Privacy statement
Version 5 · in force since 10 Sept 2026
1. Who is responsible
GoTrust BV, trading as Legendmakers, registered with the Crossroads Bank for Enterprises under number 1037.576.138, with its registered office at Morelgem 24B, 9520 Vlierzele, Belgium, a company incorporated under Belgian law, is the controller for the processing described in this statement.
Contact for anything on this page: hello@legendmakers.ai. We have not appointed a data protection officer. Our core activity is not large-scale monitoring or large-scale processing of special categories of data, so article 37 GDPR does not require one.
2. Who this statement is about
- Founders and their organisations: people who apply for a dossier and the people they name in it.
- Investors: people who hold a seat on an investor subscription.
- Recipients of a forwarded dossier: people without an account who accept an undertaking to read one dossier.
- Waitlist entries and correspondents: people who leave their details or write to us.
- People named in a dossier: founders and team members whose name appears in a dossier. This statement is also addressed to them, because we usually receive their data from the founder and not from them (article 14 GDPR).
3. What we hold, why, and on what legal basis
3.1. Your account
What: your name, e-mail address, preferred language, time of last sign-in, account status, and, if you chose a password, a hash of it. If you hold an admin or editor role, the secret behind your second factor. Your sessions: the device, browser, IP address and times, and whether an administrator was acting on your behalf.
Why: to let you sign in, to keep you signed in, and to let us revoke a stolen session at your request.
Legal basis: performance of our agreement with you.
3.2. Signing in without a password
What: your e-mail address, your IP address and the times at which a sign-in link was requested, sent and used. Sign-in attempts are counted per e-mail address and per IP address.
Why: to sign you in without a password, and to slow down abuse of the sign-in page.
Legal basis: performance of the agreement for the link; our legitimate interest in security for the rate limiting.
3.3. Your organisation and your invoices
What: the legal name, country, VAT number as you give it to us, billing address and billing e-mail address, the seats and invitations, and the invoices, each holding a frozen copy of the buyer's details at the time of issue. We do not check your VAT number against any external register, so nothing about you is sent to one.
Why: to bill you, to apply the right VAT treatment, and to keep the books.
Legal basis: performance of the agreement; legal obligation for invoicing and bookkeeping.
3.4. What a founder sends us
What: the application, all three rounds of intake answers including the financial figures of the company, uploaded files and the text we extract from them. Each intake round is stored as submitted and never overwritten. The financial figures are about the company, not about a person.
Why: to write the dossier.
Legal basis: performance of the agreement with the founder's organisation, and our legitimate interest in editorial assessment. We do not claim the journalistic exemption of article 85 GDPR: we handle a request from a person named in a dossier on its merits rather than refusing it on that ground.
3.5. People named in a dossier
What: a name, a role, one sentence of biography and a LinkedIn address for the founders and team members named. Nothing else: no private address, no date of birth, no data about employees who are not founders.
Source: the founder who applied. The founder has undertaken to tell you that your details may appear.
Why: the team section of the dossier.
Legal basis: our legitimate interest in publishing an accurate description of the company to a restricted readership, balanced against your interest, and limited to four professional data points that are, for founders, ordinarily public on the company's own website and on LinkedIn.
What you can do: see article 7.
3.6. Who reads a dossier
What: every full opening of a dossier is recorded with the reader's name, organisation, time, IP address, browser, and whether it was read on screen, as a PDF or as an export. Every page a reader sees carries their name, their organisation and the time.
Why: a founder agrees to be written about honestly, weak points included, on the understanding that we can show who has read it. This record is the one protection that works; we do not disable copying or printing because that stops nobody. We tell every reader about the record before they read anything.
Legal basis: our legitimate interest in the confidentiality of dossiers, which protects the founder. We have documented this balancing test and we send it to you on request. Investors are told in the undertaking they accept that the record is the condition of access.
Who sees it: us. Not the founder, not other investors.
