PRIVACY POLICY
Last updated: January 15, 2026
This Privacy Policy applies between you, the User of this Website, and Metup S.r.l., the owner and provider of this Website. Metup S.r.l. takes the privacy of your information very seriously. This Privacy Policy applies to our use of any and all Data collected by us or provided by you in relation to your use of the Website.
This Privacy Policy should be read alongside, and in addition to, our Terms and Conditions, which can be found at: https://capitalscout.ai/termsandcondition.
Please read this Privacy Policy carefully.
Data Controller
Metup S.r.l. is the data controller for the purpose of applicable Data Protection laws.
Registered office: Via Cavour 310, Rome, Italy, 00184
Company details: P.IVA: 12221781003
Privacy contact: affiliations@metup.it
Definitions and Interpretation
1. In this Privacy Policy, the following definitions are used:
- Data
- collectively all information that you submit to Metup S.r.l. via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws;
- Cookies
- a small text file placed on your computer by this Websites when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out in the clause below (Cookies);
- Data Protection Laws
- any applicable law relating to the processing of personal Data, including but not limited to the GDPR, and any national implementing and supplementary laws, regulations and secondary legislation;
- GDPR
- the General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR) and, where applicable, the UK General Data Protection Regulation (UK GDPR);
- Metup S.r.l., we or us
- Metup S.r.l., a company incorporated in Italy (VAT: 12221781003), whose registered office is at Via Cavour 310, Rome, Italy, 00184;
- Cookie Law
- applicable ePrivacy and cookie laws and regulations (including the EU ePrivacy rules and any national implementing laws);
- User or you
- any third party that accesses the Website and is not either (i) employed by Metup S.r.l. and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to Metup S.r.l. and accessing the Website in connection with the provision of such services;
- Website
- the website that you are currently using, https://capitalscout.ai, and any sub-domains of this site unless expressly excluded by their own terms and conditions.
2. In this Privacy Policy, unless the context require a different interpretation:
- a. The singular includes the plural and vice versa;
- b. References to sub-clauses, clauses, schedules or appendices are to sub-clauses, clauses, schedules or appendices of this Privacy Policy;
- c. A reference to a person includes firms, companies, government entities, trust and partnerships;
- d. "including" is understood to mean "including without limitation";
- e. Reference to any statutory provision includes any modification or amendment of it;
- f. The heading and sub-headings do not form part of this Privacy Policy.
Scope of this Privacy Policy
3. This Privacy Policy applies only to the action of Metup S.r.l. and Users with respect to this Website. It does not extend to any websites that can be accessed from this Website including, but not limited to, any links we may provide to social media websites.
4. For purpose of the applicable Data Protection Laws, Metup S.r.l. is the "data controller". This means that Metup S.r.l. determines the purposes for which, and the manner in which, your Data is processed.
Children
5. This Website and service are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete such data.
Data Collected
6. We may collect the following Data, which includes personal Data, from you:
- a. name;
- b. contact Information such as email addresses;
- c. account & authorization data: role, status (active/inactive), internal app user_id;
- d. access scope data: assigned_company_ids, assigned_round_ids;
- e. data provided by user in the app (business/project data): information from Companies / Projects / Rounds (e.g. company name, description, industry, website, logo, founded date, headquarters, team size, status, assigned user on Project/Round).
in each case, in accordance with this Privacy Policy;
How We Collect Data
7. We collect Data in the following ways:
- a. data is given to us by you;
- b. data is received from other sources;
- c. data is collected automatically.
Data That is Given to Us by You
8. Metup S.r.l. will collect your Data in a number of ways, for example:
- a. when you contact us through the Website, by telephone, post, e-mail or through any other means;
- b. when you use our services;
in each case, in accordance with this Privacy Policy.
Data That is Received From Third Parties
9. Metup S.r.l. will receive Data about you from the following third parties:
- a. Google (Google OAuth / Google Sign-In);
Use of Google User Data (Google OAuth)
10. When you sign in with Google, we receive limited Google account information such as your name, email address, and (if provided) profile picture.
11. We use this information only to:
- a. authenticate you and create/manage your account;
- b. operate the service (for example, account administration and access control).
12. We do not sell Google user data and we do not use Google user data for targeted advertising, data brokering, creditworthiness assessment, or lending decisions.
13. We share Google user data only with service providers strictly necessary to operate the service (for example, hosting and data storage providers) and only for the purposes described in this Privacy Policy.
14. Our use of information received from Google APIs will comply with the Google API Services User Data Policy, including the Limited Use requirements.
15. We only access and use Google user data to provide and improve user-facing features of the Service, and only as described in this Privacy Policy.
