Policy PMF-Engine
Last update: 11 September 2026
Data protection is a top priority for us as a Switzerland-based company. That is why we implement controls to ensure your information remains protected and confidential throughout our collaboration.
This PMF-Engine Policy applies to all data that we process in connection with our platform services and tools on behalf of our clients. It applies to our platform environment (primarily hosted on Miro and Notion) and other third-party tools integrated. It does not apply to the personal data that we collect as a data controller.
A separate Privacy Policy explains how we manage personal data as a controller.
Venture Guidebook by A-QUANTO AG (or AQUANTO), is committed to the protection, confidentiality and privacy of the information and data entrusted to us, and we take appropriate measures to ensure that we comply with the applicable data protection regulations.
Our clients are responsible for complying with any applicable regulations or laws. This includes notifying, disclosing, and/or obtaining consent from individuals prior to transferring personal data to AQUANTO for processing.
We regularly review and update this policy and our measures to adapt to changing or new requirements. We publish the latest version on our website and recommend you read it periodically.
Our products and services
With us, our clients gain insights into their product-market fit, business, make better decisions, and maximise their impact and progress towards their goals. Our clients can use our tools to upload and structure information, access online frameworks, and use machine learning technology to validate decisions and concepts. AQUANTO and its network experts can access this information with our client's consent to provide insights and guidance as part of our offering and contractual obligations.
Collection, use and disclosure of personal data
We process data according to the instructions we receive from our clients. We instruct our clients to use personal data in connection with our services only when necessary. We have no direct control over the personal data we process on behalf of our clients, and it is not our responsibility, as we act as data processors. Our clients are in control of compliance with all applicable laws and regulations when transferring or uploading information.
We do not share data with third parties without our customers' express consent, and we never sell our clients' personal data to third parties.
Integrations with third parties
Our clients can implement third-party interfaces on our platform. These interfaces or integrations simplify and consolidate data between them and us. We have no control over these integrations and interfaces implemented by our clients.
It is up to our clients, as data controllers, to ensure that the connection of third-party data processing is carried out in accordance with the legal requirements. We are not responsible for the collection, use, monitoring, storage, or disclosure of personal data by these third parties integrated by clients, and we encourage you to read their privacy policies and ask questions about their privacy practices as they relate to you.
Security and confidentiality of personal data
We use various security technologies and organisational controls to protect the confidentiality and security of personal data. These procedures are designed to protect personal data from unauthorised access, use, damage or disclosure. We protect personal data using encryption, security certificates or strong multi-level authentication procedures. Additionally, appropriate physical, technical and organisational measures protect all personal data.
We cannot accept responsibility for external websites (including those of our clients), third-party content, or links to this information on our website, products, or services.
Storage of personal data
We retain personal data only for as long as necessary for the purposes for which it was collected, according to statutory requirements and any other legal obligation. When personal data is no longer needed for these purposes and no legal retention period requires us to keep it, we delete it.
Third-party data storage and processing
Our PMF-Engine relies on several third-party technologies (subprocessors) to deliver the service. The primary environments for our PMF-Engine are Notion and Miro, which host and store client data on Amazon Web Services (AWS) infrastructure. In addition, we use services such as Cloudflare (for content delivery and networking), Sentry (for error monitoring), Google Workspace, and Miro (for interactive collaboration) as integrated subprocessors to support the functionality of the PMF-Engine. All these providers are contractually bound to strict data protection terms and meet recognised security standards. For example, Miro enables real-time collaborative whiteboard sessions within our PMF-Engine offerings. Miro maintains strong security controls: data in Miro is encrypted in transit and at rest, and access to boards is governed by role-based permissions. Miro is compliant with the GDPR and other privacy regulations, and does not disclose user data to third parties for its own purposes. All subprocessors we engage (including Notion and Miro) undergo due diligence and are subject to ongoing monitoring to ensure they uphold the confidentiality and integrity of our clients' data. We do not share any platform data with third parties except as needed to operate the service and as authorised by our clients. ( Policy Notion ) ( Security & Privacy Notion ) ( DPA Notion ) ( Privacy Miro ) ( Security Miro ) ( GDPR Miro )
Where your data is processed and international transfers
Our subprocessors may process personal data outside Switzerland and the EU/EEA, mainly in the United States. Where a provider is certified under the Swiss-US and EU-US Data Privacy Framework, we rely on that adequacy; where it is not, we put in place either contractual clauses or our own controls. Data stays encrypted in transit and at rest, and we act only on our clients' instructions as data processor. The current list of subprocessors and information on the safeguards is available on request.
