← Back to home

US State Privacy Notice

Version 2026-05-16

Draft — pending legal review. This document is an engineering-prepared draft and is not legal advice. It is published in versioned form for transparency while qualified counsel reviews and finalises it. For the current authoritative position contact privacy@opsfi.co.

This notice applies to you if you are a resident of a US state with a comprehensive consumer-privacy law and you use Diligence Forge as a portal user (for example as a borrower or target-company representative). It supplements the Privacy Policy; where the two differ for US residents, this notice applies. Where OpsFi processes your information on behalf of a lender or FDD-provider customer, that customer is the "business" and OpsFi is its "service provider" or "processor"; direct your requests to that customer.

1. Categories of personal information we collect

Category (CCPA §1798.140) Examples Source Business purpose
Identifiers name, business email, organisation, role You; the organisation that invited you Provide and secure the service
Professional information job title, employer, seniority level You; your organisation Role-based access
Internet / network activity IP address, user agent, sign-in and audit events Automatically, when you use the Platform Security, fraud prevention, audit
Commercial / financial information deal documents, financial records and correspondence you contribute You; deal counterparties Deliver the diligence workflow
Inferences AI-generated summaries and classifications of the content you contribute Derived by the Platform Deliver the diligence workflow

We collect only what the service requires. We do not collect sensitive personal information as defined by the CPRA except to the extent it appears in documents you or a counterparty choose to upload; we do not use it to infer characteristics about you.

2. Sale, sharing and targeted advertising

We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not use personal information for targeted advertising or profiling that produces legal or similarly significant effects. Because we do not sell or share, there is no "Do Not Sell or Share" choice to exercise; we honour Global Privacy Control signals as an opt-out of the consent-gated analytics described in the Cookie Notice (counsel to confirm GPC treatment).

3. Disclosure for business purposes

We disclose personal information to the service providers listed in the Sub-processor Register, each under a written contract that limits use to the services provided to us. We may also disclose it where required by law or to protect rights, safety and security.

4. Retention

We keep personal information for the periods described in the Retention Schedule: account data for the life of the account, financial and audit records for a statutory minimum (currently seven years), and transient data for shorter periods.

5. Your rights

Subject to applicable law and verification of your identity you may request to know what personal information we hold and how it is used; to access and receive a portable copy; to correct inaccurate information; to delete it, subject to legal-retention exceptions; and to limit the use of sensitive personal information. You may also appeal a decision on your request. You will not be discriminated against for exercising these rights.

Use "Download my data" and "Erase my data" on your account page, or contact privacy@opsfi.co. An authorised agent may submit a request on your behalf with written permission; we will verify both identities.

6. Notice at collection

At the point you create an account or are invited to a deal, the categories in §1, the purposes in §1, the fact that we do not sell or share, and the retention periods in §4 constitute our notice at collection.

7. Changes

Material changes bump POLICY_VERSION and are published in the Documentation Hub and at the public policy routes.

Questions: privacy@opsfi.co.