EPIC
Alliance

01 — Data Controller

Who we are

EPIC Alliance S.à r.l., a private limited liability company (société à responsabilité limitée) incorporated in Luxembourg on 13 July 2026, with its registered office at 26 rue Goethe, L-1637 Luxembourg, Grand Duchy of Luxembourg (RCS Luxembourg B [number pending]), provides organisational assessment and investor visibility tools to early-stage ventures through two products: EPIC Compass and EPIC Connect.

EPIC Alliance S.à r.l. is the data controller for all personal data collected through its services, within the meaning of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Luxembourg law.

Contact:
EPIC Alliance S.à r.l.
26 rue Goethe, L-1637 Luxembourg
team@epic-alliance.io
No Data Protection Officer is currently required or appointed. Privacy enquiries should be directed to the address above.

02 — Data Categories

Data we collect

We collect only the data necessary to provide our services. The table below sets out each category, why we collect it, and the legal basis under GDPR.

Data Service Purpose Legal basis
Email address Compass & Connect Account creation, magic link authentication, delivery of assessment results Contract
Art. 6(1)(b) — necessary to provide the service
Phone number Compass only Optional contact detail stored in organisation profile Consent
Art. 6(1)(a) — collected only if voluntarily provided
Assessment results & EPIC scores Compass Generation of the stage-calibrated leadership report (51 KPIs across 4 pillars) Contract
Art. 6(1)(b) — core service delivery
Organisation profile (investor-visible) Connect Visibility to vetted investors when the organisation explicitly activates this feature Contract
Art. 6(1)(b) — necessary to perform the investor-visibility subscription you activate
Payment & subscription reference Connect Managing the paid investor-visibility subscription (handled by Stripe — we never see your card details) Contract
Art. 6(1)(b) — necessary to operate the subscription
Benchmark consent status Compass (email gate) Recording opt-in to the anonymised benchmark and model-validation programme Consent
Art. 6(1)(a) — separate, unchecked opt-in checkbox
Anonymised results, internal validation Compass Internal validation of the scientific properties of the EPIC model (see Section 06) Legitimate interest
Art. 6(1)(f) — you may object at any time
What we do not collect: We never see or store your payment card details — payment is handled entirely by Stripe, and we retain only a customer reference and your subscription status. We do not collect government-issued identifiers, special category data (Article 9 GDPR), or any data from minors. We do not use behavioural tracking, analytics pixels, or advertising identifiers.

03 — Sub-Processors

Our data processors

We share your data only with the service providers listed below, each bound by a Data Processing Agreement (DPA) and appropriate transfer safeguards under Chapter V GDPR.

SB

Supabase Inc.

Database · Authentication · Magic link emails

Your data is stored at rest in the EU (Paris region). Supabase Inc. is a US-incorporated company; access by its US staff is governed by its Data Processing Agreement and the EU Standard Contractual Clauses (SCCs). Your stored data itself remains in the EU.

Database URL: ryuwkgonpzjbqxvaldkz.supabase.co

NL

Netlify Inc.

Hosting · Content Delivery Network (CDN)

EPIC Alliance websites are hosted on Netlify, a US-based provider certified under the EU–US Data Privacy Framework (with SCCs as a fallback) and bound by a Data Processing Agreement. Netlify serves static files and processes only your IP address and browser metadata transiently to deliver content; it does not process your assessment data.

Deployment: snazzy-creponne-661dad.netlify.app

BR

Brevo (Sendinblue SAS)

Email delivery · SMTP relay

All transactional emails sent by EPIC Alliance — including magic links, account confirmation emails, and password-related communications — are routed through Brevo's SMTP relay (smtp-relay.brevo.com). Brevo acts as a data processor on our behalf and does not use your email address for its own marketing purposes. Brevo (Sendinblue SAS) is a French company headquartered in Paris; your data remains within the EU under GDPR. The domain epic-alliance.io is authenticated with Brevo via DKIM and SPF.

