Data Processing Agreement
Effective September 1, 2026
1. What this is, and who it applies to
1.1 This Data Processing Agreement (the "DPA") governs how ExitPros LLC handles personal data that an advisory firm puts into DealAtrium. It forms part of the Terms of Service and applies to the relationship between us and an advisory firm.
1.2 It does not apply to buyers or sellers in their own right. A buyer or seller using the platform is not a party to this DPA and is not agreeing to it. How we handle their personal data is described in our Privacy Policy.
1.3 Where this DPA and the Terms of Service conflict on the handling of personal data, this DPA controls. On all other matters, including limitation of liability, the Terms of Service control.
2. Definitions
2.1 In this DPA:
- "Personal data" means information that identifies, relates to, describes, or could reasonably be linked with an identified or identifiable individual, and includes "personal information" as defined under applicable United States state privacy law.
- "Processing" means any operation performed on personal data, including collection, storage, retrieval, use, disclosure, and deletion.
- "Controller" means the party that determines the purposes and means of processing. Where applicable state law uses the term "business," it has the equivalent meaning.
- "Processor" means the party that processes personal data on behalf of a controller. Where applicable state law uses the terms "service provider" or "contractor," they have the equivalent meaning.
- "Data subject" means the individual to whom personal data relates. Where applicable state law uses the term "consumer," it has the equivalent meaning.
- "Subprocessor" means a third party engaged by us to process personal data on your behalf.
- "Your firm's personal data" means personal data we process on your firm's behalf as processor, as described in Section 3.2.
- "Personal data breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- "Applicable privacy law" means United States federal and state privacy law applicable to the processing under this DPA, including the Colorado Privacy Act and the state laws listed in Annex D.
2.2 "We," "us," and "our" mean ExitPros LLC. "You," "your," and "your firm" mean the advisory firm that is party to the Terms of Service.
3. Our two roles, and why there are two
3.1 Most agreements of this kind describe one relationship. This one describes two, because the platform genuinely has two.
3.2 We are a processor for your firm's data. Deal records, seller records, the documents your firm uploads, your firm's private assessments and notes about buyers, correspondence sent by your advisors, and your advisors' own accounts. Your firm decides why and how that data is processed. We process it on your instructions, as set out in this DPA.
3.3 We are a controller for buyer accounts, and for the account of any other participant admitted to a diligence room. A buyer account is not your firm's record. The same buyer may deal with several firms on this platform under one account, and that account survives the end of your firm's relationship with us. We decide how buyer identity and buyer profile data are handled, and we answer to the buyer for it. We are also the controller for our own direct communications with buyers, such as the unsubscribe page that lets a buyer stop email about a deal.
The same applies to anyone else your firm admits to a diligence room who is not one of your firm's own personnel — outside counsel, lenders, accountants and other advisers to a party. They are not buyers, but they hold an account on the same basis: we control their identity and account data and answer to them for it, while your firm controls the record of their engagement with your transaction. Their terms of access are the Diligence Room Participant Terms.
3.4 Where the line falls. Within a single buyer relationship, the split is by data category, not by person:
- We are controller for the buyer's account credentials, identity, profile, stated acquisition criteria, and communication preferences.
- We are processor for your firm for your firm's private notes and assessments about that buyer, the correspondence your advisors send them, the access your firm grants them, and the record of their engagement with your firm's deal materials.
3.5 Why this matters to you: your instructions govern the data described in Sections 3.2 and 3.4, and the deletion obligation in Section 16 applies to it. Neither extends to the data described in Section 3.3, because that data is not yours to direct us to delete. Buyer accounts are retained and deleted on the basis set out in our Privacy Policy, which at the date of this DPA provides for deletion after 24 months without a sign-in, or sooner at the buyer's request.
4. What we process, and on whose instructions
4.1 The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subject are described in Annex A.
4.2 We process your firm's personal data only on your documented instructions. Your use of the platform's features is itself an instruction. This DPA, the Terms of Service, and your configuration of the platform together constitute your complete documented instructions at the date of this DPA.
4.3 We will tell you if we believe an instruction requires us to break the law, and we may pause that processing until it is resolved.
4.4 We do not sell personal data, and we do not use it to train artificial intelligence models. We do not send document contents, deal information, or personal data to any third-party artificial intelligence or machine learning provider. This commitment is absolute and is not qualified by Section 17.
4.5 Artificial intelligence features offered by subprocessors. Some subprocessors listed in Annex B offer artificial intelligence features that would process data we send them. Where such a feature exists and enabling it is within our control, it is not enabled on our account, and we will not enable it without giving your firm at least 30 days' notice by the means described in Section 11.2. This applies to every subprocessor in Annex B.
