§ 01
Who is responsible
EigenFlow ("we") operates this domain and is the controller of the personal data described here. We are based in Cambridge, Massachusetts, United States. For anything in this notice, write to gp@eigenflow.pro and a person will answer.
§ 02
What we collect
For business correspondence, we hold a deliberately narrow set of fields:
- Professional contact details. Name, business email address, job title, and the firm you work for.
- Firm-level information. Publicly filed details about the fund or firm, such as strategy, vintage, and the filing that named you as a contact.
- Correspondence record. Whether a message was delivered, opened, or replied to, and the content of any reply you send us.
- Preference record. If you ask not to be contacted, we retain the minimum needed to honour that request.
We do not collect or hold special category data, financial account information, or any personal data about you outside your professional capacity.
§ 03
Where it comes from
We do not purchase contact lists and we do not scrape personal data. Contact details reach us through three routes:
- Public regulatory filings. Principally SEC Form D and related disclosures, published by the Commission on EDGAR, which name a contact for the issuer.
- Published business pages. A firm website or professional profile that lists a business contact for inbound enquiries.
- Introductions. A referral from a mutual contact, or a conversation at an industry event.
If none of these apply
Write to gp@eigenflow.pro. We will trace how the record entered our system, tell you what we found, and delete it. We treat this as a defect worth fixing, not a complaint to manage.
§ 04
Why we use it, and on what basis
We use these details for one purpose: to contact fund managers and their teams about whether our product is relevant to their operations, and to continue any conversation that follows.
Our lawful basis is legitimate interest, meaning direct business-to-business correspondence with professionals about services relevant to their role. We have weighed that interest against your rights, which is why we limit ourselves to public professional sources, write in low volume, address a business role rather than a private individual, and stop immediately on request. Where local law requires prior consent instead, we rely on consent and obtain it before writing.
§ 05
Who else sees it
We do not sell personal data, and we do not share it for anyone else's marketing. A small number of service providers process it on our behalf under contract, limited to what they need to perform their function: email delivery and sending infrastructure, cloud hosting, and our internal customer record system. Each is bound to use the data only on our instructions.
We may disclose data where required by law, or where necessary to establish or defend a legal claim.
§ 06
How long we keep it
- No reply. Contact records are deleted within 24 months of last contact.
- Active conversation. Retained while the conversation is live, and for 24 months after it ends.
- Opt-out record. Retained indefinitely, but only the minimum needed to make sure we never contact you again. This is the one record that deletion would defeat the purpose of removing.
§ 07
Your rights
You can ask us to do any of the following, and we will act within 30 days:
- Access. Tell you what we hold about you, and where it came from.
- Correct. Fix anything inaccurate or out of date.
- Delete. Remove your record entirely.
- Object. Stop processing based on legitimate interest, including all correspondence.
- Port. Provide your data in a portable format.
- Withdraw consent. Where we relied on consent, withdraw it at any time.
Send any of these to gp@eigenflow.pro. We do not require you to create an account or complete a form. If you are in the EEA or UK and are unsatisfied with our response, you may complain to your local supervisory authority.
§ 08
Stopping our correspondence
The short version
Reply to any message with the word stop, use the unsubscribe link in the footer, or write to gp@eigenflow.pro. Any of the three works. Removal is same-day and permanent, and you do not need to explain why.
§ 09
Security and transfers
Contact data is held in access-controlled systems, encrypted in transit and at rest, and reachable only by the people who need it. Our infrastructure is located in the United States; where data originates in the EEA or UK, transfers are made under Standard Contractual Clauses.
§ 10
Changes to this notice
If we change how we handle contact data, we will update this page and move the "last updated" date at the top. Material changes affecting people already in our records will be notified by email before they take effect.