OpenDD

Privacy Policy

Last updated: July 20, 2026 · Effective date: July 20, 2026

This Privacy Policy explains how OpenDD ("OpenDD", "we", "us", or "our") collects, uses, discloses, and protects information in connection with our website and services (the "Service"), and describes your privacy rights and choices. By using the Service, you agree to this Policy. This Policy is incorporated into our Terms of Service.

1. Who We Are 2. Information We Collect 3. How We Use Information 4. Legal Bases (EEA/UK) 5. Public-Records Data 6. Documents You Upload 7. Cookies & Similar Technologies 8. How We Share Information 9. Service Providers 10. Data Retention 11. Data Security 12. International Transfers 13. Your Rights 14. GDPR (EEA/UK) 15. CCPA/CPRA (California) 16. Children's Privacy 17. Do Not Track 18. Changes 19. Contact

1. Who We Are

OpenDD provides an online due-diligence platform that organizes information from public records. For the purposes of the EU/UK General Data Protection Regulation ("GDPR"), OpenDD is the data controller of the personal information described in this Policy, except where we process User Content on your behalf, in which case we act as a processor.

2. Information We Collect

CategoryExamples
Account dataEmail address, hashed password, verification and account status, plan and Credit balance.
Usage dataSearches you run, modules used, Credit activity, timestamps, and diagnostic/error logs.
Content you provideSearch terms and documents you upload for analysis.
Device & technical dataIP address, browser type, and similar data collected automatically to operate and secure the Service.
CookiesA strictly-necessary session cookie to keep you signed in (see Section 7).

3. How We Use Information

4. Legal Bases for Processing (EEA/UK)

Where GDPR applies, we process personal information on these bases: performance of our contract with you (to provide the Service); our legitimate interests (to operate, secure, and improve the Service, and to prevent abuse); your consent (where we ask for it); and compliance with legal obligations. You may withdraw consent at any time where processing is based on consent.

5. Public-Records Data

The results the Service returns are drawn from third-party public sources (e.g. SEC EDGAR, USPTO, U.S. Copyright Office, OFAC/BIS/DDTC, CourtListener, and news indexes). Information about companies and individuals in those results originates with those sources and is subject to their accuracy and terms. We do not control that source data; if a public source contains information about you, contact that source to correct it. We process such data to provide a research and due-diligence tool, which is a legitimate interest and, where applicable, a matter of public interest.

6. Documents You Upload & AI Processing

Documents and records you submit for analysis are processed to generate the output you request. Where AI-assisted features are enabled (for example, document summaries and extraction of officers, directors, or licenses), the relevant text may be transmitted to and processed by third-party AI providers acting as our sub-processors — currently Anthropic and/or OpenAI — solely to produce your result.

These providers process such content under their applicable terms and privacy commitments, including Anthropic's Privacy Policy and Commercial Terms, and OpenAI's Privacy Policy and API Data Usage Policies. We use these providers on terms under which submitted content is not used to train their models by default and is retained only transiently as needed to provide the service. We do not sell your documents and do not use them to train third-party models. You should not upload content you are not permitted to share with such providers; avoid submitting sensitive personal information you do not need analyzed.

7. Cookies & Similar Technologies

We use a single strictly-necessary cookie to maintain your signed-in session. This cookie is essential to provide the Service and, under the EU ePrivacy rules, does not require prior consent. We do not use advertising, cross-site tracking, or non-essential analytics cookies. If this changes, we will update this Policy and, where required, request consent.

8. How We Share Information

We do not sell or rent your personal information. We share it only: (a) with service providers acting on our behalf under contractual confidentiality and security obligations (Section 9); (b) to comply with law, legal process, or lawful requests, or to protect rights, safety, and the integrity of the Service; and (c) in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

9. Service Providers

We rely on vendors for hosting/infrastructure, email delivery, and (where enabled) AI processing. These providers may process personal information only as needed to perform services for us and are bound by appropriate data-protection terms.

10. Data Retention

We retain account and usage information for as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Saved searches are retained until you delete them or close your account. When information is no longer needed, we delete or de-identify it.

11. Data Security

We use reasonable administrative, technical, and organizational measures to protect information, including encryption in transit and salted, hashed password storage. No system is completely secure, and we cannot guarantee absolute security; you are responsible for keeping your credentials confidential.

12. International Data Transfers

We operate in the United States and may process information there and in other countries. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. By using the Service, you understand your information may be processed in the United States.

13. Your Rights & Choices

Subject to applicable law, you may access, correct, update, delete, or export your personal information, object to or restrict certain processing, and withdraw consent. You can manage much of your data from your account dashboard, or contact us. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights.

14. GDPR Rights (EEA/UK)

If you are in the EEA or UK, you have the rights to access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with your local supervisory authority. To exercise these rights, contact us; we may need to verify your identity.

15. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the rights to know, access, correct, and delete personal information, and to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law. You may exercise these rights by contacting us, and we will not discriminate against you for doing so.

16. Children's Privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

17. Do Not Track

Because there is no common industry standard for "Do Not Track" signals, the Service does not currently respond to them. We do not track users across third-party websites.

18. Changes to this Policy

We may update this Policy from time to time. We will post the revised Policy with a new "Last updated" date, and material changes may be communicated through the Service.

19. Contact Us

Questions or requests about privacy? Please reach us through our Contact page.