Server room aisle with teal accent lighting
← Back to Potentia

Data Protection

Last updated: August 2026 · Horizon Grid

This page describes the technical and organisational measures SIA "Horizon Grid" takes to protect data processed by Potentia, and how to exercise your data subject rights.

Safeguards

  • Consent is required before any account, file, or pasted text is read — enforced at the API level, not just in the UI.
  • Uploaded files (pitch decks) are parsed for text and then discarded — the file itself is never stored.
  • An optional LinkedIn connections export, if uploaded, is reduced to two aggregate counts the moment it's processed — no other person's name, email, profile link, or job title is ever stored, logged, or shown.
  • Website URLs a subject provides are fetched server-side with protections against being redirected to internal or private network addresses.
  • Passwords are stored hashed, never in plain text.
  • A report in the lowest score tier is never eligible to become a public badge, protecting subjects from a bad result being spread.

Sub-processors

We use a small number of specialist providers to run Potentia, each processing only what their role requires:

  • Vercel Inc. — application hosting and the KV database that stores request and connected-data records.
  • Stripe — payment processing; we never see or store full card details ourselves.
  • Google LLC — Gmail for transactional emails (consent links, reports, reminders) and Google Analytics for site usage statistics.
  • Serper.dev — search-snippet lookups used only as a fallback when a directly-fetched page is blocked, and only for URLs a subject themselves provided.
  • GitHub Inc. and X Corp — OAuth sign-in only, limited to the data scope shown on the consent screen before a subject connects.

Where a sub-processor is located outside the EEA, transfers to it rely on that provider's Standard Contractual Clauses. We do not sell personal data, and we do not use any sub-processor to build profiles of people who have not themselves gone through Potentia's consent flow.

Exercising your rights

Subjects can revoke a request's access at any time via their own consent link — this deletes the underlying connected data immediately. For access, rectification, erasure, or portability requests beyond that self-service control, reach us via Contact.

Data controller

SIA "Horizon Grid", registration no. 40203602016, Marijas iela 18A-10, Riga, LV-1011, Latvia, is the data controller for personal data processed through Potentia. Contact: andreyfrost@gmail.com. Full registration details are on the Legal Notices page.