Draft pending professional legal review. This document describes how DiligenceControl actually behaves today. It has not been reviewed or approved by a lawyer, it is not legal advice, and no regulatory certification is claimed.

Data processing draft

A factual description of processing carried out on a customer's behalf, so a qualified adviser can turn it into a data-processing agreement.

Roles

The customer organization decides what documents and personal data enter DiligenceControl and why. DiligenceControl processes that data only to provide the service described here, as processor on the customer’s instructions. The processor is Aaron Sperber, operating DiligenceControl as an individual business owner rather than a registered company. Notices and instructions under this draft go to support@diligencecontrol.com.

Subject matter and duration

Storing and processing acquisition documents and derived evidence for as long as the customer keeps an organization, plus the retention values the owner configures, plus backup expiry on the platform’s own schedule.

Nature and purpose of processing

  • Private storage of uploaded PDF, CSV and XLSX documents and immutable versions.
  • Deterministic parsing and extraction of values with a page/line, row/column or sheet/cell source reference and a short quoted excerpt.
  • Human review, correction and attestation of those values.
  • Coverage, conflict and calculation checks; issue tracking; counterparty requests.
  • Approval recording and generation of Evidence Package snapshots and exports.

Categories of data subjects and data

Customer personnel (email, name, job title, role, activity records), counterparty contacts (name, organization, email, messages and attachments they submit), and any personal data contained inside uploaded documents — for example tenant names or amounts inside a rent roll. Special-category data is not requested and should not be uploaded.

Technical and organizational measures actually implemented

  • Row-level database authorization derived from a verified identity and membership.
  • Verified email from the authentication provider’s authoritative record for identity checks; user-editable metadata is never trusted.
  • Private object storage; downloads only via short-lived signed links.
  • Per-deal access grants; counterparty access limited to explicitly shared items, revocable and expiring.
  • Append-only activity, evidence, exception and approval history.
  • Server-side authorization on every mutating endpoint, including exports and templates.
  • HMAC signature verification and idempotent, order-protected handling of payment webhooks.
  • Spreadsheet macros never executed; formula-looking text stored as text.
  • Aggregate-only platform administration with no impersonation.

Not implemented: malware scanning of uploads, text recognition for scanned pages, a durable background worker, tested restore, and irreversible customer-facing deletion (switched off pending review). Encryption at rest and in transit is provided by the managed platform.

Sub-processors

Two sub-processors are in use: a managed application, database and storage platform, and a managed payment provider used only for the internal-test billing flow. No other sub-processor processes customer data today. If one is added, this document is updated before that processing begins.

Sub-processing, transfers and audits

Security incidents affecting customer data are reported to the affected organization without undue delay after they are identified. International transfer mechanisms, formal audit rights and fixed notification periods are not stated here and will be added after professional legal review; no period is committed in this draft.

Deletion and return of data

On request, an organization owner can export Evidence Package snapshots and request deletion following the confirmation workflow in the product, or write to support@diligencecontrol.com. Backup copies expire on the platform’s own schedule and are described separately in the privacy draft.

Who operates DiligenceControl

DiligenceControl is operated by Aaron Sperber as an individual business owner. It is not a registered company, and no corporate entity, company number or incorporation jurisdiction exists.

All notices, privacy requests, billing questions, cancellation requests and support go to support@diligencecontrol.com. DiligenceControl is an online service and does not operate a public office address.

Other documents: Terms · Privacy · Data processing · Help