4.5.1 We do not control processing a subprocessor carries out on its own account to operate, secure, or improve its own service — automated spam or fraud screening applied to a message it transmits, for example. Sections 4.4 and 4.5 govern what we send and what we enable. They do not purport to govern a subprocessor's internal operations, which are governed by our contract with that subprocessor and by the terms referenced in Annex B.
4.5.2 Document contents are never made available to an artificial intelligence feature. The subprocessors that hold and deliver documents do offer such features, and none of those features is enabled on our account; document contents are held under the custody terms in Section 6 and are never transmitted to any subprocessor for processing beyond storage and delivery.
4.6 We do not retain, use, or disclose your firm's personal data for any purpose other than performing the services described in Annex A, or as otherwise permitted by applicable privacy law. We do not combine your firm's personal data with personal data received from another source, except where necessary to operate the platform on your instructions or as permitted by applicable privacy law.
5. Prohibited data, and how document contents are treated
5.1 The platform holds two different kinds of data and the rules differ between them. Structured fields are records we operate on. Document contents are material we hold in custody and do not read. Section 6 sets out what custody means.
5.2 Structured fields — prohibited absolutely. You must not enter any of the following into a structured field, form, tag, title, filename, or free-text note:
- Social Security numbers, taxpayer identification numbers of individuals, driver's licence numbers, passport numbers, or other government identifiers;
- financial account numbers or online banking credentials belonging to an individual;
- protected health information subject to the Health Insurance Portability and Accountability Act;
- consumer report information subject to the Fair Credit Reporting Act;
- genetic data, and biometric identifiers used or intended to be used to identify an individual, such as fingerprint, voiceprint, or facial geometry templates. Ordinary photographs, and audio or video recordings such as management interviews or facility walkthroughs, are not biometric identifiers for this purpose;
- data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, or union membership.
There is no field on the platform intended to hold any of these, and entering them into a free-text note is a breach of this DPA.
5.3 Document contents — permitted, and held under Section 6. Sell-side due diligence materials routinely contain personal data of individuals who are not parties to this DPA, most often the seller's employees. Employee censuses, payroll registers, benefit plan documents, tax returns and Schedule K-1s are ordinary diligence items, and the platform is intended to carry them. You may upload them. We hold them under the custody terms in Section 6, and we do not read them.
5.4 Prohibited in any form. Regardless of Section 5.3, you must not upload:
- payment card data subject to the Payment Card Industry Data Security Standard;
- personal data of anyone under 18;
- material you have no right to share.
5.5 Redaction is expected where the diligence process allows it. Market practice is to pseudonymise employee censuses — identifying individuals as Employee 1, Employee 2 and so on — and to disclose identities at or near closing. Where a document can carry the same diligence value in redacted or pseudonymised form, redact it. This reduces exposure for the seller, the individuals concerned, and your firm, and it is the single most effective control available in this process.
5.6 We do not inspect for compliance. We have no obligation to inspect uploaded documents for prohibited data, and Section 6 means we do not. Where we become aware that prohibited data is present, we may remove it, restrict access to it, or require you to remove it. You are responsible for the consequences of uploading data prohibited by Sections 5.2 and 5.4.
6. Document custody
6.1 Three kinds of operation. Systems can act on a file at three different depths, and this DPA treats them differently because their privacy consequences differ.
- Byte operations — storing a file, transmitting it, hashing it, encrypting it, or matching its bytes against known-malicious patterns. These act on the file as an opaque sequence of bytes and surface nothing about what it says.
- Structure operations — opening the file's format or container in order to confirm what it is, or to write an identifying marker into it. These read the format, not the meaning.
- Content reading — extracting text, optically recognising it, indexing it, searching it, summarising it, or classifying it by what it says. This is the operation that would surface the personal data inside due diligence documents, and it is the one we do not perform.
6.2 We do not read the contents of documents. We do not extract, transcribe, optically recognise, index, search, summarise, or classify by content any document uploaded to the platform. No text is extracted from a document and retained, and no index of document contents exists anywhere in the platform. Where any operation described below requires opening a document's format, it goes no further than the structure and produces no record of what the document says.
6.3 Viewing in the browser. A document may be displayed to a recipient who has passed the authorisation check described in Annex C. Our servers stream the document's bytes to that person's browser, which renders it using its own built-in viewer. Our servers do not open, convert, or rasterise the document in order to display it — displaying a document is a byte operation on our side and a rendering operation on the recipient's. Streaming a document is not reading it.
6.4 Integrity checking and malware scanning. We may validate that an uploaded file is the type it claims to be, and we may scan uploaded files for malware. Scanning necessarily inspects the file, including any embedded objects or macros it contains, because that is where malicious content hides. It produces a verdict about the file — safe or not — and no record of the file's substantive content. Neither operation extracts, indexes, retains, or exposes anything the document says.
