Privacy policy
Effective date: 20 April 2026.
Introduction
TechAngels ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our investment platform and related services. We operate under Romanian jurisdiction and comply with applicable data protection law. By using our website, you consent to the data practices described in this policy.
Information we collect about our members and why
We collect information that identifies you, including:
- Name, email address, telephone number, postal address, social media links, due diligence answers and referral: to identify you, communicate with you and ask members for feedback; social media links allow people to connect with you, unless you disagree.
- IP address, device ID and browser information: to access the website and the platform.
- Payment and billing information: for processing membership-related transactions.
- Investment history, preferences, financial information, expertise, bio, photo and accreditation status: if you are accepted, your photo is displayed on our website, unless you disagree.
- Activity data, including content uploaded, startups viewed and interacted with, members you communicate with, and usage patterns of our internal infrastructure.
- Information from third-party sources to verify identity and ensure accuracy.
- Professional background and investment experience.
Information we collect from startup applicants
On the legal basis of the legitimate interest of TechAngels Association to accept new startups for pitches, we process:
- Name and surname: to identify you.
- Email and phone number: to be able to communicate with you.
- The startup application form questionnaire: so members can understand your company, solutions and the business issues they solve.
- Key team members: the names and details of the key people in your organization. You are the data controller for the personal data you enter in these fields.
- Startup documents that might contain personal data: pitch deck, financials, media files, photos. If selected, you present these in a Zoom call to interested members; you are the data controller for the personal data in these documents.
We do not recommend including sensitive or personally identifiable information beyond what is necessary.
How we use your information
- Provide the requested services and facilitate connections between entrepreneurs and investors.
- Verify identity and accreditation status for investment compliance.
- Process payments and manage billing.
- Send communications about investment opportunities and platform updates.
- Analyze usage patterns and improve our services.
- Customize marketing and investment analyses (e.g. publishing reports and aggregated information on startups and investments made by the organisation and its members).
- Create aggregated statistical data for business insights.
- Detect fraud and address security issues.
- Comply with legal obligations and regulatory requirements.
- Facilitate startup investment (e.g. by connecting members with startups).
Data sharing and third parties
We share personal information with:
- Service providers: payment processors, hosting providers, customer support and investment-related platforms: see the subprocessors list.
- Business partners: verified entrepreneurs and investors on our platform, with appropriate consent.
- Legal compliance: in connection with legal process, court orders or regulatory requirements.
- Fraud prevention: to detect and prevent fraudulent activities.
- Emergency situations: to protect the rights, safety and security of users and the public.
Your rights (GDPR)
- Access your personal data and receive information about our processing.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data (right to be forgotten).
- Object to processing of your personal data.
- Request restriction of processing in certain circumstances.
- Data portability: receive your data in a structured format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local supervisory authority.
California residents additionally have the right to know what personal information is collected, request its deletion, opt out of the sale of personal information, and not be discriminated against for exercising their privacy rights. We do not sell personal information without explicit consent.
To exercise these rights, contact us at [email protected].
Payment information
- We collect billing information including name, address and payment method details.
- Payment processing is handled by third-party processors who maintain PCI DSS compliance.
- We do not store complete card numbers or sensitive payment data on our servers.
- Payment information is used solely for processing transactions and fraud prevention.
- Billing records are retained for accounting, tax and legal compliance purposes.
Data security
We implement technical and organizational measures including:
- Encryption of data in transit and at rest using industry-standard protocols.
- Access controls and authentication systems that limit data access.
- Regular security assessments and vulnerability testing.
- Training on data protection and security practices.
- Incident response procedures for potential data breaches.
No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
International data transfers
Personal information may be transferred to and processed in countries outside Romania and the European Union. We implement appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission, adequacy decisions where available, other lawful transfer mechanisms, and due diligence assessments of data protection standards in destination countries.
Data retention
We retain personal information for as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes and maintain records for investment compliance. Specifically:
- Member application data is retained for three years if you do not become a member, based on our legitimate interest in keeping a history of applications.
- Member data, including membership fee records, is archived for five years after your last interaction with TechAngels Association.
- Startup pitch data is retained for three years, based on our legitimate interest in keeping a history of applications.
- Online activity data is kept for the lifetime of the cookies or until you delete them.
Children's privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from minors; if we learn that we have, we will delete it.
Changes to this policy
We may update this Privacy Policy periodically. We will post the updated policy on this page with a new effective date and send email notifications for significant changes. Continued use of our services after changes take effect constitutes acceptance.
Contact
TechAngels · [email protected] · Jurisdiction: Romania. You can also contact the National Supervisory Authority for Personal Data Processing at dataprotection.ro and file a complaint with them. This Privacy Policy is governed by Romanian law and complies with the GDPR and other applicable data protection regulations.
