1. Who we are
Noverra B.V. ("Noverra", "we", "us", "our") operates the SumaqX platform available at sumaqx.com (the "Service"). Noverra is a private limited liability company incorporated under the laws of the Netherlands on 23 April 2026.
- Registered office: Haagbeemd 57, 5641NB Eindhoven, the Netherlands
- Chamber of Commerce (KvK) number: 42046760
- VAT (BTW) identification number: NL869462258B01
- General contact: [email protected]
- Privacy contact (data requests and questions): [email protected]
Noverra is the data controller of the personal data described in this Policy, unless stated otherwise (for example, when a facilitator, mentor, or investor separately collects data from you through our platform — see Section 11).
We have not appointed a statutory Data Protection Officer (DPO) under Article 37 GDPR because our processing does not currently meet the thresholds that make one mandatory. We have, however, appointed an internal Privacy Lead who is responsible for privacy oversight and who you can reach at [email protected].
2. What the SumaqX Service does
SumaqX is an AI-assisted readiness platform for founders preparing for the Dutch startup visa route operated by the Rijksdienst voor Ondernemend Nederland (RVO) and the Immigration and Naturalisation Service (IND). We help founders:
- evaluate how prepared their startup idea is for the RVO/IND route;
- upload and review supporting documents;
- request introductions to accredited RVO facilitators, mentors, and investors on the platform;
- chat with an AI advisor trained on publicly available information about the Dutch startup visa;
- optionally connect Google Calendar (when you choose to) for availability checks, booking synchronisation, and session event management.
SumaqX is not a law firm, an immigration consultancy, or an RVO facilitator. We do not represent you in your visa application. See our Terms and Conditions for the full scope.
3. Personal data we collect
We collect different categories of personal data depending on which role you use SumaqX in.
3.1 All users (account-level)
- Identity data: full name, email address, profile photo (optional), country of residence.
- Authentication data: hashed password or federated sign-in identifier (Google OAuth subject ID).
- Device and usage data: IP address, browser type, operating system, pages visited, time stamps, crash/error logs.
- Support and communications: the content of any message you send us, tickets you open, or forms you complete.
3.2 Founders
In addition to Section 3.1, when you use SumaqX as a founder we collect:
- Onboarding data: startup name, industry, stage, team size, nationality, country of residence, languages.
- Startup information: description, target country (typically the Netherlands), risk flags, readiness score and its breakdown.
- Uploaded documents (sensitive):
- Business Plan (required) — may contain commercial strategy and financial projections.
- Proof of Funds (required) — may contain bank statements, account numbers, balances.
- Passport Copy (required) — contains name, photograph, date of birth, nationality, passport number, and in some passports machine-readable zone data. Passport numbers are treated by Dutch and EU law as a national identification number under Article 87 GDPR.
- MVT Documentation (required) — Dutch long-stay authorisation materials; may include application reference numbers and personal identifiers.
- Team CVs (optional) — personal data of co-founders and team members.
- Reference Letters, Market Research, Partnership Letters (optional) — may contain third-party names and contact details.
- AI Advisor conversations: the prompts and messages you send to the AI and the responses returned.
- AI Advisor attachments: files you upload in the AI Advisor (for example PDFs or images used to ground an answer). These are stored separately from conversation text and are not the same as visa documents you manage in the document vault.
- Facilitator/mentor/investor interaction history: who you contacted, application status, any messages exchanged through the Service.
3.3 Facilitators
- Organisation name, organisation type (independent/company), accreditation reference, focus industries, capacity per month, bio, website.
- Evaluations you produce on founders, case notes, internal tasks and reports you create on the platform.
3.4 Mentors
- Areas of expertise, industries of interest, preferred startup stage, bio, hourly rate and currency (if you accept paid sessions), time zone, availability schedule.
- Booking and session data with the founders you mentor.
3.5 Investors
- Firm name, focus stages, focus industries, ticket size range, geographic focus, bio.
- Dealflow pipeline data (notes, stages, scores) about startups you are evaluating.
3.6 Payment data (Stripe)
When you subscribe to a paid plan (Free Plan, Pro Plan, or a Facilitator Dashboard plan), payment card details are collected and processed directly by Stripe. SumaqX never sees or stores your full card number, CVC, or bank account number. We receive limited billing metadata from Stripe (customer ID, subscription status, last-four digits, invoice amounts, country, VAT ID if any).
3.7 Google Calendar data (optional connection)
SumaqX may request access to Google Calendar only when a mentor or founder explicitly connects Google Calendar in the product. Connecting Calendar is optional and separate from Google Sign-In. When you connect, we may process:
- OAuth tokens needed to maintain the calendar connection;
- calendar email / account identifier associated with the connection;
- free/busy and availability information used for booking checks;
- calendar event metadata created or updated for bookings and sessions (for example title, time, attendees, and Google Meet conference details where applicable).