Data That is Collected Automatically
16. To the extent that you access the Website, we will collect your Data automatically, for example:
- a. we may process limited technical information necessary to operate and secure the service (for example, basic logs, security-related events, and platform telemetry). Where enabled by our platform or service providers, we (or our providers acting on our behalf) may also use measurement/analytics and marketing-related technologies (such as cookies or similar identifiers) to operate, secure, and improve the Website and Service, and to measure performance. You can find more information in the "Cookies" section below.
- b. we will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed "Cookies".
Our Use of Data
17. Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- a. internal record keeping;
- b. improvement of our products / services;
- c. to provide and operate the service, including user authentication, account administration, access control and allowing users to create and manage companies, project and fundraising round;
in each case, in accordance with this Privacy Policy.
18. We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interest. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed "Your rights" below).
AI-Assisted Processing
19. We may use AI-assisted and automated tools to help operate and improve the service, for example to generate recommendations (such as matching funds) and to draft content.
20. We do not use Google OAuth account data (such as your name and email) to train generalized AI models.
21. Data used for AI-assisted features may include:
- a. account and authorisation data (role and status) where necessary to provide the feature;
- b. data provided by users in the app (Companies / Projects / Round content and free-text fields).
22. AI tools may be:
- a. provided within our platform environment.
We apply appropriate safeguards and access controls. These tools are used to support the service and do not make solely automated decisions that produce legal or similarly significant effects on user. Where appropriate, human review and oversight apply.
Who We Share Data With
23. We may share your Data with the following groups of people for the following reasons:
- a. our employees, agents and/or professional advisors – to operate, administer and support the service, including account management and providing customer support;
- b. third party service providers who provide services to us which require the processing of personal data – to enable essential service functionality provided on our behalf, such as hosting and data storage (Base44) and user authentication (Google OAuth);
- c. relevant authorities – to comply with legal obligation and respond to lawful requests from public authorities;
24. We share personal data with third parties only where necessary to provide and improve user-facing features of the Service, and not for third-party advertising or independent use.
In each case, in accordance with this Privacy Policy.
Keeping Data Secure
25. We will use technical and organisational measures to safeguard your Data, for example:
- a. access to the service is controlled via secure authentication (including Google OAuth) and role-based access controls.
- b. we store your Data on secure servers.
26. Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: affiliations@metup.it
27. If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading business.
Data Retention
28. Unless a longer retention period is required or permitted by law, we keep account data for as long as your account remains active. If you request deletion or your account is closed, we will delete or anonymise your account data within 60 days, unless we are required to retain it longer by law.
29. Even if we delete your Data, it may persist on backup or archival media for up to 90 days before being overwritten, or longer where required for legal, tax or regulatory purposes.
Terms Acceptance
30. When you create an account, you are required to accept our Terms and Conditions. We record your acceptance (e.g. date/time and the version of the Terms) for compliance and contractual purposes, which can be found at: https://capitalscout.ai/termsandcondition.
Your Rights
31. You have the following rights in relation to your Data:
- a. Right to access – the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is "manifestly unfounded or excessive". Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- b. Right to correct – the right to have your Data rectified if it is inaccurate or incomplete.
- c. Right to erase – the right to request that we delete or remove your Data from our system.
- d. Right to restrict our use of your Data – the right to "block" us from using your Data or limit the way in which we can use it.
- e. Right to data portability – the right to request that we move, copy or transfer your Data.
- f. Right to object – the right to object to our use of your Data including where we use it for our legitimate interests.
32. To make enquiries, exercise any of your right set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: affiliations@metup.it.
33. It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
Transfer Outside the United Kingdom and European Economic Area
34. Data which we collect from you may be stored and processed in and transferred to countries outside of the UK and European Economic Area (EEA). For example, this could occur if our servers are located in a country outside the UK or EEA or one of our service providers is situated in a country outside the UK or EEA.
35. We will only transfer Data outside the UK or EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data, e.g. by way of data transfer agreement, incorporating the current standard contractual clauses adopted by the European Commission.
36. To ensure that your Data receives an adequate level of protection, we have put in place appropriate safeguards and procedure with the third parties we share your Data with. This ensure your Data is treated by those third parties in a way that is consistent with the Data Protection Laws.
Links to Other Websites
37. This Website may, from time to time, provide links to other websites. We have no control over such websites and are not responsible for the content of these websites. This Privacy Policy does not extend to your use of such websites. You are advised to read the Privacy Policy or statement of other websites prior to using them.
