Third Party Index

Snapshot 17465

Document
Privacy policy
URL
https://diligencevdr.ai/privacy/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
112115 bytes
SHA-256 (raw)
079d4a3915abeceaafacf56c7af9a97f4f90a3ec9c020a3d5fb496eec067e1b1
SHA-256 (normalized text)
61939749b1378a93fd5b03a6fe1973452ce422037edb925efb667142705f5d1a

Normalized text

Scripts and page chrome removed; this is what change detection compares.

On this page
Privacy Policy
Effective Date: April 19, 2026 · Last Updated: June 9, 2026
DiligenceVDR ("we", "us", "our") operates a virtual data room platform for mergers & acquisitions due diligence. This policy describes how we collect, use, and protect personal data.
Data Controller
DiligenceVDR, LLC
131 Continental Dr, Suite 305, Newark, DE 19713 US
Privacy Team (Attn: Michael Pierce, CTO)
Email: [email protected]
Legal Basis for Processing
We process personal data as necessary for the performance of our contract with you (GDPR Article 6(1)(b)). When you or your organization subscribes to DiligenceVDR, processing your data is required to deliver the service.
What We Collect
Account Data
Name, email address (provided at registration or invitation)
Organization and project membership
Authentication data (managed by WorkOS; we do not store passwords)
Usage Data
IP address, browser user agent (for audit logging and security)
Session timestamps, authentication method
Actions performed within data rooms (uploads, downloads, searches, chat messages) — logged in our tamper-evident audit trail
Document Data
Files uploaded to data rooms by authorized users
Extracted text content (for search indexing and AI-assisted review, when enabled by the project administrator)
Document metadata (file name, size, upload date, processing status)
Data We Do NOT Collect
We do not use tracking or advertising cookies (our only analytics, Cloudflare Web Analytics, is cookieless and does not track you across sites)
We do not collect data for advertising purposes
We do not sell personal data to third parties
How We Use Your Data
Providing the data room service (document storage, access control, search, collaboration)
Security and fraud prevention (audit logging, watermarking, malware scanning)
AI-assisted document review (text extraction, search indexing, chat-based Q&A) — only when enabled by the project administrator. When disabled, zero document content is sent to external AI providers.
Transactional email (invitations, notifications, account alerts)
Data Retention
Customer documents: 90 days after data room closure
Audit logs: 7 years (regulatory requirement)
User account data: 1 year after account deletion
Download packages: Expired and deleted within 24 hours
Quarantined files (malware detected): 30 days
Customers are notified at room closure and 30 days before final data disposal.
Your Rights (GDPR Articles 15–22)
You have the right to:
Access your personal data (request a copy)
Rectification (correct inaccurate data)
Erasure ("right to be forgotten") — request account deletion
Data portability (export your data in machine-readable JSON format)
Object to processing
Restrict processing
Withdraw consent (where consent is the legal basis)
To exercise any right, email [email protected] or submit a request from your account under Profile → Data & Privacy.
Data access & portability: You may request a copy of the personal data we hold about you in a structured, machine-readable format (GDPR Articles 15 and 20). Each request is reviewed by our privacy team — in part to ensure we don't disclose other people's personal data along with yours — and we will provide your data through a secure, time-limited download link within 30 days of your request.
Account deletion: Profile → Danger Zone → Request Account Deletion (14-day grace period; cancellable before expiry)
We will respond to all requests within 30 days.
U.S. State Privacy Rights
This section applies to residents of U.S. states with comprehensive consumer privacy laws, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, and Kentucky. DiligenceVDR honors the rights described below for all U.S. residents, regardless of state.
DiligenceVDR operates as a Service Provider (California Consumer Privacy Act, as amended by the California Privacy Rights Act — "CCPA/CPRA") and as a Processor under the comprehensive consumer privacy laws of other U.S. states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Rhode Island, Indiana, and Kentucky) on behalf of the customer organizations that subscribe to our service.
