This Privacy Policy explains how Diligate, Inc. ("Diligate", "we") handles information in connection with the Diligate platform ("Service"), a software platform used by M&A advisory firms ("Firms") and the users they authorize. In most cases Diligate processes information on behalf of, and under the instructions of, the Firm: the Firm is the controller of the deal and client information in its workspaces, and Diligate acts as its processor (and, in turn, as a sub-processor to the Firm where the Firm serves its own clients).
We process: (a) Account information such as name, business email, role, firm affiliation, and authentication data (including multi-factor settings); (b) Firm Content that Firms and the parties they invite upload or generate, which for M&A work commonly includes deal documents, contracts, trial balances, general ledgers, financial statements, tax records, employee and customer data, and personal information about clients, owners, and counterparties; (c) Usage and log data such as actions taken, documents accessed, IP address, timestamps, and device or browser information, used for security and audit trails; and (d) Billing information for the Firm's subscription.
We use information to: provide, operate, secure, and support the Service; perform the features a user initiates, including secure data rooms, document drafting and redlining, extraction, quality-of-earnings and financial analysis, and research; maintain access controls and audit logs; detect, prevent, and investigate abuse and security incidents; process billing; and comply with legal obligations. We do not sell personal information, and we do not use Firm Content to serve advertising.
When a user invokes an AI-assisted feature, the relevant text or data is transmitted to our AI model provider to generate the requested output, solely to perform the task the user initiated. We do not use Firm Content to train third-party foundation models, and we configure processing to disable provider-side training on our traffic where that option is offered. AI outputs are drafts for professional review and are handled with the same confidentiality as other Firm Content.
M&A workspaces routinely contain highly confidential and material non-public information. We treat Firm Content as confidential, restrict internal access to personnel who need it to operate and support the Service, and do not disclose it except as directed by the Firm or as required by law. The Firm controls who may access each workspace.
Each Firm's data is logically separated from every other Firm's data. We use access controls and database row-level security so that one Firm cannot access another Firm's content. Within a Firm, access is governed by the roles and permissions the Firm's administrator configures, including scoped access for clients and counterparties.
We rely on vetted service providers to operate the Service, which may include cloud hosting and compute, managed database, encrypted object storage for documents, and an AI model provider, and, where a Firm enables them, e-signature, accounting, and email providers. These providers process information under contractual obligations consistent with this Policy and only as needed to provide their service. A current list of sub-processors is available to Firms on request.
We maintain administrative, technical, and organizational safeguards designed to protect information, including encryption of data in transit, access controls, tenant isolation, session-based authentication with optional multi-factor authentication, and audit logging. No method of transmission or storage is perfectly secure; Firms and users must use strong credentials and appropriate access settings. We will notify the affected Firm without undue delay after becoming aware of a personal-data breach affecting its data, consistent with applicable law.
We retain information for as long as the Firm's account is active and as needed to provide the Service, then delete or de-identify it in accordance with our retention practices and the Firm's instructions. Because Firms may be subject to their own recordkeeping requirements (for example, securities recordkeeping rules), the Firm is responsible for directing any retention or export it needs. Backups and audit records may persist for a limited additional period.
We primarily process and store data in the United States. Where information is transferred across borders, we rely on appropriate safeguards as required by applicable law.
Because Diligate acts on behalf of the Firm, individuals whose information appears in a workspace (for example, a client, owner, or counterparty representative) should direct requests to access, correct, or delete their information to the Firm that controls that workspace. We will assist Firms in responding to such requests as required by applicable law.
We use strictly necessary cookies and similar technologies to keep users signed in and to secure the Service. We do not use advertising or cross-site tracking cookies.
The Service is a business tool intended for authorized professional users and is not directed to children, and we do not knowingly collect information from children.
We may update this Policy from time to time. Material changes will be communicated through the Service or to the Firm's administrator and take effect as stated in the notice.
Privacy questions may be directed to your Firm administrator or to Diligate, Inc.