Privacy Policy
Effective date: 01-Mar-2026 Last updated: 01-Mar-2026
Panacea Technology Pte. Ltd. ("Panacea", "we", "us"), a company incorporated in Singapore, operates DeckVue (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights available to you.
This Policy is written to satisfy Singapore's Personal Data Protection Act 2012 (PDPA) as our primary regulatory baseline. Because we serve users globally, we also honor the substantive rights granted by the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), and comparable laws where applicable.
1. Who we are and how to contact us
- Data controller / organization: Panacea Technology Pte. Ltd., Singapore
- Privacy contact: [email protected]
Email aliases on the aevumis.com domain are operated by Panacea Technology Pte. Ltd.
If you are in the EU/UK and require an Article 27 representative, contact us and we will provide current details or appoint one as our user base requires.
2. Who this Policy applies to
The Service is offered to two primary audiences:
- Founders who upload pitch decks for analysis.
- Investors (funds, angels, scouts) who upload, review, share, or collaborate on decks.
The Service is intended for business use only and is not directed at children under 16. Do not use the Service if you are under 16.
3. What personal data we collect
3.1 Data you provide directly
- Account data: name, email, password hash (managed via Auth0), profile photo if provided.
- Workspace / tenant data: organization name, fund name, logo, invite slug, billing role.
- Uploaded content: pitch deck PDFs and any documents you submit. These may contain personal data about you, your team, or third parties (founder names, bios, contact details, LinkedIn URLs, photos).
- Collaboration data: invitations, shared-access grants, comments, assignments.
- Billing data: Stripe customer ID, subscription plan, seat count. Card details are handled by Stripe; we do not store full card numbers.
- Support communications: messages you send us by email.
3.2 Data collected automatically
- Usage data: pages viewed, features used, request timestamps, deck processing events.
- Device/log data: IP address, browser type, operating system, referrer, error logs.
- Cookies and similar technologies: authentication session cookies (HTTP-only), and limited functional cookies. We do not currently use third-party advertising cookies.
3.3 Data generated by the Service
- Extracted structured data: company, market, team, traction, financials, etc., derived from your uploaded deck by our processing pipeline.
- Enrichment data: publicly available company information retrieved from third-party data providers.
- Verification and analysis output: fact-check results and strategic analysis generated by LLM providers based on the deck contents.
4. How we use personal data (purposes and legal bases)
| Purpose | Examples | Legal basis (GDPR) / PDPA basis |
|---|---|---|
| Provide the Service | Process decks, generate analysis, host results, enable sharing | Performance of contract; consent (PDPA s.13) |
| Authenticate and secure accounts | Auth0 login, session management, rate limiting, abuse prevention | Legitimate interests; legal obligation |
| Bill and manage subscriptions | Stripe seat counts, invoices, dunning | Performance of contract |
| Improve the Service | Aggregate usage analytics, debugging, error tracing | Legitimate interests |
| Communicate with you | Service announcements, security notices, support replies | Legitimate interests; performance of contract |
| Comply with law | Respond to lawful requests, tax records, audit logs | Legal obligation |
| Marketing (if any) | Product update emails (opt-out anytime) | Consent; legitimate interests |
We do not use your uploaded decks, extracted data, or generated outputs to train our own machine learning models, and we configure our LLM subprocessors to disable training on customer content where such controls are available (see §6).
5. Sharing and disclosure
We share personal data with the following categories of recipients:
- Other users you authorize: people you invite to your workspace or share decks with.
- Service subprocessors: see §6.
- Acquirers: in connection with a merger, acquisition, or sale of assets, subject to confidentiality.
- Authorities: where required by law, court order, or to protect rights, safety, or property.
We do not sell personal data and we do not share personal data for cross-context behavioral advertising.
