Privacy Statement — Venturee
Effective Date: August 1, 2026 · Last Updated: August 1, 2026 · Version: 2.0 (revised)
This Statement explains how Binderr B.V. ("we," "us," or "our"), the company that operates the Venturee platform and is the data controller for the processing described here, collects, uses, stores, and discloses personal data when you ("User" or "Venturist") use our platform and related services (the "Service"). We handle personal data in accordance with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and Dutch implementing law (UAVG).
Scope and Who This Applies To
This Statement applies to personal data processed through the Venturee platform, including registration, subscription management, generation and delivery of AI Artifacts, feedback, and, where available, the Maker Marketplace.
The Service is offered to individual founders and aspiring founders. Binderr treats every user as a consumer, as set out in the Terms of Service. Because we make the Service available to users outside the EEA, local privacy laws may also apply. If you reside in the United States, the United States Residents section below describes the rights available to you under California and other state privacy laws; where it conflicts with the rest of this Statement, that section controls for US residents.
Age. The Service is for adults. You must be at least 18 to use the Service. The Service is not directed to children, and we do not knowingly process the personal data of anyone under 18; if we learn that a user is under 18, we will close the account and delete the data. (The age of digital consent in the Netherlands is 16, but because the Service itself requires users to be 18, we do not process the data of anyone below that age.)
Definitions
"Personal Data" means any information relating to an identified or identifiable natural person, including registration details, User Prompts and content that contain personal data, feedback, usage data, and correspondence.
"Processing" has the meaning in the GDPR and covers any operation performed on personal data.
"Data Controller" is Binderr B.V., which determines the purposes and means of processing. Our primary establishment is in the Netherlands, and our lead supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
"Processor / Sub-processor" means a third party that processes personal data on our documented instructions (see Providers We Use).
What We Collect
- Registration and account data: name, email, login credentials, and eligibility information.
- User Prompts and content: the prompts you submit and the ventures, sites, documents, and files you create. These may contain personal data you choose to include.
- AI Artifacts: the outputs generated for you.
- Feedback: the notes and issue reports you submit, including any free-text you provide.
- Usage and performance data: how you interact with the platform (for example, feature use, generation volume, onboarding progress, error and performance logs), including your IP address and the approximate (city-level) location derived from it, used for security and fraud prevention.
- Payment and transaction metadata: where you use paid features, transaction metadata needed to process and record payment. Card payments are handled by our payment processor (Stripe); we do not store full card numbers.
How our analytics work. Our product analytics are first-party: we measure usage with our own tooling and store the results in our own database. We use no third-party analytics or advertising trackers anywhere in the Service, and no analytics data about you is sent to an advertising network. Most of what we look at is aggregate and does not identify anyone — totals such as ventures created, page views, and template popularity. Usage attributable to an individual member is accessible only to Binderr's administrator, and only for operating and improving the Service and for security.
Traffic volume on your published sites. We measure the volume of traffic your published sites generate, because our hosting costs scale with it and the fair-use provision in our Terms depends on it. This is a count of requests and resource usage; we do not analyze, profile, or track your site's visitors, and we do not use this data for any purpose other than operating the Service and applying the fair-use provision.
Advertising. Venturee helps you create advertising assets, but it does not publish them. You download your ads and publish them yourself on the advertising platforms of your choice. We do not connect to your advertising accounts, do not hold credentials or access tokens for them, and receive no data back from those platforms.
What we do not collect: visitors to your published sites. You create, publish, and operate your own websites through Venturee, and you run your own advertising campaigns. Venturee does not collect, receive, or process personal data about the visitors to your sites for its own purposes, and we do not place our own analytics or advertising tags on them. For your site's visitors, you are the controller: you are responsible for your own privacy notice, cookie consent, and handling of visitor rights requests. Because we host the infrastructure your sites run on, limited technical data (such as IP addresses in server logs) passes through our hosting providers as a necessary part of delivering your site; for that data, Binderr acts as your processor under the Data Processing Agreement (Member Sites), which you accept when you first publish a site.
You are warned not to input special categories of personal data (for example, health or biometric data under Article 9 GDPR); the Service is not designed for such processing.
How AI Generation Works and Who Processes Your Content
To generate AI Artifacts, we send your User Prompts and related content to two third-party AI model providers that act as our processors under data-processing terms: Anthropic (Claude API) and Google (Gemini API). We use these providers on paid commercial terms, under which your prompts and outputs are not used to train their models. Both are located in the United States, so this involves an international transfer (see International Data Transfers).
Your feedback (including free-text) may be processed using AI and vector-search tooling to help us identify and prioritize product improvements. This is done to improve the Service, not to make decisions about you.
We do not use your content to make decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR; AI Artifacts are generated at your request and reviewed by you.
