Privacy Policy
This Privacy Policy explains how OpenDD ("OpenDD", "we", "us", or "our") collects, uses, discloses, and protects information in connection with our website and services (the "Service"), and describes your privacy rights and choices. By using the Service, you agree to this Policy. This Policy is incorporated into our Terms of Service.
1. Who We Are
OpenDD provides an online due-diligence platform that organizes information from public records. For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), OpenDD is the data controller of the personal information described in this Policy, except where we process User Content on your behalf, in which case we act as a processor.
2. Information We Collect
| Category | Examples |
|---|---|
| Account data | Email address, hashed password, verification and account status, plan and Credit balance. |
| Usage data | Searches you run, modules used, Credit activity, timestamps, and diagnostic/error logs. |
| Content you provide | Search terms and documents you upload for analysis. |
| Device & technical data | IP address, browser type, and similar data collected automatically to operate and secure the Service. |
| Cookies | A strictly-necessary session cookie to keep you signed in (see Section 7). |
3. How We Use Information
- To provide, maintain, secure, and improve the Service and its results.
- To authenticate you and manage your account, Credits, and preferences.
- To prevent, detect, and address fraud, abuse, and security incidents.
- To respond to your requests and communicate service-related messages.
- To comply with legal obligations and enforce our Terms.
4. Legal Bases for Processing (EEA/UK)
Where GDPR applies, we process personal information on these bases: performance of our contract with you (to provide the Service); our legitimate interests (to operate, secure, and improve the Service, and to prevent abuse); your consent (where we ask for it); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.
5. Public-Records Data
The results the Service returns are drawn from third-party public sources (e.g. SEC EDGAR, USPTO, U.S. Copyright Office, OFAC/BIS/DDTC, CourtListener, and news indexes). Information about companies and individuals in those results originates with those sources and is subject to their accuracy and terms. We do not control that source data; if a public source contains information about you, contact that source to correct it. We process such data to provide a research and due-diligence tool, which is a legitimate interest and, where applicable, a matter of public interest.
6. Documents You Upload & AI Processing
Documents and records you submit for analysis are processed to generate the output you request. Where AI-assisted features are enabled (for example, document summaries and extraction of officers, directors, or licenses), the relevant text may be transmitted to and processed by our AI sub-processor — currently Anthropic (Claude API) — solely to produce your result. We also send the search terms you enter (which may include names) to public data providers such as CourtListener to run the searches you request. The full list is on our Sub-processors page.
These providers process such content under their applicable terms and privacy commitments, including Anthropic's Privacy Policy and Commercial Terms, and OpenAI's Privacy Policy and API Data Usage Policies. We use these providers on terms under which submitted content is not used to train their models by default and is retained only transiently as needed to provide the service. We do not sell your documents and do not use them to train third-party models. You should not upload content you are not permitted to share with such providers; avoid submitting sensitive personal information you do not need analyzed.
7. Cookies & Similar Technologies
We use a single strictly-necessary cookie to maintain your signed-in session. This cookie is essential to provide the Service and, under the EU ePrivacy rules, does not require prior consent. We do not use advertising, cross-site tracking, or non-essential analytics cookies. If this changes, we will update this Policy and, where required, request consent.
8. How We Share Information
We do not sell or rent your personal information. We share it only: (a) with service providers acting on our behalf under contractual confidentiality and security obligations (Section 9); (b) to comply with law, legal process, or lawful requests, or to protect rights, safety, and the integrity of the Service; and (c) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
9. Service Providers
We rely on vendors for hosting/infrastructure, email delivery, and (where enabled) AI processing. These providers may process personal information only as needed to perform services for us and are bound by appropriate data-protection terms.
10. Data Retention
We retain account and usage information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Saved searches are retained until you delete them or close your account. When information is no longer needed, we delete or de-identify it.
11. Data Security
We use reasonable administrative, technical, and organizational measures to protect information, including encryption in transit and salted, hashed password storage. No system is completely secure, and we cannot guarantee absolute security; you are responsible for keeping your credentials confidential.
12. International Data Transfers
We operate in the United States and may process information there and in other countries. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the Service, you understand your information may be processed in the United States.
13. Your Rights & Choices
Subject to applicable law, you may access, correct, update, delete, or export your personal information, object to or restrict certain processing, and withdraw consent. You can manage much of your data from your account dashboard, or contact us. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights.
14. GDPR Rights (EEA/UK)
If you are in the EEA or UK, you have the rights to access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact us; we may need to verify your identity.
15. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the rights to know, access, correct, and delete personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law. You may exercise these rights by contacting us, and we will not discriminate against you for doing so.
16. Children's Privacy
The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
17. Do Not Track
Because there is no common industry standard for "Do Not Track" signals, the Service does not currently respond to them. We do not track users across third-party websites.
18. Changes to this Policy
We may update this Policy from time to time. We will post the revised Policy with a new "Last updated" date, and material changes may be communicated through the Service.
19. Contact Us
Questions or requests about privacy? Please reach us through our Contact page.