Legal at UnDebify
Terms of Service, Privacy Policy, and Cookie Policy
The full Terms of Service, Privacy Policy, and Cookie Policy for the UnDebify platform. Use the links below to jump to each document.
Terms & Privacy v2.0 · Cookie Policy v1.8 · September 2026
Terms of Service
Version 2.0 · September 2026 · Governing law: Swiss law (FADP and Swiss Code of Obligations)
These Terms of Service ("Terms") and Privacy Policy govern access to and use of the UnDebify platform ("Platform"), operated by UnDebify, a company in formation under Swiss law ("UnDebify", "we", "us"). The Platform is provided to your company or co-founding team (the "Customer"). By creating an account or using the Platform, you accept these Terms on behalf of the Customer and confirm that you are authorised to do so. If you do not agree, do not use the Platform.
Important: UnDebify stores and processes commercial and financial data, including equity and ownership information and co-founder relationship data. Read these Terms carefully before entering any data into the Platform.
1. The Service
UnDebify is a founding team infrastructure platform designed to help early-stage co-founding teams manage ownership, roles, decisions, meetings, finances, goals, and tasks in a structured and transparent way.
The Platform currently includes the following modules:
- Dashboard - company health and personal score overview
- Goals - KPIs and quarterly objectives
- Milestones - milestone planning and review
- Tasks - task management
- Meetings - agendas, attendance, quorum, and linked items
- Resolutions - decisions, voting, and approval records
- Finances - balance, burn, and runway entries
- People - team members, roles, and responsibility areas
- Documents - internal document storage for your company
- Company - company profile and market data
- Ownership - cap table, share classes, transactions, and vesting
- Data Room - a curated selection of documents and records that can be shared with external parties under controlled access
- Activity Log - a record of actions taken in your workspace, visible to your team
- Investor Portal - a separate portal where invited investors can view data room materials and related startup information under controlled access. Investor accounts are created by invitation or by UnDebify admin grant, not by public self-signup
UnDebify is not a legal tool and does not constitute legal advice, financial advice, or tax advice. Ownership entries and decisions recorded in the Platform are operational records only and do not replace notarised documents, shareholder agreements, or legal instruments required under Swiss or other applicable law.
2. Eligibility
You may use the Platform if you are at least 18 years old and are accessing it for commercial or professional purposes. The Platform is intended for use by companies, founding teams, and other professional or commercial users, not by consumers in the sense of Swiss consumer protection law.
Company workspaces are currently limited to companies established in Switzerland. We intend to extend this to further European markets and will update these Terms when we do.
By signing up, you represent that you are authorised to enter into these Terms on behalf of the Customer (your company or co-founding team) and to bind it to these Terms.
3. Account Registration and Access
To use the Platform, you must create an account using a valid email address and provide accurate company and team information.
The Platform uses passwordless authentication. There is no password to set or remember. You sign in either through a one-time link sent to your registered email address, or with a passkey registered on your own device. Only one session per user is active at a time: signing in on a new device ends the previous session.
Because there is no password, access to your UnDebify account follows from access to your registered email address. You are responsible for securing that email account. Anyone who controls it can request a sign-in link.
If you lose access to your registered email address and have not registered a passkey, we cannot restore access to your account. Your company workspace and its data are not affected and remain available to your colleagues, but your individual login cannot be recovered and cannot be moved to a different email address. We strongly recommend registering a passkey when you first sign in.
You must notify us immediately through the contact form at if you become aware of any unauthorised use of your account.
4. Team Workspaces and Multi-User Access
The Platform supports shared workspaces where multiple co-founders and team members can access shared data. By inviting another person to your workspace, you confirm that you have the right to share that person's details and that they are informed of their data being entered into the Platform.
The Customer (the company or co-founding team, acting through the account holder who created the workspace) is the data controller for their workspace data. UnDebify acts as a data processor on behalf of the Customer for workspace-level data. See Part 2 (Privacy Policy) for full details.
