Snapshot 17455
Normalized text
Scripts and page chrome removed; this is what change detection compares.
On this page
Data Processing Addendum
Effective Date: April 19, 2026 · Last Updated: April 21, 2026
This Data Processing Addendum ("DPA") forms part of the agreement ("Agreement") between:
Customer (Controller): The organization subscribing to DiligenceVDR
DiligenceVDR (Processor): DiligenceVDR, LLC, Denver, Colorado
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person processed through the Service
"Processing" means any operation performed on Personal Data
"Sub-processor" means a third party engaged by DiligenceVDR to process Personal Data
2. Scope and Roles
Customer acts as the Data Controller. DiligenceVDR acts as the Data Processor. DiligenceVDR processes Personal Data only on documented instructions from the Customer, as necessary to provide the Service.
3. Categories of Data Processed
Data Subjects
Customer's employees, advisors, and deal counterparties who access the data room.
Personal Data Types
Identity data: name, email address
Access data: IP address, user agent, session timestamps
Activity data: audit log entries (uploads, downloads, searches, chat messages)
Document content: files uploaded by authorized users (may contain personal data at the Customer's discretion)
Processing Purposes
Providing the virtual data room service
Access control and authentication
Audit logging and compliance reporting
Security (malware scanning, watermarking, encryption)
AI-assisted search and review (when enabled by Customer)
Transactional communications (invitations, notifications, account alerts)
Service health monitoring and error reporting
4. Customer Instructions
DiligenceVDR shall process Personal Data only in accordance with:
These terms
The Agreement
Customer's configuration choices within the Service (e.g., enabling or disabling AI features, setting access permissions)
5. Security Measures (GDPR Article 32)
DiligenceVDR implements the following technical and organizational measures:
Encryption at rest (AES-256) and in transit (TLS 1.2+)
Per-project encryption keys with optional customer-managed keys
Row-level database isolation between projects
Tamper-evident audit logging with cryptographic hash chain
Dynamic watermarking on document access
Malware scanning on all uploads
Multi-factor authentication support
Role-based access control
Regular security assessments
6. Sub-processors
A current list of sub-processors is maintained at diligencevdr.ai/trust#subprocessors.
DiligenceVDR shall:
Notify Customer before engaging new sub-processors
Impose data protection obligations on sub-processors no less protective than this DPA
Remain liable for sub-processor compliance
Customer may object to a new sub-processor within 30 days of notification. If the objection cannot be resolved, Customer may terminate the affected service.
7. Data Subject Rights
DiligenceVDR shall assist Customer in responding to data subject requests (access, rectification, erasure, portability, objection, restriction) by:
Providing self-service tools (data export, account deletion)
Responding to Customer requests within 10 business days
Providing data in machine-readable format (JSON) upon request
8. Breach Notification
DiligenceVDR shall notify Customer of a confirmed Personal Data breach without undue delay and no later than 72 hours after becoming aware. Notification shall include:
Nature of the breach
Categories and approximate number of data subjects affected
Likely consequences
Measures taken or proposed to address the breach
9. Data Retention and Deletion
Upon termination of the Agreement or closure of a data room:
Customer data is retained for 90 days (retrieval period)
Customer is notified 30 days before permanent deletion
After the retention period, data is permanently deleted or crypto-shredded (encryption keys destroyed)
Audit logs are retained for 7 years in anonymized form for regulatory compliance
10. Audit Rights
Customer may:
Request DiligenceVDR's most recent security assessment or certification reports
Request written answers to reasonable security questionnaires (response within 15 business days)
Upon 30 days written notice and no more than once per year, conduct or commission an audit of DiligenceVDR's processing activities, subject to confidentiality obligations and reasonable scope limitations
11. International Transfers
Where Personal Data is transferred outside the EEA or Switzerland, DiligenceVDR relies on:
EU-U.S. Data Privacy Framework and Swiss-U.S. Data Privacy Framework — DiligenceVDR, LLC is self-certified with the U.S. Department of Commerce (record number B-07967) and adheres to the DPF Principles for personal data received from the European Union and Switzerland. See the Privacy Policy for participation details, recourse, and binding arbitration rights.
EU Standard Contractual Clauses (Module 2: Controller to Processor) — used as a complementary mechanism and where the DPF does not apply
Supplementary measures: encryption at rest and in transit, access controls, pseudonymization of audit records
The SCCs are incorporated by reference and available upon request.
Data residency options: Customers may select EU or US data residency at project creation. Document storage, database records, and processing remain within the selected region.
12. Term
This DPA remains in effect for the duration of the Agreement and continues until all Personal Data is deleted or returned.
13. Governing Law
This DPA is governed by the same law as the Agreement. For matters relating to GDPR compliance, the laws of the applicable EU Member State shall apply.
