DDScore.ai
For Investors For Evaluators For Founders Example Report Pricing News About
Sign In
For Investors For Evaluators For Founders Example Report Pricing News About Sign In

DDScore.ai — Privacy Statement (Register Description)

Effective date: 13 August 2026

2026.08.13 22:00

This document is provided in accordance with the EU General Data Protection Regulation (GDPR). It describes how personal data is processed in connection with services provided by DDScore.ai.

1. Data Controller

Playful Pixels Oy Business ID: 2410516-5 Address: Kotipolku 5, 02730 Espoo, Finland Email: [email protected]

Playful Pixels Oy is the controller for the register described in this document. For personal data contained in documents a user submits for analysis, and for public-source background data checked on that user's instruction, the user is the controller and Playful Pixels Oy acts as processor under the Data Processing Addendum (see Section 7).

2. Contact Person for the Register

Name: Mikko Heilimo Email: [email protected]

3. Name of the Register

DDScore User and Customer Register.

This register covers users and customers of the Service. Individuals named inside materials submitted for analysis are not part of this register; they are covered by the processor arrangement described in Section 7.

4. Purpose of Processing Personal Data

Personal data stored in the register is used for:

  • Providing and developing DDScore.ai services
  • Customer communication and support
  • Fulfilling legal obligations
  • Managing user accounts and subscriptions
  • Service analytics and improvement (including the use of anonymous, aggregated statistical data described in Section 7)
  • Administering survey campaigns, including survey answers, the eligibility check, promotional entitlements and the campaign messages defined in the Campaign Terms
  • Marketing communications (only with explicit user consent)

Playful Pixels Oy does not profile users of the Service.

The Service can analyse the professional background of an individual named in materials submitted by a user. It does so only where the user switches that analysis on for that specific individual. The user decides whether any such analysis is carried out and about whom, acts as controller for it, and is responsible for having the legal basis required under applicable EU and national law. Playful Pixels Oy carries out that analysis solely on the user's instruction, as processor under the Data Processing Addendum.

No decision producing legal effects concerning a data subject, or similarly significantly affecting them, is taken by Playful Pixels Oy based solely on automated processing within the meaning of Article 22 GDPR. Analysis outputs are informational inputs to decisions taken by our users.

5. Legal Grounds for Processing

The processing of personal data is based on:

  • User's consent (Article 6 (1)(a) GDPR) — for electronic marketing
  • Contractual necessity (Article 6 (1)(b) GDPR) — including the performance of a survey campaign a user has asked to join
  • Legal obligations (Article 6 (1)(c) GDPR)
  • Legitimate interest (Article 6 (1)(f) GDPR), such as customer relationship management, security, abuse prevention and service improvement

6. Contents of the Register

The register may contain the following data:

  • Name
  • Email address
  • Phone number
  • Company name (if applicable)
  • Country
  • VAT ID (if applicable)
  • IP address
  • Device hash — a one-way hash used only to detect and prevent fraudulent or abusive use of the Service, containing no information about the device, its configuration or its contents
  • User account data
  • User settings and consents within the service (e.g., language preferences, marketing consent)
  • Payment details (processed by Stripe; not stored directly)
  • Campaign audience and role, survey answers, campaign source, timestamps, connected account reference and e-mail, the result of the automated eligibility check, entitlement records, report-use trigger, campaign-message status, and the accepted Campaign Terms version

7. Processing of Personal Data in Analysis Context

DDScore.ai analyses submitted business documents on behalf of the user, using AI-powered analysis combined with mathematical methods, including proprietary Advanced Probabilistic Analysis. These documents may contain personal data relating to third parties, such as team members, founders, or other individuals mentioned in pitch decks or business plans.

Such data is:

  • Processed solely for the purpose of generating the requested analysis
  • Never added to the DDScore customer register
  • Source files are deleted immediately upon completion of report generation; the generated report is deleted within 24 hours of generation (subject to limited exceptions described in Section 13)
  • Processed solely on the documented instructions of the submitting user. Where the analysis includes a check of an individual's professional background against public sources, the user enables that check for each individual separately. The user acts as controller, decides whether and about whom the check is carried out, and determines the legal basis; Playful Pixels Oy acts as processor under the Data Processing Addendum.

The submitting user is responsible for ensuring they have the right to submit any personal data contained in uploaded documents, for enabling any background check, and for any information obligation toward the individuals concerned.

Public sharing (share link function): If the user chooses to publish a report or main image via the in-service share link function, the published version is produced by a rule-based anonymization designed to remove all personal data. It removes from the published version the entire team section of the report and any other personal data appearing elsewhere in the report. The company name and the general analytical content of the report remain visible. No automated system is infallible. The submitting user is responsible for verifying that the published content does not contain personal data they do not have the right to share, and is reminded by the user interface to do so before activating the share link.

