Legal
Last Updated: March 25, 2026
Guiding Principles
DiligenceGPT™'s privacy and security practices are grounded in the following core principles:
DiligenceGPT™ - StartupFuel Inc. ("DiligenceGPT™", "we", "our", or "us") is an AI-powered due diligence platform designed for venture capital firms, angel investors, accelerators, private equity firms, family offices, corporate VCs, institutional investors and any private market investors. We process highly sensitive and proprietary materials on behalf of our clients, including data rooms, investment memoranda, financial records, cap tables, legal agreements, and other confidential documents.
Protecting the confidentiality, integrity, and availability of this information is fundamental to our business. This Data Privacy & Security Policy describes how we collect, use, store, encrypt, and safeguard all data submitted to our platform.
We are committed to protecting your privacy. This Policy describes our practices regarding the Personal Data we collect from users of our Sites and the Materials that are made available or enabled via the Sites. Capitalized terms have the meanings given in the Definitions section at the end of this Policy.
This policy applies to all customers, authorized users, and visitors of DiligenceGPT™'s services.
We gather automatically collected information and may store it in log files. We use this information to analyze trends, administer the Sites, track users' movements around the Sites, and to gather demographic information about our user base.
Cookies. We use cookies to collect information. "Cookies" are text files containing small amounts of information which are downloaded to your device when you visit a website or application. Our Sites use the following types of cookies:
Pixel Tags. We may use Pixel Tags (also known as clear GIFs, Web beacons, or Web bugs) to track online movements of Web users and to tell us whether e-mails have been opened, helping us eliminate unwanted messages.
Google Analytics. We use Google Analytics to help analyze how users use the Sites. Google Analytics collects only the IP address assigned to you on the date you visit the Sites, not personally identifying information. We do not combine information generated through Google Analytics with your Personal Data.
No Advertisements. We do not use third parties to serve ads on the Site or collect personally identifiable information about your online activities.
If you become a registered member of DiligenceGPT™, we may collect additional Personal Data from you, as well as personal information associated with your investors and other contacts you enter into DiligenceGPT™ (“End Users”), that may include the types of information listed below.
| Category | Details |
|---|---|
| Identity Data | Names, social security numbers, forms of identification, personal information on applications and identification forms. |
| Contact Data | Addresses, email address and telephone numbers. |
| Professional Background Data | Educational and professional history. |
| Online Data | Links to your public account pages at social media and personal websites. |
| Financial Data | Your bank account, payment card details, and financial statements. |
| Transaction Data | Data on your transactions on DiligenceGPT™. |
| Investment Data | Information about your investment objectives, investment experience, prior investments, and other information you provide. |
| Content Data | Any content you post to DiligenceGPT™. |
| Marketing Data | Your preferences in receiving marketing from us and our third parties and your communication preferences. |
| Behavioral Data | Information relating to your behavior and interests based on your online activity. |
Personal Data from Third Party Sources. In addition to the Personal Data we collect directly from you, we may also collect certain Personal Data from third party sources, some of which may not be publicly available.
| Third Party Data Source | Categories |
|---|---|
| Social Media Sites | Identity Data, Contact Data, Online Presence Data |
| Our Affiliates | Identity Data, Contact Data, Marketing Data, Behavioral Data, Investment Data, Transaction Data, Financial Data, Content Data |
| Our Fund Administration Partners | Identity Data, Contact Data, Investment Data, Transaction Data, Financial Data |
| Analytics Providers | Behavioral Data, Technical Data |
| Identity Verification and Compliance Service Providers | Identity Data, Contact Data |
In general, we use your Personal Data to support the services we provide to help you manage and grow your firm and support the investor community. Client data is used strictly and exclusively for:
Unless you provide permission, your Personal Data will remain confidential unless required by law. We do not sell, license, share, or otherwise disclose client data to any third party for commercial purposes. Client data is never used as a basis for advertising, market research, or any purpose outside the contracted services.
All client data submitted to DiligenceGPT™ is stored within secure, enterprise-grade cloud infrastructure. Given the highly sensitive and proprietary nature of the materials we handle, we apply the following protections as a baseline standard for all clients.
Personal Data submitted by you for document generation and other purposes will be retained for such period as may be required to fulfill the purposes set out in this Policy, or such other period as may be required by law. You may request deletion of your Personal Data by us, and we will use commercially reasonable efforts to honor your request, but please note that we may be required by law to keep such information and not delete it. When we delete any information, it will be deleted from the active database, but may remain in our archives for the period described above.
Clients retain full and exclusive ownership of all data, documents, and materials they submit to the DiligenceGPT™ platform, including all proprietary deal information, data room contents, and investment-related files.
DiligenceGPT™ processes client data solely for the purpose of delivering the contracted due diligence services. We make no claim to any intellectual property, commercial rights, or ownership interest in client-submitted materials.
Any AI-generated outputs produced by DiligenceGPT™ based on client data (e.g., reports, summaries, assessments) are the property of the client unless otherwise agreed in writing.
DiligenceGPT™ is designed specifically to handle the most sensitive categories of financial and investment data. We apply enhanced protections to all data room contents and proprietary materials:
We implement enterprise-grade security controls across all layers of our infrastructure:
Access to client data is restricted to a minimal set of authorized DiligenceGPT™ personnel with a documented, legitimate operational need. All such access is logged and reviewable.
DiligenceGPT™ may engage carefully vetted third-party service providers to support our operations, which may include:
All subprocessors are subject to binding contractual obligations regarding confidentiality, data protection, and non-use of client data for any purpose beyond the defined service scope. DiligenceGPT™ maintains a current list of subprocessors available to enterprise clients upon request.
