Insuja
Request demo ↗Request access →

Privacy notice

Clear roles. Separate data. Limited use.

EFFECTIVE / 28 JUL 2026

This notice covers the public site, access and consultation intake, and the investor, buyer, and seller portals.

Legal & trust

Legal centerPrivacyTerms of useAcceptable useCookies & local storageSubprocessorsData processing addendumInvestment disclaimer

Questions or rights requests: hi@insuja.com

1. Scope and our role

This notice explains how the INSUJA service handles personal data. For public-site visits, access requests, consultation requests, account administration, security, and our own business operations, the INSUJA provider is the controller. For customer content placed in an investor, buyer, or seller workspace, the customer normally determines the purpose and means of processing and is the controller; the INSUJA provider acts as its processor under the applicable agreement.

The legal provider for a contracted workspace is identified in the order form or service agreement. Contact hi@insuja.com for the current controller details or to exercise a privacy right.

2. Data we handle

  • Public intake: name, work email, company, requested platform and access type, optional context, consent record, request reference, preferred meeting time, time zone, and service need.
  • Account and identity: business identity, organization and workspace identifiers, role, authentication events, session identifiers, and account status. Passwords and authentication secrets are handled by the identity system and are not written into public intake records.
  • Investor and buyer work: targets, checklists, tasks, private notes, investment reasoning, portfolio records, permissions, audit events, and controlled seller releases.
  • Seller work: rooms, folders, documents, versions, release packages, recipients, questions, access history, permissions, retention decisions, and legal holds.
  • Security and operations: request time, network and browser signals, rate-limit keys, bounded error and outcome codes, and audit evidence. The designed telemetry channel excludes customer content, document names, tokens, and free-form error bodies.
  • Support and contracting: messages, contact details, service records, order information, and billing or compliance contacts where applicable.

3. Why we use data

We use personal data to:

  • respond to requests and decide whether to offer access;
  • provide, secure, support, and improve the requested service;
  • authenticate users and enforce organization and workspace access;
  • maintain audit, release, retention, and legal-hold controls;
  • prevent abuse, fraud, unauthorized access, and service disruption;
  • communicate operational, security, and contractual information;
  • meet legal obligations and establish, exercise, or defend claims.

Depending on the context, the legal basis is taking steps at your request before entering a contract, performing a contract, complying with law, protecting our legitimate interests in a secure B2B service, or consent where the law requires it. We do not use customer content to train a generalized AI model unless a customer separately authorizes that use in writing.

4. Sources and required fields

We receive data from you, your organization, an authorized workspace administrator, your browser or device, and service providers that support the requested operation. Required form fields are needed to review or answer a request. Optional context may be omitted. Do not submit passwords, tokens, private keys, or unnecessary deal-sensitive or special-category personal data through public forms.

5. Disclosures

We disclose data only as needed to operate the service: to contracted infrastructure and communications providers, to authorized members of the relevant customer workspace, to professional advisers under confidentiality, in a corporate transaction subject to appropriate safeguards, or when required by law. We do not sell personal data or share it for cross-context behavioral advertising.

Buyer-private information is not disclosed to sellers. Seller drafts and hidden material are not disclosed to buyers. A seller release may cross the boundary only when an authorized seller publishes and releases an exact package to an exact authorized buyer.

6. International transfers

Providers may process data outside your country. Where transfer rules apply, we use an available lawful mechanism such as an adequacy decision, approved standard contractual clauses, or another legally recognized safeguard. Deployment region and transfer details may also be set in the applicable order form or data-processing agreement.

7. Retention

  • A public access application is assigned a one-year review period. A legal hold, active account, provisioning record, security need, or claim may require longer retention.
  • Consultation records are kept while the request is handled and then erased under the applicable operational retention schedule, subject to legal or security needs.
  • Customer workspace content follows the customer-approved retention policy, contractual instructions, backup schedule, and legal holds. Deletion fails closed while those controls are unresolved.
  • Portal connection values and opaque session tokens are held in the current browser tab's session storage and are cleared when that tab session ends or the user signs out.
  • Minimal audit, deletion, and security evidence may be kept for the period reasonably needed to demonstrate compliance, resolve incidents, or defend claims.

8. Security

Controls include encryption, least-privilege access, separate public, buyer-private and seller-private boundaries, deny-by-default authorization, short-lived or scoped credentials, versioned releases, audit evidence, rate limiting, and controlled deletion. No service can guarantee absolute security. Users must protect their account and report suspected compromise promptly.

9. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent without affecting earlier lawful processing. You may also object to a decision based solely on automated processing. INSUJA does not make solely automated decisions that grant portal access or make an investment decision.

Send a request to hi@insuja.com. We may verify your identity and authority before acting. If a customer controls the relevant workspace data, we will direct the request to that customer or assist it as processor. You may complain to your competent supervisory authority; in Spain this is the Agencia Española de Protección de Datos.

10. Children

The service is designed for business users and is not directed to children. Users must be at least 18 and able to act for the organization they represent.

11. Changes and contact

We may update this notice to reflect service or legal changes. The effective date identifies the current version. Material changes will be communicated where required. Questions and rights requests may be sent to hi@insuja.com.

INSUJA
InsujaPrivate-company investment infrastructure.
© 2026 INSUJA
Investment infrastructureInvestment lifecyclePortfolio operationsRequest accessRequest a demoBuyer platformSeller VDRServicesAccess processDocumentationSecurityFAQPrivacyTermsAcceptable useCookiesSubprocessorsData processingInvestment disclaimerLegal center