Anonymous statistical data: After analysis, the Service retains anonymous, aggregated statistical data consisting of the 12 section scores, GICS-based industry classification, country/region, and timestamp. This data contains no link to the user or to the submitted material, is not personal data within the meaning of the GDPR, and is retained indefinitely for product development purposes only. It is not used to train machine learning models and is not transferred to third parties.

Survey campaigns: Survey answers, eligibility and entitlement records are processed by Playful Pixels Oy as controller, on the basis of contractual necessity to perform the campaign the user asked to join, with legitimate interest applying to proportionate duplicate and abuse-prevention checks and to evaluating and improving the Service.

8. Regular Sources of Data

Personal data is collected from:

  • Users themselves during account creation or usage
  • Contact forms and support interactions
  • Optional campaign survey forms and the connected DDScore account
  • Billing and payment systems
  • Website usage and analytics tools

9. Regular Disclosures of Data

Data may be disclosed to:

  • Payment processors (e.g., Stripe)
  • Third-party AI model service providers, under confidentiality and GDPR-compliant contracts
  • Authorities upon valid legal request

Playful Pixels Oy's own servers are located in a machine room it operates itself in Finland. No external party administers them or has access to them.

If the user activates the in-service share link function, the published version of the report or main image is made publicly accessible via the open Internet at the user's voluntary choice (see Section 7).

We never sell user data. Data is not disclosed to third parties for unrelated marketing.

10. Transfer of Data Outside the EU or EEA

Data is primarily stored and processed within the EU/EEA. If processing occurs outside the EEA, appropriate safeguards — such as Standard Contractual Clauses (SCCs) — are in place to ensure adequate protection in accordance with GDPR.

11. Data Protection Principles

Data is stored securely using industry best practices:

  • TLS 1.3 encryption in transit and AES-256 encryption at rest
  • Role-based access controls and multi-factor authentication for staff. In the context of support-request handling, access to submitted materials is restricted to the support team and the development team.
  • Hard-coded automatic purge: uploaded source files are deleted immediately upon report completion, and generated reports are deleted within 24 hours of generation, unless a share link is active — see the retention table in Section 13.
  • Regular vulnerability scanning and third-party penetration testing
  • Back-up, business-continuity and disaster-recovery plans for system infrastructure and metadata (excluding processed documents)

No Training: We do not use personal data, uploaded documents, or generated reports to train or fine-tune machine learning models. The anonymous statistical data described in Section 7 is also not used for training and is not transferred to third parties.

12. Right of Access and Correction

Users have the right to:

  • Request access to their personal data
  • Correct inaccurate data
  • Withdraw consent at any time
  • Request deletion (right to be forgotten)
  • Restrict or object to data processing
  • Receive their data in a portable format
  • Lodge a complaint with the Finnish Data Protection Ombudsman

To exercise these rights, contact [email protected]. We reply within one (1) month, extendable by two (2) months for complex requests.

For personal data processed in the analysis context described in Section 7, the submitting user is the controller and is the correct addressee for such requests. We assist that user as required under the Data Processing Addendum. If you do not know who submitted the material, you may contact us at [email protected] and we will forward your request to the controller where we are able to identify them. Because of the deletion periods set out in Section 13, this is often no longer possible.

13. Data Retention (Zero Trace Policy)

Data typeRetention period
Uploaded source filesAutomatically and permanently deleted immediately upon completion of report generation
Generated analysis reportsAutomatically and permanently deleted within 24 hours of generation, regardless of whether accessed. Where a share link is activated, the report is retained for as long as the share link is active and is deleted within 24 hours of the link being deleted.
Public-source background data (processor role)Deleted with the related report, and therefore subject to the same retention period as the report
Published share content (when share link function is used)Retained while the share link is active; removed from our servers immediately upon deletion of the share link or closure of the account
Support ticket attachments (report and any voluntarily attached source materials)14 days from submission, extendable by mutual agreement of both parties
Anonymous statistical data (12 section scores, GICS classification, country/region, timestamp)Retained indefinitely for product development. Not personal data.
Account & subscription recordsDuration of customer relationship + 10 years (Finnish Accounting Act)
Technical logs24 months
Device hash10 years
Support tickets (text content)24 months after last correspondence
Incomplete or unconnected campaign submissions30 days
Identifiable campaign survey answersDeleted or effectively anonymised 12 months after campaign closure
Campaign terms acceptance, eligibility and entitlement evidenceCampaign duration plus the period needed to resolve any related claim, then deleted or minimised
Marketing consent recordWhile the consent remains active; after withdrawal, only the record needed to honour the withdrawal and to demonstrate compliance is kept

Please remember to download your analysis report before it expires; both the report and the source files are subject to the deletion schedule set out above.

© 2026 Playful Pixels Oy — All rights reserved.

DDScore.ai - Make Better Decisions

Company

Login For Investors For Evaluators For Founders Pricing News About

Legal

Terms of Service Data Processing Addendum Privacy Policy Register Description

© 2026 DDScore.ai — A Playful Pixels Product