Privacy Policy
Effective Date: July 2026 — Version 1.0
1. Data Controller
Oakshore Pte. Ltd. (UEN: 202617271M), an Exempt Private Company Limited by Shares incorporated in the Republic of Singapore, with its registered office at 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987 ("Oakshore," "we," "us," or "our"), is the data controller responsible for processing your personal data when you use our SaaS platform, website, and related services (collectively, the "Platform").
2. Information We Collect
We collect the following categories of personal and corporate data:
2.1. Account & Identity Data
Full name, email address, phone number (optional), corporate title, organizational affiliations, LinkedIn profile URL, and profile photograph.
2.2. Verification (KYC/AML) Data
Government-issued identification (passport, national ID, driver's license), proof of address, corporate registration documents (Certificate of Incorporation, ACRA BizFile or equivalent), ultimate beneficial owner (UBO) identification, and investor accreditation declarations or supporting documentation.
2.3. Business & Deal Data
Startup profiles (company name, industry, location, stage, one-liner, target raise), pitch decks, cap tables, revenue metrics, financial models, term sheets, signed legal instruments, wire transfer instructions (bank name, account number, SWIFT/BIC), and AI Analyst Interview transcripts and responses.
2.4. Communications Data
Messages exchanged within bilateral Deal Rooms, syndicate chats between investors, Investor Relations (IR) Hub broadcast updates, and contact form submissions.
2.5. Usage & Technical Data
IP addresses, browser type and version, device type, operating system, referring URLs, pages visited, time and date of access, interaction metrics (including document view duration and Deal Room activity), and Google Analytics identifiers.
2.6. Engagement Signal Data
We record certain investor engagement signals (such as Deal Room views and pipeline stage transitions) to provide founders with visibility into investor activity on their fundraising round. This data is strictly scoped — founders can only see signals relating to their own startup.
3. How We Use Your Information
We do not sell your personal or corporate data. We use the information we collect for the following specific purposes:
- Account Operation: Creating and managing your account, authenticating your identity, and maintaining session security.
- KYC/AML Compliance: Verifying your identity, screening against sanctions lists, and fulfilling our anti-money laundering obligations.
- Platform Services: Operating Deal Rooms, facilitating bilateral communications, processing state transitions in the deal execution workflow, and providing the Data Room, IR Hub, and syndication features.
- AI Processing: Utilizing our AI engine (powered by Google's Gemini models via the Genkit framework) to process your interview responses and generate standardized Deal Memos. Your interview data is sent to Google's AI API for processing and is subject to Google's Gemini API Terms of Service. Your data is not used to train Oakshore's or any third-party's generalized AI models.
- Discovery & Filtering: Enabling investors to search and filter listed startups based on user-defined criteria (industry, stage, geography, check size). This is a passive directory function — no algorithmic investment recommendations are made.
- Transactional Communications: Sending authenticated system emails (deal notifications, verification status updates, capital call alerts, and platform announcements) via our email infrastructure.
- Analytics & Improvement: Understanding how Users interact with the Platform to improve its performance, layout, and functionality. Analytics data is aggregated and anonymized where possible.
- Security & Fraud Prevention: Detecting, preventing, and investigating security incidents, unauthorized access, and fraudulent activity, including through Google reCAPTCHA v3.
- Legal Compliance: Fulfilling legal obligations, responding to lawful requests from regulatory authorities, and enforcing our Terms of Service.
- Payment Processing: Processing SaaS subscription payments through our payment processor (post-Beta).