Categories of Personal Information we collect
Under the CCPA, personal information falls into statutory categories. In the preceding 12 months, we have collected the following categories directly from you or automatically through your use of the Service:
Category (CCPA §1798.140(v))	Collected	Examples
A. Identifiers	Yes	Name, email address, IP address
B. Customer records (Cal. Civ. Code §1798.80(e))	Yes	Name, email, employer
C. Protected classification characteristics	No	—
D. Commercial information	No	—
E. Biometric information	No	—
F. Internet or network activity	Yes	Session timestamps, actions within the data room (uploads, downloads, searches, chat)
G. Geolocation data	Limited	IP-derived region only; no precise geolocation
H. Sensory data	No	—
I. Professional / employment information	Yes	Role, organization, advisor relationship
J. Education information	No	—
K. Inferences	No	—
L. Sensitive Personal Information (CPRA)	Limited	Account credentials (authentication is managed by WorkOS; we do not store passwords)
Sources of Personal Information
Directly from you at registration, invitation acceptance, or profile update
Automatically from your use of the Service (IP, user agent, session timestamps, audit events)
From the customer organization that invites you to a data room
Purposes of use
We use the categories above solely to:
Provide, secure, and support the Service
Authenticate access and enforce role-based permissions
Maintain tamper-evident audit logs for compliance and security
Detect and prevent security incidents, fraud, and malicious activity
Communicate with you about your account (transactional email)
We do not use Personal Information for advertising, marketing analytics, training machine-learning models on your data, or any purpose unrelated to delivering the Service.
We do not sell or share Personal Information
DiligenceVDR does not sell Personal Information and does not share Personal Information for cross-context behavioral advertising, as those terms are defined in CCPA §1798.140(ad) and §1798.140(ah). We have not sold or shared Personal Information in the preceding 12 months and have no intention to do so. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" opt-out mechanism is required; however, we honor Global Privacy Control signals as described below.
Disclosures of Personal Information for a business purpose
In the preceding 12 months, we have disclosed Personal Information for business purposes only to the categories of sub-processors described in the "Third Parties We Share Data With" section below (see diligencevdr.ai/trust for the authoritative list), each of whom is contractually bound as a Service Provider or Processor and prohibited from using the information for any purpose other than providing services to us.
Retention
We retain Personal Information only as long as necessary to provide the Service and comply with our legal obligations. Specific retention periods are stated in the "Data Retention" section above.
Your rights
Residents of U.S. states with comprehensive consumer privacy laws have the following rights (exact scope varies by state; we honor the full set for all U.S. residents):
Right to know / access — request disclosure of the Personal Information we hold about you
Right to delete — request deletion of your Personal Information
Right to correct — request correction of inaccurate Personal Information
Right to data portability — receive your Personal Information in a machine-readable JSON format
Right to limit use of Sensitive Personal Information — direct us to limit the use of Sensitive Personal Information. DiligenceVDR collects limited Sensitive PI (authentication credentials only). If AI features are enabled for your data room, project administrators can disable AI processing at any time, which prevents any document content from being sent to external AI providers.
Right to opt out of sale or sharing — not applicable; we do not sell or share
Right to opt out of automated decision-making or profiling — not applicable; DiligenceVDR does not make automated decisions producing legal or similarly significant effects
Right to non-discrimination — we will not deny, charge different prices for, or provide a different level or quality of service because you exercised any privacy right
Right to appeal a denial of a privacy-rights request, where provided by your state's law — see "Appeals" below
How to exercise your rights
In your account — Submit an access / portability request under Profile → Data & Privacy; after review we provide your data through a secure, time-limited download link (see "Your Rights" above). You can also request account deletion under Profile → Danger Zone (right to delete, with a 14-day cancellable grace period).
Email — [email protected]
Response time — within 45 days, extendable once by 45 additional days when reasonably necessary (we will notify you of any extension and the reason)
Authorized agents
You may designate an authorized agent to submit requests on your behalf. We will require:
Written authorization signed by you
Verification of your identity (typically through your DiligenceVDR account)
Verification of the agent's identity
Submit authorized-agent requests to [email protected].
Appeals
If we deny a privacy-rights request and your state's comprehensive privacy law provides an appeal right, you may appeal by emailing [email protected] within 60 days of the denial. We will respond within the timeframe required by your state's law (typically 45 to 60 days) with a written explanation of our decision. If your appeal is denied, you may contact the Attorney General of your state.
Global Privacy Control (GPC)
DiligenceVDR honors Global Privacy Control signals as a valid opt-out of sale and sharing. Because we do not sell or share Personal Information, GPC does not change our processing of your data, but we do not override or ignore the signal.