6. Subprocessors
The Service relies on the following third-party providers to deliver core functionality. Each has been selected for its security and privacy posture. The list below is current as of the "Last updated" date and may be updated; material changes will be notified in-app or by email.
| Subprocessor | Purpose | Data processed | Region |
|---|---|---|---|
| Auth0 (Okta) | Authentication, identity, session management | Email, name, password hash, login metadata | US/EU |
| Supabase (PostgreSQL) | Primary application database | Account, workspace, deck metadata, processing results | US |
| Cloudflare R2 | Object storage for uploaded PDFs and tenant logos | Pitch deck files, logos | Global edge |
| Stripe | Subscription billing and payment processing | Billing contact, subscription, payment tokens | US/EU |
| AI / LLM providers | Deck extraction, strategic analysis, fact-checking, and company enrichment | Deck text/images and derived data submitted to the provider | US / EU |
| Hosting and operational monitoring | Application hosting, logging, and error tracking | Application traffic, logs, error traces, IP addresses | US |
The current list of AI / LLM providers is available on request from [email protected] and is disclosed in our Data Processing Addendum to enterprise customers. For each LLM subprocessor we use the API tier and account settings that, where offered by the provider, disable use of customer content for model training and apply zero- or short-retention defaults. Provider terms govern their processing and may change.
7. International data transfers
Because we are headquartered in Singapore and our subprocessors operate globally, your personal data may be transferred to and processed in jurisdictions outside your country of residence, including the United States and the European Economic Area.
For transfers out of the EU/UK we rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by additional safeguards where appropriate. For transfers out of Singapore we ensure recipients are bound to a comparable standard of protection as required by PDPA s.26.
8. Data retention
We retain personal data for as long as your account is active and for as long as needed to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements.
- Uploaded decks and derived analysis are retained while your workspace is active so that you and your collaborators can return to them.
- Account and billing records are retained for the period required by applicable tax, accounting, and corporate law.
- Logs and operational data are retained for a rolling operational window.
You may request deletion of specific decks, your workspace, or your account at any time (see §10). On account closure we will delete or de-identify personal data within a reasonable period, except where retention is required by law.
9. Security
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:
- TLS 1.2+ in transit and encryption at rest at our storage and database providers.
- Tenant isolation enforced at the application and database layers.
- Auth0-managed credentials; no plaintext password storage.
- Signed, short-lived tokens for unauthenticated share-links (HMAC, 15-minute TTL).
- Role-based access controls (owner / admin / analyst / viewer).
- Least-privilege access for staff and audit logging.
No system is perfectly secure. If we become aware of a personal data breach affecting you, we will notify you and the relevant authority as required by applicable law.
10. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your data ("right to be forgotten" under GDPR; deletion request under PDPA).
- Restrict or object to certain processing.
- Portability: receive your data in a machine-readable format.
- Withdraw consent where we rely on consent (without affecting prior lawful processing).
- Lodge a complaint with a supervisory authority — in Singapore, the Personal Data Protection Commission (PDPC); in the EU/UK, your local DPA/ICO; in California, the California Privacy Protection Agency.
- CCPA-specific: right to know, delete, correct, and to non-discrimination. We do not sell or share personal data for cross-context behavioral advertising.
To exercise any of these rights, email [email protected]. We will respond within the timeframes required by applicable law (30 days under PDPA; 30 days under GDPR, extendable by 60 days; 45 days under CCPA).
11. Third-party content and links
Decks you upload may reference third parties (e.g., team members, advisors, customers). You represent that you have the necessary basis to share their information with us for processing. Where you act as a data controller and we act as processor, our Data Processing Addendum (see DPA.md) applies.
12. Cookies
We use cookies that are strictly necessary for authentication and session management. We do not currently use advertising or cross-site tracking cookies. If this changes we will update this Policy and, where required, present a cookie consent banner.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email or in-app notice at least 14 days before they take effect, except where a shorter period is required by law.
14. Contact
Questions, requests, or complaints:
Panacea Technology Pte. Ltd. Email: [email protected] Registered address: #15-1282, 209A, Punggol Place, Singapore 821209