1. Controller and scope
Due Diligence HQ (DD HQ) is operated by:
5IP Technology GmbH
c/o Jürgen Samuel
Hurdnerstrasse 98
8640 Hurden
Switzerland
UID: CHE-417.366.049
Commercial Register No.: CH-130.4.037.145-3
Email: 5pt.gmbh@gmail.com
This Privacy Policy explains how 5IP Technology GmbH processes personal data when you visit duediligencehq.com, contact us, apply for a role, create or use an account, participate in a DD HQ interview or assessment, or otherwise use the Service. It applies to our processing as controller under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU GDPR or UK GDPR.
2. Our roles
We act as controller for website, contact, account, billing, security, support, recruitment and our own business-operation data. When a Customer submits personal data in Customer Content and we process it only to provide the Service on the Customer's instructions, the Customer is normally controller (or processor for another controller) and 5IP Technology GmbH is processor or subprocessor. That processing is governed by the Data Processing Addendum and Customer instructions.
3. Personal data we process
Depending on your interaction, we may process:
- account and identity data, including name, business email, organisation, role, account identifiers, authentication status, organisation memberships, project permissions and policy acceptances;
- contact and sales data, including enquiries, correspondence, meeting details and support or inbox messages;
- Customer Content, including uploaded documents, data-room files, contracts, financial or transaction material, prompts, instructions and other information supplied by or for a Customer;
- analysis and output data, including extracted text, chunks and indexes, evidence, classifications, findings, reports, project knowledge, chat messages, review decisions and report versions;
- interview and assessment data, including invite and participant details, consent records, recordings where separately agreed, transcripts, responses, public-source research, generated assessments and review status;
- recruitment data, including application details, curriculum vitae, contact data and hiring correspondence;
- usage, cookie and security data, including IP address, browser and device data, session identifiers, timestamps, login activity, application interactions, system events, errors, audit events and consent choices; and
- billing data, including legal name, billing address, invoice email, tax identifiers, subscription and seat data, payment-method brand and last four digits, invoices and transaction references. Full card details are processed by Stripe rather than stored by DD HQ.
Customer Content can contain personal data about employees, directors, shareholders, beneficial owners, customers, suppliers, advisers, applicants, interview participants and other people. Customers are responsible for lawful collection and disclosure of that data.
4. Sources
We obtain data from you, Customer workspace administrators, other authorised Customer users, uploaded material, configured identity and payment providers, public registers and websites when a Customer enables public research, and automatically from use of the Service. If data is not obtained directly from you, we provide this notice and any additional notice required in the circumstances.
5. Purposes and legal grounds
We process data to provide and administer the Service; authenticate users; enforce organisation and project permissions; ingest, analyse and report on Customer Content; operate AI, chat, interview and assessment functions; provide support and agreed professional review; administer trials, subscriptions, seats, invoices and taxes; answer enquiries and process job applications; maintain audit trails; secure, monitor and troubleshoot the Service; prevent fraud and misuse; improve functionality; comply with law; and establish, exercise or defend legal claims.
Under Swiss law, we process personal data in accordance with the FADP principles of lawfulness, good faith, transparency, proportionality, purpose limitation, accuracy and security. Where processing would infringe personality rights, we rely on consent, an overriding private or public interest, or law as applicable. Where the GDPR or UK GDPR applies, the legal ground is performance of a contract or pre-contract steps, compliance with law, legitimate interests in operating and securing a business service, or consent for optional tracking and other activities where consent is required.
6. AI, embeddings and automated analysis
DD HQ uses AI to extract, classify, summarise, assess and generate content. Depending on Customer configuration, relevant Customer Content and instructions may be sent to supported providers including OpenAI or Anthropic; OpenAI may also be used to create embeddings for retrieval. Only data reasonably necessary for the requested operation should be submitted.
AI outputs may contain errors or incorrect inferences. DD HQ is designed for decision support and human review. 5IP Technology GmbH does not itself use DD HQ outputs to take solely automated decisions about individuals that produce legal or similarly significant effects. Customers configuring workflows involving such decisions must assess and satisfy applicable notice, explanation, human-review and challenge rights, including Article 21 FADP where applicable.