3.7. Forwarded dossiers
What: the e-mail address to which a subscriber forwarded a dossier, the name and e-mail address the recipient entered, the times at which the link was sent, opened and expired or was revoked, the recipient's IP address and browser, and the version of the undertaking accepted. Held on the record of the organisation that sent it.
Why: to let a subscriber forward a dossier under conditions, and to know who read it.
Legal basis: performance of the agreement with the sending organisation; legitimate interest in confidentiality as in 3.6.
3.8. What you accepted
What: for every set of terms or undertaking you accept: who, for which organisation, which version, when, from which IP address, with which browser. For a forward recipient, the name and e-mail address they entered.
Why: to be able to show, later, what you agreed to.
Legal basis: our legitimate interest in evidence of consent to contractual terms; performance of the agreement.
3.9. Our own audit log
What: role changes, status changes, publications, credit grants, refunds, administrator impersonation, forwards and revocations, with who did it, when, from which IP address and browser, and why.
Why: to account for what we did, especially where roles, money, status or visibility change.
Legal basis: legitimate interest in accountability; in part legal obligation.
3.10. Messages between investors and founders
What: sender, recipient, text and status of messages on the co-founder tier.
Why: to let an investor on that tier write to a founder who asked for a co-founder, with the founder's acceptance of the first message.
Legal basis: performance of the agreement with both parties.
3.11. AI runs
What: the full request we send to our AI provider and the full answer we receive, per call, including failed calls, and a flag stating whether the request was pseudonymised.
Why: to be able to reconstruct exactly what was asked and answered if a founder disputes an analysis.
Legal basis: legitimate interest in accountability and in defending legal claims.
3.12. Data subject requests
What: the request and how we handled it.
Why: to prove that we handled it.
Legal basis: legal obligation.
3.13. Waitlist and correspondence
What: name, e-mail address and company for a waitlist entry; the content of e-mail you send us.
Why: to contact you about the platform and to answer you.
Legal basis: legitimate interest in responding to your request; for the waitlist, the steps you asked us to take before entering an agreement.
4. What we do not do
We do not track you. There is no analytics, no advertising pixel, no external font, no content delivery network and no third-party script.
We use two cookies, both strictly necessary: lm_session, which keeps you signed in, and lm_forward, which carries a forwarded dossier link. Both are httpOnly and sameSite=lax. Because neither needs consent, there is no cookie banner.
We do not sell personal data. We do not send marketing e-mail, and we do not rely on consent as a legal basis for anything. The only e-mail we send is about your account, your subscription, your dossier or your request.
We do not profile anyone and we take no decision about anyone by automated means alone. Rank is calculated from a score set by an analyst, and no automated process decides on any person.
5. Who receives personal data, and where it goes
5.1. Our own infrastructure
The application, the database, file storage and the mail server run on our own hardware in the European Union. Since September 2026 our e-mail is sent through our own mail server; there is no external e-mail provider.
5.2. Payment provider
Stripe processes card and SEPA direct debit payments. Stripe Payments Europe Ltd, Ireland, receives the data needed to take payment and to comply with its own legal obligations, as our processor and, for its own fraud prevention and legal duties, as an independent controller. Where Stripe processes data outside the European Economic Area it does so under the European Commission's standard contractual clauses.
5.3. AI provider
Anthropic provides the language model that writes first drafts of dossier sections. What goes there is dossier text and founder material insofar as needed to draft. Personal data of investors and of forward recipients never goes there.
For companies that selected strict confidentiality, the company name and the names of persons are replaced with placeholders before anything leaves our systems, and restored only when the draft is shown to the analyst. Each AI run records whether it was pseudonymised, so this is verifiable, not asserted. For those companies the financial figures are withheld from the provider entirely rather than pseudonymised, because a revenue figure, a customer count and a runway together identify a company to anyone in its market; the analyst writes that section by hand.
This may involve a transfer outside the European Economic Area. The provider is Anthropic PBC in the United States. We rely on the European Commission's standard contractual clauses, and the pseudonymisation of strict dossiers is a supplementary measure. Our transfer impact assessment is on file and we send it to you on request.
