Skip to content
Legal

Privacy Policy

How website information is handled.

Effective August 17, 2026. This policy explains what information eidergroup.com collects, how it is used, and the choices you have.

1. Who we are

This website is operated by Eider Group, LLC, a Maine limited liability company ("Eider Group," "we," "our," or "us").

For the purposes of the UK and EU General Data Protection Regulation, Eider Group is the controller of the personal information described in this policy.

2. Scope of this policy

This policy applies to eidergroup.com and to information we receive through it, including through the Start a Venture form.

It does not apply to:

  • websites, products, or services operated by ventures we build, back, or work with, each of which has its own policies;
  • third-party websites we link to; or
  • information you provide to us outside this website, such as in direct correspondence or under a separate written agreement, which is handled under that agreement.

3. Information you provide

We collect the information you choose to give us through the Start a Venture form:

  • your name;
  • your email address;
  • your company or venture name, if you provide one;
  • your role, if you provide one;
  • the stage you are at;
  • the market you are building in;
  • what kind of support you are looking for; and
  • the description of your venture that you write.

We also receive whatever information you include if you contact us directly.

Please do not send us sensitive personal information — such as health information, government identification numbers, payment card details, or information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or sexual orientation. We do not need it and do not ask for it.

4. Job applications

If you apply for a role through the Careers page, we collect your name, email address, the role you applied for, your résumé, and — if you choose to send one — a cover letter and a short message.

We use this only to consider your application, to contact you about it, and to keep a record of who has applied. It is not used for marketing and is not shared outside Eider Group except with professional advisers where genuinely necessary.

Documents you upload are stored separately from the public website, are not published, and are readable only by Eider Group. Please include only what is relevant to your application; there is no need to send identification documents, financial details, or health information at this stage.

We keep applications for as long as reasonably necessary to run the process and to consider you for future roles, and you may ask us to delete yours at any time by contacting privacy@eidergroup.com.

5. Information collected automatically

When you visit this website, our hosting and infrastructure providers automatically record limited technical information as part of delivering and protecting the site, including your IP address, browser type and version, device and operating system, referring page, the pages you request, and the date and time of the request.

This information is used to serve the site, keep it available, diagnose faults, and detect abuse. It is generated by ordinary server and network operation.

We also use Umami, an open-source analytics product that we run on our own infrastructure rather than as a hosted service, to understand in aggregate how the website is being used — how many people visit, which pages they read, and roughly where in the world they are. This is measurement of the website, not of you: it records the page requested, the referring site, and general device and country information, and it reports that back to us only as totals.

Our analytics works without cookies, and without storing anything on your device at all. To tell one visit from another it takes ordinary request information — your IP address and the user agent your browser sends — and converts it into an anonymized hash. That hash is what gets counted; the IP address itself is not retained as part of the measurement. The hash is regenerated daily, so it cannot be used to recognize you tomorrow, and it exists nowhere but our own analytics database. It is not an account, not a profile, and not something we can turn back into your identity.

Umami sets no cookies, assigns no persistent identifier to you, and does not follow you to other websites. It does not build a profile of you, and the data it produces is not used for advertising. Because we host it ourselves, those measurements are not sent to Umami or to any other analytics company.

We may also use heatmaps and anonymous session replay on a small sample of visits, to see where a page confuses people or where a layout fails. Where we do, it records what the page looked like and how it was used — the pages viewed, pointer movement, clicks, and scrolling — as a short, anonymous reconstruction of the session. What you type is not part of it: values entered into form fields are masked in your browser before anything is sent, so text you enter into the venture, careers, or suggestion forms is never captured by a recording. A replay carries no name, email address, or account, only the same daily anonymous hash described above. Like the rest of our analytics, replays are stored on our own infrastructure, are not shared with anyone, and use no cookies and no storage on your device.

Beyond that, this website does not use advertising networks, tracking pixels, or cross-site tracking of any kind, and we do not sell or share what our analytics produces.

6. Cookies and similar technologies

This website does not use advertising, marketing, or cross-site tracking cookies.

Cookies are set only where they are strictly necessary — specifically, an authentication cookie is set for administrators who sign in to the content management system at /admin. If you are an ordinary visitor and do not sign in, that cookie is not set for you.

We do use analytics, as described in section 5, but the product we chose is deliberately cookieless: it stores nothing on your device, reads nothing from it beyond what your browser sends with any ordinary request, and does not track you between visits or across other websites. The same is true of the heatmaps and session replay described in that section — they set no cookies and write nothing to your device either. That is why you are not asked to accept cookies when you arrive.

Most browsers let you block or delete cookies through their settings. Because we do not rely on non-essential cookies, blocking them will not meaningfully affect your use of this website.

If we introduce cookies or other non-essential technologies that are not strictly necessary, we will update this policy and, where required, ask for your consent first.

7. How we use information

We use the information described above to:

  • review and respond to venture inquiries and other messages you send us;
  • evaluate whether there is a fit between your venture and how we work;
  • contact you about your inquiry;
  • operate, maintain, secure, and improve this website;
  • detect, investigate, and prevent fraud, abuse, and security incidents; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use it to build advertising profiles.

We do not use the contents of your venture inquiry to train machine learning or artificial intelligence models.