4. Legal Bases for Processing
We process your personal data on the following legal bases under the Personal Data Protection Act 2012 (PDPA) of Singapore and, where applicable, the UK/EU General Data Protection Regulation (GDPR):
| Processing Activity | PDPA Basis | GDPR Basis |
|---|---|---|
| Account creation & authentication | Consent / Contractual necessity | Art. 6(1)(b) — Contract |
| KYC/AML identity verification | Legal obligation / Consent | Art. 6(1)(c) — Legal obligation |
| Deal Room operation & bilateral communication | Contractual necessity | Art. 6(1)(b) — Contract |
| AI Deal Memo generation | Consent | Art. 6(1)(a) — Consent |
| Analytics & platform improvement | Legitimate interest | Art. 6(1)(f) — Legitimate interest |
| Transactional email dispatch | Contractual necessity | Art. 6(1)(b) — Contract |
| Security & fraud prevention | Legitimate interest | Art. 6(1)(f) — Legitimate interest |
| Legal & regulatory compliance | Legal obligation | Art. 6(1)(c) — Legal obligation |
5. Information Sharing & Sub-Processors
We maintain strict access controls. We do not sell, rent, or trade your personal data. Information is shared only under the following circumstances:
5.1. Within the Platform
Startup data (company profiles, Deal Memos) is visible only to verified investors who satisfy the access criteria set by the founder. Deal Room data is strictly isolated to the two authenticated counterparties (founder and investor) assigned to that room. No third party — including other Oakshore users — can access a Deal Room they are not a party to.
5.2. Sub-Processors
We share necessary data with the following trusted third-party service providers under contractual data processing obligations:
| Sub-Processor | Purpose | Data Location |
|---|---|---|
| Google Cloud / Firebase | Database hosting, authentication, file storage, cloud infrastructure | United States (multi-region) |
| Google AI (Gemini API) | AI Deal Memo generation, interview processing | United States |
| Google reCAPTCHA v3 | Bot detection and fraud prevention during onboarding | United States |
| Google Analytics | Aggregated platform usage analytics | United States |
| Resend | Transactional email delivery | United States |
| Stripe | Subscription payment processing (post-Beta) | United States |
5.3. Legal Disclosure
We may disclose personal data where required by law, subpoena, court order, or regulatory mandate from competent authorities in Singapore or other applicable jurisdictions. We may also disclose data to protect the rights, property, or safety of Oakshore, our Users, or the public.
6. International Data Transfers
Oakshore is incorporated in Singapore. However, our infrastructure is hosted on Google Cloud Platform / Firebase, which utilizes United States multi-region data centers. This means that your personal data will be transferred to, stored, and processed in the United States and potentially across Google's global infrastructure.
Additionally, when you engage with counterparties in other jurisdictions through the Platform (e.g., a Singapore-based founder sharing deal information with a US-based investor), your data may be accessed from those jurisdictions.
PDPA Compliance (Section 26):We ensure that adequate protections are in place for cross-border transfers of personal data through contractual arrangements with our sub-processors (including Google's Data Processing Addendum) that provide a standard of protection comparable to the PDPA.
GDPR Compliance: For transfers of personal data of EU/UK residents to the United States and other non-adequate countries, we rely on European Commission-approved Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA), as incorporated into our agreements with sub-processors. Copies of the relevant transfer mechanisms may be obtained by contacting our DPO at dpo@oakshore.app.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law. The following retention periods apply:
| Data Category | Retention Period | Justification |
|---|---|---|
| Account profile data | Duration of active account + 30 days post-deletion | Account recovery window |
| KYC/AML verification documents | 5 years post-account closure | Aligned with MAS CDD guidelines and international AML standards |
| Deal Room records (messages, executed documents, state transitions) | 7 years post-deal closure | Singapore limitation period for contractual claims (6 years) + 1-year buffer |
| Wire transfer instructions | 90 days post-deal closure, then securely deleted | Highly sensitive financial data; no purpose for long-term retention |
| AI Interview transcripts | Duration of active fundraising round + 12 months | Purpose expires once the Deal Memo is generated and the round closes |
| Usage & analytics logs | 24 months (rolling) | Standard industry practice for platform improvement |
| Contact form submissions | 12 months post-resolution | Customer support records |
Note on Immutable Records: Certain Platform records (Deal Room messages, state transition logs, and executed documents) are architecturally immutable — once created, they cannot be modified or deleted by any party, including Oakshore. This immutability is a security feature designed to preserve the integrity of bilateral commercial agreements. Deletion requests for these records will be addressed in accordance with the applicable legal retention obligations.