Annex A — U.S. State Privacy Laws Addendum
This Annex supplements the Data Processing Addendum ("DPA") to address requirements of U.S. state comprehensive consumer privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), the Utah Consumer Privacy Act ("UCPA"), the Texas Data Privacy and Security Act ("TDPSA"), the Oregon Consumer Privacy Act ("OCPA"), the Montana Consumer Data Privacy Act ("MTCDPA"), the Iowa Consumer Data Protection Act, the Delaware Personal Data Privacy Act ("DPDPA"), the Nebraska Data Privacy Act ("NDPA"), the New Hampshire Privacy Act, the New Jersey Data Privacy Act ("NJDPA"), the Tennessee Information Protection Act ("TIPA"), the Minnesota Consumer Data Privacy Act ("MCDPA"), the Maryland Online Data Privacy Act ("MODPA"), the Rhode Island Data Transparency and Privacy Protection Act, the Indiana Consumer Data Protection Act, and the Kentucky Consumer Data Protection Act (collectively, together with any other comprehensive U.S. state privacy laws in effect from time to time, the "U.S. State Privacy Laws"). To the extent this Annex conflicts with the DPA, this Annex controls for processing subject to U.S. State Privacy Laws.
A.1 Roles
Customer is the "Business" under CCPA/CPRA or the "Controller" under every other U.S. State Privacy Law named above.
DiligenceVDR is the "Service Provider" under CCPA/CPRA or the "Processor" under every other U.S. State Privacy Law named above.
A.2 Purpose and scope of processing
DiligenceVDR processes Personal Information (as defined under the applicable U.S. State Privacy Laws) solely for the Business Purposes set forth in the Agreement and this DPA, which include: operating the virtual data room service, access control, authentication, audit logging, security (malware scanning, watermarking, encryption), and — when enabled by Customer — AI-assisted search and review.
A.3 Service Provider / Processor obligations
Pursuant to CCPA/CPRA §1798.140(ag)(1) and the equivalent provisions of the other U.S. State Privacy Laws, DiligenceVDR:
(a) Shall not Sell or Share Personal Information, as those terms are defined under the CCPA/CPRA and parallel state laws.
(b) Shall not retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in the Agreement, including not retaining, using, or disclosing Personal Information (i) outside the direct business relationship between the parties, or (ii) for any Commercial Purpose other than the Business Purposes.
(c) Shall not combine Personal Information received from, or on behalf of, Customer with Personal Information received from, or on behalf of, any other person, or collected from DiligenceVDR's own interaction with a Consumer, except as permitted for Service Providers under CCPA Regulations §7050(b) (service-quality, fraud-prevention, security, and debugging purposes internal to DiligenceVDR's provision of the Service).
(d) Certifies that it understands the restrictions in this Section A.3 and will comply with them.
(e) Shall notify Customer promptly if DiligenceVDR determines it can no longer meet its obligations under the U.S. State Privacy Laws.
A.4 Customer's right to take reasonable steps
Customer has the right, upon notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information by DiligenceVDR, including termination of the Agreement.
A.5 Sub-processor flow-down
DiligenceVDR shall flow down the obligations in Section A.3 to all sub-processors engaged in processing Personal Information subject to U.S. State Privacy Laws. The current sub-processor list is maintained at diligencevdr.ai/trust#subprocessors.
A.6 Consumer rights assistance
DiligenceVDR shall assist Customer in fulfilling Customer's obligations to respond to Consumer rights requests under U.S. State Privacy Laws (access, deletion, correction, portability, opt-out where applicable, limit use of Sensitive Personal Information, non-discrimination) by providing:
Self-service tools available to end users (data export, account deletion, profile correction)
Responses to Customer requests within 10 business days
Technical measures to effectuate deletion, including crypto-shredding of per-project encryption keys
A.7 Security and confidentiality
DiligenceVDR shall implement and maintain reasonable security procedures and practices appropriate to the nature of the Personal Information, as required by CCPA §1798.81.5 and the equivalent provisions of the other U.S. State Privacy Laws. Specific technical and organizational measures are set forth in Section 5 of the DPA.
A.8 Data Protection Assessments
DiligenceVDR shall provide Customer, upon reasonable request, with information reasonably necessary for Customer to conduct Data Protection Assessments (or equivalent impact assessments) required by applicable U.S. State Privacy Laws, including those of Virginia, Colorado, Connecticut, Oregon, Minnesota, Maryland, Tennessee, New Hampshire, New Jersey, Delaware, Indiana, Kentucky, Rhode Island, Texas, Nebraska, and Montana.
A.9 Deidentified data
If either party processes deidentified data, the processing party shall: (i) take reasonable measures to ensure the data cannot be associated with a Consumer or household, (ii) publicly commit to maintaining the data in deidentified form, and (iii) contractually obligate any recipients to comply with (i) and (ii).
A.10 Order of precedence
To the extent of any conflict between the terms of this Annex and any other terms of the Agreement or DPA, the terms of this Annex shall prevail with respect to processing subject to U.S. State Privacy Laws.
Execution
To execute this DPA for your organization, contact [email protected]. A countersigned PDF copy will be provided for your records.