5.4. Readers of a dossier
Investors on the tiers a founder selected, and recipients of a forward, see the four data points in 3.5 about the people named. A corporate subscriber sees every published dossier. From the moment a reader has read that data, what they do with it outside the platform is their own processing, and they have undertaken to use it only to decide whether to approach the company.
5.5. Authorities
We disclose personal data where the law, a court or a competent authority requires it. Where we lawfully can, we tell the person concerned.
5.6. Successor
If our business is sold or transferred, personal data goes to the successor under this statement, and we tell you.
6. How long we keep it
| Data | Retention |
|---|---|
| Invoices and supporting records | Seven years after the end of the financial year, under Belgian bookkeeping and VAT law. This takes precedence over a deletion request. |
| Account, organisation and dossier content | For as long as the account exists. On deletion the account and the people named in a dossier are anonymised immediately; backups holding the earlier state rotate out within ninety days |
| Reading log (3.6) and forwarding records (3.7) | Five years, matching the period during which the confidentiality undertakings run |
| Acceptance records (3.8) | Ten years after the agreement ends, matching the limitation period for contractual claims under Belgian law |
| Audit log (3.9) | Seven years, aligned with the bookkeeping records it often explains |
| AI runs (3.11) | Five years |
| Sessions and sign-in links | Expired sessions and links are deleted daily |
| Rate limiting counters | Twenty-four hours |
| Messages (3.10) | For as long as both accounts exist, then twelve months |
| Data subject requests (3.12) | Three years |
| Waitlist entries | Until you sign up or ask us to remove you, and in any case no longer than twelve months |
7. Your rights
You have the rights below under the GDPR. Write to hello@legendmakers.ai, or use your account page where indicated. We answer within one month, and we may extend that by two further months for complex requests, in which case we tell you. We may ask you to confirm your identity before acting on a request.
Access and portability. If you have an account, sign in and download everything we hold about you as a JSON file from your account page. Otherwise write to us.
Rectification. A founder edits the company profile in the portal. A published dossier is different: a change becomes a request to the analyst, because a published dossier never changes silently. A factual error we accept is corrected in a new, dated version. A person named in a dossier may ask us to correct their name, role, biography or LinkedIn address.
Erasure. Ask us from your account page or by e-mail. On execution we take any published dossier down, anonymise the people named in it, anonymise the account and revoke all sessions. We keep invoices for the seven years in article 6, and we keep what we need to establish, exercise or defend a legal claim.
Restriction. You may ask us to restrict processing while a dispute about accuracy or lawfulness is resolved.
Objection. You may object to processing we base on legitimate interest. We then stop unless we have compelling legitimate grounds that override your interests. One case is worth stating plainly: if you object to us recording that you opened a dossier, we cannot give you access to dossiers, because that record is the condition on which founders agreed to be read. A person named in a dossier may object to appearing in it; we then weigh that objection against the founder's agreement and the interest in an accurate dossier, and we tell you what we decide and why.
No automated decisions. We take none, so there is nothing to contest on that ground.
Complaint. Complain to us first; we would rather know. You may also complain to the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, www.gegevensbeschermingsautoriteit.be, or to the supervisory authority of the member state where you live or work.
8. Security
The platform runs on our own hardware in the EU. Access is by passwordless sign-in link, with a mandatory second factor for admin and editor roles. Sessions expire on their own, we revoke them on request, and we revoke all of them when an account is suspended or deleted. Every full dossier opening is logged. Passwords, where used, are stored as hashes. Uploaded files and extracted text are stored on our own object storage. Exports are watermarked. We keep an audit log of administrative actions.
If a breach of personal data is likely to result in a high risk to you, we tell you without undue delay, and we notify the Data Protection Authority within 72 hours where the law requires it.
9. Children
The platform is for businesses and their founders. We do not knowingly process data of anyone under 16.
10. Changes
We publish a new version of this statement rather than editing the existing one, and we date it. Where a change affects what we do with your data in a way that matters, we tell you by e-mail.
Previous versions are available on request.