California "Shine the Light" (Cal. Civ. Code §1798.83)
California residents may request information about our disclosures of Personal Information to third parties for their direct marketing purposes. DiligenceVDR does not disclose Personal Information for third-party direct marketing. Requests: [email protected].
Changes
If we materially change our U.S. state privacy practices, we will update this section and notify account holders by email at least 30 days before the changes take effect.
Audit Log Retention & Deletion
Audit logs are retained for 7 years for regulatory compliance. When you delete your account, personally identifiable information within audit records (name, email, IP address) is anonymized. The audit trail is preserved in anonymized form to maintain integrity for compliance purposes.
Document Translation
When a project user requests translation of an uploaded document:
The document file is sent to DeepL SE (Cologne, Germany) for translation. DeepL processes the file in the EU and does not use customer data for model training under the Growth plan we use
Supported formats: PDF (native text only), DOCX, PPTX, XLSX. Scanned/image-only PDFs are translated using our in-house AI pipeline (Google Vertex AI) instead of DeepL
Translation is always user-initiated — no documents are sent to DeepL automatically
The translated file is stored encrypted in the same regional storage bucket as the original
AI Processing
When AI features are enabled for a data room:
Only extracted text from uploaded documents is sent to our AI provider (Google Cloud Vertex AI) for indexing, search, and chat
The primary model is Google Gemini; Anthropic Claude (offered via Vertex AI's partner-model program) is used as an in-region fallback when Gemini is degraded. Both models run on Google's infrastructure in the project's region under the Google Cloud DPA — Google is the sole sub-processor for AI processing, and no separate Anthropic data path exists
Document content is processed under Google's API terms, which prohibit use of customer data for model training; the same prohibition applies to Vertex partner models
Project administrators can disable AI processing entirely — when disabled, no document content leaves our infrastructure
Data Room Activity and Access Logging
When you access a data room hosted on DiligenceVDR, we record activity about how documents in that room are used. This includes which documents are opened, active viewing time, media playback progress, and the IP address from which each document is opened. Document downloads are additionally recorded in a tamper-evident audit trail. This logging is always on; it is a standard, expected feature of a virtual data room, where a defensible record of who accessed which materials — and from where — is integral to the service.
We process this information as a processor, on behalf of and at the direction of the organization that operates the data room (the controller). That organization's lawful basis under Article 6(1)(f) GDPR is its legitimate interest in maintaining a secure and auditable record of access to confidential transaction materials; this is not based on your consent, and there is no per-room opt-out, because the logging is necessary to provide the data room. The organization operating the room is responsible for providing any further notice required to its participants.
This data is visible only to the administrators of the data room, never to other participants. IP addresses are captured on document open only — not on each page or scroll. Activity data is stored in the data room's own region (data for EU-based projects remains in the EU) and is retained for up to 24 months from the event, after which it is deleted. If you exercise your right to erasure, your IP address is removed from these records ahead of that window while the aggregate access event is retained in anonymized form.
Where a data room permits downloads, each delivered copy is individually marked to identify the recipient. We write recipient-identifying details — an opaque per-recipient identifier and your email address — into the downloaded file's document properties, and, where the room enables watermarking, into a visible mark rendered on the document itself. This lets a leaked copy be traced back to the recipient; it rests on the same Article 6(1)(f) legitimate-interest basis as the access and IP logging described above, the opaque identifier resolves only against our own systems, and every such resolution is recorded in our tamper-evident audit log.
We do not use data room activity for advertising, and we do not sell or share it. It is never used for metering or billing.
Data Security
All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
Per-project encryption keys with optional customer-managed keys (BYOK)
Row-level database isolation between projects
Tamper-evident audit logging with cryptographic hash chain
Dynamic watermarking on document downloads
Per-recipient forensic marking of downloaded copies
Malware scanning on all uploaded files
Multi-factor authentication available (TOTP, WebAuthn/passkeys)
International Transfers
Our infrastructure operates in the United States, with EU residency options available for enterprise customers. For transfers outside the EEA, we rely on Standard Contractual Clauses (SCCs) with supplementary measures including encryption at rest and in transit.
See our sub-processor list at diligencevdr.ai/trust#subprocessors for data locations and DPA links.
Data Privacy Framework (DPF) Notice
DiligenceVDR, LLC is self-certified with the U.S. Department of Commerce for the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF). We adhere to the Data Privacy Framework Principles regarding the processing of personal data received from the European Union and Switzerland. To learn more about the Data Privacy Framework (DPF) program, please visit https://www.dataprivacyframework.gov/.
