Draft pending professional legal review. This document describes how DiligenceControl actually behaves today. It has not been reviewed or approved by a lawyer, it is not legal advice, and no regulatory certification is claimed.

Privacy notice (draft)

What the running system stores, where it stores it, who can reach it, and how deletion behaves today.

Who is responsible

DiligenceControl is operated by Aaron Sperber as an individual business owner; it is not a registered company. Privacy and data-protection questions go to support@diligencecontrol.com. For the documents you upload, your organization decides what is collected and why; DiligenceControl processes them on your instructions.

What is stored

  • Account data — email address, verification state and sign-in metadata held by the authentication provider, plus an optional name and job title you enter.
  • Organization data — organization name, memberships and roles, per-deal access grants, invitations.
  • Deal and document data — deals, uploaded PDF/CSV/XLSX files in private storage, immutable document versions, extracted values with their source references and short quoted excerpts, processing job records, issues, counterparty requests and responses, approvals, Evidence Package snapshots, Excel templates and mappings.
  • History — append-only activity, evidence, exception and approval history recording who did what and when.
  • Billing — subscription state and payment-provider identifiers. Card details are never received or stored by DiligenceControl; they are handled by the payment provider.

Who can reach it

Access is enforced by the database from your verified identity and membership, not by hiding buttons. Members of one organization cannot read or change another organization’s records, documents or snapshots. A member without access to a deal cannot open it or download its files. Private document downloads use short-lived signed links. A counterparty who redeems a request link can only see the specific items shared with them, and that access can be revoked and expires.

A platform administrator can see aggregate counts only — organizations, users and processing job status totals. There is no impersonation, and customer document contents are not exposed to platform administration.

Processors

DiligenceControl runs on a managed application and database platform, uses a managed payment provider for the internal-test billing flow, and stores documents in that platform’s private object storage. Those are the only processors in use today; if another is added, this notice is updated before it starts processing customer data. Documents are never sent to a public malware-scanning service, and no document contents are sent to any third-party model without an explicit in-product action.

Retention and deletion

Archiving keeps records and is reversible. Permanent deletion is separate: an organization owner requests it, confirms it by typing an exact phrase, and only then can it run. Retention day values for archived deals, generated exports, processing artifacts and counterparty access grants are configurable by the owner; DiligenceControl does not assert any legal retention period.

A confirmed organization deletion covers database records, private files, generated exports, processing artifacts and external request grants. Irreversible customer-facing execution is currently switched off pending review, so the action reports exactly what would be removed. Sign-in accounts themselves are managed by the authentication provider.

Backups expire separately. The managed backend keeps its own backups on its own schedule, so deleted data can remain inside a backup copy until that copy ages out. Restore has not been exercised on this project, so restore behaviour is unverified.

Your rights

Depending on where you are, you may have rights to access, correct, export or delete personal data. Export is available today through the Evidence Package exports and organization records; deletion follows the workflow above. Requests can be sent to support@diligencecontrol.com, which is monitored by the operator personally. Requests are answered as promptly as reasonably possible; no fixed response time is promised while the service is pre-launch.

Security posture

Row-level database authorization, private storage with signed links, verified-email identity checks, HMAC-verified payment webhooks and append-only history are implemented and tested with synthetic accounts. No security certification has been obtained and none is claimed.

Who operates DiligenceControl

DiligenceControl is operated by Aaron Sperber as an individual business owner. It is not a registered company, and no corporate entity, company number or incorporation jurisdiction exists.

All notices, privacy requests, billing questions, cancellation requests and support go to support@diligencecontrol.com. DiligenceControl is an online service and does not operate a public office address.

Other documents: Terms · Privacy · Data processing · Help