7. Recipients and service providers
We may disclose data, only as necessary, to:
- infrastructure, hosting, object-storage, database, email, monitoring, security, document-processing and support providers;
- supported AI and embedding providers enabled for the relevant workspace;
- Google when a user chooses Google sign-in and, after analytics consent, where configured analytics tags are loaded through Google Tag Manager;
- Stripe for subscriptions, invoicing, tax calculation and payment processing;
- authorised personnel, contractors or specialists providing support or separately agreed human review, subject to confidentiality and access controls;
- accountants, auditors, insurers and legal or other professional advisers;
- authorities where disclosure is required by law or a lawful order; and
- a buyer, investor or successor in a merger, financing, restructuring or asset sale, subject to appropriate safeguards.
We do not sell personal data. A current description of Customer-data subprocessors is included in the Data Processing Addendum or made available on request.
8. International disclosures
Data may be processed in Switzerland, the EEA, the United Kingdom, the United States and other countries associated with a Customer-selected or operational provider. Destination countries and providers depend on deployment and workspace configuration.
For disclosures from Switzerland, we use a destination recognised in Annex 1 to the Swiss Data Protection Ordinance or safeguards permitted by Articles 16 and 17 FADP, such as recognised standard contractual clauses with Swiss adaptations and supplementary measures where required. Where the GDPR or UK GDPR applies, we use an adequacy decision, applicable standard contractual clauses, the UK addendum or another lawful mechanism. Information about the relevant destination and safeguards is available on request.
9. Retention
We keep personal data only as long as necessary for the relevant purpose and legal obligations. The Data Retention & Deletion Notice gives the operational schedule. Key periods currently include:
- completed data-portability export files: 7 days;
- IP addresses in audit and consent records: 90 days before redaction;
- raw billing webhook payloads: 90 days before redaction;
- interview recording artifacts: 365 days, unless a shorter period is agreed or earlier deletion is required;
- recruitment applications: 365 days, unless law or a separate notice requires another period; and
- accounting records and invoices: generally 10 years where Swiss accounting law requires it.
Account data and Customer Content are normally retained for the service relationship and then deleted, returned, anonymised or retained only where an agreement, legal obligation, dispute hold or ordinary backup cycle requires it. Some audit records may be retained without the originating IP address to protect security and demonstrate accountability.
10. Security
We use technical and organisational measures appropriate to risk. The implemented architecture includes organisation and project scoping, role-based permissions, authenticated private-file delivery, expiring signed storage links where configured, encryption in transit, production object-storage encryption where configured, encrypted storage of workspace AI credentials, secure cookie settings, audit logging, platform-admin multi-factor authentication and background deletion controls. No system is completely secure.
If we act as controller and become aware of a breach likely to result in a high risk to personality or fundamental rights, we notify the FDPIC as soon as possible as required by Article 24 FADP and inform affected people where necessary for their protection. As processor, we notify the relevant Customer of a personal-data breach without undue delay as stated in the DPA.
11. Your rights
Subject to applicable conditions and exceptions, you may request information and access; correction; deletion or destruction; restriction or cessation of processing; objection; withdrawal of consent for future processing; and data portability for qualifying automated processing. You may also request information about an automated individual decision and, where applicable, express your view and request human review.
Authenticated users can request an export or deletion through the in-app Data Rights page. Other people may email 5pt.gmbh@gmail.com. We may verify identity and, where we act only as processor, refer the request to the relevant Customer. Swiss access requests are generally answered within 30 days unless an applicable exception permits more time. You may report a significant concern to the Federal Data Protection and Information Commissioner (FDPIC); where the GDPR or UK GDPR applies, you may also complain to the competent supervisory authority.
12. Cookies and tracking
Strictly necessary technologies support authentication, session security, CSRF protection and consent choices. Optional analytics and marketing technologies are disabled by default and are loaded only after the relevant opt-in where configured. You may reject or change optional choices at any time through Cookie Preferences. See the Cookie Policy for names, purposes and retention.
13. Children
DD HQ is a business service and is not directed to children. Users must be at least 18 and authorised to act for their organisation. Customers must not use the Service to process children's data unless they have assessed and implemented all required safeguards.
14. Changes
We may update this Policy for changes in the Service, providers, law or processing. We publish the new version and effective date and provide additional notice where a material change requires it. The platform may require renewed acceptance of a new version.
15. Contact
Privacy questions and rights requests may be sent to 5pt.gmbh@gmail.com or the postal address in section 1.