Trust & Transparency

FoundersDeck is built on the principle that trust must be earned through transparency, not marketing claims. This page documents exactly where your data goes, who processes it, and how we protect it.

Data Residency

All data is stored and processed exclusively in Nuremberg, Germany.

  • Hosting provider: Netcup GmbH, Nuremberg, Germany
  • Data center location: Nuremberg, Bavaria, Germany
  • Legal jurisdiction: German law and EU regulations exclusively
  • Transatlantic data transfers: None

Legal Status

FoundersDeck is operated under German and EU law exclusively. We are:

  • Not subject to the US CLOUD Act
  • Not subject to FISA Section 702
  • Not subject to any non-EU government data access legislation
  • Not owned or controlled by any US parent company or VC fund

This means no foreign government can compel us to disclose your data through legal mechanisms that bypass EU protections.

Sub-Processor List

Under GDPR Article 28, we maintain a complete list of all sub-processors involved in delivering FoundersDeck. We will notify customers of any changes at least 30 days in advance.

ProviderPurposeLocationLegal Basis
Netcup GmbHServer hosting, databaseNuremberg, GermanyDPA
Resend, Inc.Transactional email deliveryEU processingDPA + SCCs
Cloudflare, Inc.DNS managementEU endpointsDPA + SCCs
Polar.shPayment processing (MoR)EUDPA

Changelog

  • 2026-03-25 — Initial sub-processor list published

Data Processing Agreement (DPA)

If you process personal data through FoundersDeck, a DPA is required under GDPR Article 28. We provide a pre-signed DPA for immediate use — no sales call, no email, no waiting.

Our DPA covers all data processing activities within FoundersDeck, including monitoring checks, incident detection, alerting, and status page rendering. It includes our complete sub-processor list and data flow documentation.

DPA download will be available at launch.

Data Flow

Here is exactly what happens with your data at each step:

1. Monitor Checks

Our server in Nuremberg sends HTTP/Ping requests to your monitored URLs. The response status, response time, and any error information is stored in our PostgreSQL database — also in Nuremberg. No data leaves Germany.

2. Alerting

When an incident is detected, alerts are dispatched based on your configured channels. Email alerts go through Resend. Slack/Discord/Webhook alerts go directly to the endpoint you specified. Alert content contains only your monitor name, status, and timestamp.

3. Status Pages

Public status pages are rendered server-side in Nuremberg and served with zero cookies, zero tracking scripts, and zero third-party requests. Visitor browsers connect only to our German server.

4. Payments

All payment processing is handled by Polar.sh as Merchant of Record. FoundersDeck never stores credit card numbers or payment credentials. Polar.sh handles billing, invoicing, and tax compliance.

Your GDPR Rights

Art. 15

Right of access — Request a copy of all personal data we hold about you.

Art. 16

Right to rectification — Correct inaccurate personal data at any time through your account settings.

Art. 17

Right to erasure — Delete your account and all associated data. Automated, no support ticket required.

Art. 20

Right to data portability — Export all your monitoring data, incident history, and configuration in open formats (JSON, CSV).

Art. 21

Right to object — Object to processing of your personal data at any time.

Questions?

If you have questions about our data practices, sub-processor list, or need assistance with your GDPR rights, contact us at info@foundersdeck.dev.