Trust & Security

How GPX handles your data.

An institutional summary of where your information lives, who processes it, how it is protected, and how you can have it removed. Every claim on this page describes controls that are in place today.

Last updated 10 July 2026

01

Data handling

Documents you upload — teasers, information memoranda, term sheets and similar files — are parsed entirely in your browser. Only the extracted text is transmitted to GPX and to our matching provider, OpenAI, for analysis. The extracted text of a document is its substantive content, so please only upload material you are comfortable sharing for that analysis.

GPX drafts introductions and outreach for you to review. GPX never sends messages or outreach on your behalf. Any hands-on, managed outreach is only available through a separate Greenpeak advisory engagement and only with your written approval for each message.

02

Encryption & hosting

All data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256. The primary database, authentication service and file storage are hosted on Supabase infrastructure in the European Union, region eu-west-1 (Ireland). Backups are retained in the same region.

03

Subprocessors

The following subprocessors handle limited categories of your data on our behalf. This list matches the subprocessors named in our Privacy Policy.

SubprocessorPurposeRegion
SupabaseDatabase, authentication and file storageEU — eu-west-1 (Ireland)
StripePayments and subscription billingEU / US (global processor)
ResendTransactional email deliveryEU / US
ApolloContact enrichment for decision-maker intelligenceUS
OpenAISemantic matching and embeddings for document analysisUS (zero data retention on API)

04

Data retention & deletion

Account information and any briefs you upload are retained for as long as your account is active. On request following account closure, all associated personal data and uploaded-brief content is deleted from production systems within 30 days. Backup copies expire on the standard backup rotation.

To request deletion, email privacy@101globalcapital.com from the address on your account.

05

Security practices

  • Role-based access control for every application surface.
  • Row-level security enforced at the database layer on all customer data.
  • API keys are hashed at rest and shown to you exactly once at creation.
  • Service credentials are scoped to least privilege and rotated on staff change.
  • Administrative access is audit-logged with immutable records.
  • Production secrets are stored in a managed secret store, not in source control.

06

Breach notification

In the event of a confirmed personal-data breach affecting your account, we will notify you without undue delay and, in any case, within 72 hours of becoming aware of the breach, together with the information required to understand its scope and any recommended action on your side.

07

Certifications

GPX is not yet SOC 2 certified. A SOC 2 Type II readiness programme is planned for 2027. Until then, the controls described on this page — encryption, EU hosting, RLS, least-privilege access, audit logging and breach notification — are the controls we operate today. We do not claim any certification we do not hold.

08

Security contact

For security reports, vulnerability disclosures or urgent questions about data handling, contact the security role alias:

security@101globalcapital.com

Monitored by the GPX security team — not a personal mailbox.

Last updated 10 July 2026. Operating entity: Greenpeak Investment Consulting, Dubai UAE.

Privacy PolicyTerms of Service