← Deal Desk

Deal Desk — Data Processing Agreement

Version 2026-08-01 · Incorporated into and governed by the Terms of Service.

Attorney review required before first paying customer. This draft is
accurate to how the system is actually built, which is most of the work — but
a lawyer needs to check it against the states and, if you ever sell abroad, the
jurisdictions you operate in.

1. Roles

For personal information you upload — your investors, your team, your vendors —

you are the controller and we are the processor. You decide what to

collect and why. We process it only on your instructions.

We are the controller only for our own account and billing records about you.

2. Scope of processing

Subject matter. Providing the Deal Desk service.

Duration. For as long as your subscription is active, plus the 60-day

retention window after termination.

Categories of data subject. Your investors and their representatives; your

employees and contractors; your vendors and subcontractors.

Categories of personal information.

CategoryExamplesWhere it is stored
Contactname, email, phone, addressdatabase, encrypted at rest
Identityentity name, last four of a tax IDdatabase, encrypted at rest
Tax identifiersSSN or EIN contained inside an uploaded W-9restricted bucket, encrypted at rest, Owner/Admin only, every access logged
Financialcontributions, distributions, preferred return, ownershipdatabase, encrypted at rest
Employmentrole, permissions, activitydatabase

We do not require you to enter a Social Security number as a data field, and the

Service provides none. An SSN reaches us only if it appears inside a document you

choose to upload.

3. Our obligations

We will:

include your use of the Service and any support request you make;

aware of a personal data breach affecting your data, with what we know at the

time and updates as we learn more;

it sooner on request, except where law requires retention;

4. Your obligations

You will:

for investors who do not require a 1099 or K-1 from you;

the Staff role for anyone who only enters costs;

hold their records.

5. Security measures

Encryption. In transit via TLS 1.2 or higher. At rest via AES-256 on both

database and object storage.

Access control. Isolation between customers is enforced by Postgres row-level

security, evaluated by the database on every query, not by application code.

Role-based access is described in the Terms. Tax documents live in a separate

storage bucket that Staff and Investor roles cannot read under any circumstances.

Audit logging. Membership changes, permission changes, distributions recorded,

exports, and every single access to a tax document are written to an append-only

log visible to the workspace Admin.

Least privilege. Our own staff do not access customer data as a matter of

course. Support access requires your request or an incident, is performed through

an impersonation mechanism, and is written to your audit log where you can see it.

Backups. Encrypted, with point-in-time recovery.

Passwords. Hashed with bcrypt by our authentication provider. We never see them.

Payment cards. We never receive, transmit or store card numbers. Stripe

handles payment data directly.

6. Subprocessors

You authorize the following. We will give at least 30 days' notice before adding

one, and you may object on reasonable data protection grounds.

SubprocessorPurposeLocation
SupabaseDatabase, authentication, file storage, and the sign-in and password-reset email that goes with themUnited States
Amazon Web ServicesUnderlying infrastructureUnited States
NetlifyWebsite hosting, and the server-side call that reaches the document readerUnited States
StripePayment processing and billingUnited States
AnthropicSettlement statement reading, when you use that featureUnited States

On the document reader: a document you submit to it is sent for analysis and

returned as extracted figures. It is not retained for model training. If you would

rather no document ever leave your workspace, do not use that feature; every

figure it produces can be typed in by hand.

7. International transfers

The Service is hosted in the United States. If you are outside the United States,

you instruct us to transfer data there, and we will put appropriate safeguards in

place where the law requires them.

8. Data subject requests

If one of your investors contacts us directly, we will refer them to you. We will

help you respond within a reasonable time. Deleting an investor and their

documents is something you can do yourself at any time.

9. Audit

On reasonable notice, no more than once a year, you may request information

demonstrating compliance with this DPA. We will provide our current security

documentation and answer reasonable questions. If we hold a SOC 2 report at the

time, that report satisfies this section.

10. Liability

Liability under this DPA is subject to the limitations in the Terms of Service.

11. Conflict

If this DPA conflicts with the Terms of Service on the processing of personal

information, this DPA governs.