Certain actions in the Platform require approval from more than one person before they take effect. Where such requirements apply, they are shown in the Platform at the time the action is submitted.
5. Acceptable Use
You agree to use the Platform only for lawful purposes and in accordance with these Terms. You agree not to:
- Enter false, misleading, or fabricated equity or ownership data
- Use the Platform to facilitate or conceal fraud
- Attempt to access data belonging to other users or workspaces without authorisation
- Reverse engineer, copy, or reproduce the Platform or parts of it
- Use automated tools to scrape, extract, or mass-download Platform data
- Share access to your account with third parties outside your workspace
6. Beta Access
The Platform is currently available as a beta product. Features may change, be removed, or behave differently than described. Beta access is provided without warranty of any kind. UnDebify reserves the right to modify or discontinue beta features at any time without notice.
We will use reasonable efforts to notify users of material changes via email or in-platform notification.
7. Intellectual Property
UnDebify retains all intellectual property rights in the Platform, including its design, code, workflows, and content. Nothing in these Terms transfers any intellectual property rights to you.
You retain ownership of all data you enter into the Platform. By entering data, you grant UnDebify a limited, non-exclusive licence to store, process, and display that data for the purpose of delivering the service to you. This licence ends when you delete the relevant data or close your account, subject to legal retention obligations.
8. No Legal or Financial Advice
The Platform assists with operational structure and team alignment. It does not provide legal advice, tax advice, financial advice, or notarial services. Equity splits, shareholder agreements, and other legal instruments must be reviewed and formalised by qualified legal counsel under applicable Swiss or other law.
UnDebify strongly recommends engaging a qualified legal partner before finalising any equity structure or co-founder agreement. The Platform supports that process - it does not replace it.
9. Fees and Subscription
Where applicable, use of the Platform is subject to the fees and subscription terms presented at the time of signup or plan upgrade. All fees are stated in Swiss Francs (CHF) unless otherwise specified and are exclusive of applicable taxes.
During the beta phase, access is free of charge and no credit card is required. You may select a plan at signup for future billing. Live card payment processing is not enabled in the current release, and charging will begin only with reasonable advance notice.
10. Closing Your Account or Workspace
Stopping your use of the Platform and having your data permanently erased are two separate things.
Cancelling the account from within the Platform makes the workspace inactive. Nothing is destroyed: your records are retained and remain available to you if you return. Cancellation requires the approval of every founder, so no single account can end a workspace on its own.
Permanent erasure is not self-service and cannot be triggered from within the Platform. To have a company workspace, or your individual account, permanently erased, send us a request through the contact form at . We process erasure requests under dual control: one person raises the request and a second approves it before it is executed. Once executed, the record and its related data are permanently deleted and cannot be recovered. Billing records such as invoices are retained where we are legally required to keep them.
Export your data before requesting permanent erasure. See section 21 for what the available exports contain and who can generate them.
UnDebify may suspend or terminate your account if you materially breach these Terms, if continued provision of the service creates legal or compliance risk, or if the Platform is discontinued.
11. Limitation of Liability
To the maximum extent permitted by Swiss law, UnDebify's total liability to you in connection with the Platform shall not exceed the fees paid by you in the 12 months preceding the event giving rise to the claim, or CHF 500 where no fees have been paid.
UnDebify is not liable for: loss of data caused by your actions or third-party actions; errors in ownership or financial data entered by you or your team members; disputes between co-founders arising from data recorded in the Platform; or consequential, indirect, or incidental damages of any kind.
12. Governing Law and Jurisdiction
These Terms are governed by Swiss law, excluding conflict of law rules. The courts of Zurich, Switzerland, have exclusive jurisdiction over any dispute arising from these Terms, unless mandatory statutory rules require otherwise.
For users based in the European Union or European Economic Area, mandatory consumer protection or data protection provisions of your country of residence may apply in addition to Swiss law.