See Section 6 for how we use Google user data, Limited Use commitments, and how to disconnect.
3.8 Data we do NOT knowingly collect
- We do not process special categories of personal data (Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a person, health data, or data concerning sex life or sexual orientation) except where you voluntarily include such information in a free-text field, in an uploaded document, or in an AI Advisor conversation. We ask that you do not upload such information unless it is strictly necessary for your visa application.
4. Why we process your data and on what legal basis
Under Article 6 GDPR (and Article 9 where applicable), we need a lawful basis for each purpose. The table below summarises ours.
| # | Purpose | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|---|
| 1 | Create and manage your account | Identity + auth | Contract (Art. 6(1)(b)) |
| 2 | Deliver the readiness, scoring, document, and roadmap features | All founder data in §3.2 | Contract |
| 3 | Power the AI Advisor | AI Advisor conversations and attachments | Contract |
| 4 | Match founders with facilitators, mentors, and investors | Onboarding data + startup data | Contract |
| 5 | Process payments and manage subscriptions | Payment metadata from Stripe | Contract + Legal obligation (tax/accounting) |
| 6 | Comply with Dutch tax, accounting, and AML obligations | Billing metadata, VAT number | Legal obligation (Art. 6(1)(c)) |
| 7 | Keep the platform secure; prevent abuse, fraud, and unlawful use | Device/usage data, logs | Legitimate interests (Art. 6(1)(f)) — our interest in a safe service; balanced against your rights |
| 8 | Send service emails (account notifications, security alerts, receipts) | Email + account data | Contract |
| 9 | Send marketing emails (product updates, newsletters) | Consent (Art. 6(1)(a)) — you can opt out at any time | |
| 10 | Improve SumaqX by analysing aggregated usage | Aggregated/pseudonymised usage data | Legitimate interests |
| 11 | Defend legal claims and comply with lawful requests | Whatever is relevant | Legitimate interests / Legal obligation |
| 12 | Process passport data and other national identifiers | §3.2 documents | Contract — we rely on the contractual necessity exception of Art. 87 GDPR and national law specifics; you may decline, but we cannot deliver visa-readiness services without it |
| 13 | Provide optional Google Calendar booking sync (availability, events, Meet links) | §3.7 Google Calendar data | Contract (Art. 6(1)(b)) — only after you explicitly connect Calendar |
We do not sell your personal data. We do not share your personal data with third parties for their own direct marketing.
5. Who we share your data with
SumaqX shares personal data only with the following categories of recipients, and only as necessary.
5.1 Sub-processors (acting on our instructions)
| Sub-processor | Role | Location of processing | Transfer mechanism |
|---|---|---|---|
| Supabase (Supabase Inc., US) — EU region infrastructure | Hosted database, authentication, file storage, realtime; secure storage of optional Google Calendar OAuth tokens | EU (Frankfurt or Ireland region) | Data stays in the EU; US parent has access under Standard Contractual Clauses (SCCs) and supplementary measures |
| Stripe Payments Europe Ltd. (Ireland) | Payment processing, subscription management, tax invoicing | EU (Ireland); US for certain support and fraud detection | Intra-EU processing; US access uses Stripe's EU-US Data Privacy Framework as primary, with SCCs (2021) as backup |
| Anthropic PBC (US) / OpenAI LLC (US) | Large-language-model inference for the AI Advisor | United States | SCCs + supplementary technical and contractual measures. As part of the Business Plan Review and Pitch Deck Review features, the content you submit is processed using AI language models (via our AI sub-processors, OpenAI and/or Anthropic) to generate feedback and scoring. This AI-based processing is core to how these features work. |
| Google LLC (US) | Google Sign-In (OAuth) and, when you explicitly connect it, Google Calendar API access | US | Independent-controller for OAuth/Calendar (Google API Terms and User Data Policy; no standard processor DPA). Google's EU-US Data Privacy Framework, with SCCs as backup. Sign-In uses minimum profile data (name, email, avatar); Calendar access is limited to the purposes in Section 6 |
| Cloudflare, Inc. (US) | Static-site hosting (Cloudflare Pages, deployed from GitHub) and network error reporting (NEL) | Global edge network | SCCs; Cloudflare is EU-US Data Privacy Framework certified |
| n8n (self-hosted, operated by EZ Digital Solutions B.V.) | Workflow automation / AI orchestration: routes and processes AI Advisor, scoring, and business-plan-review requests between SumaqX and OpenAI/Anthropic | Netherlands | Intra-EU processing |
| Zoho Corporation | Email delivery for the contact form (name, email, and message submitted by prospects) | India / United States | SCCs in Zoho's DPA, which must be signed separately by the account admin (not automatic with Zoho's Terms of Service) |
If we engage a transactional email provider or a product-analytics provider in the future, we will update this Policy with the provider's identity and relevant transfer safeguards before that provider processes personal data for SumaqX.
