Effective 11 August 2026. This policy explains what information eidergroup.com collects, how it is used, and the choices you have.
1. Who we are
This website is operated by Eider Group, LLC, a Maine limited liability company ("Eider Group," "we," "our," or "us").
For the purposes of the UK and EU General Data Protection Regulation, Eider Group is the controller of the personal information described in this policy.
2. Scope of this policy
This policy applies to eidergroup.com and to information we receive through it, including through the Start a Venture form.
It does not apply to:
- websites, products, or services operated by ventures we build, back, or work with, each of which has its own policies;
- third-party websites we link to; or
- information you provide to us outside this website, such as in direct correspondence or under a separate written agreement, which is handled under that agreement.
3. Information you provide
We collect the information you choose to give us through the Start a Venture form:
- your name;
- your email address;
- your company or venture name, if you provide one;
- your role, if you provide one;
- the stage you are at;
- the market you are building in;
- what kind of support you are looking for; and
- the description of your venture that you write.
We also receive whatever information you include if you contact us directly.
Please do not send us sensitive personal information — such as health information, government identification numbers, payment card details, or information revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, or sexual orientation. We do not need it and do not ask for it.
4. Job applications
If you apply for a role through the Careers page, we collect your name, email address, the role you applied for, your résumé, and — if you choose to send one — a cover letter and a short message.
We use this only to consider your application, to contact you about it, and to keep a record of who has applied. It is not used for marketing and is not shared outside Eider Group except with professional advisers where genuinely necessary.
Documents you upload are stored separately from the public website, are not published, and are readable only by Eider Group. Please include only what is relevant to your application; there is no need to send identification documents, financial details, or health information at this stage.
We keep applications for as long as reasonably necessary to run the process and to consider you for future roles, and you may ask us to delete yours at any time by contacting privacy@eidergroup.com.
5. Information collected automatically
When you visit this website, our hosting and infrastructure providers automatically record limited technical information as part of delivering and protecting the site, including your IP address, browser type and version, device and operating system, referring page, the pages you request, and the date and time of the request.
This information is used to serve the site, keep it available, diagnose faults, and detect abuse. It is generated by ordinary server and network operation.
As of the effective date of this policy, this website does not use analytics products, advertising networks, tracking pixels, session recording, fingerprinting, or cross-site tracking of any kind.
6. Cookies and similar technologies
This website does not use advertising, marketing, analytics, or cross-site tracking cookies.
Cookies are set only where they are strictly necessary — specifically, an authentication cookie is set for administrators who sign in to the content management system at /admin. If you are an ordinary visitor and do not sign in, that cookie is not set for you.
Most browsers let you block or delete cookies through their settings. Because we do not rely on non-essential cookies, blocking them will not meaningfully affect your use of this website.
If we introduce analytics or other non-essential technologies in future, we will update this policy and, where required, ask for your consent first.
7. How we use information
We use the information described above to:
- review and respond to venture inquiries and other messages you send us;
- evaluate whether there is a fit between your venture and how we work;
- contact you about your inquiry;
- operate, maintain, secure, and improve this website;
- detect, investigate, and prevent fraud, abuse, and security incidents; and
- comply with legal obligations and establish, exercise, or defend legal claims.
We do not use your information for automated decision-making that produces legal or similarly significant effects, and we do not use it to build advertising profiles.
We do not use the contents of your venture inquiry to train machine learning or artificial intelligence models.
8. Legal bases for processing
Where the UK or EU GDPR applies, we rely on the following legal bases:
- Legitimate interests — to respond to inquiries you send us, to operate and secure this website, and to prevent abuse. Our interest is in running a venture studio and communicating with founders who approach us, balanced against your rights.
- Consent — where we ask for it, such as for any future non-essential cookies or marketing messages. You may withdraw consent at any time.
- Legal obligation — where we must retain or disclose information to comply with law.
- Steps prior to entering a contract — where you ask us to consider working with you.
9. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
We disclose information only as follows:
- Service providers. To the vendors that host this website, store its database, and store its media, acting on our instructions and bound to protect the information. These are described in the next section.
- Professional advisers. To our lawyers, accountants, and insurers where reasonably necessary.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganisation, or sale of assets, subject to appropriate protections.
- Legal requirements. Where reasonably necessary to comply with applicable law or legal process, to respond to lawful requests from public authorities, to enforce our agreements, or to protect the rights, property, or safety of Eider Group, our users, or the public.