13. Changes to These Terms
We may update these Terms from time to time. Where changes are material, we will provide at least 30 days notice via email or in-platform notification before the changes take effect. Continued use of the Platform after that date constitutes acceptance of the updated Terms.
Privacy Policy
UnDebify takes data privacy seriously. The Platform stores and processes commercial data, including equity ownership records, co-founder relationship information, and financial metrics. We are committed to handling this data with transparency, proportionality, and security.
This Privacy Policy applies to all users of the UnDebify platform and is governed by the Swiss Federal Act on Data Protection (FADP) and, where applicable to EU/EEA users, the EU General Data Protection Regulation (GDPR).
14. Who is Responsible for Your Data
UnDebify, a company in formation under Swiss law, is the data controller for personal data processed in connection with account registration, product usage, and communications. Until UnDebify is entered in the Swiss commercial register, it operates as a partnership between its founders, who are personally responsible for its obligations. Once registration is complete, these Terms and this Privacy Policy will be updated to name the registered company, which will assume those obligations.
For workspace data entered by a team, the Customer (the company or co-founding team, acting through the primary account holder) acts as controller of that data. UnDebify processes workspace data as a data processor under the Customer's instructions.
Data protection contact: the contact form at
15. What Data We Collect
ACCOUNT AND IDENTITY DATA
- Full name and email address
- Date of birth where held on your person profile
- Passkey credential data where you register a passkey. We store the public part of the credential only. The private key never leaves your device
- Account creation date and last login
- Language and appearance preferences
- Sign-in and security data: IP address, browser and device signals, and login event records
- First-party product usage events stored in our own database, for example portal page visits. These are never sent to an external analytics vendor
We do not store passwords. The Platform uses passwordless authentication, so no password or password hash exists for your account.
COMPANY AND TEAM DATA
- Company name, legal form, and country of incorporation
- Co-founder names, email addresses, and roles
- Team member profiles where added to a workspace
EQUITY AND FINANCIAL DATA
- Cap table entries: shareholder names, share classes, share counts, and transaction history
- Equity percentages and vesting schedules
- Financial metrics entered by the user: burn rate, runway, balance
DECISIONS AND GOVERNANCE RECORDS
- Decision logs, quorum records, voting records, and resolution text entered by users
- Meeting notes and agenda items
- Audit records of security-relevant and governance-relevant actions, including who performed an action and when
DOCUMENTS
- Files uploaded to your workspace or data room, and metadata about them
TECHNICAL LOGS
- Error logs and performance diagnostics used to maintain Platform stability and security. These are generated and held within our own infrastructure and are not sent to an external monitoring service
PROFILE AND PROFESSIONAL BACKGROUND DATA
- Bio text you choose to add to your profile
- LinkedIn URL where provided
- Profile photo where uploaded
Profile photo, bio, and LinkedIn URL are optional. These fields are not required to use the Platform, and you can update or delete them at any time from your account settings.
CONTACT DATA
- Phone number where provided voluntarily
- Business address or location where entered
Contact data beyond email is optional and entered at your discretion. By default it is used for team coordination within your workspace. If your workspace turns on Data Room sharing options such as team contact details or LinkedIn profiles, the selected fields become visible to the investors you have invited.
16. Legal Basis for Processing
We process your data on the following legal bases under FADP and GDPR:
- Contract performance - to deliver the service you signed up for (account data, workspace data, equity and financial data)
- Legitimate interest - to maintain Platform security and stability, and to understand how the Platform is used (error logs, performance diagnostics, audit records, first-party usage events)
- Legal obligation - where required by Swiss law, for example data retention requirements
- Consent - for any processing not covered above, including optional product communications beyond transactional emails
17. How We Use Your Data
We use the data we collect to:
- Operate and deliver the Platform and its features
- Authenticate your identity and secure your account, including sending sign-in links
- Send transactional communications, for example account confirmation, notification of a new passkey registered on your account, and plan changes
- Send product and collaboration notifications covering governance, tasks, meetings, finances, and optional product messages. Most categories can be adjusted in your account settings. Certain founder and ownership notices cannot be turned off, because they concern decisions that affect your stake in the company
- Understand how the Platform is used, based on first-party usage events and aggregated patterns
- Respond to support requests
- Comply with legal and regulatory obligations
We do not use your data to sell advertising or to build profiles for third-party use.