We require appropriate data processing terms with each sub-processor before they process personal data for SumaqX.
5.2 Other users on the platform
- Facilitators you apply to see the founder profile, startup summary, and any documents you share with them.
- Mentors you book see your founder profile, startup summary, and any notes you share with them.
- Investors see only startup information you have explicitly made visible to investors; they receive no contact information about you until you accept an intro request.
Within those exchanges, the other user may act as a separate data controller for the data they receive. Their own privacy practices are outside of our direct control; we contractually require them to comply with the GDPR.
5.3 Professional advisors and authorities
Accountants, auditors, legal counsel, and Dutch authorities (e.g. the Belastingdienst, AP, or police) where a legal obligation or lawful order applies.
5.4 Business transactions
If Noverra is acquired, merged, or sells assets, personal data may transfer as part of the transaction. We will give prior notice where required by law.
6. Google Calendar and Google user data
This section explains how SumaqX uses Google user data obtained through Google APIs (in particular Google Calendar). It is written so that Google reviewers and users can clearly understand our Limited Use commitments.
6.1 When we request Calendar access
SumaqX may request access to Google Calendar only when a mentor or founder explicitly connects Google Calendar in the Service. We do not connect your Calendar merely because you signed in with Google. You can use SumaqX without connecting Calendar.
SumaqX requests Google Calendar access only for the Calendar features currently visible in the product: availability checks, booking/session synchronisation, event creation/update/cancellation, and Google Meet details where applicable. SumaqX's policy and product use of Google Calendar data are limited to those booking and session purposes, even if the configured Google permission could technically allow broader calendar access.
6.2 How we use Calendar access
When you connect Google Calendar, access is used to:
- check availability (including free/busy information) for booking and scheduling;
- synchronise confirmed bookings and mentoring/consulting sessions with your calendar;
- create, update, and cancel Google Calendar events related to those bookings and sessions;
- attach or manage Google Meet conference details for sessions where applicable.
6.3 What we store
SumaqX may store OAuth tokens securely in Supabase (our EU-hosted backend) so we can maintain the calendar connection and perform the booking/session actions above on your behalf. We may also store limited connection metadata (such as calendar email and sync status) and booking-related event identifiers needed to update or cancel events later.
6.4 What we do not do with Google user data
- SumaqX does not sell Google user data.
- SumaqX does not use Google Calendar data for advertising.
- SumaqX does not use Google Calendar data to train generalized AI/ML models.
- Human access to Google user data is limited to user-requested support, security or abuse investigation, or compliance with applicable law.
6.5 Transfers and sharing of Google user data
Google user data is transferred only as necessary:
- to provide the user-requested Calendar booking/session functionality;
- for security purposes;
- to comply with applicable law; or
- as part of a merger, acquisition, or sale of assets, only where required notices and/or consents are obtained.
Our service providers that help operate those functions (for example Supabase for secure token storage, and Google for the Calendar API itself) act under SumaqX's instructions or under their own terms as API providers. Other SumaqX users (such as a founder booking a mentor) only receive the information needed for that booking (for example session time and Meet link), not broad access to your Google Calendar.
6.6 Google API Services User Data Policy — Limited Use
SumaqX's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain English:
- we use Google user data only to provide the user-facing Calendar booking and session features that are prominent in the SumaqX interface (availability checks, booking sync, and calendar event/Meet management);
- we do not use that data for advertising;
- we do not sell it;
- we do not use it to train generalized AI/ML models;
- human access to that data is limited to user-requested support, security or abuse investigation, or compliance with applicable law.
6.7 Disconnecting and deletion
You can disconnect Google Calendar from SumaqX in the product settings (for example mentor or founder calendar/settings flows). You can also revoke SumaqX's access at any time in your Google Account permissions.
After you disconnect, or if you request deletion, we delete or invalidate stored OAuth tokens and related calendar-connection data we no longer need to operate the Service, subject to short technical retention in backups and any legal retention obligations. To request deletion of stored Google Calendar tokens or related data, email [email protected].
7. International data transfers
Because some of our sub-processors are located in the United States, your personal data may be transferred outside the European Economic Area (EEA).
For any such transfer we rely on:
- European Commission Standard Contractual Clauses (SCCs) (2021/914/EU, Module 2 or 3);
- Supplementary measures where appropriate (pseudonymisation, encryption in transit and at rest, minimised data fields sent to the recipient);
- A transfer impact assessment for each US-based sub-processor.
You can request a list of the specific transfer safeguards in place by emailing [email protected].
