Legal

Privacy Policy

Last updated 26 August 2026

Who we are

noclue Ltd (“noclue”, “we”, “us”) — a company registered in England and Wales (company no. [—], registered office [—]) — runs week-long, invite-only expeditions for founders and the member network around them. We are the controller of your personal data.

Because we operate from the UK and welcome founders based in the EU/EEA, both the UK GDPR and the EU GDPRapply to how we handle your data, and we comply with both. Our lead supervisory authority is the UK Information Commissioner’s Office (ICO); if you’re in the EU/EEA you also have rights before your local authority (see Your rights).

Questions about privacy, or to reach our EU representative: privacy@noclue.vc.

What we collect

  • Account data: your name, email, and password (stored hashed; we never see it in plain text).
  • Application data: the answers you give when applying (startup, links, what you’re building, and similar).
  • Profile & network data: your founder profile — bio, startup, stage, sector, location, links, and your “asks” and “offers”. This is shown to other members in the directory according to the visibility you choose.
  • Scheduling data: if you book a selection call, the booking is handled by Calendly and we receive the time and a video-call link.
  • Payment data: handled by Stripe. We never see or store your full card details; we keep a payment reference, amount, and status.
  • Agreement and e-signature data: the agreement version, signing status and timestamps, signature evidence, completed PDF, audit trail, and signing certificate needed to prove and administer the cohort confidentiality agreement.
  • Trip & safety information: if you’re confirmed, we collect travel details and an intake form that may include dietary needs, allergies, relevant medical information, accessibility needs, and an emergency contact. Some of this is special-category data (e.g. health), processed only with your explicit consent and only to run the expedition safely.
  • Member activity: intro requests, nominations you make, and resources you post.
  • Waitlist data: your name and email, if you join the waitlist.
  • Technical and analytics data: basic logs and strictly necessary cookies to keep you signed in and operate the site. We use Vercel Web Analytics to collect anonymous, aggregate page views, short-lived visitor counts, and limited interactions such as application steps, signups, waitlist joins, nominations, checkout starts, purchases, and outbound-link clicks. It uses no analytics cookies or persistent identifiers. Query strings and private account, member, and admin pages are excluded, and we do not send form answers, names, email addresses, payment references, or transaction IDs to analytics.

Why we use it & our legal bases

We rely on the equivalent bases under both the UK GDPR and the EU GDPR:

  • To run the programme and your place in the network — review applications, take and refund payments, schedule calls, operate the cohort and the network. Basis: Article 6(1)(b), performance of a contract.
  • To keep the expedition safe — dietary, medical, accessibility and emergency-contact information. Basis: Article 9(2)(a), your explicit consent, which you can withdraw at any time. If you choose not to share safety-critical information, you may not be able to take part in some activities.
  • To communicate with you — about your application, place, and logistics. Basis: contract, and our legitimate interests in running the programme well.
  • To protect confidential ideas and administer signed agreements — issue and retain confidentiality agreements, control private access, and establish, exercise or defend legal claims. Basis: Article 6(1)(b), performance of a contract, and Article 6(1)(f), our and participants’ legitimate interests.
  • To operate, secure and improve the service. Basis: Article 6(1)(f), legitimate interests.
  • To understand aggregate use of our public pages. Vercel Web Analytics records anonymous page views and short-lived visitor counts without cookies, cross-site tracking, or persistent identifiers. Basis: Article 6(1)(f), our legitimate interest in understanding whether and how the public site is used.
  • To meet legal obligations — e.g. retaining payment records for tax and accounting. Basis: Article 6(1)(c), legal obligation.

No automated decisions.Applications are reviewed by people. We don’t make decisions about you by automated means alone.

We do not sell your personal data, and we don’t use it for advertising.

Who we share it with

Other members. The parts of your profile you choose to make visible are shown to other members in the directory. You control this in your profile settings, and can set yourself to cohort-only or hidden.

Processors that run the service on our behalf: Stripe (payments), Calendly (call scheduling), our self-hosted Documenso service (electronic signatures), Resend (email), Railway (database hosting), and Vercel (application hosting and anonymous aggregate web analytics). Each processes your data only on our instructions and only as needed to provide its service, under a data-processing agreement with us.

We may also disclose data where we’re legally required to, or to establish or defend legal claims.

International transfers

Some of our processors handle data outside the UK and the EU/EEA (for example, in the US). Where that happens, we put appropriate safeguards in place:

  • for transfers from the UK, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses;
  • for transfers from the EU/EEA, the EU Standard Contractual Clauses, or reliance on the EU–US Data Privacy Framework where the processor is certified.

You can ask us for more detail on the safeguards that apply to a particular transfer.

Our EU representative

As a UK-based controller offering places to founders in the EU/EEA, we have appointed a representative in the EU under Article 27 of the EU GDPR. You can contact them for any matter relating to our processing of EU/EEA residents’ data at [EU representative name & contact — to be appointed].

Retention

We keep account, application, and profile data while your account is active, or as long as we need it to run the programme and network, and then delete or anonymise it — except where we must keep records longer. Payment and accounting records are retained for the period required by law (at least 6 years in the UK; longer where another applicable rule requires it). Safety and intake information is deleted after the relevant expedition. You can ask us to delete your data at any time (see below). Executed confidentiality agreements and their audit evidence are normally retained for six years after the relevant cohort or relationship ends, and longer only where needed for an active dispute or legal obligation.

Your rights

Under the UK GDPR and, where it applies, the EU GDPR, you can access, correct, export, or delete your personal data, object to or restrict certain processing, and withdraw any consent you’ve given (without affecting processing already carried out). Email privacy@noclue.vc and we’ll respond within the time the law allows (normally one month).

You also have the right to complain to a data protection authority — in the UK, the Information Commissioner’s Office (ico.org.uk); in the EU/EEA, your local supervisory authority.

A note on emergency contacts

If you give us an emergency contact, please make sure that person is happy for you to share their details with us for that purpose.

Cookies

We use strictly necessary cookies to keep you signed in and operate the site. Vercel Web Analytics measures aggregate use of public pages without cookies or browser storage. It does not create a persistent user profile; its temporary visitor identifier is discarded after 24 hours. We remove query strings and do not measure private account, member, or admin pages with it.

Changes

We may update this policy as the service evolves. We’ll revise the date above and, for material changes, let members know directly.

← Back to noclue.vc