Privacy PolicyFailup Ventures
Privacy Policy
This policy explains how Failup Ventures Management Oy and its US subsidiary Failup Management Advisory Inc. (together “Failup”, “we”, “us”) collect and use personal data, and what rights you have over that data. It applies to this website, to personal data we receive when you contact us, send us a pitch or invest in a fund we manage, and to personal data about founders, key personnel and other people we research or assess as part of our investment activity.
We process personal data in accordance with the EU General Data Protection Regulation (2016/679) (“GDPR”) and the Finnish Data Protection Act (1050/2018).
Controller
Failup Ventures Management Oy Business ID: 3300453-4 c/o Vencubator, Katariinankatu 1, 00170 Helsinki, Finland
Failup Management Advisory Inc. Delaware file number: 7578652 San Francisco, California, United States
Each company is the controller of the personal data it processes. Failup Management Advisory Inc. is a wholly owned subsidiary of Failup Ventures Management Oy; where it processes personal data of people in the EU, this policy applies to that processing as well.
Failup Ventures Management Oy is also the controller of personal data processed in managing the funds for which it is the registered alternative investment fund manager (AIFM), currently Failup Fund I Ky (Business ID 3363774-5) and Failup Fund II Ky (Business ID 3637695-8).
Privacy enquiries:
Personal data we process
Website connection data. When you visit failup.com, your browser sends technical information to our hosting and content delivery providers to load the website and its assets. This includes your IP address, the pages and files requested, and browser request headers. This information is used to deliver and secure the website.
Contact and pitch data. If you email us or send us materials about a company, we process the names, contact details, professional background and company information contained in that correspondence and in any deck or data room you share with us.
Investor data. If you are, or are considering becoming, an investor in a fund we manage, we process identification and contact details, tax residency, bank details, and the identity and ownership information we are required to collect to meet our anti-money-laundering obligations. Providing that information is a legal requirement under the Act on Preventing Money Laundering and Terrorist Financing (444/2017): without it we cannot admit you to a fund. Customer due diligence data may also be used to prevent, detect and investigate money laundering, terrorist financing and the offences behind them.
Portfolio and diligence data. During diligence and for the life of an investment we process information about founders, key personnel and shareholders of companies we evaluate or hold, such as their names, roles, contact details, professional background, shareholdings and the results of reference checks.
Where the data comes from
Most personal data comes from you directly. Technical connection data is sent automatically when you use this website. We also receive personal data from others: from companies about their founders, key personnel and shareholders; from co-investors and people who introduce companies to us; and from investors about their representatives and beneficial owners. We may also obtain information from public sources such as company registers, professional networks, company websites and news coverage, and from commercial company databases.
Why we process it, and on what legal basis
Legitimate interests (GDPR Article 6(1)(f)). To operate, secure and maintain this website; to evaluate investment opportunities; to manage our portfolio; and to communicate with founders, co-investors and investors. We balance these interests against your rights, and you may object as described below.
Performance of a contract (Article 6(1)(b)). Where you are yourself a party to the contract, for example as an individual investor in one of our funds or as a party to an investment or shareholders’ agreement: to administer subscriptions, capital calls, distributions and reporting, and to perform our obligations under that agreement. Where the contract is with a company or other entity you represent or own, we rely instead on our legitimate interests in performing that contract.
Legal obligation (Article 6(1)(c)). To meet customer due diligence, record-keeping and reporting duties under the Finnish Act on Preventing Money Laundering and Terrorist Financing (444/2017), the Act on Alternative Investment Fund Managers (162/2014), and applicable tax and accounting law.
Consent (Article 6(1)(a)). Where consent is required, for example for marketing communications. You may withdraw consent at any time; withdrawal does not affect processing carried out beforehand.
Analytics and cookies
The public pages of this website do not include visitor analytics, session recording or advertising trackers, and do not set analytics or advertising cookies.
Your browser still connects to our hosting and content delivery providers to load pages, images and other assets, as described under “Website connection data” above.
We do not use advertising networks, and we do not sell personal data.
Who we share data with
We share personal data only where necessary, with: our US subsidiary, Failup Management Advisory Inc.; our hosting and content delivery providers; our email, productivity, document-signing and data-room providers; our outsourced back-office and accounting provider and the auditors of the funds we manage; banks; legal, tax and compliance advisers; and co-investors where relevant to a transaction.
We also disclose personal data to authorities where we are legally required to do so, including supervisory, tax and anti-money-laundering authorities and the Finnish Patent and Registration Office.
Service providers that process personal data on our behalf do so as processors, on our instructions and under data processing terms.
Transfers outside the EU/EEA
We operate in Finland and, through Failup Management Advisory Inc., in the United States. Some of our service providers are also established outside the EU/EEA, and this website is served from hosting infrastructure in the United States. Where personal data is transferred outside the EU/EEA, we rely on an adequacy decision of the European Commission or on the European Commission’s Standard Contractual Clauses, together with any supplementary measures required.
You can ask us for a copy of the safeguards we rely on, or for more information about the service providers we use, at jesse@failup.com.
How long we keep it
We retain personal data for as long as needed for the purposes described above, subject to applicable legal retention requirements.
Website connection data is kept in our hosting providers’ server logs for a short period for security and troubleshooting, and then deleted.
Material relating to companies we did not invest in is deleted when it is no longer relevant to our activity, and earlier on request.
Customer due diligence records are retained for five years after the end of the relationship, as required by anti-money-laundering law. Accounting records are retained for the periods set by the Finnish Accounting Act (1336/1997): ten years for books and financial statements and six years for vouchers and business correspondence. Contractual records are retained for the limitation periods that apply to them.
Security
We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit, and restricting access to personal data to those who need it for their role.
Your rights
Under the GDPR you have the right to:
— obtain confirmation of whether we process personal data about you, and a copy of it;
— have inaccurate or incomplete data corrected;
— have data erased where there is no longer a lawful reason for us to keep it (data we must keep by law, such as anti-money-laundering records, is deleted when the statutory period ends);
— ask us to restrict processing, for example while a dispute about accuracy or our legitimate interests is resolved, or where you need the data kept for a legal claim;
— receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
— object to processing based on our legitimate interests; and
— withdraw consent where processing is based on consent.
You can also object at any time to the use of your personal data for direct marketing, and we will then stop using it for that purpose.
To exercise any of these rights, contact jesse@failup.com. We may need to verify your identity before we act on a request. We respond within one month, which we may extend by two further months for complex requests, and we will tell you if we do.
If you believe we have processed your personal data unlawfully, you have the right to lodge a complaint with the Office of the Data Protection Ombudsman in Finland (Tietosuojavaltuutetun toimisto, tietosuoja.fi), or with the supervisory authority in the EU/EEA country where you live or work or where the alleged infringement took place.
Changes to this policy
We may update this policy as our activities or the law change. The date below shows when the current version took effect. Material changes will be signalled on this page.
Effective date: 23 September 2026