← Back to home

Privacy Policy

Version 2026-05-16

Draft — pending legal review. This document is an engineering-prepared draft and is not legal advice. It is published in versioned form for transparency while qualified counsel reviews and finalises it. For the current authoritative position contact privacy@opsfi.co.

This policy explains how OpsFi ("we", "us") handles personal data of individuals who use the Diligence Forge platform ("the Platform") as portal users — primarily borrowers, target-company representatives, and their named contacts. For these individuals OpsFi is the data controller.

Where OpsFi processes personal data on behalf of a lender or FDD-provider customer (their employees, and the financial information of the deals/targets they upload), OpsFi is a processor; that processing is governed by the Data Processing Agreement between OpsFi and that customer, and the customer's own privacy notice — not this policy.

1. Who we are

OpsFi is a UK-registered company. Data-protection contact: privacy@opsfi.co (counsel to confirm the registered entity name, address, ICO registration number, and whether a statutory DPO / EU/UK representative is required).

2. What we collect and why

Category Examples Purpose Lawful basis (Art. 6) — counsel to confirm
Account & identity name, email, organisation, role Provide and secure access Contract / legitimate interests
Authentication & security hashed credentials, MFA factors, session/JWT cookie, IP, user-agent Account security, fraud/abuse prevention Legitimate interests / legal obligation
Deal-collaboration data documents you upload, notes, messages, meeting details you provide Deliver the diligence workflow you participate in Contract / legitimate interests
Consent records which policy version you accepted, when, IP/user-agent Demonstrate consent (Art. 7) Legal obligation
Usage & audit logs actions taken, AI-feature usage, timestamps Security, audit, billing, service integrity Legitimate interests / legal obligation

We do not sell personal data. We do not use your personal data to train third-party AI models; AI features process content transiently to produce the requested output (see §6).

3. Cookies

We use a strictly-necessary authentication cookie and, only with your consent, product-analytics. See the Cookie Notice.

4. Who we share it with

Service providers ("sub-processors") that host and operate the Platform — see the Sub-processor register. Each is bound by a data- processing contract. Some are located outside the UK/EEA; transfers rely on the UK IDTA / EU SCCs (counsel to confirm per provider). We also disclose data where required by law.

5. How long we keep it

Per the Retention Schedule. In summary: account data for the life of the account; financial, audit and contractual records for a statutory minimum (currently 7 years); transient operational data is deleted sooner. Erasure requests are honoured subject to those legal-retention obligations (see §7).

6. AI processing

Some features send the content you are working on to AI service providers (see the sub-processor register) to generate analysis you request. Inputs are processed transiently for that request; we do not permit the provider to train on your content. AI output is assistive and reviewed within the diligence workflow. The AI Use and Privacy Policy describes the AI features, providers, logging and controls in detail.

7. Your rights

Subject to UK/EU GDPR you may request: access and a portable copy (Art. 15/20), rectification, erasure (Art. 17), restriction, and objection. The Platform provides self-service "Download my data" and "Erase my data" on your account page. Where OpsFi is only a processor for your data (e.g. you are a lender/FDD-provider employee), we route your request to your organisation, which is the controller. Erasure does not delete records we must retain by law; those are de-identified instead. You may complain to the UK ICO (or your local supervisory authority). Residents of US states with comprehensive privacy laws have the additional rights described in the US State Privacy Notice.

8. Security

RLS-enforced tenant isolation, MFA for privileged roles, encrypted transport and at-rest storage, audit logging, rate limiting, and a documented incident- response process (Art. 33 — 72-hour breach notification).

9. Changes

Material changes bump POLICY_VERSION; you will be asked to review and accept the new version before continuing to use the Platform.

Contact privacy@opsfi.co for any privacy request or question.