Legal

Privacy Policy

How DueDilio collects, uses, and protects your personal information when you use our platform.

Last updated: June 27, 2026
DueDilio LLC
Miami, FL & Delaware

Table of Contents

Effective: January 1, 2025
Privacy questions?
1.

Introduction & Scope

DueDilio LLC (“DueDilio,” “we,” “us,” or “our”) is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you access or use the DueDilio platform — including the website at www.duedilio.com and the web application at app.duedilio.com (collectively, the “Platform”).

This Policy applies to all users of the Platform globally, including buyers, sellers, business brokers, M&A advisory firms, and service providers, regardless of their country of residence. By using the Platform, you agree to the collection and use of information as described here. If you do not agree, please do not use the Platform.

DueDilio serves Clients and Service Providers worldwide. While we are headquartered in the United States, users in other countries may have additional rights or protections under their applicable local privacy laws. Where such laws impose specific obligations on DueDilio or grant you specific rights, we will comply to the extent required by applicable law.

DueDilio LLC is a Delaware limited liability company with its principal place of business at 68 SE 6th St #3310, Miami, FL 33131. Questions may be directed to hey@duedilio.com.

2.

Summary of Key Points

This summary provides key points from this Policy. See the relevant sections for full details.

What do we collect?

Contact info, account data, project and deal details, payment info, and usage data. See Section 3.

Do we sell your data?

No. DueDilio does not sell personal information to third parties for their own marketing or commercial purposes.

Who do we share data with?

Matched Service Providers, technology vendors, and as required by law. See Section 5.

How long do we keep data?

For as long as your account is active and as needed for legal obligations. See Section 8.

What are your rights?

Access, correction, deletion, and opt-out rights depending on your jurisdiction. See Section 10.

Do we use cookies?

Yes, for site functionality, analytics, and marketing. See Section 7.

3.

Information We Collect

3.1 Information You Provide Directly

When you register, submit a project, or apply as a Service Provider, you may provide:

  • Identity & contact information: Name, email address, phone number, mailing address, job title, and company name;
  • Account credentials: Username, password, and account preferences;
  • Project and deal information: Business description, deal parameters, financial data, target company details, and related deal materials;
  • Service Provider application data: Professional credentials, licenses, work history, client references, and the following additional information collected during the vendor application process:
    • Attorney or law firm status;
    • Services offered, service categories, and experience level;
    • Geographic location (country and state/province), jurisdictions served (including US state-level), and cross-border transaction capability;
    • Industry experience profile, client types served, and deal size ranges;
    • Pricing structure, typical fee ranges, and minimum engagement thresholds;
    • Subcontractor use and arrangements;
    • E&O / professional liability insurance status;
    • Risk disclosure data: history of material negative client outcomes, terminated engagements, or unresolved disputes in the preceding five years; history of legal proceedings, regulatory enforcement, license suspension, or professional disciplinary actions related to professional services; and
    • Availability of client references and work samples.
  • Payment information: Billing address and payment card data (processed by our third-party payment processor; we do not store full card numbers);
  • Communications: Messages, proposals, and correspondence through the Platform;
  • Third-party business information: When Clients submit projects, they provide detailed financial, operational, and descriptive information about businesses that are the subjects of transactions — including acquisition targets, businesses being prepared for sale, and businesses subject to post-acquisition work. This information may include revenue, EBITDA, workforce composition, accounting systems, technology infrastructure, deal stage, and related context. These businesses are not themselves users of the Platform. Clients represent that they are authorized to submit this information in accordance with any applicable confidentiality obligations or non-disclosure agreements (see Section 6.4 of the Terms of Service). DueDilio uses this information solely to facilitate provider matching and proposal preparation, and does not use or retain it for any other commercial purpose;
  • Introduction and relationship records: For Service Providers, we record the date of first introduction between each Service Provider and each Client through the Platform. This record is used to determine the applicable 24-month Referral Fee Period under the Provider Agreement and these Terms;
  • Off-platform revenue reports: Service Providers are required under their Provider Agreement to report gross fees received from referred Clients during the applicable Referral Fee Period, including fees from engagements entered into directly between the parties outside the Platform. DueDilio collects and retains this financial reporting data for referral fee calculation and enforcement purposes.

3.2 Information Collected Automatically

When you visit or use the Platform, we automatically collect:

  • Log and usage data: IP address, browser type, OS, pages viewed, links clicked, and time spent;
  • Device data: Device type, hardware model, and network information;
  • Location data: Approximate location derived from IP address (not precise GPS);
  • Cookie and tracking data: Data collected via cookies and similar technologies (see Section 7).

3.3 Information from Third Parties

We may receive information from third parties in limited circumstances, including:

  • Referral Partners: Referral Partners who direct users to the Platform may provide contact information to facilitate account creation or project submission;
  • Authentication providers: If you log in via a third-party service (e.g., Google), we receive basic profile information from that service;
  • Professional data sources: Publicly available professional information used for Service Provider vetting.
4.