Sender address: EPIC Alliance <hello@epic-alliance.io>

ST

Stripe

Payment processing · Connect subscription

Stripe is a US-based provider certified under the EU–US Data Privacy Framework (with SCCs as a fallback) and bound by a Data Processing Agreement. Stripe collects and holds your card data directly, within its own PCI scope — we receive only a customer reference and your subscription status, never your card details.

AN

Anthropic

Artificial intelligence · EPIC Coach & EPIC Analyst

Anthropic is US-based. Transfers rely on the Standard Contractual Clauses in Anthropic's Data Processing Agreement, complemented by Zero-Data-Retention mode: prompts and outputs are not retained beyond the API call. Anthropic does not use API data to train its models. Content you provide to the Coach or the Analyst is processed solely to generate the response.

We do not use third-party email marketing platforms. All transactional emails are triggered by Supabase Auth and delivered via Brevo SMTP. We will update this list if we engage additional processors and will notify you as required by GDPR.

04 — Data Retention

How long we keep your data

Data Retention period
Email address 3 years from the date of last activity, or until account deletion is requested — whichever is earlier
Phone number 3 years from the date of last activity, or until account deletion is requested — whichever is earlier
Assessment results & EPIC scores Retained while the account is active. Deleted promptly upon a verified erasure request (see Section 07)
Organisation profile (investor-visible) Retained while the investor-visibility subscription and the account are active. Immediately removed from investor view upon cancellation; deleted from our systems on account deletion
Payment & subscription reference Retained while the subscription is active, and thereafter for as long as required by applicable accounting and tax law
Benchmark consent record Retained for as long as anonymised data derived from the relevant assessment is used in benchmark outputs. The record is deleted no later than 30 days after the associated assessment data is fully removed from benchmark datasets. Consent may be withdrawn at any time — see Section 10
Internal validation data Raw, identifiable records are excluded from all future processing upon objection or account deletion. Anonymised and aggregated results already produced — which no longer identify any person — fall outside the GDPR and are retained

05 — Sharing & Disclosure

Who we share your data with

Investors (EPIC Connect)

Your organisation profile and assessment scores are never visible to investors by default. Visibility is a paid, opt-in subscription that is off by default and starts only when you activate it yourself. Only organisations with an active investor-visibility subscription appear in the investor discovery interface. You may cancel at any time from your account; you then disappear from the investor interface immediately.

Benchmark reports

EPIC Alliance intends to produce and sell aggregated benchmark reports. These reports use only anonymised and aggregated data from organisations that have given separate, explicit consent for this purpose (see Section 10). No individual organisation is ever identifiable in any published benchmark output. Data from organisations that have not given benchmark consent is never included.

AI processing

When you use EPIC Coach or EPIC Analyst, the relevant context is processed by Anthropic as our sub-processor, under the safeguards described in Section 03. It is not used to train any model and is not retained beyond the request.

Legal obligations

We may disclose personal data if required to do so by applicable law, court order, or regulatory authority. We will notify you of any such disclosure to the extent permitted by law.

We do not sell, rent, or trade personal data to any third party for their own marketing or commercial purposes. Ever.

06 — Model Validation

Internal validation of the EPIC model

Your individual assessment records — which identify your organisation — are processed internally to validate the reliability of the EPIC model. The outputs of this work are anonymised, aggregated statistics (for example reliability coefficients) in which no individual organisation or person is identifiable. Those outputs may appear in validity documentation that we may publish or share. Your individual records are never disclosed to any third party.

Legal basis: Legitimate interest
Art. 6(1)(f) — our legitimate interest in ensuring the validity of our own instrument, as recognised for scientific research.

Your right to object: you can object to this processing at any time by emailing us at team@epic-alliance.io. We will apply your objection without any detriment to your use of the service. Your objection takes effect for the future: your records are removed from all subsequent validation work, while aggregate statistics already produced are not recomputed — they no longer identify you.

07 — GDPR Rights

Your rights

Under GDPR, you have the following rights in relation to your personal data. All requests should be sent to team@epic-alliance.io. We will respond within 30 days.