6.4.1 No warranty of detection. This Section 6.4 describes operations we are permitted to perform. It is not a representation that any particular file has been validated or scanned, nor a warranty that validation or scanning detects a mislabelled file or malicious content. No malware scanning is reliable against novel or targeted threats. Do not rely on the platform as your malware control. Scan files you download with your own tools, and do not upload material you know or suspect to be infected.
6.4.2 Marking for traceability. We may apply an identifying mark to a copy of a document served to a specific recipient — a visible watermark, or an embedded identifier allowing a leaked copy to be traced back to the recipient it was issued to. Applying a mark is a structure operation: it requires opening the document's format in order to write the marker, and it does not involve reading, interpreting, extracting, indexing, or retaining what the document says. A marked copy is generated for delivery and is not stored in place of the original. Where a document is marked, the recipient is told that it has been. This section describes an operation we are permitted to perform, not a representation that any particular document carries a mark.
6.5 Metadata is not contents. We do operate on the information recorded about a document — filename, file type and size, who uploaded it, when, which deal or room it belongs to, the category assigned to it, who has been granted access, and when it was accessed. Search, sorting, and status tracking run on that metadata. Naming a file so that it discloses personal data therefore places that data outside custody, which is why filenames are covered by Section 5.2.
6.6 No artificial intelligence processing. Consistent with Section 4.4, document contents are never transmitted to any artificial intelligence or machine learning provider and are never used to train a model. Section 6.2 is the mechanism that makes that commitment structural rather than a matter of policy.
6.7 If this ever changes. We will not begin processing document contents for any purpose beyond Sections 6.3, 6.4, 6.4.1 and 6.4.2 without giving your firm at least 30 days' notice under Section 21, and without the legal basis required under applicable privacy law being in place. If you object, Section 11.3 applies.
7. Seller-uploaded materials and diligence rooms
7.1 How the platform is used. Advisory firms use the platform as an intermediary through which sellers upload due diligence materials and correspond with the firm and with authorised buyers. A firm may also create a diligence room for a transaction and admit specified parties to it.
7.2 Your firm remains responsible for that material. Material uploaded by a seller at your firm's direction, and material exchanged in a diligence room your firm creates, is your firm's personal data under Section 3.2. We process it on your instructions. The seller is not a party to this DPA and gives us no instructions.
7.3 Your firm's representations about seller material. For each seller whose materials are uploaded, you confirm that:
- the seller has the authority to disclose the materials, including any personal data of its own personnel or of third parties contained in them;
- any notice or consent required under applicable privacy law from the individuals whose personal data appears in those materials has been given or obtained before upload;
- the seller has been told that the platform is used to hold and distribute the materials; and
- the redaction expectation in Section 5.5 has been communicated to the seller.
7.4 A contractual representation is not consent. Where applicable privacy law requires consent from an individual for the processing of their sensitive data, a representation from your firm or from the seller does not supply it. Section 7.3 allocates responsibility between us; it does not create a lawful basis. This is the reason the custody model in Section 6 exists, and the reason Section 5.5 matters.
7.5 Room membership and access. Where your firm creates a diligence room, your firm decides who is admitted, what each party may see, and when access is revoked. We enforce those decisions; we do not make them. Admitting a party to a room is an instruction under Section 4.2.
7.6 Requests from individuals in uploaded materials. An individual whose personal data appears inside an uploaded document — an employee of the seller, for example — will ordinarily have no relationship with us and no account. If such a person contacts us, we handle it under Section 13: we do not respond substantively, we direct them to your firm, and we tell you. Because we do not read document contents, we cannot locate a named individual inside stored documents without your firm identifying the documents concerned.
8. Your responsibilities
8.1 You confirm that you have a lawful basis for giving us personal data about buyers and sellers, that you have told those people how their data will be used, and that you have the right to upload and share the materials you upload.
8.2 You are responsible for who you grant access to, and for revoking access when it should be revoked.
8.3 Advisors who connect their own mailbox are responsible for the content of the email they send through it, and for complying with applicable email and marketing law.
8.4 You are responsible for the accuracy of the personal data you provide and for the content of free-text notes your advisors record.
8.5 You are responsible for ensuring your advisors do not enter data prohibited by Section 5.2 into structured fields, filenames, or free-text notes. Because we do not read document contents, a structured field is one of the few places prohibited data becomes visible to us, and it is the place we can least afford it to be.
8.6 Where seller materials are uploaded, the representations in Section 7.3 apply for each seller.
8.7 Where a document is uploaded that contains personal data of individuals who are not users of the platform, you remain the point of contact for those individuals under Section 13.
