This notice applies to you if you are a resident of a US state with a comprehensive consumer-privacy law and you use Diligence Forge as a portal user (for example as a borrower or target-company representative). It supplements the Privacy Policy; where the two differ for US residents, this notice applies. Where OpsFi processes your information on behalf of a lender or FDD-provider customer, that customer is the "business" and OpsFi is its "service provider" or "processor"; direct your requests to that customer.
1. Categories of personal information we collect
| Category (CCPA §1798.140) | Examples | Source | Business purpose |
|---|---|---|---|
| Identifiers | name, business email, organisation, role | You; the organisation that invited you | Provide and secure the service |
| Professional information | job title, employer, seniority level | You; your organisation | Role-based access |
| Internet / network activity | IP address, user agent, sign-in and audit events | Automatically, when you use the Platform | Security, fraud prevention, audit |
| Commercial / financial information | deal documents, financial records and correspondence you contribute | You; deal counterparties | Deliver the diligence workflow |
| Inferences | AI-generated summaries and classifications of the content you contribute | Derived by the Platform | Deliver the diligence workflow |
We collect only what the service requires. We do not collect sensitive personal information as defined by the CPRA except to the extent it appears in documents you or a counterparty choose to upload; we do not use it to infer characteristics about you.
2. Sale, sharing and targeted advertising
We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not use personal information for targeted advertising or profiling that produces legal or similarly significant effects. Because we do not sell or share, there is no "Do Not Sell or Share" choice to exercise; we honour Global Privacy Control signals as an opt-out of the consent-gated analytics described in the Cookie Notice (counsel to confirm GPC treatment).
3. Disclosure for business purposes
We disclose personal information to the service providers listed in the Sub-processor Register, each under a written contract that limits use to the services provided to us. We may also disclose it where required by law or to protect rights, safety and security.
4. Retention
We keep personal information for the periods described in the Retention Schedule: account data for the life of the account, financial and audit records for a statutory minimum (currently seven years), and transient data for shorter periods.
5. Your rights
Subject to applicable law and verification of your identity you may request to know what personal information we hold and how it is used; to access and receive a portable copy; to correct inaccurate information; to delete it, subject to legal-retention exceptions; and to limit the use of sensitive personal information. You may also appeal a decision on your request. You will not be discriminated against for exercising these rights.
Use "Download my data" and "Erase my data" on your account page, or contact privacy@opsfi.co. An authorised agent may submit a request on your behalf with written permission; we will verify both identities.
6. Notice at collection
At the point you create an account or are invited to a deal, the categories in §1, the purposes in §1, the fact that we do not sell or share, and the retention periods in §4 constitute our notice at collection.
7. Changes
Material changes bump POLICY_VERSION and are published in the Documentation
Hub and at the public policy routes.
Questions: privacy@opsfi.co.
This document is view-only inside Diligence Forge and is not available for printing or download. Sign in and open Settings → Documentation to read it.