We do not send your workspace content to any external artificial intelligence or machine learning service, and we do not use it to train models. This applies to all workspace data, including ownership, financial, governance, and co-founder data.
18. Data Sharing and Third Parties
We keep the number of parties involved in operating the Platform deliberately small.
INFRASTRUCTURE AND EMAIL
Hosting, the database, file storage, and email delivery are all provided by Infomaniak Network SA under a signed data processing agreement. Infomaniak owns and operates its own datacentres in Switzerland, certified to ISO 27001 and ISO 9001. Under that agreement, Infomaniak informs us in advance of any change to the service providers it engages on our behalf, and we have the right to object. Sign-in links and transactional emails are sent over an encrypted connection through that same mail service, so no separate email delivery vendor is involved.
DEPLOYMENT TOOLING
Container images used to deploy the Platform are pulled from GitHub Container Registry, and our deployment pipeline runs on GitHub. This tooling is used to build and release the software. It does not process your workspace content.
SERVICES WE DO NOT USE
- Third-party analytics or usage-tracking services
- External error monitoring or performance monitoring services
- Content delivery networks
- Advertising networks or data brokers
- External artificial intelligence or machine learning services
PROFESSIONAL ADVISORS
Legal and accounting advisors, subject to professional confidentiality obligations.
ACCESS BY UNDEBIFY PERSONNEL
A small number of technical personnel can access workspace data where necessary to operate the Platform or to respond to a support request. Administrative changes made by our personnel are recorded in an internal audit log. Permanent erasure of a company or a user account requires two people: one to raise the request and a second to approve it. We do not access workspace content for any purpose other than operating the service and supporting you.
We will disclose your data to public authorities only where required by applicable law and after exhausting available legal remedies to protect your privacy where permitted.
We do not sell your data. We do not share equity, financial, or co-founder data with investors, partners, or other platforms, except where your workspace deliberately shares it through the Data Room and the related investor access controls, or where you give explicit, revocable consent.
19. Where Your Data Is Stored
The Platform is operated from Switzerland. Compute, the database, and uploaded files all run in a Swiss region of Infomaniak Public Cloud. This is set in the service configuration, not left to chance.
If data is transferred to processors outside Switzerland or the EU/EEA, we ensure adequate protection through standard contractual clauses or other mechanisms recognised under FADP and GDPR, and we will update this policy accordingly.
20. Data Retention
We retain your data for as long as your account is active. After that:
- A workspace whose plan has been cancelled becomes inactive. Its records are retained until permanent erasure is requested and executed
- Company workspace and individual account data are permanently deleted once we have processed and approved an erasure request. There is no automated self-service deletion timer in the product
- Data required for legal compliance, for example invoicing records, is retained for the period required by applicable law, even where the rest of the record has been deleted
- Technical logs (error and performance diagnostics) are written to the standard output of the application host and retained according to the host and container defaults of our infrastructure provider. There is no fixed application-level deletion schedule for these logs
- Audit records of governance and security-relevant actions are append-only: their content cannot be edited or deleted, apart from narrow technical fields that keep records linked to one another. They are retained for the life of the workspace, so that the history of decisions and ownership changes stays complete, and are removed only when a company workspace is permanently erased
The database and uploaded files are backed up daily to Swiss backup storage. Backups are retained on a rolling basis and are overwritten in the ordinary course, which means data deleted from the live Platform may persist in a backup until that backup expires.