If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.
Regulatory Oversight
The Federal Trade Commission (FTC) has jurisdiction over DiligenceVDR, LLC's compliance with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF).
Independent Recourse Mechanism
In compliance with the EU-U.S. DPF and the Swiss-U.S. DPF, DiligenceVDR, LLC commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the Swiss-U.S. DPF.
Binding Arbitration
Under certain conditions, more fully described on the Data Privacy Framework website (https://www.dataprivacyframework.gov/framework-article/ANNEX-I-introduction), you may invoke binding arbitration for complaints regarding DPF compliance not resolved by any of the other DPF mechanisms. DiligenceVDR, LLC is obligated to arbitrate claims and follow the terms set forth in Annex I of the DPF Principles, provided that an individual has invoked binding arbitration by delivering notice to our organization and following the procedures and subject to the conditions set forth in Annex I.
Liability for Onward Transfers
DiligenceVDR, LLC's accountability for personal data that it receives in the United States under the EU-U.S. DPF and Swiss-U.S. DPF and subsequently transfers to a third party is described in the DPF Principles. We remain responsible and liable under the DPF Principles if third-party agents process personal data in a manner inconsistent with the Principles, unless we prove we are not responsible for the event giving rise to the damage.
Required Disclosures
DiligenceVDR, LLC may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Third Parties We Share Data With
We disclose Personal Information only to third parties acting as processors (service providers) on our behalf, each under a written data processing agreement that prohibits any use of the information outside the scope of providing services to us. We do not disclose Personal Information to any third party acting as an independent controller.
The categories of sub-processors we engage, and the purposes for each, are:
Category	Purpose of disclosure
Cloud hosting, CDN & object storage	Application hosting, edge delivery, DDoS protection, encrypted document storage
Application & database hosting	Application runtime and managed database infrastructure
Authentication & identity	Sign-in, enterprise SSO/SAML, directory sync, multi-factor authentication
AI / LLM provider (optional per project)	Document text extraction, embeddings, semantic search, and chat-based Q&A — only when AI features are enabled by the project administrator
Document translation (optional per project)	Translates uploaded documents (PDF, DOCX, PPTX, XLSX) when a project user requests translation — only when translation is initiated by a project user
Transactional email	Invitation, notification, and account-alert emails
Website analytics	Aggregate, cookieless traffic measurement for our public website (Cloudflare Web Analytics) — no cookies, no cross-site tracking, no device fingerprinting
Error monitoring	Application error reporting and performance telemetry
Payments	Billing and subscription management
The authoritative list of named sub-processors — with specific providers, hosting locations, and DPA links — is maintained at diligencevdr.ai/trust#subprocessors. We will notify affected customers before adding new sub-processors.
Your Choices
We offer you the following means to limit how your Personal Information is used or disclosed:
Disclosure to third-party controllers — We do not disclose Personal Information to any third party acting as an independent controller. If this ever changes, we will provide advance notice and an opportunity to opt out before any such disclosure.
Materially different or new uses — If we propose to use your Personal Information for a purpose that is materially different from, or incompatible with, the purposes described in this policy, we will give you advance notice and an opportunity to opt out (or, where sensitive data is involved, to opt in) before the new use takes effect.
AI / LLM processing — AI features are off by default at the project level. Project administrators may enable or disable AI processing at any time; when disabled, no document content is sent to any external AI provider.
Transactional email — Account-critical notifications (security alerts, invitations, access changes) cannot be disabled because they are required to operate the Service. We do not send marketing email derived from account data.
Access, correction, export, deletion, objection, restriction — Submit a request under Profile → Data & Privacy or email [email protected]. See "Your Rights" above for the full list.
Children
DiligenceVDR is a B2B service for professional use. We do not knowingly collect data from anyone under 16.
Changes to This Policy
We will post changes to this page and update the "Last updated" date. Material changes will be communicated via email to account holders.
Privacy Contact
Privacy Team (Attn: Michael Pierce, CTO)
Email: [email protected]
DiligenceVDR, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713 US
You may contact us with any questions about how we handle your personal data or to exercise your rights under GDPR.
Contact
Privacy: [email protected]
Security issues: [email protected]
General: [email protected]