Our brand is trust. A data room holds a company's secrets. If we sold your data, or did anything with it you would dislike, we would be ruined. So we do not. The rest of this page is the detail.
1. Who is responsible
Figure 4 AB, org. no. 559301-7998, registered in Sweden, is the data controller for the personal data described here. Reach us at [email protected].
For personal data inside the documents an organisation uploads, that organisation is the controller and Figure 4 is its processor. This policy covers both.
2. What we collect
- Account data. Your name and email address, and the organisation you belong to. Sign-in is handled by an identity service we host ourselves. We never see your password.
- Room content. The documents your organisation uploads, the text we extract from them, and the findings, reports and chat messages produced from them.
- Audit events. Who opened, uploaded, removed, evaluated or shared what, and when. This log is append-only and is part of the product.
- Billing data. Stripe holds your payment details. We hold a Stripe customer id, your subscription status and the date it is paid until.
- Technical data. Server logs with IP address, browser and request path, kept for security and debugging.
We use no analytics or advertising trackers.
3. Why we process it
- To provide the service you signed up for, including answering diligence questions from your documents.
- To keep the service secure and to keep an audit trail of room access.
- To bill subscriptions and keep the accounting records the law requires.
- To send the emails the service needs: invitations, sign-in codes, password resets and billing notices.
The legal bases are performance of a contract, our legitimate interest in a secure and auditable service, and our legal obligations. We do not send marketing email.
4. Who else processes it
We use these categories of provider to run the service. Each acts on our instructions.
- AI model providers — receive document text per request to answer diligence questions.
- Web search providers — receive a short description of the company, never its documents, to find its competitors.
- A payment processor — holds your payment details and manages the subscription.
- An email delivery provider— sends the service's emails.
Documents, extracted text, the database and the identity service run on infrastructure operated by Figure 4 in Sweden. Some providers are in the United States, and transfers to them rest on the EU standard contractual clauses. Ask us at [email protected] for the current list.
5. Who sees your data
The members of your organisation see what their role allows. In a room, the fund sees what the company has released to it. A syndicate partner sees what the fund has granted. An issued report is a frozen snapshot that anyone with its link can read.
Figure 4 staff do not open rooms except to fix a problem you asked us to fix, or when the law requires it. We do not sell personal data.
6. How long we keep it
- Account and room content: as long as your organisation exists.
- After you ask us to delete your organisation: gone within 30 days, except invoices and accounting records, which Swedish law makes us keep for seven years.
- Server logs: 30 days.
7. Your rights
Under the GDPR you may ask for access to your personal data, correction, deletion, restriction, portability, and you may object to processing based on legitimate interest. Email [email protected]. You may also complain to the Swedish Authority for Privacy Protection (IMY).
For personal data inside another organisation's documents, contact that organisation. We help them answer.
8. Cookies
Despun sets two cookies: a session cookie that keeps you signed in, and a preference cookie that remembers light or dark mode. Both are needed for the site to work. There are no third-party cookies.
9. Changes
We update this policy when our processing changes. The date at the top says when. For a material change we email your organisation's admins before it takes effect. The terms of service govern the rest of the relationship.