Privacy Policy
Last updated 17 July 2026
This policy explains how UpCapital Global FZCO (Dubai Silicon Oasis, Dubai, United Arab Emirates), operator of StartedUp (startedup.io)(“StartedUp”, “we”), handles personal data. We process personal data in accordance with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the “PDPL”).
1. What we collect
- Account & subscription: your email, name, preferences and — if you set one — a password, which we store only as a salted cryptographic hash (we can never read it and it is never written to logs).
- Sign-in & sessions: session identifiers (stored hashed), sign-in link tokens (stored hashed, valid 15 minutes, single-use) and the browser user-agent of active sessions. Expired sessions and tokens are deleted automatically.
- Contract workspace: if your organisation uses the contract workspace, the documents you upload, the terms extracted from them, workspace membership records, and an append-only audit log of privileged actions (who approved, corrected, deleted or invited — kept for security and legal accountability).
- Introduction requests: your name, email and the enquiry details you submit when you ask to be introduced to a partner.
- Partners: business and contact details, and electronic-signature metadata (name, title, timestamp, IP, device) when signing an agreement.
- Usage: searches and interactions, used in aggregate to improve the Service.
2. How we use it
- To provide the Service and respond to your requests.
- To make an introduction to a partner — only with your explicit consent, and only sharing the details needed for that introduction.
- To send updates you have asked for (you can unsubscribe any time).
- To operate the referral program (lead records, statements, audits).
3. Lawful basis & consent
We rely on your consent for introductions and marketing, and on our legitimate interest in operating and improving the Service. You can withdraw consent at any time.
4. Sharing
We share your details with a partner only when you ask for an introduction and consent to it. We use trusted processors to run the Service — including our database host, email provider and, for the contract workspace’s AI extraction, Anthropic (which does not train on this data). Some processors store data outside the UAE (currently in the United States) under contractual safeguards, as permitted by PDPL Articles 22–23. We do not sell your personal data. Contract workspace content is visible only to approved members of that workspace.
5. Your rights
Under the PDPL you may request access to, correction or deletion of your personal data, object to or restrict processing, and withdraw consent. Account holders can edit preferences or delete their account in account settings — deletion removes your profile, sessions, sign-in tokens and workspace memberships. Audit-log entries naming you as an actor are retained on a security and legal-accountability basis. Workspace admins can hard- delete a contract, which also removes its extracted data, derived obligations, drafts and the stored original file. For anything else, email us and we will action it.
6. Retention & security
We keep personal data only as long as needed for the purposes above or as required by law (referral records may be retained for up to two years for audit). Security measures include: TLS for all traffic, passwords hashed with scrypt and unique salts, session and sign-in tokens stored only as SHA-256 digests, changing your password revokes all other active sessions, rate-limiting on sign-in and registration, and access to contract workspaces restricted by role with an append-only audit trail.
7. Contact
Data requests or questions: ceo@theupcapital.com.