9. Confidentiality
9.1 Access to your data is limited to people who need it to operate or support the platform, and everyone with such access is bound by written confidentiality obligations that survive the end of their engagement with us.
9.2 We do not access the contents of your deal documents except where necessary to provide or support the service, to keep it secure, or where you ask us to.
9.3 This Section 9 survives termination of this DPA and of the Terms of Service.
10. Security
10.1 We maintain technical and organisational measures appropriate to the risk, described in Annex C.
10.2 The measures in Annex C describe the platform as at the effective date of this DPA. We may change them as the platform develops, but we will not materially reduce the overall level of protection during your subscription. Where a specific measure in Annex C is replaced by a different measure providing equivalent or better protection, that is not a reduction.
11. Subprocessors
11.1 You authorise us to use the subprocessors listed in Annex B. Each is bound by written terms that impose data protection obligations comparable to those in this DPA, and we remain responsible to you for their performance.
11.2 We will give you at least 30 days' notice before adding or replacing a subprocessor listed in Annex B. Notice is given by email to your firm's account administrators and by updating Annex B.
11.2.1 Annex B lists the subprocessors we engage directly. Each of those subprocessors engages its own vendors, and the notice periods they give us are shorter than the one we give you — typically fourteen to thirty days. Where a subprocessor changes its own vendors, we will pass that notice on to you as soon as reasonably practicable after we receive it, which may be less than 30 days. The objection right in Section 11.3 applies in the same way, but the timetable in those cases is set by our subprocessor, not by us.
11.3 If you have a reasonable objection on data protection grounds, tell us within that period and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service, or the subscription as a whole where the affected part is not severable, on written notice. In that case we will refund any prepaid fees covering the period after termination takes effect, on a pro-rata basis, and no early termination charge applies.
12. Personal data breach
12.1 If we become aware of a personal data breach affecting your firm's personal data, we will notify you without undue delay, and in any event within 72 hours of becoming aware.
12.2 The notification will describe what happened, the categories and approximate volume of data involved so far as known, the likely consequences, and the steps we are taking.
12.3 We will provide reasonable assistance with any notification you are required to make to a regulator or to affected individuals. An initial notification will not be delayed merely because the investigation is incomplete.
13. Requests from individuals
13.1 If a buyer, seller, or other individual contacts us directly with a request concerning personal data your firm controls, we will not respond substantively on your behalf. We will tell them to contact your firm, and we will tell you about the request without undue delay.
13.2 Taking account of the nature of the processing, we will give you reasonable assistance in responding to such requests, including access to the data through the platform and the export described in Section 16. We will provide that assistance within a period that allows you to meet your own statutory response deadline, provided you notify us with reasonable time remaining.
13.3 Where a request concerns data for which we are the controller under Section 3.3, we handle it ourselves under our Privacy Policy.
14. Assistance with assessments and compliance
14.1 Taking account of the nature of the processing and the information available to us, we will provide reasonable assistance with:
- any data protection assessment, data protection impact assessment, or equivalent evaluation you are required to carry out under applicable privacy law in respect of processing on the platform;
- your obligations regarding the security of processing;
- your obligations to notify a regulator or affected individuals of a personal data breach; and
- any consultation with a regulator arising from an assessment.
14.2 Assistance under this Section 14 is provided at no charge where the request is proportionate and infrequent. Where a request requires substantial engineering or professional time, we will tell you before incurring it and agree a reasonable charge with you.
15. Demands from government and law enforcement
15.1 If we receive a subpoena, court order, warrant, or other legally binding demand from a government body or law enforcement agency for your firm's personal data, we will:
- notify you promptly and before disclosing anything, unless legally prohibited from doing so;
- where we are prohibited from notifying you, use reasonable efforts to obtain a waiver of that prohibition, and record the demand so that we can tell you once the prohibition lapses;
- disclose only the specific data the demand requires, and no more;
- where the demand appears overbroad, unlawful, or procedurally defective, use reasonable efforts to challenge or narrow it; and
- give you a reasonable opportunity to seek a protective order or other relief before we disclose, where the timetable permits.
15.2 We will not voluntarily disclose your firm's personal data to any government body or law enforcement agency in the absence of a legally binding demand, except where we reasonably believe disclosure is necessary to prevent imminent death or serious bodily injury.
15.3 Nothing in this Section 15 requires us to defy a lawful order or to expose ourselves to contempt or criminal liability.
16. Export, deletion, and what we keep
16.1 Export. You may request an export of your firm's data at any time, and on termination. We will provide it within 30 days, in two parts: a machine-readable file of your records, and an archive of documents received through the platform, including executed non-disclosure agreements and buyer submissions.
16.2 What the export does not include. Deal marketing materials your firm uploaded — confidential information memoranda, financial statements, teasers — are not included. Those originated with you and you hold the originals; the platform distributes them rather than serving as their system of record. Keep your own copies.
