at bypass, we respect your fundamental right to privacy. this policy details, under strict EU GDPR compliance, how your personal data and pitch decks are handled.
This Privacy Policy applies to all personal data collected and processed by Bypass ("we", "us", "our"), operating the website and platform at bypass.com and related studio services.
Under Article 4(7) of the General Data Protection Regulation (GDPR), Bypass acts as the Data Controller for the personal data collected from founders, investors, and platform visitors.
contact@bypass.comazasratruth@bypass.comIn strict accordance with Article 6 of the GDPR, we only process your personal data when we have a lawful legal basis to do so:
| Legal Basis (GDPR Art. 6) | Application Context |
|---|---|
| Art. 6(1)(a) Consent | When you explicitly sign up for newsletters, submit contact requests, or opt-in to optional communications. |
| Art. 6(1)(b) Contractual Performance | Necessary to deliver requested Pitch Deck Audits, process founder applications, manage user accounts, and provide Studio services. |
| Art. 6(1)(c) Legal Obligation | Compliance with applicable legal, tax, accounting, or regulatory requirements. |
| Art. 6(1)(f) Legitimate Interests | Securing platform infrastructure, detecting fraud, maintaining system integrity, and optimizing user experience. |
We collect information directly provided by you, as well as data gathered automatically during your platform interaction:
We use the collected personal data strictly for specified, explicit, and legitimate purposes (GDPR Art. 5(1)(b)):
We engage trusted third-party service providers (Data Processors) under strict GDPR Article 28 data processing agreements:
| Processor | Purpose | Location / Compliance |
|---|---|---|
| Supabase Inc. | Database storage, authentication, and access control. | EU/US GDPR Compliant (SCCs & DPA) |
| Vercel Inc. | Web application hosting, edge delivery, and DNS. | Global CDN / GDPR Compliant |
| PostHog Inc. | Privacy-friendly product analytics & telemetry. | EU Hosting Option / Pseudonymized |
International Transfers: Where personal data is transferred outside the European Economic Area (EEA), we enforce Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to Art. 46(2)(c) GDPR to guarantee adequate protection.
Data Retention Schedule: Pitch deck files and uploaded presentation assets are automatically purged after 30 days. Founder contact details (name, email, LinkedIn, and interaction history) are stored securely to support ongoing communication until account closure or an explicit erasure request (GDPR Art. 17).
As a data subject under European data protection laws, you possess comprehensive rights regarding your personal information:
We implement state-of-the-art technical and organizational security controls to protect your data against unauthorized access, loss, or alteration:
To submit a Data Subject Access Request (DSAR), request data erasure, or ask privacy questions, contact our Data Protection Lead directly. We respond to all verified requests within 30 days as mandated by GDPR.
Submit GDPR Request (report@islamic.systems)