1. Who is responsible
The controller of the personal data described here is Finstig AB, registered in Sweden under company number 559544-2863, at Eklanda Byväg 11, 431 59 Mölndal.
For any question about this notice or about your data, write to info@finstig.com.
2. What we hold
- Account data. Your email address, authentication credentials handled by our authentication provider, and your two-factor authentication enrolment. We never see or store your password in readable form.
- Profile data. First and last name, year of birth, gender, country and preferred language.
- Venture content. Everything written into a venture workspace: the venture description, answers you give, the resulting business knowledge base, tasks, execution plans, milestones, team roster entries and reported outcomes.
- Conversations. The full transcript of your conversations with MAX, our AI advisor, including anything you dictate by voice. Audio is transcribed and the transcript is kept; we do not retain the audio recording after transcription.
- Usage and diagnostic data. Sign-in events, technical logs, error reports and aggregate measures of AI usage, used to run and secure the service.
- Support messages. Anything you submit through the in-app feedback widget, together with the page you were on.
3. Why we hold it, and on what basis
- To provide the service — running your workspace, generating advisor guidance, building your plan. Legal basis: performance of our contract with you.
- To keep the service secure and working — authentication, abuse prevention, diagnostics, support. Legal basis: our legitimate interest in a secure, reliable service.
- To operate the FINSTIG benchmark — see section 6. Legal basis: your consent, recorded per venture, which you can withdraw at any time.
- To meet legal obligations — accounting and record keeping where the law requires it. Legal basis: legal obligation.
4. Who can see it
- You. Everything in your own venture.
- Co-founders and members you invite into the same venture, at the access level you give them. You control who is invited and can remove them.
- Programme managers — an accelerator, incubator or investor running a cohort your venture joined — see only the specific categories of information your venture switched on for that programme, and only while your venture is a member of it. You can change those categories or leave the programme at any time, and every change is logged.
- FINSTIG staff, where necessary for support, safety and maintaining the service, under confidentiality obligations.
- Our processors — the infrastructure, database, hosting, email and AI model providers listed in section 5, acting on our instructions under contract.
We do not sell your personal data, and we do not use it for third-party advertising.
5. AI processing
MAX is built on large language models operated by third-party providers. To generate a reply, the relevant parts of your conversation and your venture's knowledge base are sent to one of those providers, processed, and returned to you. Voice dictation is sent to a speech-to-text provider for transcription.
We contract with these providers as processors and select services that do not use submitted content to train their public models. We may change provider or model over time to improve quality, cost or availability; the categories of processing described here stay the same. A current list of providers is available on request at the contact address in section 1.
6. The FINSTIG benchmark
If your venture takes part in the benchmark, once a month we record a single row of numbers about it. That row contains scores, counts, dates, and category or range values — for example which stage the venture is in, how complete its knowledge base is, how many people are on the team as a band rather than a number, and whether funding or revenue has been reported as a band rather than an amount.
The row carries an opaque key, not your venture's name or identifier. It contains no free text, no names, no conversation content and none of the business knowledge you build inside the workspace. Nothing you write in the workspace is contributed.
These rows are used to produce aggregate comparisons — how ventures at a similar stage typically progress — which we show back to participating founders and may publish or license as aggregate statistics. We do not publish rows that could single out an individual venture.
Participation is per venture and is on by default for new ventures, so that comparisons are available to you as the dataset grows. We tell you about it in the app the first time you sign in, and you can change it at any time in Settings. Turning it off stops any further rows from being recorded. Rows already recorded are anonymous and are kept as part of the aggregate dataset, because they can no longer be linked back to you.
7. How long we keep it
Venture content, conversations and profile data are kept for as long as your account is open. If you delete a venture, its content is removed. If you close your account, we delete or anonymise your personal data within 90 days, except where we must keep records to meet a legal obligation. Anonymous benchmark rows are not personal data and are retained.
8. Where your data is processed
We are based in Sweden and our infrastructure is hosted in Europe. Some of our processors, in particular AI model providers, operate outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy of it
- have inaccurate data corrected
- have your data deleted
- receive the data you provided in a portable, machine-readable format
- object to or restrict processing based on our legitimate interests
- withdraw consent for the benchmark at any time, without affecting the service
You can withdraw benchmark consent yourself in Settings at any time. For access, correction, a copy of your data or deletion, write to us at the contact address in section 1 and we will respond within one month.
Where providing a copy would reveal the confidential design of our platform, we provide your own content and the guidance you received rather than our internal method, as permitted under Article 15(4).
If you believe we have handled your data incorrectly, you can complain to your national supervisory authority — in Sweden, Integritetsskyddsmyndigheten (IMY).
10. Security
Access to the service requires two-factor authentication. Data is encrypted in transit and at rest, access to production systems is restricted to the people who need it, and each venture's data is isolated by database-level access rules so one venture cannot read another's.
11. Changes to this notice
If we make a material change we will tell you inside the product before it takes effect. If the change concerns the benchmark, we will ask you to confirm your participation again.
Version 24 August 2026 — first published.