8. Legal bases for processing

Where the UK or EU GDPR applies, we rely on the following legal bases:

  • Legitimate interests — to respond to inquiries you send us, to operate and secure this website, and to prevent abuse. Our interest is in running a venture studio and communicating with founders who approach us, balanced against your rights.
  • Consent — where we ask for it, such as for any future non-essential cookies or marketing messages. You may withdraw consent at any time.
  • Legal obligation — where we must retain or disclose information to comply with law.
  • Steps prior to entering a contract — where you ask us to consider working with you.

9. How we share information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

We disclose information only as follows:

  • Service providers. To the vendors that host this website, store its database, and store its media, acting on our instructions and bound to protect the information. These are described in the next section.
  • Professional advisers. To our lawyers, accountants, and insurers where reasonably necessary.
  • Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate protections.
  • Legal requirements. Where reasonably necessary to comply with applicable law or legal process, to respond to lawful requests from public authorities, to enforce our agreements, or to protect the rights, property, or safety of Eider Group, our users, or the public.
  • With your direction or consent.

10. Service providers we rely on

This website is delivered using a small number of infrastructure providers:

  • a cloud hosting provider, which serves the website and processes requests;
  • Neon, which hosts the Postgres database in which form submissions and site content are stored;
  • Cloudflare R2, which stores the images and files used on the site.

The analytics product described in section 5, Umami, is open-source software we run on our own infrastructure. It is not a service provider: no analytics company receives the measurements it produces.

Typefaces used on this site are served from our own infrastructure, so visiting the site does not send a request to a third-party font provider.

We review the providers we use and engage them under terms that require appropriate confidentiality and security.

11. International transfers

We are based in the United States and our providers process information in the United States and potentially in other countries where they operate.

If you are located in the United Kingdom, the European Economic Area, or another region with data transfer restrictions, your information may be transferred to a country whose data protection laws differ from those of your jurisdiction. Where required, such transfers are made under an appropriate transfer mechanism, such as the European Commission's standard contractual clauses.

12. Data retention

We keep venture inquiries for as long as reasonably necessary to evaluate and respond to them, to maintain a record of who has approached us and on what basis, and to establish, exercise, or defend legal claims.

Technical logs generated by our hosting and infrastructure providers are retained for a short period as part of ordinary operation and security.

Information may persist in backups, archives, and security records for a reasonable period after deletion from active systems. When we no longer have a legitimate need for information, we delete it or render it no longer identifying.

You may ask us to delete your inquiry, and we will do so unless we are required or permitted by law to retain it.

13. Security

We use reasonable technical and organizational measures appropriate to the limited information this website collects, including encryption in transit, access controls on the content management system, and restricted access to the underlying database and storage.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If you believe you have found a security vulnerability affecting this website, please report it to security@eidergroup.com rather than disclosing it publicly.

14. Your privacy rights

Depending on where you live, you may have some or all of the following rights in relation to your personal information:

  • to know what information we hold about you and to obtain a copy of it;
  • to have inaccurate or incomplete information corrected;
  • to have your information deleted;
  • to restrict or object to how we process it, including objecting to processing based on legitimate interests;
  • to receive your information in a portable, machine-readable format;
  • to withdraw consent where we rely on it, without affecting processing already carried out; and
  • not to be discriminated against for exercising these rights.

To exercise any of these rights, contact privacy@eidergroup.com. We may need to verify your identity before responding, and we will respond within the period required by applicable law.

If you are in the UK or EEA and are not satisfied with our response, you may lodge a complaint with your local supervisory authority.

15. California privacy rights

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you rights to know, delete, correct, and access information about the personal information we collect, and to be free from discrimination for exercising those rights.

In the twelve months preceding the effective date of this policy, the categories of personal information this website collects are identifiers (such as name, email address, and IP address), professional or employment-related information (such as company and role), and internet or network activity information (such as pages requested). These are collected from you directly and through ordinary server operation, and are used and shared for the purposes described in this policy.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not knowingly collect or process sensitive personal information for purposes that would require a right to limit its use.

To exercise your rights, contact privacy@eidergroup.com. You may use an authorized agent, and we may ask for proof of authorization.

16. Other United States privacy rights

Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, among others — may have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling.

We do not conduct targeted advertising, sell personal information, or carry out profiling that produces legal or similarly significant effects.

To exercise your rights, or to appeal a decision we have made about a request, contact privacy@eidergroup.com.

17. Marketing communications

We reply to inquiries you send us. Those replies are not marketing.

If we ever send marketing messages, we will do so only where permitted, every message will include a way to unsubscribe, and we will honor opt-outs promptly. Opting out of marketing does not stop us replying to something you asked us about.

18. Children's privacy

This website is intended for business audiences and is not directed to children under sixteen (16), and we do not knowingly collect personal information from them.

If you believe a child has provided us with personal information, contact privacy@eidergroup.com and we will take reasonable steps to delete it.

19. Changes to this policy

We may update this policy from time to time. The effective date at the top of this page indicates when the current version took effect.

Where changes are material, we will take reasonable steps to bring them to your attention. Your continued use of this website after the effective date constitutes acknowledgment of the updated policy.

20. Contact

Eider Group, LLC, a Maine limited liability company
Maine, United States

Privacy requests: privacy@eidergroup.com
Legal notices: legal@eidergroup.com
Security reports: security@eidergroup.com
Website: eidergroup.com