Privacy Policy
Effective date: 20 July 2026
Last updated: 20 July 2026
This Privacy Policy explains how DADEPO LTD (DaDepo, we, us or our) collects, uses, shares, stores and protects personal data when you visit our websites, create or use a DaDepo account, upload or review documents, use an Asset Passport or another DaDepo feature, communicate with us, or otherwise interact with our services.
This Policy is a privacy notice. It does not mean that every use of personal data is based on consent. We rely on the lawful basis that applies to each purpose, as described below.
This Policy is intended to provide the transparency information required by the UK GDPR and the Data Protection Act 2018, as amended, and by the EU GDPR where that law applies to particular processing.
1. Who we are
DADEPO LTD is a private limited company registered in England and Wales under company number 15582642. Our registered office is:
7 Bell Yard
London
England
WC2A 2JR
For personal data that we collect for our own account administration, identity checks, platform operation, security, billing, communications and legal compliance, DADEPO LTD is normally the data controller.
You can contact us about privacy or exercise your data protection rights at:
Email: [email protected]
Subject line: Data protection request
2. Scope and our different data protection roles
This Policy applies to DaDepo websites, applications, public pages, portals, document intake and analysis features, Asset Passports, asset workspaces, controlled sharing, buyer and seller workflows, Offerboard features, credits and billing, support, and other services that link to this Policy.
Our role depends on why personal data is processed:
- DaDepo as controller. We decide why and how to process account, security, KYC, billing, service-use, support and compliance data.
- DaDepo as processor. A business customer may upload documents containing personal data about employees, customers, debtors, counterparties, beneficial owners, advisers or other people. Where that customer determines the purpose and essential means of this processing and DaDepo processes the data only to provide the requested service, the customer is normally the controller and DaDepo is its processor. The applicable agreement or data processing addendum governs that processing.
- Separate responsibilities. DaDepo may still process limited information as an independent controller when necessary for security, fraud prevention, billing, legal claims or compliance with law.
The legal role is determined by the facts, not only by the label used in an agreement. If another organisation gave your information to DaDepo, you may also need to read that organisation's privacy notice.
3. Personal data we collect
The data we collect depends on the features you use and the information you or another authorised person provides.
3.1 Account and profile data
This may include:
- name, username, email address, telephone number and password credentials in protected form;
- organisation, role, job title and business contact details;
- account identifiers, active person, participant or organisation relationships and permissions;
- authentication information, security settings and multi-factor authentication status;
- information received from an enabled external sign-in provider; and
- subscription, account status, preferences and accepted policy versions.
3.2 Identity, KYC and compliance data
Where a feature, risk assessment or applicable law requires identity or business verification, we or a verification provider may process:
- full legal name, former names, date of birth, nationality and residential address;
- government-issued identity document data and copies;
- photograph, selfie, liveness result or other identity-matching data, where used;
- company registration, directorship, ownership and beneficial-owner information;
- tax residence or similar compliance information, where required;
- sanctions, politically exposed person, adverse-media or other screening results;
- source-of-funds or source-of-wealth information, where justified and required; and
- verification status, risk indicators, review notes and supporting evidence.
Some of this information may be biometric data, criminal-offence data or other specially protected data. We process it only where the feature is enabled and we have both an Article 6 lawful basis and any additional condition required by applicable law.
3.3 Documents, asset packages and related content
When documents or asset information are uploaded, imported, created, reviewed or shared, we may process:
- contracts, claims, invoices, receivables, licences, court documents, correspondence and supporting evidence;
- names, contact details, identifiers, signatures, roles and information about parties or representatives contained in those files;
- financial terms, payment information, obligations, dates, disputes, collateral and transaction history contained in the material;
- document titles, descriptions, tags, language, type, file name, size, hash, version, source and upload time;
- extracted text, structured facts, summaries, classifications, warnings, confidence indicators and source references;
- Asset Passport information, provenance, review status, visibility, access permissions and lifecycle events; and
- comments, corrections, confirmations and decisions made by authorised users.
Documents may contain personal data about people who do not have a DaDepo account. Users must avoid uploading irrelevant personal data and should redact or minimise information that is not needed for the intended workflow.
3.4 Public listings and controlled sharing data
Depending on choices made by an authorised user, we may process and display:
- public asset titles, summaries, categories, jurisdictions and other listing information;
- information shared privately with selected recipients;
- access requests, invitations, approvals, refusals and revocations;
- NDA status, agreement events and associated audit information;
- buyer mandates, indications of interest, offers and negotiation messages; and
- information needed to show who accessed or acted on shared material.
