Legal & Transparency

GDPR Privacy Policy

at bypass, we respect your fundamental right to privacy. this policy details, under strict EU GDPR compliance, how your personal data and pitch decks are handled.

Effective Date: February 3, 2026EU General Data Protection Regulation (Regulation 2016/679)
Zero Data Selling
We never monetize, rent, or sell your personal details or startup information to third parties.
Automatic 30-Day Purge
Submitted pitch decks are automatically deleted in 30 days while your contact details remain stored for ongoing support.
Full Rights & Control
Request data access, correction, export, or complete deletion at any time under GDPR Art. 15–22.
Encrypted & Secure
End-to-end encryption in transit and granular Row-Level Security (RLS) database isolation.
1Data Controller & Identity

This Privacy Policy applies to all personal data collected and processed by Bypass ("we", "us", "our"), operating the website and platform at bypass.com and related studio services.

Under Article 4(7) of the General Data Protection Regulation (GDPR), Bypass acts as the Data Controller for the personal data collected from founders, investors, and platform visitors.

  • Data Controller Name: Bypass Studio
  • Primary Contact Email: contact@bypass.com
  • Founder & DPO Direct: azasratruth@bypass.com
3Categories of Data We Collect

We collect information directly provided by you, as well as data gathered automatically during your platform interaction:

  • Account & Contact Data: Full name, email address, LinkedIn profile URL, phone number, role, and authentication credentials.
  • Startup & Application Data: Startup name, website URL, deck files (PDFs/presentations), traction metrics, funding targets, revenue models, and founder responses.
  • Technical & Telemetry Data: IP address, device type, browser identification, operating system, timestamped access logs, and referral headers.
  • Interaction & Support Data: Inquiries, feedback forms, community participation notes, and customer support history.
4How We Use Your Data

We use the collected personal data strictly for specified, explicit, and legitimate purposes (GDPR Art. 5(1)(b)):

  • Evaluating pitch decks and generating 36-metric investor benchmark scorecards.
  • Providing authentic Musharakah-grounded advice, ecosystem access, and venture support.
  • Creating, maintaining, and authenticating your Bypass account session.
  • Responding to founder inquiries, meeting scheduling, and application status updates.
  • Monitoring system stability, preventing cyber abuse, and ensuring cybersecurity compliance.
5IP Confidentiality
  • Contact Information Retention: Your contact details (such as name, email address, LinkedIn profile, and submission metadata) remain securely stored in our database so we can maintain ongoing founder support, follow-up communications, and account services.
  • Automated Scoring: Automated deck parsing systems process material in memory to compute metrics and deliver diagnostic reports.
6Third-Party Processors & Sub-Processors

We engage trusted third-party service providers (Data Processors) under strict GDPR Article 28 data processing agreements:

ProcessorPurposeLocation / Compliance
Supabase Inc.Database storage, authentication, and access control.EU/US GDPR Compliant (SCCs & DPA)
Vercel Inc.Web application hosting, edge delivery, and DNS.Global CDN / GDPR Compliant
PostHog Inc.Privacy-friendly product analytics & telemetry.EU Hosting Option / Pseudonymized
7International Data Transfers & Retention

International Transfers: Where personal data is transferred outside the European Economic Area (EEA), we enforce Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR to guarantee adequate protection.

Data Retention Schedule: Pitch deck files and uploaded presentation assets are automatically purged after 30 days. Founder contact details (name, email, LinkedIn, and interaction history) are stored securely to support ongoing communication until account closure or an explicit erasure request (GDPR Art. 17).

8Your Rights Under GDPR (Art. 15–22)

As a data subject under European data protection laws, you possess comprehensive rights regarding your personal information:

Right of Access (Art. 15)
Request confirmation and a copy of all personal data held about you.
Right to Rectification (Art. 16)
Correct any inaccurate or incomplete personal records immediately.
Right to Erasure (Art. 17)
Request permanent deletion ("Right to be Forgotten") of your personal data.
Right to Restriction (Art. 18)
Limit the scope or manner in which your data is processed.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV).
Right to Object (Art. 21)
Object to processing based on legitimate interests or direct marketing.
9Cookies & Tracking Technologies

We use essential functional cookies to keep you signed in and maintain security tokens. Optional performance analytics cookies (e.g. PostHog) help us optimize platform responsiveness.

  • Strictly Necessary Cookies: Required for account authentication (Supabase session tokens). Cannot be disabled.
  • Analytical & Performance Cookies: Used to understand user flow and improve pitch audit responsiveness.

You can manage cookie settings directly in your browser preferences at any time.

10Security Measures

We implement state-of-the-art technical and organizational security controls to protect your data against unauthorized access, loss, or alteration:

  • TLS 1.3 cryptographic protocols for data in transit across all endpoints.
  • PostgreSQL Row-Level Security (RLS) policies enforcing database isolation per user session.
  • Role-Based Access Control (RBAC) preventing unauthorized administrative privileges.
Exercise Your Data Rights

To submit a Data Subject Access Request (DSAR), request data erasure, or ask privacy questions, contact our Data Protection Lead directly. We respond to all verified requests within 30 days as mandated by GDPR.

Submit GDPR Request (report@islamic.systems)