21. Your Rights
Under FADP and, where applicable, GDPR, you have the following rights regarding your personal data:
- Right of access - you can request a copy of the personal data we hold about you
- Right to rectification - you can correct inaccurate data
- Right to erasure - you can request deletion of your data, subject to legal retention obligations
- Right to data portability - you can request your data in a structured, commonly used, machine-readable format
- Right to restriction - you can ask us to limit how we use your data in certain circumstances
- Right to object - you can object to processing based on legitimate interest
- Right to withdraw consent - where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing
HOW TO EXERCISE THEM
- For workspace data, the Platform provides two exports. Founders, and executives with Company or Finance responsibility, can generate a company export package containing your core company records in a machine-readable format, with checksums so a recipient can confirm the files were not altered. Founders can additionally generate an evidence pack, a readable report of the company's governance and ownership history, also with checksums.
Neither export currently covers every module in the Platform. Each package includes a file listing exactly what it contains and what it leaves out. If you need data that is not in either export, ask us through the contact form and we will provide it.
For personal data held about you as an individual, contact us through the form at and we will provide it in a machine-readable format. Where you are a member of a company workspace, requests concerning that company's records should be directed to the company, which is the controller of that data.
We will respond within 30 days. For complex or multiple requests, we may extend this period by a further 60 days with prior notification.
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch, or with the supervisory authority in your EU member state if applicable.
22. Security
We implement technical and organisational measures appropriate to the sensitivity of the data we process. These include:
- Passwordless authentication using one-time sign-in links and passkeys. No passwords are stored
- One active session per user at a time. Signing in on a new device ends any previous session
- Rate limiting and lockout controls on sign-in requests
- Encryption of data in transit (TLS 1.2 or higher), with HTTP Strict Transport Security enforced
- Origin and referer checks on state-changing requests, and SameSite restrictions on the session cookie, to protect against cross-site request forgery
- Uploaded files held in private object storage, encrypted at rest by our infrastructure provider, with every download authorised against your permissions at the time of the request
- Separation of company data enforced at database level rather than in application logic alone, so that data from one company workspace cannot be returned to another
- Role-based and permission-based access controls within workspaces
- Approval requirements from more than one person on defined governance actions, and unanimous founder approval to cancel an account
- Dual control on permanent erasure of a company or a user account, so that no single person on our side can execute it
- Audit records of security-relevant and governance-relevant events, with your workspace activity visible to your own team in the Activity Log module
- Infrastructure operated in ISO 27001 and ISO 9001 certified Swiss datacentres owned by our provider, who commits contractually to annual intrusion testing of that infrastructure
- Daily backups of the database and uploaded files to Swiss backup storage
- Regular security reviews during development
No system is perfectly secure. In the event of a data breach likely to result in a high risk to your rights, we will notify the competent supervisory authority (in Switzerland, the FDPIC) and affected users within the timeframes required by applicable law.
23. Cookies and Tracking
The Platform uses necessary and functional cookies only: to keep you signed in, remember which company or investor workspace you are viewing, handle passkey sign-in, and store your language and appearance preferences. A small amount of data is also held in your browser storage, including meeting minutes drafts saved as you write them.
We use no third-party analytics cookies, no advertising cookies, and no tracking pixels. Nothing on the Platform is loaded from a third-party service. We do record a limited set of first-party usage events on our own servers, described in section 15. No cookie consent banner is shown, because no optional and no third-party cookies are set.
The Cookie Policy at www.undebify.com/legal#cookies lists every cookie and browser storage item in full, with its purpose and lifetime.
You can manage cookies through your browser settings. Note that disabling session cookies will prevent you from staying logged in to the Platform.
24. Children's Data
The Platform is not intended for use by persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has registered, please contact us through the form at and we will delete the account promptly.
25. Changes to This Privacy Policy
We may update this Privacy Policy as the Platform evolves. Where changes materially affect how we process your data, we will notify you with at least 30 days advance notice. The version you accepted at registration remains the version that applies to you until we notify you of an update under this section. The current version is always available at www.undebify.com/legal#privacy.