Tero

Privacy policy

Last updated 13 July 2026

Who we are

Tero (tero.capital) provides software for UK angel investors: due-diligence research, portfolio monitoring and news alerts. The data controller is TRCPL Ltd, trading as Tero: company number 17336273, registered in England and Wales, ICO-registered (contact: support@tero.capital). Tero is software, not a fund, custodian or financial adviser.

What we collect and why

Account data (email, name, password hash), used to operate your account. Lawful basis: contract.

Portfolio data you enter (companies, amounts invested, dates, ownership), used to provide dashboards, monitoring and briefs. Lawful basis: contract. This is your data; we never share or sell it, and platform administrators cannot browse it. Our admin tooling shows usage counts only.

Documents you upload (decks, memos), processed to produce your diligence report, stored privately, deletable by you. Lawful basis: contract.

Research on third parties (founders, companies) is compiled from public sources at your request. Lawful basis: legitimate interests (investor due diligence). Reports flag unverified items and are decision support, not automated decisions.

Support messages and invites, used to respond to you and deliver invitations. Lawful basis: legitimate interests.

Service usage metrics: when you signed in last and how much AI processing (token counts, number of searches) your account used, to monitor costs, capacity and abuse. These are counts and timestamps only, never the content of your reports or questions. Lawful basis: legitimate interests.

Where your data lives

Your data is stored and processed in London. Database and documents: Supabase, hosted in AWS eu-west-2 (London). Application compute: Vercel serverless functions, London region (static pages are served from Vercel's global edge network).

Named sub-processors: Supabase (database & auth, London), Vercel (hosting), Anthropic (AI processing; API inputs are not used to train Anthropic's models and are retained only briefly for abuse monitoring), Resend (email delivery). Each acts under our instructions, under a data-processing agreement. We do not sell data to anyone.

Public-record research providers (Companies House, the FCA register, search and traffic data providers) receive only the company names, domains and director names you ask us to research, never your identity, portfolio or documents.

No advertising trackers and no advertising cookies: sign-in state is kept by Supabase Auth, and our visitor analytics (Vercel Web Analytics) are cookieless.

International transfers

Where a sub-processor processes data outside the UK (for example Anthropic or Resend in the United States), the transfer is safeguarded by that provider's data-processing agreement incorporating the UK International Data Transfer Addendum / EU Standard Contractual Clauses, as required by UK GDPR.

Retention

Your data stays while your account is active. Delete your account (Profile → Delete my account) and everything (portfolio, reports, documents, messages) is erased immediately and irreversibly from the live database. Backups roll off within 30 days.

Your rights

Access and portability: export all your data as JSON from your Profile at any time.

Erasure: delete your account yourself from your Profile. No email required, no waiting.

Rectification and objection: edit your data in-app, or contact support@tero.capital.

You can complain to the ICO (ico.org.uk) if you believe we've mishandled your data.

Security

Row-level security isolates every account at the database layer; documents live in per-user private storage; all traffic is encrypted in transit and data encrypted at rest; passwordless and password sign-in are both handled by Supabase Auth, so we never see or store plaintext passwords.

Questions? support@tero.capital · Tero is software, not a fund or adviser. tero.capital