This policy explains how OpsFi ("we", "us") handles personal data of individuals who use the Diligence Forge platform ("the Platform") as portal users — primarily borrowers, target-company representatives, and their named contacts. For these individuals OpsFi is the data controller.
Where OpsFi processes personal data on behalf of a lender or FDD-provider customer (their employees, and the financial information of the deals/targets they upload), OpsFi is a processor; that processing is governed by the Data Processing Agreement between OpsFi and that customer, and the customer's own privacy notice — not this policy.
1. Who we are
OpsFi is a UK-registered company. Data-protection contact: privacy@opsfi.co (counsel to confirm the registered entity name, address, ICO registration number, and whether a statutory DPO / EU/UK representative is required).
2. What we collect and why
| Category | Examples | Purpose | Lawful basis (Art. 6) — counsel to confirm |
|---|---|---|---|
| Account & identity | name, email, organisation, role | Provide and secure access | Contract / legitimate interests |
| Authentication & security | hashed credentials, MFA factors, session/JWT cookie, IP, user-agent | Account security, fraud/abuse prevention | Legitimate interests / legal obligation |
| Deal-collaboration data | documents you upload, notes, messages, meeting details you provide | Deliver the diligence workflow you participate in | Contract / legitimate interests |
| Consent records | which policy version you accepted, when, IP/user-agent | Demonstrate consent (Art. 7) | Legal obligation |
| Usage & audit logs | actions taken, AI-feature usage, timestamps | Security, audit, billing, service integrity | Legitimate interests / legal obligation |
We do not sell personal data. We do not use your personal data to train third-party AI models; AI features process content transiently to produce the requested output (see §6).
3. Cookies
We use a strictly-necessary authentication cookie and, only with your consent, product-analytics. See the Cookie Notice.
4. Who we share it with
Service providers ("sub-processors") that host and operate the Platform — see the Sub-processor register. Each is bound by a data- processing contract. Some are located outside the UK/EEA; transfers rely on the UK IDTA / EU SCCs (counsel to confirm per provider). We also disclose data where required by law.
5. How long we keep it
Per the Retention Schedule. In summary: account data for the life of the account; financial, audit and contractual records for a statutory minimum (currently 7 years); transient operational data is deleted sooner. Erasure requests are honoured subject to those legal-retention obligations (see §7).
6. AI processing
Some features send the content you are working on to AI service providers (see the sub-processor register) to generate analysis you request. Inputs are processed transiently for that request; we do not permit the provider to train on your content. AI output is assistive and reviewed within the diligence workflow. The AI Use and Privacy Policy describes the AI features, providers, logging and controls in detail.
7. Your rights
Subject to UK/EU GDPR you may request: access and a portable copy (Art. 15/20), rectification, erasure (Art. 17), restriction, and objection. The Platform provides self-service "Download my data" and "Erase my data" on your account page. Where OpsFi is only a processor for your data (e.g. you are a lender/FDD-provider employee), we route your request to your organisation, which is the controller. Erasure does not delete records we must retain by law; those are de-identified instead. You may complain to the UK ICO (or your local supervisory authority). Residents of US states with comprehensive privacy laws have the additional rights described in the US State Privacy Notice.
8. Security
RLS-enforced tenant isolation, MFA for privileged roles, encrypted transport and at-rest storage, audit logging, rate limiting, and a documented incident- response process (Art. 33 — 72-hour breach notification).
9. Changes
Material changes bump POLICY_VERSION; you will be asked to review and accept
the new version before continuing to use the Platform.
Contact privacy@opsfi.co for any privacy request or question.
This document is view-only inside Diligence Forge and is not available for printing or download. Sign in and open Settings → Documentation to read it.