Right to lodge a complaint

If you believe your data has been processed unlawfully or your rights have not been respected, you have the right to lodge a complaint with the Luxembourg supervisory authority:

Commission Nationale pour la Protection des Données (CNPD)
www.cnpd.lu
15, Boulevard du Jazz · L-4370 Belvaux · Luxembourg

We encourage you to contact us first at team@epic-alliance.io so we can resolve any concern directly and promptly.

08 — International Transfers

International transfers

EPIC Alliance is established in Luxembourg and processes personal data under the GDPR. Your stored data resides in the EU (Supabase, Paris region). Where a sub-processor is located outside the EEA, the transfer is protected by an appropriate Chapter V mechanism:

  • EU–US Data Privacy Framework — Stripe and Netlify (with SCCs as a fallback).
  • EU Standard Contractual Clauses, complemented by Zero-Data-Retention — Anthropic.
  • Data stored at rest in the EU, with SCCs covering US staff access — Supabase.

A Data Processing Agreement is in place with each sub-processor. Users located outside the EEA acknowledge that their personal data is processed under the GDPR and Luxembourg law, which may differ from the data protection laws of their country of residence.

California residents — CCPA notice

We do not sell personal information. The rights of access, deletion, and portability described in Section 07 of this policy are available to California residents on an equivalent basis. To exercise any of these rights, contact team@epic-alliance.io.

09 — Cookies

Cookies and local storage

EPIC Alliance uses session cookies only, set automatically by Supabase Auth to maintain your authenticated session. These cookies are strictly necessary for the service to function and do not require your consent under the ePrivacy Directive.

We do not use:

  • Analytics or tracking cookies (no Google Analytics, Hotjar, Mixpanel, etc.)
  • Advertising or retargeting cookies
  • Third-party social media cookies
  • Persistent fingerprinting technologies

We also use browser localStorage to store data locally on your device during and after the assessment flow. This is persistent browser-local storage — it is not a cookie, not transmitted to third parties, and not used for tracking. The following data may be stored in localStorage until you clear your browser storage or complete the email gate flow (at which point scores are cleared):

  • Email address
  • Phone number (if provided)
  • Name and founder name
  • Organisation / company name
  • City, country, sector
  • Pillar scores (E, P, I, C), assessment answers, stage index
  • Opt-in status and assessment progress flags

None of this data is shared with advertisers, analytics providers, or any third party. It is used solely to carry your progress through the assessment flow across pages.

If we introduce analytics or any non-essential cookies in the future, we will update this policy and implement a consent mechanism before activation.

10 — Commercial Use of Data

Benchmark programme

EPIC Alliance intends to produce and sell aggregated benchmark reports providing market-level intelligence on organisational maturity across the EPIC ecosystem. These reports are a separate commercial activity from the EPIC Compass assessment service.

How it works:

  • Participation in the benchmark programme is entirely voluntary.
  • Consent is collected via a separate, unchecked opt-in checkbox at the Compass email gate — it is never bundled with acceptance of Terms or this Privacy Policy (Article 7(4) GDPR).
  • The legal basis for this processing is consent (Article 6(1)(a) GDPR).
  • Only data from consenting organisations is included in benchmark datasets.
  • All benchmark outputs are fully anonymised and aggregated. No individual organisation, score, or profile is identifiable in any published report.
  • Declining benchmark consent has no impact on access to your EPIC Compass report or any other feature.

Withdrawing consent: You may withdraw your benchmark consent at any time by contacting team@epic-alliance.io. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Where withdrawal is received after anonymised data has already been incorporated into a published aggregate report, removal from that specific published output may not be technically possible — however, your data will be excluded from all future benchmark processing.

11 — Policy Updates

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or service features. When we make material changes, we will notify you by email at the address associated with your account at least 14 days before the changes take effect. The updated policy will also be published on this page with a revised effective date.

For non-material updates (corrections, clarifications, formatting), we will update the page without individual notice but will revise the effective date.

Your continued use of EPIC Alliance services following notification of material changes constitutes your acknowledgment of the updated policy. If you do not agree to material changes, you may request account deletion at any time by contacting team@epic-alliance.io.