Privacy Policy
Last updated: 2026-07-23 · Applies to the LifeMatch invite-only pilot
Who we are
LifeMatch is an invite-only platform that connects screened life-science startups with screened investors. The service is operated by MTLS Group / Medflow, which acts as the data controller for the personal data described below. You can reach us about anything in this policy at ms@mtlsgroup.com.
What data we collect
Account data: your name, email address, role (founder or investor), and password (stored only as a secure hash by our authentication provider — we never see it).
Profile data you provide:for investors, your organization, investment thesis, sectors, stages, check size, and optional profile photo URL and LinkedIn link. For founders, your startup's profile — company details, team, traction, fundraising status, updates, and optional logo URL. You decide what goes in your profile; only submit information you are comfortable showing to the other side of the platform after screening.
Usage data: basic product events (for example that a discovery session started, a profile was viewed, or a follow request was sent) tied to your account, used to operate and improve the pilot. We do not sell this data or use third-party advertising trackers.
Why we process it (legal bases)
We process account and profile data to provide the service you signed up for (performance of a contract, GDPR art. 6(1)(b)): screening applications, matching startups with investor theses, and delivering mutual-consent connections. We process usage data and screening/audit records under our legitimate interest (art. 6(1)(f)) in running a safe, high-quality, invite-only platform — including keeping an audit log of screening decisions.
Who sees your data
Your profile is visible to the other side of the platform only after our screening approves it — investors see approved, published startup profiles; founders see the profile of an investor who requests to follow them. Our administrators see submissions during screening. We never make profiles public on the open web.
We use a small set of processors to run the service: Supabase (database, authentication and hosting of application data, EU region), Vercel (web hosting), and Sentry (error monitoring, which may briefly process technical data such as IP addresses when an error occurs). Each processes data on our instructions under their data-processing agreements.
How long we keep it
We keep your account and profile data while your account is active. If your application is rejected, the submission and its screening feedback are retained so you can revise and resubmit. If you delete your account, we remove your profile data; audit records of screening decisions may be retained in anonymized or minimized form where we have a legitimate interest in keeping them.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, ask for a copy in a portable format, object to processing based on legitimate interest, and lodge a complaint with your supervisory authority (in Denmark: Datatilsynet). To exercise any of these rights — including full account deletion — email ms@mtlsgroup.com from the address on your account. We respond within one month.
Changes to this policy
We may update this policy as the pilot evolves. Material changes will be announced to registered users by email or in the product, and the "last updated" date above always reflects the current version.