How We Use Your Information

We use the information we collect for the following purposes:

  • To operate and provide the Platform: Creating accounts, processing payments, facilitating project submissions and provider matching;
  • Provider vetting and network management: Reviewing applications, verifying credentials, and maintaining the DueDilio Verified™ network;
  • Communications: Responding to inquiries, sending project updates, delivering proposals, and providing customer support;
  • Platform improvement: Analyzing usage patterns, testing features, and improving performance and user experience;
  • Marketing and outreach: Sending newsletters and promotional materials (where you have opted in or where permitted by applicable law);
  • Legal compliance and fraud prevention: Complying with legal obligations, detecting and preventing fraud, and enforcing our Terms of Service;
  • Referral fee tracking and enforcement: Recording client-provider introduction dates, tracking the 24-month Referral Fee Period for each introduced relationship, collecting and processing off-platform revenue reports from Service Providers, calculating referral fees owed, and enforcing fee obligations under the Provider Agreement and these Terms;
  • Business operations: Accounting, tax compliance, dispute resolution, and general business administration.

We process your personal information only when we have a valid legal basis, including: performance of a contract with you; your consent; compliance with a legal obligation; or our legitimate business interests where not overridden by your rights.

5.

When & With Whom We Share Your Information

5.1 Matched Service Providers

When you submit a project, we share relevant project information — including your project description, deal parameters, and contact information — with matched Service Providers so they can prepare proposals. This is a core function of the Platform. Service Providers are bound by DueDilio’s Provider Agreement, which includes confidentiality obligations.

Vendor profile anonymization: To protect Service Provider privacy, DueDilio displays providers to Clients using a first name and last initial only (e.g., “Michael T.”) until mutual engagement is established. Full identity, contact details, and firm identifying information are not shared with Clients through the public profile. Contact details collected during the vendor application process are used by DueDilio for internal account management and are not disclosed to Clients.

5.2 Technology Vendors & Infrastructure Partners

We share information with third-party vendors providing services on our behalf, including cloud hosting (Bubble platform), payment processing, email delivery, analytics, and data storage. These vendors are contractually bound to use your information only as directed by DueDilio.

5.3 Business Transfers

If DueDilio is involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.

5.4 Legal Compliance & Protection

We may disclose your information when required by law, legal process, or governmental request; to enforce our Terms or agreements; to detect or prevent fraud or security issues; or to protect the rights, property, or safety of DueDilio, our users, or the public.

5.5 Aggregate & De-identified Data

We may share or publish aggregated, de-identified, or anonymized information that cannot reasonably identify you, for research or analytical purposes.

5.6 No Sale of Personal Information

DueDilio does not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.

6.

Referral Partner Disclosures

DueDilio operates a Referral Partner Program through which certain third-party organizations (“Referral Partners”) direct prospective users to the Platform. Referral Partners may provide DueDilio with your name and contact information to facilitate your registration or project submission.

DueDilio may pay compensation to Referral Partners. The existence of a Referral Partner relationship does not affect the Platform Access Fee charged to Clients, and DueDilio’s matching and curation standards apply equally to all Clients regardless of referral source. DueDilio complies with applicable disclosure requirements, including the FTC’s material connections guidelines (16 C.F.R. Part 255). Referral Partners who are attorneys are required to comply with all applicable state bar rules governing attorney referral arrangements.

7.

Cookies & Tracking Technologies

We use cookies and similar tracking technologies (web beacons, pixels) to collect and store information about your use of the Platform. Cookies are small text files stored on your device. We use the following categories:

  • Essential / strictly necessary cookies: Required for the Platform to function (e.g., session management, authentication, security). These cookies cannot be disabled without materially affecting Platform functionality and do not require your consent.
  • Functional / preference cookies: Remember your choices and preferences (e.g., language, account settings) to personalize your experience. These are deployed on a legitimate-interest basis for registered users; we obtain consent for non-registered visitors where required by law.
  • Analytics cookies: Help us understand usage patterns and improve the Platform (e.g., Google Analytics). Analytics cookies that process personal data are deployed only with your consent where required by applicable law.
  • Marketing and retargeting cookies: Used to deliver relevant advertising on third-party platforms (e.g., Facebook Pixel, Google Ads). These cookies are deployed only with your prior, freely given, specific, and informed consent where required by applicable law (including GDPR for EU/EEA/UK visitors).

7.2 Cookie Consent

Where required by applicable law — including GDPR for users in the EU, EEA, and UK — we obtain your consent before placing non-essential cookies on your device. You will be presented with a cookie consent banner when you first visit the Platform. Through this banner, you may accept all cookies, reject all non-essential cookies, or manage your preferences by category. You may change or withdraw your cookie consent at any time by adjusting your preferences through the consent management tool available in the Platform footer, or by adjusting your browser settings.

Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal. Disabling certain cookies may limit Platform functionality. To opt out of interest-based advertising industry-wide, visit www.aboutads.info/choices or the NAI opt-out tool at optout.networkadvertising.org.

7.3 Third-Party Tracking

Certain third-party services integrated into the Platform (such as Google Analytics and advertising networks) may set their own cookies governed by those parties’ privacy policies. DueDilio does not control third-party cookies. A list of third-party cookie providers used on the Platform is available through the cookie consent management tool.

8.

Data Retention

We retain your personal information for as long as your Account is active or as reasonably necessary to fulfill the purposes described in this Policy:

  • Account data: Retained for the duration of your Account plus a reasonable period after closure to support dispute resolution and legal compliance;
  • Transaction and payment records: Retained for a minimum of seven (7) years to comply with tax and financial record-keeping requirements;
  • Project and deal information: Retained for the duration of your Account and a period thereafter to support potential disputes or legal claims;
  • Referral fee records (Service Providers): Introduction date records, client-provider relationship identifiers, and off-platform revenue reports are retained for the full 24-month Referral Fee Period applicable to each introduced client-provider relationship, plus an additional period of at least two (2) years after the close of that period to support dispute resolution, audit, and enforcement of referral fee obligations. This retention applies even if a Service Provider’s Account is closed or terminated before the expiration of an active Referral Fee Period;
  • Marketing communications: Retained until you opt out, after which we retain a record of your opt-out preference.

When retention is no longer necessary, we will delete or anonymize your personal information, or securely isolate it from further processing until deletion is possible.

9.

Data Security & Breach Notification

DueDilio implements reasonable technical, organizational, and administrative security measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These include encryption of data in transit (TLS/HTTPS), access controls limiting employee access to personal information on a need-to-know basis, and regular security assessments of our platform infrastructure.

No method of transmission over the Internet or electronic storage is 100% secure. If you believe your Account has been compromised, contact us immediately at hey@duedilio.com.

The Platform application is hosted on a third-party cloud infrastructure platform. Users whose project activities involve particularly sensitive confidential information are encouraged to execute separate non-disclosure agreements directly with any Service Providers engaged through the Platform.

9.3 Data Breach Notification

In the event of a security incident that results in unauthorized access to, or disclosure of, personal information constituting a data breach under applicable law, DueDilio will:

  • Notify affected users: Provide written notice to affected registered users at the email address on file, without undue delay and in any event within the timeframes required by applicable law. In Florida, our primary jurisdiction, we aim to notify within 30 days of confirming a breach as required by Fla. Stat. § 501.171;
  • Notify regulators: Report the breach to applicable regulatory authorities as required by law, including within 72 hours to relevant EU/EEA supervisory authorities where GDPR applies;
  • Describe the incident: Include in any notice, to the extent known: the nature of the breach, the categories of personal information affected, the likely consequences, and the measures DueDilio has taken or will take to address the breach.

Notification obligations are subject to exceptions under applicable law, including where law enforcement requests delay. Nothing in this section creates obligations beyond those required by applicable law. If you believe a breach may have affected your Account, contact us immediately at hey@duedilio.com.

10.

Your Privacy Rights

10.1 General Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Right to access: Request a copy of the personal information we hold about you;
  • Right to correction: Request correction of inaccurate or incomplete information;
  • Right to deletion: Request deletion of your personal information, subject to legal exceptions;
  • Right to restriction: Request that we restrict processing in certain circumstances;
  • Right to portability: Request your data in a structured, machine-readable format (where applicable);
  • Right to object: Object to processing for certain purposes, including direct marketing;
  • Right to withdraw consent: Withdraw consent at any time where processing is consent-based.

To exercise any right, contact us at hey@duedilio.com. We will respond within 30 days. We may verify your identity before fulfilling your request.

Opting out of marketing: Click the “unsubscribe” link in any marketing email or contact us at hey@duedilio.com. We will continue to send service-related communications necessary to administer your Account.

10.2 EU, EEA, and UK Users (GDPR)

If you are located in the European Union, European Economic Area, or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR) or the UK GDPR, as applicable. In addition to the rights described in Section 10.1 above, you have the right to lodge a complaint with your local supervisory authority if you believe we have not complied with applicable data protection law. A list of EU supervisory authorities is available at ec.europa.eu. For UK residents, complaints may be directed to the Information Commissioner’s Office (ICO) at ico.org.uk.