Legal Bases
- Contractual necessity (Art. 6(1)(b)): creating and running your account, generating AI Artifacts from your prompts, and providing the Service's features.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, service maintenance, and product improvement (including usage analytics and feedback analysis). We carry out balancing tests and apply data minimization; where analytics can be performed on anonymized data, GDPR does not apply to that anonymized data, and where data is only pseudonymized we continue to treat it as personal data.
- Consent (Art. 6(1)(a)): marketing communications, and non-essential cookies and similar technologies. You may withdraw consent at any time without affecting prior lawful processing.
- Legal obligation (Art. 6(1)(c)): retaining records we are required to keep (for example, tax and accounting records).
Cookies and Similar Technologies
We use strictly necessary cookies to operate the Service and, subject to your consent, analytics or functional cookies. We request consent for non-essential cookies and similar technologies as required by Dutch ePrivacy rules (the cookie provision of the Telecommunicatiewet). You can manage your preferences through our cookie controls.
Providers We Use (Sub-processors)
We rely on a limited set of providers that process personal data strictly on our instructions. The table below reflects our current providers. The specific transfer mechanism relied on for each, with where dated evidence is filed, is recorded in our internal transfer register.
| Provider | Purpose | Region | Transfer safeguard (if outside EEA) |
|---|---|---|---|
| Supabase | Database and authentication hosting | Ireland (eu-west-1) — EEA | Data at rest stays in the EEA; Standard Contractual Clauses cover limited US support access |
| Render | Application and site hosting | Ohio, United States | EU–US Data Privacy Framework, with Standard Contractual Clauses as fallback |
| Anthropic (Claude API) | AI generation from your prompts and content | US | EU–US Data Privacy Framework, with Standard Contractual Clauses |
| Google (Gemini API) | AI generation from your prompts and content | US | EU–US Data Privacy Framework, with Standard Contractual Clauses (under paid-tier data-processor terms) |
| Stripe | Payment processing | US / EEA | EU–US Data Privacy Framework, with Standard Contractual Clauses |
Anthropic and Google are the only recipients of your prompts and content for AI generation. If we add or change an AI provider, we will update this list before doing so.
The table above is the complete list of providers that process your personal data. Tools we use for our own business purposes that do not receive your data — for example, avatar video generation for our own marketing — are not listed. Because we do not publish advertising for you, no advertising platform or intermediary receives your personal data from us.
We do not sell your personal data, and we do not share it with third parties for their own purposes. Where you choose to engage a Maker, any personal data you send to that Maker is shared at your initiative, and the Maker then acts as an independent controller for its own processing. Before the Marketplace becomes available, we will put contractual safeguards in place requiring Makers to meet GDPR standards; this Statement does not cover a Maker's independent processing.
Data Retention
- Account and content: retained while your account is active. If you cancel, we delete your account and content within 30 days, except for data we must retain by law or to resolve disputes.
- Backups: residual copies in backups are purged on our rolling backup cycle.
- Billing and tax records: retained for the period required by Dutch fiscal law (currently seven years).
- Usage and security logs: retained for a limited period, then deleted or anonymized.
Security
We implement appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit (TLS 1.3) and at rest, access controls on a least-privilege basis, and regular security testing. Our primary database is hosted in Ireland (EEA); our application and site hosting runs in Ohio, United States. No system is perfectly secure, and you should keep your own copies of anything you cannot afford to lose.
In the event of a personal data breach (Art. 4(12) GDPR), we will act to secure the data and, where required, notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, and affected individuals without undue delay where the breach poses a high risk to their rights.
Your Rights
Subject to the conditions in the GDPR, you have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21), and the right not to be subject to solely automated decisions with legal or similarly significant effects (Art. 22). You may withdraw consent at any time where processing is based on consent.
To exercise these rights, contact us using the details below. We respond within one month, extendable by two further months for complex or numerous requests, and we will tell you if we need the extension. If you reside in the United States, see United States Residents below for the rights available to you under state privacy laws, including the right to appeal a declined request.
International Data Transfers
Our primary database is hosted in Ireland, within the EEA, so your data at rest remains in the EEA. However, our application and site hosting runs in Ohio, United States, which means personal data is transferred to and processed in the United States whenever it passes through the application. Your prompts and content are additionally transferred to the United States for AI generation by Anthropic and Google.
Where we transfer personal data outside the EEA, we rely on an appropriate safeguard under Chapter V GDPR. For providers certified under the EU–US Data Privacy Framework, we rely on the European Commission's adequacy decision for that framework. For all other transfers we rely on the European Commission's Standard Contractual Clauses (2021 version), supported by a transfer impact assessment and, where needed, supplementary measures. See Providers We Use for the current list.