Changes of Business Ownership and Control
38. Metup S.r.l. may, from time to time, expand or reduce our business and this may involve the sale and/or the transfer of control of all or part of Metup S.r.l. Data provided by Users will, where it is relevant to any part of our business so transferred, be transferred along with that part and the new owner or newly controlling party will, under the terms of this Privacy Policy, be permitted to use the Data for the purposes for which it was originally supplied to us.
39. We may also disclose Data to a prospective purchaser of our business or any part of it.
40. In the above instances, we will take steps with the aim of ensuring your privacy is protected.
Cookies
41. This Website may place and access certain Cookies and similar identifiers on your device. Metup S.r.l. uses Cookies and similar technologies to enable core functionality and security and, where enabled, for measurement/analytics and marketing-related purposes.
42. All Cookies used by this Website are used in accordance with applicable Cookie Law.
43. Cookies used by this Website may include:
- (i) Strictly necessary cookies (required to operate the service, security and authentication),
- (ii) Functionality cookies (to remember settings and ensure services work properly),
- (iii) Analytics/measurement cookies (to measure usage and performance),
- (iv) Marketing/advertising cookies (to measure campaigns and support advertising/retargeting where enabled).
44. You can find a list of Cookies that we use in the Cookies Schedule below.
45. You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies but this can be changed. For further details, please see the help menu in your internet browser. You can switch off Cookies at any time; however, you may lose functionality that enables you to access the Website more quickly and efficiently.
46. You can choose to delete Cookies at any time; however, you may lose any information that enables you to access the Website more quickly and efficiently including, but not limited to, personalisation settings.
47. It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
48. For more information generally on cookies, including how to disable them, please refer to aboutcookies.org.
General
49. You may not transfer any of your rights under this Privacy Policy to any other person. We may transfer our rights under this Privacy Policy where we reasonably believe your rights will not be affected.
50. If any court or competent authority finds that any provision of this Privacy Policy (or part of any provision) is invalid, illegal or unenforceable, that provision or part-provision will, to the extent required, be deemed to be deleted, and the validity and enforceability of the other provisions of this Privacy Policy will not be affected.
51. Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
52. This Agreement will be governed by and interpreted according to the laws of Italy. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the courts of Rome, Italy.
Changes to This Privacy Policy
53. Metup S.r.l. reserves the right to change this Privacy Policy as we may deem necessary from time to time or as may be required by law. Any changes will be posted on the Website and communicated to the user.
You may contact Metup S.r.l. by email at affiliations@metup.it.
Cookies Schedule
Below is a list of cookies that we use or that may be set when you use the Website/Service. We try to ensure this list is complete and up to date, but if you think that we have missed a cookie or there is any discrepancy, please let us know.
IMPORTANT NOTE:
- Some cookies are set by our service providers or third parties (e.g., authentication, security, hosting, analytics/measurement, marketing tools) acting on our behalf.
- During Google OAuth sign-in, Google may set third-party cookies on Google domains (e.g., google.com). Those cookies are controlled by Google and governed by Google's own policies.
A) Strictly necessary (security / authentication)
- base44_sessionId
Purpose: session management / authentication for the Service. - XSRF-TOKEN
Purpose: security (CSRF protection).
B) Functional / service operation (platform / hosting / payments & fraud prevention)
- _stripe_mid, _stripe_sid
Provider: Stripe
Purpose: payment security and fraud prevention (even if only loaded by embedded Stripe components). - _dd_s
Provider: monitoring / reliability provider
Purpose: security/monitoring and service reliability. - _wixCIDX, _wixUIDX, bSession, hs, svSession
Provider: platform/hosting layer
Purpose: service operation, security, and session/site functionality.
C) Analytics / measurement
- _clck, clsk
Provider: Microsoft Clarity (measurement)
Purpose: usage measurement and website/service performance analytics. - mp_[…] (e.g., mp_XXXXXXXX…)
Provider: analytics/measurement provider (e.g., Mixpanel)
Purpose: analytics/measurement of product usage and performance.
D) Marketing / advertising (where enabled)
- _fbp
Provider: Meta (Facebook)
Purpose: marketing/advertising measurement and retargeting. - _gcl_au, _gcl_aw
Provider: Google Ads / conversion measurement
Purpose: advertising measurement / conversion tracking. - _rdt_uuid, _rdt_em, _rdt_pn
Provider: marketing/advertising technology
Purpose: marketing measurement / attribution / retargeting identifiers. - MUID
Provider: Microsoft
Purpose: advertising/measurement identifier (where enabled).
(Expiry/duration)
Cookie expiry varies by cookie and provider and can be inspected in your browser settings (DevTools → Application → Cookies → "Expires/Max-Age").