Legal bases for processing (EU/UK users): Where GDPR applies, we process your personal information on the following legal bases:

  • Contract performance: Processing necessary to provide the Platform services you have requested or to take steps prior to entering a contract with you (e.g., account creation, project submission, provider matching);
  • Legitimate interests: Processing for our legitimate business interests, including Platform security, fraud prevention, analytics, and service improvement, where those interests are not overridden by your rights;
  • Consent: Processing for marketing communications, non-essential cookies, and other activities where we have obtained your explicit consent. You may withdraw consent at any time;
  • Legal obligation: Processing required for compliance with applicable law, regulatory requirements, or lawful requests from governmental authorities.

10.3 International Data Transfers

DueDilio LLC is headquartered in the United States, and your personal information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your country of residence. By using the Platform, you acknowledge that your personal information may be transferred to and processed in the United States.

For transfers of personal information from the EU, EEA, or UK to the United States, we rely on applicable legal transfer mechanisms. These may include: (a) the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the EU-U.S. DPF, and/or the Swiss-U.S. DPF, as applicable and if DueDilio has self-certified or relies on a sub-processor that has self-certified thereunder; or (b) Standard Contractual Clauses (SCCs) approved by the European Commission or the UK Information Commissioner’s Office. We take reasonable steps to ensure that your personal information receives an adequate level of protection in the countries where it is processed.

10.4 Automated Decision-Making

The Platform and all content, features, functionality, design, code, logos, trademarks (including “DueDilio®” and “DueDilio Verified™”), service marks, and other intellectual property therein (collectively, “DueDilio IP”) are owned by DueDilio LLC or its licensors. No rights in DueDilio IP are transferred to you under these Terms except the limited license in Section 2. You may not use DueDilio’s name, logo, or marks without prior written consent.

11.

California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

11.1 Categories of Personal Information Collected

In the past 12 months, DueDilio has collected the following categories of personal information:

Category
Examples
Collected
A. Identifiers
Name, email, postal address, IP address, account name
Yes
B. California Customer Records
Name, contact info, employment, financial information
Yes
C. Protected classifications
Gender, date of birth
No
D. Commercial information
Transaction history, payment information
Yes
E. Biometric information
Fingerprints, voiceprints
No
F. Internet / network activity
Browsing and usage data on the Platform
Yes
G. Geolocation data
Approximate location from IP address
Yes
H. Sensory data
Audio, visual recordings
No
I. Professional / employment-related
Business role, professional credentials (providers)
Yes
J. Education information
Student records
No
K. Inferences
Profiles drawn from above data
No

11.2 Your California Rights

  • Right to know: Request disclosure of personal information collected, its sources, business purposes, and third parties with whom it was shared;
  • Right to delete: Request deletion of personal information we have collected, subject to certain exceptions;
  • Right to correct: Request correction of inaccurate personal information;
  • Right to opt out of sale/sharing: DueDilio does not sell or share personal information for cross-context behavioral advertising as defined under CCPA;
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.

To submit a California privacy request, contact us at hey@duedilio.com. We will verify your identity and respond within 45 days.

12.

Florida Residents

DueDilio is headquartered in Miami, Florida, and all users — not only Florida residents — benefit from DueDilio’s compliance with Florida privacy and data security law.

12.1 Florida Data Breach Notification (Fla. Stat. § 501.171)

Florida’s data breach notification statute applies to any business that maintains computerized personal information of Florida residents, regardless of revenue or size. DueDilio complies with this statute. In the event of a qualifying breach, DueDilio will notify affected Florida residents within 30 days of determining that a breach has occurred, as required by law. See Section 9.3 of this Policy for our full breach notification procedures.

12.2 Florida Digital Bill of Rights (FDBR)

The Florida Digital Bill of Rights (Fla. Stat. Ch. 501, Part III), effective July 1, 2024, grants privacy rights to Florida consumers in connection with large technology platforms. DueDilio’s current assessment is that it does not meet the revenue thresholds required for FDBR applicability ($1 billion+ annual global gross revenues). Accordingly, the FDBR’s consumer rights provisions do not currently apply to DueDilio. DueDilio will monitor its obligations under the FDBR and update this Policy if its applicability status changes.

13.

Do-Not-Track

Most web browsers include a Do-Not-Track (“DNT”) feature. As of the date of this Policy, no uniform technology standard for recognizing and implementing DNT signals has been established. DueDilio does not currently respond to DNT signals. If a standard is adopted in the future, we will update this Policy accordingly.

14.

Children's Privacy

The Platform is intended solely for use by individuals 18 years of age or older. We do not knowingly collect personal information from any person under the age of 18. In compliance with the Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501 et seq., we do not knowingly collect, solicit, or maintain personal information from children under the age of 13. If we become aware that we have inadvertently collected personal information from any minor, we will promptly delete it from our systems. If you believe we have collected personal information from a minor, please contact us immediately at hey@duedilio.com.

15.

Updates to This Policy

We may update this P

15.

Contact Us

We may update this P