The transfer mechanism relied on for each provider is recorded, with where to file dated evidence, in our internal transfer register. Render, Anthropic, Google, and Stripe are certified under the EU–US Data Privacy Framework, with Standard Contractual Clauses underneath as a fallback; Supabase relies on Standard Contractual Clauses, and because its data at rest stays in the EEA, only limited support access is an actual transfer.
United States Residents
This section applies if you reside in the United States. It describes how we handle your personal information and the rights we make available to you. Binderr operates Venturee from the Netherlands, and EU data-protection law applies to our processing as controller — which generally gives you protections beyond what US state law requires, in addition to the rights below.
Michigan. Many of our users reside in Michigan. Michigan has not enacted a comprehensive consumer data privacy law; a bill to create one (Senate Bill 359, the Personal Data Privacy Act) was introduced in June 2025 and was pending as of mid-2026. Until such a law takes effect, Michigan residents rely on targeted state statutes and federal law. The most relevant to us are the Identity Theft Protection Act (breach notification and reasonable safeguards), the Michigan Consumer Protection Act (which prohibits unfair or deceptive practices, so our privacy statements must be accurate and honored), and the Social Security Number Privacy Act (we do not collect SSNs). We do not sell or rent user data and are not a data broker.
Other states. More than twenty states have comprehensive consumer privacy laws, most applying only above size thresholds — commonly 100,000 residents of that state per year, or a revenue threshold (California: annual gross revenue above $26,625,000), or deriving 50% or more of revenue from selling personal information. Whether these thresholds apply to Binderr depends on our size and activities, which we monitor (see What would change our position below). Regardless of thresholds, some requirements always apply and we comply with them: FTC Act § 5 (our privacy statements must be accurate), state breach-notification laws in all 50 states, CalOPPA (a posted privacy policy meeting content rules), and COPPA (Venturee is 18+, and we do not knowingly collect children's data). We extend the rights below to all US users as a single operating standard, whether or not your state currently requires it.
What we do not sell or share. We do not sell personal information and have not sold it in the preceding twelve months. We do not share personal information for cross-context behavioral advertising, and we do not use sensitive personal information for any purpose that would trigger a right to limit its use. Our analytics are first-party and no personal information is disclosed to advertising networks. If any of this changes, we will provide a clear opt-out and honor Global Privacy Control signals before doing so.
Your site's visitors are yours. If you publish a site, you are the business/controller for its visitors — your site's privacy notice, consent mechanisms, opt-out handling, and rights requests are yours to provide. If your own site crosses a state-law threshold or deploys advertising tags, those obligations fall on you, not on Binderr. Binderr acts only as your service provider/processor for the hosting, under the Data Processing Agreement (Member Sites).
Your rights. We extend to all US users the rights to access, delete, correct, and port your personal information; to opt out of sale, sharing, or targeted advertising (which we do not engage in); to non-discrimination for exercising a right; and to appeal a declined request. You can also export your ventures, code, documents, and files directly from the product at any time. We do not offer financial incentives in exchange for personal information.
Exercising your rights, appeals, and complaints. Submit a request using the contact details below. You may use an authorized agent (we will ask for proof of authorization). We verify requests against the email on your account and respond within 45 calendar days, extendable by a further 45 with notice; Californian users receive acknowledgment within 10 business days. If we decline, we will explain why and how to appeal; to appeal, contact us with "Privacy Appeal" in the subject line, and if we deny the appeal we will tell you how to contact your state attorney general. Michigan residents may contact the Michigan Attorney General, Consumer Protection Division (PO Box 30213, Lansing, MI 48909); Californians may also contact the California Privacy Protection Agency.
What would change our position.
| Trigger | Consequence |
|---|---|
| Michigan SB 359 or a successor is enacted | Michigan comprehensive obligations; reassess before the effective date |
| Processing personal data of 100,000+ residents of any single state in a year | Most state comprehensive laws apply |
| Annual gross revenue above the California threshold ($26,625,000; CPI-adjusted, next adjustment due January 2027) | CCPA/CPRA applies |
| Ceasing to qualify as an SBA small business | Texas law applies in full |
| Deploying advertising or analytics tags that disclose data to third parties | "Sale"/"sharing"/targeted-advertising obligations; universal opt-out signal handling |
| Adding or changing an AI provider, or a provider changing its training position | Update the provider list before the change takes effect |
Contact and Complaints
For privacy questions or to exercise your rights, contact:
Privacy contact: Ittai Flascher (CTO) · Email: ittai@venturee.work · Postal address: Geertestraat 27 BS, 3511XD Utrecht The Netherlands.
If you believe our processing infringes the GDPR, you may lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens (AP) · Bezuidenhoutseweg 33, 2594 AM Den Haag, The Netherlands.
We encourage you to contact us first so we can try to resolve the matter.