- With your direction or consent.
10. Service providers we rely on
This website is delivered using a small number of infrastructure providers:
- a cloud hosting provider, which serves the website and processes requests;
- Neon, which hosts the Postgres database in which form submissions and site content are stored; and
- Cloudflare R2, which stores the images and files used on the site.
Typefaces used on this site are served from our own infrastructure, so visiting the site does not send a request to a third-party font provider.
We review the providers we use and engage them under terms that require appropriate confidentiality and security.
11. International transfers
We are based in the United States and our providers process information in the United States and potentially in other countries where they operate.
If you are located in the United Kingdom, the European Economic Area, or another region with data transfer restrictions, your information may be transferred to a country whose data protection laws differ from those of your jurisdiction. Where required, such transfers are made under an appropriate transfer mechanism, such as the European Commission's standard contractual clauses.
12. Data retention
We keep venture inquiries for as long as reasonably necessary to evaluate and respond to them, to maintain a record of who has approached us and on what basis, and to establish, exercise, or defend legal claims.
Technical logs generated by our hosting and infrastructure providers are retained for a short period as part of ordinary operation and security.
Information may persist in backups, archives, and security records for a reasonable period after deletion from active systems. When we no longer have a legitimate need for information, we delete it or render it no longer identifying.
You may ask us to delete your inquiry, and we will do so unless we are required or permitted by law to retain it.
13. Security
We use reasonable technical and organisational measures appropriate to the limited information this website collects, including encryption in transit, access controls on the content management system, and restricted access to the underlying database and storage.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you believe you have found a security vulnerability affecting this website, please report it to security@eidergroup.com rather than disclosing it publicly.
14. Your privacy rights
Depending on where you live, you may have some or all of the following rights in relation to your personal information:
- to know what information we hold about you and to obtain a copy of it;
- to have inaccurate or incomplete information corrected;
- to have your information deleted;
- to restrict or object to how we process it, including objecting to processing based on legitimate interests;
- to receive your information in a portable, machine-readable format;
- to withdraw consent where we rely on it, without affecting processing already carried out; and
- not to be discriminated against for exercising these rights.
To exercise any of these rights, contact privacy@eidergroup.com. We may need to verify your identity before responding, and we will respond within the period required by applicable law.
If you are in the UK or EEA and are not satisfied with our response, you may lodge a complaint with your local supervisory authority.
15. California privacy rights
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you rights to know, delete, correct, and access information about the personal information we collect, and to be free from discrimination for exercising those rights.
In the twelve months preceding the effective date of this policy, the categories of personal information this website collects are identifiers (such as name, email address, and IP address), professional or employment-related information (such as company and role), and internet or network activity information (such as pages requested). These are collected from you directly and through ordinary server operation, and are used and shared for the purposes described in this policy.
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising. We do not knowingly collect or process sensitive personal information for purposes that would require a right to limit its use.
To exercise your rights, contact privacy@eidergroup.com. You may use an authorised agent, and we may ask for proof of authorisation.
16. Other United States privacy rights
Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana, among others — may have similar rights to access, correct, delete, and obtain a copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling.
We do not conduct targeted advertising, sell personal information, or carry out profiling that produces legal or similarly significant effects.
To exercise your rights, or to appeal a decision we have made about a request, contact privacy@eidergroup.com.
17. Marketing communications
We reply to inquiries you send us. Those replies are not marketing.
If we ever send marketing messages, we will do so only where permitted, every message will include a way to unsubscribe, and we will honour opt-outs promptly. Opting out of marketing does not stop us replying to something you asked us about.
18. Children's privacy
This website is intended for business audiences and is not directed to children under sixteen (16), and we do not knowingly collect personal information from them.
If you believe a child has provided us with personal information, contact privacy@eidergroup.com and we will take reasonable steps to delete it.
19. Changes to this policy
We may update this policy from time to time. The effective date at the top of this page indicates when the current version took effect.
Where changes are material, we will take reasonable steps to bring them to your attention. Your continued use of this website after the effective date constitutes acknowledgement of the updated policy.
20. Contact
Eider Group, LLC, a Maine limited liability company
Maine, United States
Privacy requests: privacy@eidergroup.com
Legal notices: legal@eidergroup.com
Security reports: security@eidergroup.com
Website: eidergroup.com