Hectofy — Privacy Policy & Data Protection Notice
Effective Date: August 12, 2026
Last Updated: August 2026
1. Introduction & Overview
Hectofy Inc. ("Hectofy", "we", "our") respects the privacy of our VC General Partners, fund managers, and portfolio company founders. This Privacy Policy explains how we collect, use, store, and protect information when you visit hectofy.com or use our portfolio intelligence platform.
2. Information We Collect
- Account & Registration Data: User email address, fund name, partner name, and authentication credentials (e.g. Google OAuth tokens).
- Portfolio Company Metrics: Startup website domain, company name, aggregated headcount growth, web traffic estimates, open-source GitHub commit velocity, and authorized read-only financial totals (ARR, cash burn, runway months).
- Automatically Collected Technical Data: IP address, browser type, login timestamps, and session logs (stored strictly for security auditing in
demo_leads).
3. We NEVER Sell Your Personal or Fund Data
- Zero Data Sale: Hectofy does NOT sell, rent, or trade customer personal information, portfolio financial ledgers, or LP reports to third parties, data brokers, or advertising networks under any circumstances.
- CCPA / CPRA Compliance: Pursuant to the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), California residents and funds have the right to request access to, deletion of, or opt-out of data disclosures.
4. CAN-SPAM Act Compliance (Founder Invitation Outreach)
When General Partners dispatch Magic Authorization Invites to portfolio founders via Hectofy:
1. Accurate Sender Info: All emails explicitly display the verified GP sender identity and Reply-To address (gp@horizon.vc).
2. Opt-Out & Unsubscribe: Every automated founder invite email contains a 1-click Unsubscribe link and physical mailing address.
3. No Misleading Subject Lines: Subject lines accurately reflect the nature of the portfolio verification request.
5. Third-Party Integrations & Data Processing
Hectofy connects to third-party data providers solely to provide contracted portfolio analytics: * Public APIs: GitHub REST API, SimilarWeb, PyPI, Google News RSS. * Permissioned OAuth Feeds: Plaid, QuickBooks Online, Gusto (read-only metadata scope). * AI Report Generation: Google Gemini 3.5 Pro API (processed via ephemeral zero-retention enterprise API endpoints).
6. Data Security & Storage
- Encryption: All data in transit is encrypted via TLS 1.3. All stored data is encrypted at rest using AES-256.
- Per-Fund Tenant Isolation: Multi-tenant database boundary checks enforce strict fund-level data segregation.
- Zero Default Support Access: Hectofy employees have zero default access to customer fund ledgers.
7. Children's Privacy Notice (COPPA)
Hectofy is strictly a B2B financial software platform intended for business professionals aged 18 and older. We do not knowingly collect personal information from children under 13.
8. Data Retention & Deletion Rights
Subscribers have the right to request a complete export of their fund data or permanent account erasure. Upon written request to privacy@hectofy.com, all fund database records and access tokens will be permanently purged within 30 days.
9. Contact Our Data Protection Team
For privacy or compliance inquiries: privacy@hectofy.com | Hectofy (Registered entity address details will be updated upon final incorporation).