Google Gmail. If you sign up for DiligenceGPT™ with a Gmail address and upon your authorization, DiligenceGPT™ will automatically sync with your Gmail account. This means that DiligenceGPT™ will access your Gmail contacts, emails, calendar, distribution lists, subject lines and URLs of tracked links from your email, if you use the email tracking functionality. We will use Google User Data only to provide or improve user-facing features of DiligenceGPT™. Our use and transfer to any other application of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
Google Drive. You have the option to connect your Google Drive account to DiligenceGPT™. If you choose to do so, you will be able to see your files, upload and download your files, and store file contents and titles on DiligenceGPT™.
Third Party Websites. The Sites may contain links to third party websites. When you click on a link to any other website or location, you will leave our Site and go to another site, and another entity may collect Personal Data or Anonymous Data from you. We have no control over, do not review, and cannot be responsible for, these outside websites or their content. We encourage you to read the privacy policies of every website you visit.
DiligenceGPT™ maintains a formal Incident Response Plan (IRP) for identifying, containing, and remediating security incidents involving client data. In the event of a confirmed or suspected data breach affecting client data:
Given the sensitivity of financial and investment data processed on our platform, we treat all potential security events with the highest urgency.
DiligenceGPT™ aligns its practices with applicable data protection and privacy regulations, including:
We are actively working toward SOC 2 Type II compliance and other industry-standard security certifications as the company scales. Enterprise clients may request details on our current compliance posture and roadmap.
Certain U.S. states have enacted comprehensive privacy laws that create additional privacy obligations for businesses and provide their residents with additional privacy rights. In addition to the rights granted in Section 13 below, if you are a resident of a state with enhanced privacy rights, you may also have the right to:
DiligenceGPT™ does not sell any personal information associated with our services.
The EEA and the United Kingdom have each enacted privacy laws. The EU's and the UK's General Data Protection Regulation (collectively, the “GDPR”) create additional privacy obligations for ‘Controllers’ of personal data and provide EU and UK residents with additional privacy rights.
| Processing Activity | Legal Basis under GDPR |
|---|---|
| Collection and processing of our client or their End Users' Personal Data to maintain and fulfill the Services | Contract fulfillment |
| Use of customer service tools on our platform | Contract fulfillment |
| Improving our products and services | Legitimate interest |
| Product marketing or service-related communications to clients | Legitimate interest |
| Use of cookies and other tracking technologies | Consent |
Controller Designation: Under the GDPR, we are designated as a “Controller” of our client personal data. However, in receipt of our clients' End User personal data, we operate as a “Processor”. A list of our subprocessors is available to our Clients on demand.
Cross-Border Data Transfers: DiligenceGPT™ may store personal data in Canada and the United States. If you are a resident of the EEA, UK, or Switzerland, we may transfer to, and store, the data we collect about you in countries other than the country in which the data was originally collected. For business services, we may rely on the Standard Contractual Clauses (“SCCs”) adopted by the European Commission, as well as the UK's “International Data Transfer Addendum” to the SCCs.
Additional Rights for UK or EEA Residents: If you are a UK or EEA resident, the GDPR grants you the right to lodge a complaint against us with your local data protection authority.
If you reside in Canada or Singapore, you may request to access and/or correct your Personal Data currently in our possession by writing to us. We may transfer your Personal Data to a country or territory outside Canada or Singapore in accordance with requirements prescribed under PIPEDA, Quebec Bill C-27, or the Singapore Personal Data Protection Act ("PDPA") to ensure that we provide a standard of protection to Personal Data so transferred that is comparable to the protection under applicable law.
Clients and authorized users have the following rights with respect to their data:
If you opt in to receive SMS or text messages from DiligenceGPT™, we collect your phone number and a record of your consent. We use your phone number to send you messages related to contact lookups, event management, and support. Message and data rates may apply. Message frequency varies based on your use of the platform. You may opt out at any time by replying STOP to any message. We do not share your phone number with third parties for their marketing purposes.
All data rights requests may be submitted to: privacy@startupfuel.com
DiligenceGPT™ will respond to all data rights requests within 10 business days.
The Sites and the services available on the Sites are not intended for children below 16 and we do not knowingly collect or solicit personal information from anyone under the age of 16. If you are under the age of 16, please do not submit any personal information through the Sites.
Mandated Disclosures. Regardless of any choices you make regarding your Personal Data, we may disclose Personal Data if we believe in good faith that such disclosure is necessary (a) in connection with any legal investigation; (b) to comply with relevant laws or to respond to subpoenas or warrants served on DiligenceGPT™; (c) to protect or defend the rights or property of DiligenceGPT™ or users of the Sites; and/or (d) to investigate or assist in preventing any violation or potential violation of the law, this Policy, or our Terms of Use.
Corporate Restructuring. We may share some or all of your Personal Data with entities within our group of companies. We may also share some or all of your Personal Data in connection with or during negotiation of any merger, financing, acquisition or dissolution transaction or proceeding involving sale, transfer, divestiture, or disclosure of all or a portion of our business or assets.
StartupFuel Inc. (DiligenceGPT™) may update this Data Privacy & Security Policy from time to time to reflect changes in our practices, technology, or legal requirements. Material changes will be communicated to clients via email and platform notification at least 14 days prior to taking effect. Continued use of the platform following such notice constitutes acceptance of the updated policy.
StartupFuel Inc.
Toronto, Ontario, Canada
privacy@startupfuel.com
https://www.dgpt.io
Questions? Contact us at privacy@startupfuel.com
© 2026 StartupFuel Inc. (DiligenceGPT™). All rights reserved.