Information marked public may be visible to anyone and may be copied, indexed or redistributed outside DaDepo. Private or NDA-controlled access reduces exposure but cannot guarantee that an authorised recipient will never retain or misuse information.
3.5 Billing, credits and transaction data
Where billing, subscriptions or internal credits are used, we may process:
- subscription type and billing status;
- credit balance, grants, purchases, use, expiry and adjustment history;
- service operation, price, reference, timestamp and audit information;
- payment amount, currency, status and provider transaction reference;
- billing contact and invoice information; and
- refund, cancellation, dispute and reconciliation information, where applicable.
Payment providers process payment credentials under their own privacy notices. DaDepo generally receives payment status and reference information rather than complete payment-card details.
3.6 Communications and support data
This may include messages, support requests, feedback, attachments, call or meeting notes, notification preferences, and records of how and when we responded.
3.7 Technical, device and security data
When you use our services, we may automatically collect:
- IP address, browser type, device and operating-system information;
- sign-in, session, request, error and security-event data;
- date, time, referring page, pages or features used and related identifiers;
- cookie and similar-technology information; and
- logs needed to detect abuse, investigate incidents and maintain the service.
We do not use technical data to make claims about a person's identity or conduct without appropriate review and context.
3.8 Data from other sources
We may receive personal data from:
- your organisation, its administrators or authorised representatives;
- other users who upload a document, invite you, share an asset or enter information about a transaction;
- identity, KYC, sanctions or fraud-prevention providers;
- authentication, payment, communications, hosting, storage or analytics providers;
- public registers, courts, regulators and other publicly available sources; and
- professional advisers, counterparties or business partners involved in a requested workflow.
4. Why we use personal data and our lawful bases
The following table summarises our main purposes and the lawful bases we normally rely on under the UK GDPR. More than one basis may apply where the purposes are genuinely different.
| Purpose | Examples | Normal lawful basis |
|---|---|---|
| Provide and administer the service | Create an account, store documents, create and manage asset packages, enable access, show balances and provide requested features | Performance of a contract; steps requested before entering a contract |
| Verify identity and authority | Confirm the identity of users, representatives, beneficial owners or counterparties and determine whether a person may act for an organisation | Legal obligation where applicable; contract; legitimate interests in preventing impersonation and unauthorised activity |
| KYC, sanctions, fraud and compliance checks | Conduct proportionate verification and screening, investigate suspicious activity and respond to lawful requests | Legal obligation where applicable; legitimate interests in protecting the platform, users and the public; additional legal conditions where protected data is involved |
| Process and analyse documents | Extract text, classify documents, identify possible facts or gaps, generate a draft or Asset Passport and link findings to source material | Contract; legitimate interests in improving accuracy, usability and review efficiency |
| Enable user-controlled disclosure | Publish information chosen for public display or share it with selected recipients, including NDA-controlled access | Contract; actions taken at the user's request; legitimate interests in enabling controlled business review |
| Operate buyer, seller and negotiation workflows | Manage access requests, mandates, offers, messages and workflow status | Contract; legitimate interests in providing traceable business communications and preventing abuse |
| Billing, subscriptions and credits | Process purchases, maintain the credit ledger, apply charges, prevent duplicate charges and keep accounting records | Contract; legal obligation; legitimate interests in accurate billing and fraud prevention |
| Secure, troubleshoot and improve the service | Authenticate sessions, monitor performance, prevent spam and attacks, investigate incidents, debug errors and improve usability | Legitimate interests in operating a secure, reliable and effective service; legal obligation where applicable |
| Communicate with you | Send service messages, security alerts, policy notices, support replies and information you request | Contract; legal obligation; legitimate interests in service administration |
| Send marketing | Send product news or other marketing and measure engagement | Consent where required; otherwise legitimate interests for proportionate business-to-business marketing, with the right to object at any time |
| Establish, exercise or defend legal claims | Preserve relevant records, investigate disputes and enforce our agreements | Legitimate interests; legal obligation; establishment, exercise or defence of legal claims |
| Corporate administration | Audit, governance, professional advice, restructuring or a potential business transaction | Legal obligation; legitimate interests in responsible corporate management |
Where we rely on legitimate interests, we consider the necessity of the processing, its expected benefit, its effect on individuals and the safeguards available. You may object to processing based on legitimate interests as explained below.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal. Refusing optional data or withdrawing consent may affect only the feature that depends on it.
Some data is necessary to create or secure an account, perform a requested service, process payment, verify authority, or meet a legal requirement. If required data is not provided, we may be unable to provide the relevant feature or may need to restrict the account.