16.3 Deletion or return. At your direction, we will delete or return your firm's personal data at the end of the provision of services. The export in Section 16.1 is the mechanism for return. Unless you direct otherwise, we delete your firm's data from active systems within 30 days of termination. This includes deal records, seller records, uploaded deal materials, correspondence, your firm's private notes about buyers, and executed non-disclosure agreements held for your firm.
16.4 Export before you terminate. Because executed non-disclosure agreements are deleted with the rest of your firm's data, request your export before or at termination if you want to keep them. We do not retain a copy for you afterwards. The buyer receives their own copy by email from the signature provider at the time of signing, and firms that enable the NDA webhook receive a copy into their own systems automatically as each agreement completes.
16.5 What deletion does not cover. Buyer accounts are not your firm's data and are not deleted when your firm leaves — see Sections 3.3 and 3.5. Deal marketing materials your firm uploaded originated with you and you hold the originals; we delete our copies, and you should keep yours.
16.5.1 Records of agreement. Where a person accepts a set of terms on the platform — your firm's acceptance of these terms, a seller's acceptance before uploading, a participant's acceptance on entering a diligence room — we retain a record of it: name, email address, the version accepted, and when. We retain these records after the related account and firm data are deleted, and we do not remove them on request. The record is the evidence that the handling of the underlying material was authorised, and erasing it would destroy the only proof that the material was held lawfully. We retain nothing else about the account and use these records for no other purpose.
16.5.2 Records of release. Where documents are released from a diligence room, we retain a manifest of what was released, to whom, and who authorised it — document list, file hashes, marking mode, and date. We retain the manifest after the released archive and the underlying documents are deleted, and we do not remove it on request. It exists so that your firm, the seller, and the recipient can each establish what was released and on whose authority. It contains no document contents.
16.5.3 The retention in Sections 16.5.1 and 16.5.2 is limited to what is described there. Neither is used for any purpose other than establishing authority and what was released, and neither is disclosed except as required by law or to a party establishing its own position in relation to the material. Both are disclosed in our Privacy Policy.
16.6 Backups. Deleting a record from our active database does not immediately remove it from our hosting provider's daily database backups, which are retained for 7 days and are not separately editable. After that window no copy remains. Documents and files are stored separately from the database and are not included in those backups, so a deleted document is removed immediately with no backup copy.
17. De-identified, aggregated, and operational data
17.1 Operational telemetry. We collect and use data about how the platform runs and is used — feature usage counts, request volumes, performance timings, error rates, and similar operational measurements — to operate, secure, support, and improve the service. This telemetry does not include document contents, deal materials, free-text notes, seller identity, or buyer identity.
17.2 The benchmark programme is opt-in and off by default. We may offer a market benchmark showing aggregate transaction statistics across participating firms. Your firm contributes nothing to it unless an administrator of your firm switches participation on. Participation can be switched off at any time.
17.2.1 Until participation can be switched on in the platform, no firm participates and no field described in Section 17.3 is collected, derived, or contributed. This Section 17 governs the programme from the point the setting becomes available.
17.3 What a participating firm contributes. Only the following derived fields, and only for deals created or updated after participation begins:
- sector, at NAICS three-digit level;
- revenue band and EBITDA band, in ranges — never exact figures;
- geography, at state or multi-state region level — never metropolitan area, city, or postal code;
- milestone dates: listed, first inquiry, NDA executed, marketing materials released, letter of intent, closed or withdrawn;
- counts: inquiries received, non-disclosure agreements executed, buyers reaching diligence;
- outcome: closed, withdrawn, or expired.
17.4 What is never contributed, under any circumstance. Documents or their contents; free-text notes or assessments; company names; seller identity or seller contact details; buyer identity or buyer contact details; exact revenue, EBITDA, or transaction price; correspondence; and any personal data.
17.5 Suppression threshold. No statistic is published or displayed unless the cohort it is drawn from contains at least 5 contributing firms and at least 20 deals. Where a cohort falls below either threshold, the statistic is suppressed entirely. It is not rounded, approximated, ranged, or otherwise represented.
17.6 Participation is forward-only. Switching participation on contributes deals from that date onward. Deals created before that date are not contributed, because the authority to contribute them was not in place when they were opened.
17.7 Withdrawal is not retroactive. Switching participation off stops all further contribution immediately. Statistics already computed and published from previously contributed fields cannot be recomputed to remove your firm's contribution, and we do not represent otherwise.
17.8 Per-deal exclusion. A participating firm may exclude any individual deal from contribution. Excluded deals contribute nothing, including counts.
