Version 2026-08-01 · Incorporated into and governed by the Terms of Service.
Attorney review required before first paying customer. This draft is
accurate to how the system is actually built, which is most of the work — but
a lawyer needs to check it against the states and, if you ever sell abroad, the
jurisdictions you operate in.
For personal information you upload — your investors, your team, your vendors —
you are the controller and we are the processor. You decide what to
collect and why. We process it only on your instructions.
We are the controller only for our own account and billing records about you.
Subject matter. Providing the Deal Desk service.
Duration. For as long as your subscription is active, plus the 60-day
retention window after termination.
Categories of data subject. Your investors and their representatives; your
employees and contractors; your vendors and subcontractors.
Categories of personal information.
| Category | Examples | Where it is stored |
|---|---|---|
| Contact | name, email, phone, address | database, encrypted at rest |
| Identity | entity name, last four of a tax ID | database, encrypted at rest |
| Tax identifiers | SSN or EIN contained inside an uploaded W-9 | restricted bucket, encrypted at rest, Owner/Admin only, every access logged |
| Financial | contributions, distributions, preferred return, ownership | database, encrypted at rest |
| Employment | role, permissions, activity | database |
We do not require you to enter a Social Security number as a data field, and the
Service provides none. An SSN reaches us only if it appears inside a document you
choose to upload.
We will:
include your use of the Service and any support request you make;
aware of a personal data breach affecting your data, with what we know at the
time and updates as we learn more;
it sooner on request, except where law requires retention;
You will:
for investors who do not require a 1099 or K-1 from you;
the Staff role for anyone who only enters costs;
hold their records.
Encryption. In transit via TLS 1.2 or higher. At rest via AES-256 on both
database and object storage.
Access control. Isolation between customers is enforced by Postgres row-level
security, evaluated by the database on every query, not by application code.
Role-based access is described in the Terms. Tax documents live in a separate
storage bucket that Staff and Investor roles cannot read under any circumstances.
Audit logging. Membership changes, permission changes, distributions recorded,
exports, and every single access to a tax document are written to an append-only
log visible to the workspace Admin.
Least privilege. Our own staff do not access customer data as a matter of
course. Support access requires your request or an incident, is performed through
an impersonation mechanism, and is written to your audit log where you can see it.
Backups. Encrypted, with point-in-time recovery.
Passwords. Hashed with bcrypt by our authentication provider. We never see them.
Payment cards. We never receive, transmit or store card numbers. Stripe
handles payment data directly.
You authorize the following. We will give at least 30 days' notice before adding
one, and you may object on reasonable data protection grounds.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, and the sign-in and password-reset email that goes with them | United States |
| Amazon Web Services | Underlying infrastructure | United States |
| Netlify | Website hosting, and the server-side call that reaches the document reader | United States |
| Stripe | Payment processing and billing | United States |
| Anthropic | Settlement statement reading, when you use that feature | United States |
On the document reader: a document you submit to it is sent for analysis and
returned as extracted figures. It is not retained for model training. If you would
rather no document ever leave your workspace, do not use that feature; every
figure it produces can be typed in by hand.
The Service is hosted in the United States. If you are outside the United States,
you instruct us to transfer data there, and we will put appropriate safeguards in
place where the law requires them.
If one of your investors contacts us directly, we will refer them to you. We will
help you respond within a reasonable time. Deleting an investor and their
documents is something you can do yourself at any time.
On reasonable notice, no more than once a year, you may request information
demonstrating compliance with this DPA. We will provide our current security
documentation and answer reasonable questions. If we hold a SOC 2 report at the
time, that report satisfies this section.
Liability under this DPA is subject to the limitations in the Terms of Service.
If this DPA conflicts with the Terms of Service on the processing of personal
information, this DPA governs.