8. Data Security
We employ institutional-grade security measures to protect your data, including:
- Encryption: All data is encrypted in transit (TLS/HTTPS) and at rest (Google Cloud's default encryption using AES-256).
- Tenant Isolation: Deal Room data is scoped to the two authenticated counterparties via Firestore security rules. No third party can access a Deal Room they are not a party to.
- Authentication: Firebase Authentication with email verification, supplemented by KYC document verification.
- Server-Side Projection: Sensitive metadata (such as AI interview transcripts) is stripped server-side before reaching any client browser.
- Immutability Controls: Critical records (Deal Room messages, state transitions) are protected by database-level immutability rules that prevent retroactive modification.
- Bot Protection: Google reCAPTCHA v3 protects against automated abuse during onboarding.
However, no method of electronic transmission or storage is entirely secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
Advisory — External Link Security: Documents indexed in your Data Room via external URLs (e.g., DocSend, Google Drive, Notion) remain hosted and access-controlled by their respective platforms. Oakshore stores only the link metadata. For maximum security, we recommend email-gating or password-protecting your external links.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
9.1. PDPA Rights (Singapore)
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete personal data.
- Withdrawal of Consent: Withdraw your consent for specific processing activities (note: this may affect our ability to provide certain services).
9.2. GDPR Rights (EU/UK Residents)
In addition to the above, EU/UK residents have the following rights:
- Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to legal retention obligations.
- Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Restriction of Processing: Request that we restrict the processing of your personal data in certain circumstances.
- Objection: Object to processing based on legitimate interests.
- Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (see Section 10 below).
- Supervisory Authority: Lodge a complaint with a supervisory authority. For UK residents, this is the Information Commissioner's Office (ICO). For EU residents, this is the relevant national data protection authority in your member state.
9.3. How to Exercise Your Rights
Submit all data subject requests to our Data Protection Officer at dpo@oakshore.app. We will respond to all valid requests within thirty (30) calendar days of receipt. We may request verification of your identity before processing your request. We may charge a reasonable fee for manifestly unfounded or excessive requests.
10. Automated Processing & AI
Oakshore uses automated processing, including AI systems, in the following contexts:
- AI Deal Memo Generation: Your responses to the AI Analyst Interview are processed by Google's Gemini large language model to generate a structured 8-pillar Deal Memo. This is a data structuring function — the AI does not make investment recommendations or decisions with legal effect.
- AI IC Memo Auto-Draft: Investors may auto-draft an Investment Committee Memo. This structures the investor's own notes — it does not recommend whether to invest.
No Automated Decisions with Legal Effect: Oakshore does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect you. All investment decisions, deal terms, and bilateral agreements are negotiated and executed by the Users themselves.
11. Children's Privacy
The Platform is not directed at, and is not intended for use by, individuals under the age of eighteen (18). We do not knowingly collect personal data from children. If you believe that a child under 18 has provided personal data to Oakshore, please contact our DPO at dpo@oakshore.app, and we will take steps to delete such data.
12. Data Breach Notification
In the event of a data breach that is likely to result in significant harm to affected individuals or that affects 500 or more individuals, Oakshore will:
- Notify the Personal Data Protection Commission (PDPC) of Singapore within three (3) calendar days of completing our assessment of the breach, in accordance with the PDPA (as amended 2020).
- Notify affected individuals as soon as practicable, providing details of the breach, the data involved, and recommended protective measures.
- Where applicable, notify the relevant EU/UK supervisory authority within seventy-two (72) hours of becoming aware of the breach, in accordance with GDPR Article 33.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Platform, updating the "Effective Date" at the top of this page, and, where the changes materially affect how we process your personal data, sending notice to your registered email address at least thirty (30) calendar days prior to the changes taking effect.
Your continued use of the Platform after the effective date of any modification constitutes your acceptance of the updated Privacy Policy.
For privacy-related inquiries or data subject requests, please contact our Data Protection Officer at dpo@oakshore.app.
Oakshore Pte. Ltd. — 7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987.