17.9 Access. The benchmark is available to participating firms. Firms that do not participate do not receive access to it. Non-participation has no other effect on the service and does not affect pricing, support, or any other feature.
17.10 This section does not weaken Section 4.4. Nothing here permits us to use your firm's personal data, your deal materials, or any contributed field to train artificial intelligence or machine learning models, or to transmit any of them to a third-party artificial intelligence or machine learning provider.
18. Information and audit
18.1 On written request, no more than once in any 12-month period, we will provide the information reasonably necessary to demonstrate our compliance with this DPA, including a current description of our security measures and subprocessors.
18.2 We are a small organisation and do not host on-site inspections as a matter of course. We will cooperate with a reasonable assessment of our processing on the terms in this Section 18, and where applicable privacy law entitles you to an assessment, this Section 18 is how we meet it.
18.3 An assessment will be conducted on at least 30 days' written notice, during business hours, no more than once in any 12-month period except where required by a regulator or following a personal data breach affecting your firm's personal data, and in a manner that does not compromise the confidentiality of other firms' data or the security of the platform. You bear your own costs and our reasonable costs of cooperating.
18.4 We may satisfy a request under this Section 18 by providing a report prepared by a qualified and independent assessor, using an accepted control standard and covering the systems that process your firm's personal data, where such a report is available and current.
18.5 Where an audit or inspection is required by law or by a regulator, we will cooperate on reasonable notice, on the same confidentiality basis.
19. Location of data
19.1 The platform's own data stores, in which your firm's records and uploaded documents are held, are located in the United States. Other subprocessors, the limited data each receives, and what we can and cannot represent about where each processes it, are set out in Annex B.
19.2 This DPA is written for processing governed by United States law. Annex D sets out terms applicable under United States state privacy law, including the Colorado Privacy Act and the California Consumer Privacy Act.
19.3 Annex E is reserved for terms applicable to personal data protected by the EU or UK General Data Protection Regulation. If your firm has data subjects in those jurisdictions, contact us before putting their personal data into the platform so that Annex E can be completed and agreed.
20. Liability
20.1 The limitations and exclusions of liability in the Terms of Service apply to this DPA. Claims arising under this DPA and claims arising under the Terms of Service are subject to a single aggregate cap, and this DPA does not create a separate or additional cap.
20.2 Nothing in this Section 20 limits liability that cannot be limited by applicable law, or either party's obligations under applicable privacy law to the individuals whose personal data is processed.
21. Changes to this DPA
21.1 We may update this DPA. We will change the effective date above and, for material changes, notify your firm's account administrators by email at least 30 days before the change takes effect.
21.2 A material change is one that reduces our obligations to you, expands our permitted use of your firm's personal data, or materially reduces the protections in Annex C.
21.3 If you reasonably object to a material change on data protection grounds, tell us before it takes effect. If we cannot resolve the objection, you may terminate on the same basis as Section 11.3.
21.4 Adding a subprocessor is governed by Section 11, not this Section 21.
22. Term and governing law
22.1 This DPA takes effect when your firm begins using the platform and continues until the firm's data has been deleted in accordance with Section 16.
22.2 Sections 9, 15, 16, 20, and this Section 22 survive termination.
22.3 This DPA is governed by the laws of the State of Colorado, without regard to its conflict of laws rules, consistent with the Terms of Service. The state and federal courts located in Colorado have exclusive jurisdiction over any dispute arising from it.
23. Contact
ExitPros LLC, a Colorado limited liability company
3123 W Union Ave, Englewood, CO 80110
privacy@dealatrium.com
Annex A — Details of the processing
Subject matter and duration. Provision of the DealAtrium deal platform for the duration of the firm's subscription, plus the deletion period in Section 16.
Nature and purpose. Hosting, storage, retrieval, transmission and deletion of deal and contact records; controlled distribution of confidential deal documents to authorised recipients; sending correspondence at an advisor's direction; recording buyer engagement with deal materials; facilitating non-disclosure agreement signature.
Categories of data subject:
- Advisors and firm personnel — the firm's own users of the platform
- Buyers — prospective acquirers who inquire on a deal or are recorded by an advisor (processed by us as controller for their account and identity; see Section 3)
- Sellers — business owners whose companies are marketed, and their nominated contacts
- Diligence room participants — outside counsel, lenders, accountants and other advisers admitted to a room by the firm (processed by us as controller for their account and identity, as for buyers; see Section 3.3)
Types of personal data: name, business email address, telephone number, job title, employer or company name, business location, and, for buyers, acquisition criteria and a record of their engagement with deal materials and correspondence. Free-text notes written by advisors may contain further personal data of the advisor's choosing. IP addresses and email addresses are recorded from the public inquiry form for abuse prevention.
Special category and regulated data in structured fields: none is requested, and the platform has no field for it. Entering it into a structured field or free-text note is prohibited by Section 5.2.
