Legal

Privacy Policy

How we collect, use, and protect your data.

Draft pending legal review. This policy is a working draft and has not yet been reviewed by qualified counsel. It is not yet contractually binding.

Last updated: 1 June 2026

This Privacy Policy explains how DealBook collects, uses, shares, and protects personal data when you use our website at dd.sosorry.co.uk and our due-diligence platform (together, the “Service”). DealBook provides AI-assisted due diligence for private funds. We are committed to handling your data lawfully, transparently, and in a way that keeps the highly confidential documents you entrust to us secure and within the EU/UK envelope.

1. Who we are

DealBook Ltd (“DealBook”, “we”, “us”, “our”) is a company registered in England. We are the data controller in respect of the personal data described in this policy, except where we act as a processor on behalf of our customers (see “Customer documents” below). You can reach us, including our data protection contact, at dd@sosorry.co.uk.

2. The law we follow

We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR) where applicable, and the Data Protection Act 2018. This policy is governed by the laws of England & Wales.

3. Controller and processor roles

For account data, billing data, website analytics, and contact-form submissions, we act as a data controller— we decide why and how that data is processed. For the fund documents you upload and the personal data they may contain, we act as a data processor on your behalf: we process those documents only on your instructions, to deliver the due-diligence outputs you have asked us to produce. Where we act as a processor, the terms of our data processing agreement (DPA) govern that relationship and take precedence over this policy.

4. What data we collect and why

Account data

When you create an account we collect your email address. We use it to authenticate you, to operate and secure your account, and to send you essential service communications.

  • Lawful basis: performance of a contract (UK GDPR Art. 6(1)(b)) and our legitimate interests in securing the Service (Art. 6(1)(f)).

Authentication data

We support sign-in by email one-time code and by WebAuthn passkeys. Passkey authentication stores public-key credentials only; we never receive or store your biometric data or private keys, which remain on your device.

  • Lawful basis: performance of a contract and legitimate interests in account security.

Customer documents

To deliver due-diligence outputs, you upload fund documents — for example prospectuses, due-diligence questionnaires (DDQs), pitch decks, and track records. These documents are highly confidential and may contain personal data relating to fund staff or third parties. We process them solely to produce the analysis you request, as your processor.

  • Lawful basis: you are responsible for ensuring you have a lawful basis to share this data with us; we process it under your instructions in performance of our contract with you.

Billing data

When you subscribe to a paid plan, payments are handled by Stripe. We receive limited billing metadata (such as plan, transaction status, and the last four digits of a card) but never store full card numbers, which are handled directly by Stripe.

  • Lawful basis: performance of a contract and compliance with our legal obligations (Art. 6(1)(c)), such as tax and accounting record-keeping.

Contact-form submissions

If you contact us through our website, we collect your name, email address, your message, and the category you select. We use this to respond to your enquiry.

  • Lawful basis: our legitimate interests in responding to enquiries and taking steps at your request prior to entering into a contract.

Usage and product analytics

We use PostHog to understand how the Service is used so we can improve it. See “Cookies and analytics” below.

  • Lawful basis: consent where required, otherwise our legitimate interests in operating and improving the Service.

5. How your documents are processed by AI

DealBook uses large language models to read and analyse your fund documents. Document content is sent to our AI sub-processors — AWS Bedrock and Google Vertex AI — strictly to generate your due-diligence outputs. We rely on these providers’ enterprise terms, under which your inputs and outputs are not used to train their foundation models or any third-party models.

All AI processing happens inside EU regions (see “International transfers”). We also use Langfuse to trace and monitor our own LLM calls for quality, cost, and reliability; this observability data is retained within our EU envelope.

6. Sharing and sub-processors

We do not sell your personal data. We share data only with the sub-processors that power the Service, each bound by contractual data-protection obligations and engaged for the purposes below:

  • Amazon Web Services (AWS)— AI inference (Bedrock), outbound and inbound email (SES), object storage (S3), and serverless processing (Lambda).
  • Google Cloud— AI inference via Vertex AI (Gemini models).
  • Supabase— database, authentication, and file storage.
  • Stripe— payment processing.
  • PostHog— product analytics.
  • Langfuse— LLM observability and tracing.
  • Inngest— background job orchestration.
  • Vercel— application hosting and content delivery.

We may also disclose data where required by law or to protect the rights, property, or safety of DealBook, our customers, or others. A current sub-processor list is available on request at dd@sosorry.co.uk.

7. International transfers

All customer data is processed and stored within the EU/UK envelope. Our infrastructure is configured to keep data in EU regions at every stage: AWS Bedrock (eu-west-2, London), Google Vertex AI (europe-west4, Netherlands), Supabase Postgres and Storage (EU), and AWS SES (eu-west-1). We do not transfer customer document data outside the EU/UK.

8. Retention

We keep personal data only for as long as necessary for the purposes set out in this policy. Account data is retained for the life of your account and for a reasonable period afterwards. Due-diligence records remain queryable for as long as you maintain them with us, so they are available for ongoing reference; you can request their deletion at any time. Billing records are kept for as long as required by applicable tax and accounting law. Contact-form submissions are retained only as long as needed to handle your enquiry and any follow-up.

9. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls and least-privilege permissions, EU-only data residency, and verification of AI outputs before they are shown to users. We are working towards SOC 2 certification; this is in progress and not yet certified. No system is perfectly secure, but we take reasonable steps to safeguard your data and will notify affected users and the relevant supervisory authority of a personal-data breach where required by law.

10. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • access the personal data we hold about you;
  • request correction of inaccurate or incomplete data (rectification);
  • request deletion of your data (erasure), subject to legal limits;
  • receive your data in a portable, machine-readable format (portability);
  • object to or restrict certain processing;
  • withdraw consent at any time where we rely on consent.

To exercise any of these rights, email us at dd@sosorry.co.uk. We will respond within the statutory timeframe. Where the personal data relates to documents you uploaded as a controller, we will assist you in fulfilling data-subject requests in line with our DPA.

11. Cookies and analytics

We use a small number of cookies and similar technologies that are necessary to operate and secure the Service (for example, to keep you signed in). We also use PostHog to collect product-usage analytics that help us understand and improve the Service. Where consent is required for non-essential analytics, we will ask for it, and you can change your choice at any time. You can also control cookies through your browser settings.

12. Children

The Service is a business-to-business product intended for professional users. It is not directed at, or intended for use by, anyone under 18, and we do not knowingly collect personal data from children.

13. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update constitutes acceptance of the revised policy.

14. Contact and complaints

If you have any questions about this policy or how we handle your data, contact us at dd@sosorry.co.uk. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk or with your local supervisory authority in the EU.

Questions about your data?

We're happy to walk you through it.

Email our team or read our security overview.