We work with the following subprocessors:
-
Notion: workspace hosting content and client information
-
Miro: collaborative whiteboard
-
Amazon Web Services (AWS): cloud infrastructure underlying Notion and Miro
-
Cloudflare: content delivery and networking
-
Sentry: error monitoring
-
Google Workspace: productivity and collaboration
-
OpenAI and Anthropic: AI features (see below)
Use of AI Services (OpenAI and Anthropic)
To extend our PMF-Engine's capabilities, we integrate generative AI services from OpenAI and Anthropic. These AI tools (such as OpenAI's GPT models and Anthropic's Claude) provide features like research, analytics, recommendations, and content validation within the PMF-Engine.
Any data sent to these AI models is processed solely to generate the requested output and is not used to train the providers' models. In practice, when a client uses an AI-powered feature, the relevant information (for example a text prompt or query) is securely transmitted to the AI provider's API, and a response is returned. OpenAI and Anthropic do not retain or use our prompts or outputs to improve their large-language models beyond this temporary processing. By default, OpenAI may retain API request data for a short period (up to 30 days) to monitor for abuse and ensure service quality, after which it is deleted from their systems. Anthropic similarly applies limited retention for API interactions and does not store conversation content long-term by default. We also offer a Zero-Data-Retention option on client request: if enabled, neither OpenAI nor Anthropic retains any of your data after generating the AI output, and prompts and responses are erased from the AI providers' servers once the interaction is complete. Whether by default or in zero-retention mode, your data is not used to train OpenAI's or Anthropic's models. We remove or anonymise personal data beyond what is necessary in these AI requests, and all communications with the AI services are encrypted in transit. Both providers make a Data Processing Addendum and appropriate transfer safeguards available for international transfers. ( Policy Anthropic ) ( API Anthropic ) ( Privacy Policy OpenAI ) ( Enterprise Privacy OpenAI ) ( API OpenAI )
Continued GDPR and FADP compliance
We regularly review and update our platform's data protection measures to align with evolving regulations and practices. Notion, Miro, OpenAI, Anthropic, and our other subprocessors each affirm commitments to privacy, including adherence to the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP). Notion offers a Data Processing Addendum, uses Standard Contractual Clauses to transfer data internationally, and employs encryption and access controls to safeguard client content. Miro's infrastructure is SOC 2 Type II audited and runs on secure AWS data centres, and Anthropic and OpenAI maintain SOC 2 compliance and documented security controls for their AI services. All personal data processed on our platforms remains under our control as the data processor, and we act only on our clients' instructions when handling that data. We do not use or disclose any client data for our own purposes or to unauthorised parties. Where a client integrates additional third-party tools with our PMF-Engine, we will work with them to check that those tools meet the necessary privacy requirements, though the client, as data controller, bears responsibility for such integrations. If you have any questions about our platform's privacy protections, including the use of AI tools, Miro, Notion, or other subprocessors, please contact our data protection contact as listed in our Privacy Policy. We will continue to update this Policy PMF-Engine to reflect any changes in our data processing or the addition of new subprocessors.
Data protection measures
Notion implements several measures to protect the confidentiality of data:
-
Encryption: Data is encrypted both at rest and in transit to prevent unauthorised access.
-
Access controls: Strict access controls ensure that only authorised personnel can access personal data.
-
Monitoring and auditing: Continuous monitoring and regular security audits identify and address potential vulnerabilities.
-
Incident response: Notion has a documented incident response plan to manage and mitigate any data breaches promptly. ( Notion Privacy Policy ) ( Notion security and privacy )
Subprocessors, standards, and change notification
Subprocessors must adhere to the same data protection standards, and we vet them for strong security practices. When we add or replace a subprocessor, we update this policy and notify clients as set out in their contract, in line with Article 28 GDPR. Notion likewise provides a list of its subprocessors and lets customers receive notifications about new ones. ( Notion subprocessors )
You can review Notion's Privacy Policy and Data Processing Addendum for more detailed information.
Data protection contact
If you have any questions about this policy or our data protection practices, please use the contact information in our Privacy Policy to contact us.
Version history
This is Version 1.4, effective 11 September 2026. Earlier versions:
-
Version 1.3, 10 February 2026
-
Version 1.2, 6 May 2025
-
Version 1.1, 14 January 2025
-
Version 1.0, 3 September 2024