Special category and regulated data inside documents: the platform is used to carry sell-side due diligence materials, which routinely contain personal data of the seller's personnel and of third parties — including dates of birth, compensation, and government identifiers appearing in tax returns, payroll registers, employee censuses, and benefit plan documents. Such data is expected to be present inside uploaded documents. Our processing of it is limited to the custody operations in Section 6: storage, streaming to authorised recipients, malware scanning, file type and integrity validation, marking for traceability, and deletion. We do not read, extract, index, or search document contents, and no such data is held in any queryable form.
Annex B — Subprocessors
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Supabase | Database and file storage | United States |
| Vercel | Application hosting | United States |
| Clerk | Authentication and login | See note below |
| Resend | Transactional email such as invitations and notifications | United States (primary processing) |
| Cloudflare | Domain routing, bot protection on public forms, and email routing | Global edge network; see note below |
| GoHighLevel | Non-disclosure agreement delivery and electronic signature. Receives buyer name, email address, telephone number and the deal reference in order to issue and track the agreement | See note below |
| Where an advisor connects a Google mailbox, to send that advisor's own correspondence. Send-only; we never read mailbox contents | Determined by the advisor's own mailbox provider | |
| Microsoft | The equivalent for a Microsoft mailbox, on the same send-only basis | Determined by the advisor's own mailbox provider |
| Sentry | Error monitoring. Receives diagnostic detail about software faults: error messages, stack traces, the route on which a fault occurred, and excerpts of our own application source code surrounding the faulting line. Request bodies, cookies, document contents, Storage paths and signed access links are stripped in our own application before transmission, not after receipt. Retention is no more than 90 days | United States |
Note on processing location.
The platform's own data stores — the database and document storage in which deal records, seller records, and uploaded documents are held — are located in the United States. That is the location claim that governs your firm's data, and it is the one this DPA depends on.
The remaining subprocessors receive only the limited categories of data described in the table above. Each is a United States company. Several operate global networks through which data may be routed or processed outside the United States, and some offer a choice of processing region. We do not represent that every subprocessor processes exclusively within the United States, and nothing in this DPA is conditioned on that being so. We will tell you the current configuration for any subprocessor on request under Section 18.
Where an advisor connects their own Google or Microsoft mailbox, mail is sent through that advisor's own mailbox provider and its location follows the advisor's own arrangements with that provider, not ours.
Annex C — Security measures
The measures below describe the platform as at the effective date of this DPA and are subject to Section 10.2.
- Authorisation checked on every request. Access to deal materials is re-checked against the permissions recorded for that specific person and deal on every request. There is no cached permission state anywhere in the platform.
- No public document links. Documents are never delivered by public or signed URL. A document is streamed by the server only after the authorisation check passes, and no storage path or link to stored content reaches a browser on any delivery path. Uploading works in the opposite direction: to upload a file, a browser is issued a short-lived, write-scoped authorisation limited to the single path of the file it is itself uploading. That authorisation confers no read access to anything, including the file it was issued for.
- Database access is default-deny. Row Level Security is enabled on every table in the application schema with no permissive policies, so the public and authenticated database roles are denied outright. This is a backstop against direct database access rather than the mechanism that authorises application requests: the application connects with a single privileged server-side credential, and all authorisation is enforced in one centralised data-access layer rather than being spread across the application.
- Documents are held, not read. No component of the platform extracts, transcribes, optically recognises, indexes, searches, summarises, or classifies document contents, and there is no full-text index of document contents anywhere in the system. Documents are streamed to an authorised recipient's browser, which renders them with its own built-in viewer; our servers do not convert or rasterise a document in order to display it. Where an operation permitted by Section 6.4 requires opening a document's format — validating its type, scanning it, or writing an identifying marker into a copy served to a named recipient — it goes no further than the file's structure and produces no record of what the document says.
- Tenant isolation. Every query is scoped to the firm making it. Seller data and any field that joins to it are excluded from responses served to buyers.
- Encryption. Data is encrypted in transit. Mailbox refresh tokens are encrypted at rest with AES-256-GCM under a key held separately from the database.
- Authentication. Sign-in is by emailed magic link through a specialist provider; we never store passwords. Administrative surfaces are gated by role.
- Abuse protection. The public inquiry form is protected by a bot check and by per-address and per-network rate limiting.
- Least-privilege mailbox access. Where an advisor connects a mailbox, the permission requested is send-only. We cannot read, import, or store mailbox contents.
No system is perfectly secure, and we do not claim otherwise.
Annex D — United States state privacy law
This annex applies to the extent a state privacy law listed below applies to your firm's processing on the platform. Where it conflicts with the body of this DPA, this annex controls for that processing.
