Integration Data Access Authorization
One-time company authorization for connecting third-party systems to Lunaseed.
ONE-TIME COMPANY AUTHORIZATION. This Authorization is accepted once, the first time an authorized Founder connects any Company integration through Lunaseed. After acceptance, it governs future Company-approved integrations without requiring the Founder to accept this document again for each connection. The accepted version and audit record are locked as historical evidence of the authorization.
This Integration Data Access Authorization (the “Authorization”) is between Lunaseed Inc. (“Lunaseed”) and the company on whose behalf an authorized founder accepts it (the “Company”). It governs Lunaseed’s access to third-party business systems that the Company chooses to connect to Lunaseed now or in the future.
This Authorization does not itself select any integration, account, data category, historical period, or recipient. Those choices are made through the product when an authorized Company user initiates a connection or other permitted action.
1. One-Time Acceptance and Company Record
The Founder accepts this Authorization once on behalf of the Company. Lunaseed may automatically create and retain an acceptance record. The Founder does not manually complete these fields.
The acceptance record is evidence of the authorization actually given at that time. It is not editable by the Founder or other users after acceptance. A later withdrawal, account closure, or deletion request does not rewrite the historical acceptance record, although future access and retained data remain subject to the withdrawal and deletion provisions below.
2. What the Company Authorizes
By accepting this Authorization, the Company authorizes Lunaseed, directly and through approved service providers, to connect to third-party operating systems, software services, accounts, or data sources that the Company later chooses to connect through the Service.
For a connection initiated by an authorized Company user, Lunaseed may receive, retrieve, transmit, parse, normalize, index, analyze, structure, store, and otherwise process the information made available through the permissions granted for that connection, solely to provide Lunaseed’s diligence and related platform functionality.
This Authorization applies to future Company-approved integrations without requiring a new acceptance of this document each time. The act of selecting a provider, account, permission, scope, or historical period in the product is an operational instruction under this Authorization, not a new legal agreement.
3. Company Control Over Each Connection
This Authorization does not give Lunaseed unrestricted access to Company systems. A source system is accessed only when an authorized Company user initiates or approves the applicable connection through Lunaseed and completes any authentication or permission steps required by the source provider.
For each connection, the source provider or Lunaseed interface may display available accounts, permissions, data categories, or historical periods. The Company controls the choices made through that connection flow, subject to the source provider’s technical limitations.
4. Read-Only Snapshot Model; No Write Access
Lunaseed’s standard diligence integration model is read-only. Lunaseed does not use a standard integration connection to create, edit, delete, approve, submit, transfer, or otherwise modify records in the connected source system.
Where supported, Lunaseed uses temporary authorization to capture a point-in-time snapshot of permitted information and then ceases ongoing source access after capture is completed, subject to temporary technical persistence reasonably necessary to complete the transfer, verify completion, recover from interruption, or perform another Company-initiated connection or refresh.
A source provider may technically describe broader permissions in its authorization interface than Lunaseed actually uses. Lunaseed will use the connection only for the authorized, read-only Company purpose described in this Authorization and the applicable product flow.
5. Authentication, OAuth, and Credentials
Connections may use OAuth, access tokens, API credentials, or other authorization mechanisms supplied by the source provider. The Company should use only Lunaseed’s designated connection flow and should not place passwords, private keys, or other source-system credentials into ordinary Lunaseed text fields.
Lunaseed and approved integration infrastructure providers may handle connection tokens only as reasonably necessary to establish and operate the authorized connection. Tokens do not authorize Lunaseed to use a source account for unrelated purposes.
6. Authority of the Founder and Company
By accepting this Authorization, the Founder represents on behalf of the Company that the Founder is authorized to provide this Company-level authorization and that the Company has the right to permit Lunaseed to access and process data from systems the Company later chooses to connect.
The Company is responsible for ensuring that users who initiate future integrations have appropriate Company authority and Lunaseed permissions. Acceptance of this Authorization does not itself grant a user permission to connect a system; product permissions and Company authorization still control who may initiate a connection.
7. Data Scope, Historical Range, and Source Limitations
The categories and historical periods available through an integration vary by provider, API, Company account configuration, permissions, and product selection. Lunaseed may offer standard retrieval windows such as 3, 6, 12, or 24 months, with 12 months commonly used as a default where supported, but some providers may offer shorter, longer, or otherwise limited periods.
The Company’s actual data scope for a connection is determined by the source system, the permissions granted, and the choices made in the connection flow. No fixed integration name, account, data scope, or historical period is embedded into this one-time Authorization.
8. Use of Integration Data in Lunaseed
Lunaseed may use authorized integration data to create structured records, source-linked evidence, Fact Sheets, factual extractions, classifications, indexes, embeddings, Carter context, Investigation context, and other diligence outputs or platform functionality selected by the Company or an authorized organization user.
Integration-derived information may remain in Lunaseed after the live source connection ends because the snapshot and derived outputs can form part of the Company’s diligence record, subject to applicable permissions, retention, and deletion rules.
9. Sharing With Venture Firms and Other Recipients
This Authorization governs access to Company-approved source systems; it does not, by itself, authorize Lunaseed to disclose integration-derived information to a particular venture capital firm, investment firm, or other recipient.