5. AI-assisted processing
DaDepo may use AI-assisted tools to help:
- extract text and possible facts from uploaded documents;
- suggest a document type, title, summary, tags or structured description;
- identify possible missing information, inconsistencies or review questions;
- prepare draft asset information, narrative or an Asset Passport;
- support search, matching, completeness or commercial-signal features; and
- help authorised staff draft or review support and platform content.
AI output can be incomplete, outdated or wrong. It is an aid to review, not a determination of legal validity, ownership, value, transferability, compliance, registration or suitability for a transaction. Users are expected to review source material and correct or reject suggestions.
We may send relevant document text, prompts, metadata and identifiers to contracted AI service providers when an AI feature is requested or enabled. We seek to limit the information sent to what is needed for the task and apply contractual, access and transfer safeguards appropriate to the service. Current provider arrangements and retention settings must be reflected in DaDepo's operational records and, where appropriate, its subprocessor information.
DaDepo does not intend to use AI output alone to finalise, sign, register, list or transfer an asset, accept an offer, or complete settlement. Those material actions require an authorised user's instruction or another appropriate human-controlled step. If we introduce solely automated decision-making that produces legal or similarly significant effects, we will provide the additional information and safeguards required by law, including an available route to request human review where applicable.
6. Public, private and NDA-controlled information
DaDepo provides visibility and access controls, but the user remains responsible for selecting an appropriate disclosure setting and having authority to disclose the material.
Before uploading or sharing personal data about another person, the user or customer should ensure that it:
- has a lawful basis and, where needed, an additional condition for protected data;
- has provided required privacy information or can rely on a lawful exception;
- has authority to disclose confidential or restricted information;
- respects contractual, professional, employment and regulatory duties;
- shares only what is necessary for the stated purpose; and
- uses redaction, private access or NDA-controlled sharing where appropriate.
An NDA is a contractual confidentiality control. It does not by itself create a data protection lawful basis, prove authority to disclose, or make unnecessary personal data appropriate to upload. Conversely, the absence of an NDA does not remove DaDepo's own legal obligations, but DaDepo cannot be responsible for a user's independent decision to disclose material that the user was not authorised to disclose.
When information is made public at a user's instruction, public recipients may be independent controllers of copies they obtain. When information is shared with a selected professional, buyer, adviser or counterparty, that recipient may also have its own privacy obligations.
7. Who we share personal data with
We may share personal data only where necessary for a stated purpose, at your instruction, or where permitted or required by law. Recipient categories may include:
- people and organisations you invite, authorise or choose to make information available to;
- administrators and authorised users of the organisation connected to your account;
- hosting, cloud storage, authentication, security, communications and customer-support providers;
- document extraction, AI analysis and related technology providers;
- KYC, identity-verification, sanctions-screening and fraud-prevention providers;
- payment providers, such as PayPal or Revolut where enabled, and accounting providers;
- professional advisers, insurers, auditors and dispute-resolution providers;
- courts, law-enforcement bodies, regulators, tax authorities and public bodies where disclosure is lawful; and
- a buyer, investor, lender or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality and legal safeguards.
Service providers acting for DaDepo are authorised to process personal data only for agreed services and are subject to contractual and security requirements appropriate to their role.
DaDepo does not sell personal data for money. A user's decision to publish or disclose asset information through a DaDepo workflow is not a sale of personal data by DaDepo.
8. International transfers
DaDepo is established in the United Kingdom. Some service providers or authorised recipients may process personal data in the European Economic Area or in other countries.
Where personal data is transferred outside the United Kingdom or, where applicable, outside the EEA, we use an available lawful transfer mechanism. Depending on the transfer, this may include:
- a UK or EU adequacy decision;
- the UK International Data Transfer Agreement or UK Addendum;
- European Commission Standard Contractual Clauses;
- another legally permitted safeguard; or
- a specific statutory exception where appropriate.
We also consider whether supplementary technical, contractual or organisational measures are needed. You may contact us for information about the safeguard relevant to your data, subject to legitimate confidentiality restrictions.