D.1 Laws covered
The Colorado Privacy Act; the California Consumer Privacy Act as amended by the California Privacy Rights Act; the Virginia Consumer Data Protection Act; the Connecticut Data Privacy Act; the Utah Consumer Privacy Act; the Texas Data Privacy and Security Act; the Oregon Consumer Privacy Act; the Montana Consumer Data Privacy Act; and any other United States state privacy law applicable to the processing, in each case as amended.
D.2 Roles
For processing described in Sections 3.2 and 3.4, your firm is the controller or business and we are the processor, service provider, or contractor. For processing described in Section 3.3, we are the controller or business in our own right.
D.3 Processor and service provider commitments
We commit that, in respect of your firm's personal data:
(a) No sale, no sharing. We do not sell your firm's personal data, and we do not share it for cross-context behavioural advertising. We receive no monetary or other valuable consideration for it.
(b) Purpose limitation. We do not retain, use, or disclose your firm's personal data for any purpose other than the specific business purposes set out in Annex A and performance of the services, or as otherwise permitted by applicable privacy law. We do not retain, use, or disclose it outside the direct business relationship between us and your firm.
(c) No commingling. We do not combine your firm's personal data with personal data received from another source, except where necessary to perform a business purpose permitted by applicable privacy law.
(d) Certification. We understand the restrictions in this Annex D and will comply with them.
(e) Notification of inability to comply. We will notify you promptly if we determine that we can no longer meet our obligations under applicable privacy law, and we will cease processing or take other reasonable steps to remediate.
(f) Your right to remediate. You may take reasonable and appropriate steps to stop and remediate unauthorised use of your firm's personal data by us, including requiring us to stop the processing, delete the affected data, or provide documentation of remediation.
(g) Monitoring. You may take reasonable and appropriate steps to confirm that we use your firm's personal data consistently with your obligations under applicable privacy law, on the terms set out in Section 18.
(h) Subcontracting. Each subprocessor is engaged under a written contract imposing obligations materially equivalent to those in this Annex D. Subprocessor engagement is governed by Section 11.
(i) Confidentiality. Everyone we allow to process your firm's personal data is subject to a duty of confidentiality, as set out in Section 9.
(j) Deletion or return. At the end of the provision of services we delete or return your firm's personal data at your direction, as set out in Section 16.
(k) Assistance. We assist you with data subject rights requests (Section 13), with data protection assessments and security obligations (Section 14), and with breach notification (Section 12).
(l) Demonstrating compliance. We make available to you the information reasonably necessary to demonstrate compliance, and cooperate with assessments, as set out in Section 18.
D.4 De-identified data
Where we hold or create de-identified data under Section 17, we will: take reasonable measures to ensure it cannot be associated with an individual, household, or firm; maintain and use it only in de-identified form; not attempt to re-identify it, except to test the effectiveness of the de-identification; and contractually oblige any recipient to the same. The suppression thresholds in Section 17.5 form part of those measures.
D.5 Sensitive data
D.5.1 Structured fields. We do not request sensitive personal data or sensitive data as defined under applicable privacy law, and no structured field on the platform collects it. Section 5.2 prohibits you from entering it.
D.5.2 Inside documents. Sensitive data is expected to be present inside due diligence materials uploaded to the platform. Where it is, our processing of it is limited to the custody operations described in Section 6. We do not read, extract, index, search, or otherwise interpret it, we do not use or disclose it for any purpose other than providing the service, and we hold it in no queryable form.
D.5.3 Consent and notice are your firm's responsibility. Where applicable privacy law requires consent from an individual, or notice to them, before their sensitive data is processed, obtaining that consent or giving that notice is your firm's responsibility under Section 7.3, discharged before the material is uploaded.
D.5.4 We make no claim that this substitutes for consent. A contractual allocation of responsibility between us and your firm does not create a lawful basis for processing an individual's sensitive data. Section 7.4 states this expressly. The custody model in Section 6 and the redaction expectation in Section 5.5 exist because they reduce the underlying exposure, which contractual language alone cannot.
D.5.5 Where consent is withdrawn or an individual objects, and your firm identifies the documents concerned, we will delete or restrict access to those documents on your instruction. We cannot locate an individual inside stored documents ourselves, for the reason given in Section 7.6.
Annex E — European Economic Area and United Kingdom
Reserved, and intentionally not in force. This DPA is written for processing governed by United States law. No terms under the EU or UK General Data Protection Regulation — including standard contractual clauses, a transfer impact assessment, or the appointment of a representative — form part of this agreement at present.
If your firm intends to put personal data of individuals in the European Economic Area or the United Kingdom into the platform, contact privacy@dealatrium.com before doing so, and this annex will be completed and agreed with you.