Any disclosure of Company diligence information to a requesting firm remains subject to the applicable Diligence Data Sharing Authorization, workspace permissions, and other Lunaseed agreements. A new requesting firm does not require the Company to re-accept this Integration Data Access Authorization, but it may require a separate data-sharing authorization for that firm.
10. Future Connections, Refreshes, and Reconnections
After the Company has accepted this Authorization once, future integrations, reconnects, and Company-initiated refreshes do not require acceptance of this document again. The authorized user still must complete the operational connection flow, including any source-provider authentication, account selection, or permission approval required for that particular connection.
Lunaseed may preserve technical records of each integration event, including provider, source account identifier, selected permissions or scope, connection time, initiating user, and related audit metadata, without treating each event as a new legal agreement.
11. Disconnecting and Prospective Withdrawal
The Company may disconnect a specific integration or request that Lunaseed stop future source access. The Company may also withdraw this Authorization prospectively by contacting Lunaseed, subject to reasonable verification of the request.
Withdrawal stops new source access once technically effective. It does not retroactively invalidate access or processing that was authorized before withdrawal, erase the historical acceptance record, or automatically delete information already lawfully captured, processed, or disclosed. Existing data remains subject to the applicable retention, deletion, and recipient obligations.
12. Retention and Deletion
Integration data and resulting snapshot information are retained under Lunaseed’s Privacy Policy and applicable agreements. Customer data is generally retained while the relevant account or engagement remains active, subject to earlier valid deletion requests.
- Valid deletion request. Applicable customer data is removed from active production stores, including applicable PostgreSQL records, Amazon S3 files, integration snapshots, MongoDB archive copies, and other active production stores within 30 days, except for limited legal, billing, security, fraud-prevention, dispute, or audit records that may lawfully be retained.
- Termination without a separate deletion request. Lunaseed may provide a 30-day export or recovery period and then delete or de-identify applicable customer content from active systems within 90 days, subject to permitted retention exceptions.
- Backups. Encrypted rolling backups are retained for 35 days and then automatically expire or are overwritten. Deleted data may remain in a backup only until the applicable backup expires.
These deletion rules govern data controlled by Lunaseed. They do not require a source provider, venture firm, or another authorized recipient to delete information it independently retains under its own lawful obligations.
13. Privacy, Security, and AI Processing
Lunaseed processes integration data in accordance with its Privacy Policy and, where applicable, its Data Processing Addendum. Lunaseed maintains administrative, technical, and organizational safeguards appropriate to the nature of the information, including access controls, encryption in transit and at rest where supported, logging, infrastructure security, and secrets-management practices.
Lunaseed does not use Company or customer content to train generalized artificial-intelligence or foundation models. Lunaseed may use approved cloud, integration, model, embedding, or other service providers to provide selected platform functions. The use of a provider does not mean that every provider receives every Company’s data or every category of integration data.
14. Third-Party Services and Source Accuracy
Third-party source systems are governed by their own terms, APIs, permissions, security controls, privacy practices, and availability. The Company remains responsible for complying with obligations applicable to its source accounts.
Lunaseed does not control the completeness, accuracy, schema, permissions, uptime, or continued availability of a third-party integration. A snapshot reflects the information the source system makes available through the authorized connection at the relevant time and may be limited, delayed, aggregated, truncated, or otherwise affected by the provider.
15. Relationship to Other Lunaseed Agreements
This Authorization supplements the Lunaseed Terms of Service and Privacy Policy and, where applicable, other Company or organization agreements. The Diligence Data Sharing Authorization separately governs disclosure to a requesting firm. The Founder Verification Disclosure & Authorization separately governs founder verification. The Contributor Access & Confidentiality Agreement separately governs contributor access.
This Authorization is intended to remain the Company’s standing integration-access authorization after one acceptance. Lunaseed will not require re-acceptance merely because the Company connects a different integration, reconnects a prior integration, changes the requesting VC firm, or participates in a new diligence engagement.
If applicable law requires renewed consent, or if Lunaseed materially expands the nature of source access beyond the read-only Company-directed model described here, Lunaseed may require a new authorization before the expanded access occurs.
16. Electronic Acceptance and Locked Record
The Founder accepts this Authorization electronically by checking the acceptance box and selecting “Agree & Continue” (or an equivalent clearly identified affirmative control) the first time the Founder attempts to connect a Company integration through Lunaseed.
Electronic acceptance has the same effect as written acceptance to the extent permitted by law. Lunaseed may retain an immutable or otherwise access-controlled audit record of the acceptance, including the Founder’s identity, Company, timestamp, Authorization version, IP address, device or browser information, and related technical metadata reasonably necessary to evidence the acceptance.
The accepted document version and acceptance record are locked as historical records and are not edited when future integrations are connected. If the Company later withdraws authorization, Lunaseed records the withdrawal separately rather than altering the original acceptance record.
17. In-Product Acceptance
The following acceptance language appears the first time a Founder connects a company integration:
I am authorized to act for the company and agree to the Integration Data Access Authorization. I authorize Lunaseed to connect to Company-approved third-party systems that I or other authorized Company users choose to connect now or in the future, and to access and process permitted information on a read-only basis as described in this Authorization.
AGREE & CONTINUE
18. Contact
Questions about this Authorization may be sent to legal@lunaseed.io. Privacy questions may be sent to privacy@lunaseed.io.
Lunaseed Inc.
6221 Cypress Ave
El Cerrito, CA 94530
United States