9. How long we retain personal data
We keep personal data only for as long as necessary for the purpose collected, including service delivery, security, dispute resolution, accounting and legal compliance. Retention depends on the data and context. Our normal criteria include:
| Data category | Normal retention approach |
|---|---|
| Account and core service records | While the account or relevant relationship is active and normally for up to six years afterwards where needed for contracts, disputes or legal claims |
| KYC and AML records | For the period required by applicable law or justified compliance needs; where statutory AML retention applies, this is commonly up to five years after the relationship ends unless a different period is required or permitted |
| Billing, payment and credit records | Normally up to six years after the relevant financial period or transaction, and longer if required for an active dispute or legal obligation |
| Uploaded documents and asset packages | For as long as needed to provide the customer-selected workspace, Asset Passport, controlled sharing or lifecycle service; after authorised deletion or account closure, residual copies may remain for a limited backup cycle or legal hold |
| Access, NDA, offer and workflow records | For the active workflow and then for a period proportionate to security, audit and dispute needs, normally not exceeding six years unless required by law or an active claim |
| Support communications | For as long as needed to answer the request and normally up to three years after closure, unless linked to a contract, complaint, security incident or claim requiring longer retention |
| Security and technical logs | For a limited period appropriate to security monitoring and investigation, normally up to 12 months, unless an event requires preservation for longer |
| Marketing preferences | Until you withdraw consent or object, plus a minimal suppression record so that we can respect the request |
We may delete or anonymise data earlier when it is no longer needed. We may retain it longer when required by law, a court order, an investigation, a payment dispute or the establishment, exercise or defence of legal claims. Anonymised information that no longer identifies a person may be retained and used for statistics, security and service improvement.
10. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and access. Depending on the system and risk, these measures may include:
- identity and access controls, role-based permissions and multi-factor authentication options;
- encryption in transit and, where appropriate, at rest;
- document hashes, version information and audit logging;
- environment separation, backups and recovery procedures;
- monitoring, vulnerability management and incident-response procedures;
- supplier due diligence and data processing terms; and
- staff confidentiality and access restrictions.
No internet transmission, recipient access or storage system can be guaranteed to be completely secure. Users should use strong unique credentials, protect authentication devices, review visibility settings, limit document content, and report suspected compromise promptly.
If you believe your account or personal data has been compromised, contact [email protected] without delay.
11. Your data protection rights
Depending on your location, the processing and applicable exemptions, you may have the right to:
- be informed about how your personal data is used;
- request access to your personal data and receive a copy;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive certain data in a portable, machine-readable form;
- withdraw consent where processing relies on consent; and
- request safeguards relating to solely automated decisions with legal or similarly significant effects, including human review where applicable.
These rights are not absolute. For example, we may need to preserve data required by law, needed to protect another person's rights, contained in evidence, or necessary for a legal claim. Where DaDepo acts only as a processor for a customer, we may refer the request to that customer or assist it in responding.
To exercise a right, email [email protected] with the subject Data protection request. Please describe the account, data or processing involved. We may ask for information reasonably needed to verify your identity and authority. We normally respond within one month, although the law may allow additional time for a complex request.
You will not normally be charged. A reasonable fee may be permitted, or a request may be refused, where the law allows this for a manifestly unfounded or excessive request. If we refuse or limit a request, we will explain why unless the law prevents us from doing so.
12. Complaints
Please contact us first so that we have an opportunity to investigate your concern:
Email: [email protected]
Subject line: Data protection complaint
You also have the right to complain to the Information Commissioner's Office (ICO), the United Kingdom data protection supervisory authority:
Make a data protection complaint to the ICO
If the EU GDPR applies to the relevant processing, you may also have the right to complain to the data protection authority in the EEA country where you live, work or believe an infringement occurred.
13. Cookies and similar technologies
We use strictly necessary cookies and similar technologies to operate authentication, security, sessions and essential preferences. We may use optional analytics or other non-essential technologies only where permitted and, where required, after obtaining consent.
You can manage available choices through the cookie banner or browser settings. Disabling necessary cookies may prevent account or security features from working. More information should be provided in DaDepo's Cookie Notice or cookie settings interface.
14. Children
DaDepo is a business and asset-document service and is not intended for children. You must be at least 18 years old or otherwise have legal capacity and authority to use an account on behalf of an organisation. We do not knowingly offer accounts directly to children.
Documents concerning a child must not be uploaded unless the uploader has appropriate authority and a lawful basis, the information is necessary for the relevant purpose, and additional protections required by law are observed. If you believe a child has provided account data directly or that children's data has been processed inappropriately, contact us.
15. Links and third-party services
Our services may link to third-party websites or integrate with services controlled by other organisations. Their processing is governed by their own privacy notices when they act as independent controllers. This Policy does not cover a third party's independent use of personal data.
16. Changes to this Policy
We review this Policy when our services, providers or legal obligations change. We will publish the updated version with a revised “Last updated” date. If a change is material, we will provide an appropriate additional notice before it takes effect, such as an account message, email or prominent website notice.
If a new purpose is incompatible with the purpose for which personal data was originally collected, we will identify an appropriate lawful basis and provide any notice or obtain any consent required before beginning that processing.
17. Contact us
Questions, rights requests and complaints about this Policy or DaDepo's use of personal data may be sent to:
DADEPO LTD
7 Bell Yard
London
England
WC2A 2JR
Email: [email protected]