protection Act (Isikuandmete kaitse seadus).
Estonian Electronic Communications Act (Elektroonilise side seadus), where applicable to cookies and electronic direct marketing.
Estonian Accounting Act and Taxation Act, where applicable to mandatory retention of transaction records.
Directive 2002/58/EC concerning privacy and electronic communications, as implemented in applicable national law.