8. How long we keep your data
| Data category | Retention |
|---|---|
| Account and profile data | For as long as your account is active, plus up to 12 months after deletion request (to allow for reactivation and dispute resolution) |
| Uploaded visa documents (passport, proof of funds, MVT) | For as long as your account is active, plus up to 6 months after you delete them from the platform (to allow for recovery), after which they are permanently deleted from our systems and backups within 90 days |
| Pitch Deck and Business Plan files uploaded for scoring and review | Retained for as long as necessary for the purposes described in this policy. These files are not automatically deleted when your account is deleted: account deletion removes your personal identity but preserves scoring and business records. To request deletion of these specific files, contact us at [email protected]. |
| AI Advisor conversation history | Stored while your account remains active. To request deletion of a specific AI conversation, contact us at [email protected]. We will process your request without undue delay, in accordance with applicable data protection law. On account closure, deleted within 30 days |
| AI Advisor uploaded attachments | Automatically deleted after approximately 10 days. No user action is required. There is no self-service control to delete these files on demand. |
| Google Calendar OAuth tokens and connection metadata | For as long as the connection remains active; deleted or invalidated when you disconnect Calendar or close your account, with residual backup copies removed within 90 days |
| Booking-related calendar event identifiers | For as long as needed to update or cancel the related booking/session events, then deleted with the booking records under normal retention |
| Payment and invoice data | 7 years after the end of the relevant fiscal year (Dutch tax retention obligation under Article 52 General Tax Act / AWR) |
| Support tickets and email correspondence | 24 months from the last interaction |
| Security and access logs | 12 months |
| Analytics events (pseudonymised) | 26 months |
| Marketing preferences and unsubscribe lists | Indefinitely, for suppression-list purposes (required by law to honour opt-outs) |
When a retention period ends, data is deleted or fully anonymised.
9. Your rights under the GDPR
You have the following rights in relation to your personal data. They are free to exercise; we will respond within one month of receiving your request (extendable by two further months for complex requests).
- Right of access (Art. 15) — request a copy of your data.
- Right to rectification (Art. 16) — correct inaccurate data.
- Right to erasure (Art. 17) — ask us to delete your data ("right to be forgotten"), subject to limits (for example, we must retain invoice data for tax law).
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests, including profiling.
- Right to withdraw consent (Art. 7(3)) — where consent is the basis, you can withdraw it at any time without affecting the lawfulness of prior processing.
- Right not to be subject to a solely automated decision with legal or similarly significant effects (Art. 22). Our readiness score and AI Advisor outputs are informational tools and are not used to make final, automated decisions about visa admissibility, plan eligibility, or facilitator matching. A human is always in the loop for any decision that materially affects you.
- Right to lodge a complaint with the Dutch Data Protection Authority — Autoriteit Persoonsgegevens (AP), Postbus 93374, 2509 AJ Den Haag, +31 (0)70 888 85 00, autoriteitpersoonsgegevens.nl — or with the supervisory authority of your country of residence.
To exercise any right: email [email protected]. We may ask you to verify your identity before responding.
10. Cookies and similar technologies
SumaqX only uses strictly necessary storage required for the Service to function — specifically, an authentication token (via Supabase) that keeps you signed in, and a small number of functional local-storage items (for example, remembering your last-viewed page or UI preferences) that are set only after you sign in. We do not use analytics, advertising, or tracking cookies of any kind, and no consent banner is required under applicable ePrivacy rules for this strictly-necessary-only usage.
11. When other users are the data controller
When a facilitator, mentor, or investor uses the platform to collect additional data from you (for example, a facilitator's internal case-management notes), that user is the data controller of the data they collect. Noverra acts as a data processor on their behalf for the storage and transmission of that data, and is separately a controller of the same data for our own audit, security, and billing purposes (so-called joint or parallel controllership, depending on the exact activity).
You can always ask the relevant user directly, and you can also ask us to facilitate the request.
12. Security
We use technical and organisational measures that are appropriate to the risk, including:
- encryption in transit (TLS 1.2+) and at rest (Supabase managed keys, AES-256);
- row-level security (Postgres RLS) on every database table;
- least-privilege access for staff; two-factor authentication on administrative accounts;
- logical separation of documents in private Supabase Storage buckets with policy-based access;
- secure storage of optional Google Calendar OAuth tokens with access limited to the account owner and server-side booking sync;
- routine back-ups and tested recovery procedures;
- code review and dependency scanning before production deploys.
No system is completely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Dutch AP within 72 hours and notify you without undue delay where required (Articles 33–34 GDPR).
13. Changes to this Policy
We may update this Policy from time to time. If changes are material, we will notify you by email or a prominent notice on the Service at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
14. Contact
- Privacy questions and requests: [email protected]
- General: [email protected]
- Postal: Noverra B.V., Haagbeemd 57, 5641NB Eindhoven, the Netherlands
This Policy is governed by Dutch law. Non-exclusive jurisdiction lies with the competent courts in the district of Eindhoven, without prejudice to your mandatory consumer rights.