Legal
Privacy Policy
Last updated: 1 September 2026
1. Data controller and scope
Bravae Business Services SLU (a Feu Du Nord Investments company), Avinguda Diagonal 497, 08029 Barcelona, Spain, is the controller of personal data processed through Tentadeal. Contact: customer.service@bravae.com.
This Privacy Policy describes how Tentadeal processes personal data in connection with the platform. It forms part of the framework described in the Terms of Service and should be read together with them and with the Cookie Policy.
Tentadeal is intended exclusively for professional and business use. The personal data processed is accordingly limited, in the ordinary course, to professional contact and role information of people acting for companies, buyers and investors.
2. What we process and why
Account and intake data — name, role, work email, phone and company details submitted through the intake forms — to review applications, operate private workspaces, deliver notifications and administer access. Legal basis: performance of a contract and pre-contractual steps.
Anonymous profile and activity data — structured, banded business signals (sector, region, revenue band, transaction openness), investment theses, indications of interest, consents, Conversation Ranges and platform actions — to provide the matching, discovery, review and reveal functionality that participants request. Legal basis: performance of a contract.
Market-sourced business contact data — professional contact details of companies mapped from professional market sources — used solely to present those companies in anonymised, non-identifying form and to approach them confidentially, through human outreach, when a qualified buyer registers interest. Legal basis: legitimate interest in providing B2B introduction services. These contacts are never exposed to other participants before the company itself decides to join, and the persons concerned can object at any time (see section 9).
Payment data — processed by Stripe as an independent payment provider; Tentadeal does not store card details. Legal basis: performance of a contract and legal obligations.
Technical and security data — IP addresses, request metadata, session identifiers and audit records of platform actions (reviews, consents, payments, reveals) — to authenticate users, secure the platform, prevent fraud and abuse, enforce rate limits and resolve disputes. Legal basis: legitimate interest in the security, integrity and auditability of the platform.
Communications — transactional emails (verification, sign-in links, platform notifications) delivered through Resend. Legal basis: performance of a contract.
3. Confidentiality by design
Identity data is stored separately from anonymous profiles. Information designated as Reveal-protected — including participant identity, exact location and contact details — is not intentionally disclosed by Tentadeal to another participant before a completed mutual Reveal, except where the participant has expressly authorised disclosure or where disclosure is required by law.
Pre-reveal fields are structured and filtered to prevent accidental disclosure of contact details or identifying information. Participants are contractually required not to include identifying information in fields intended to remain anonymous, and not to attempt to infer the identity of an anonymous participant.
Anonymisation reduces but cannot completely eliminate the possibility of identity inference by combining available information with external knowledge. Tentadeal designs its banded signals to keep that risk low, but cannot guarantee its complete absence.
4. Matching and automated processing
Tentadeal uses automated processing to order, filter and suggest anonymous profiles against investment theses (matching). Matching results are indicative signals only.
No decision producing legal effects or similarly significant effects on a participant is taken solely by automated means: access to the network, approvals, outreach to market-sourced companies and dispute handling are always subject to human review.
5. Who receives personal data
Counterparties, upon Reveal — when the participants concerned give the explicit consents required by the platform and the applicable fee is settled, the identity and contact details designated for disclosure are shared with the specific counterparty. Legal basis: the participant's consent, expressed through the Reveal mechanism.
Service providers acting as processors — hosting and cloud infrastructure providers, the database provider, Stripe (payments) and Resend (email delivery) — under data processing terms consistent with EU law.
Tentadeal's operating team — the Feu Du Nord backoffice personnel who perform reviews, outreach and support, under confidentiality obligations.
Public authorities — where disclosure is required by applicable law or by a binding order.
Tentadeal does not sell personal data.
6. International transfers
Some service providers may process data outside the European Economic Area. Where that is the case, transfers rely on an adequacy decision (including the EU-U.S. Data Privacy Framework where applicable) or on Standard Contractual Clauses, together with supplementary measures where appropriate.
7. Retention
Account and workspace data is kept while the account is active and thereafter as required for legal obligations (typically six years for commercial records in Spain).
Intake submissions that are rejected or never completed are kept for a limited period for audit and fraud-prevention purposes and then deleted or anonymised.
Market-sourced contact data is removed upon objection or when it is no longer relevant to the introduction service.
Audit records, consents, payment records and reveal records are retained for as long as necessary to evidence the operations they document and to comply with legal obligations.
8. Security
Tentadeal applies technical and organisational measures appropriate to the risk, including separation of identity data from anonymous profiles, hashed authentication tokens, encrypted transport, access controls, rate limiting and audit logging.
As stated in the Terms of Service, no internet-based service can guarantee absolute security. Where a security incident affecting personal data occurs, Tentadeal will act in accordance with its obligations under applicable data protection law, including notification duties where they apply.
Once information has been lawfully disclosed through a Reveal, or otherwise transferred by a participant outside systems controlled by Tentadeal, its further storage, security and use are the responsibility of the party holding it.
9. Your responsibilities as a participant
When you submit personal data relating to other people — for example, colleagues or representatives — you confirm that you are entitled to provide it for the purposes described in this Policy.
When you receive personal data through a completed Reveal, you become an independent controller of that data. You are responsible for processing it lawfully, for your own compliance with applicable data protection law, and for any further disclosure you make.
You should not submit sensitive personal data or information beyond what the platform's structured fields request; the platform is designed to operate on limited, professional, mostly non-personal business signals.
10. Your rights
You may exercise your rights of access, rectification, erasure, restriction, portability and objection by writing to customer.service@bravae.com. Where processing is based on legitimate interest — including the processing of market-sourced business contacts — you may object at any time, and the data will be removed unless compelling legitimate grounds prevail.
You may also lodge a complaint with the Agencia Española de Protección de Datos (AEPD) or with your local supervisory authority.
11. Cookies
Tentadeal uses only strictly necessary cookies, as described in the Cookie Policy. Web analytics are collected without cookies and without persistent identifiers.
12. Changes to this Policy
Tentadeal may update this Policy where reasonably necessary because of legal, regulatory, security, technical or product changes. The version in force and its effective date are published on this page. Where a change materially affects how personal data is processed, Tentadeal will take reasonable steps to inform affected participants.
