Privacy Policy
Dotnitron Technologies Pvt. Ltd. · Last Updated: September 18, 2026
Dotnitron Technologies Pvt. Ltd. ("Underlying", "we", "us", or "our") provides an evidence workroom and verification platform for private-equity and M&A diligence teams. This Privacy Policy details our data governance principles, collection practices, and security safeguards.
01.Customer-Controlled Diligence Data
We act as a data processor (or service provider) for all customer-controlled transaction data processed through our workspace. This includes virtual data room (VDR) documents, audited financial models, CIM files, expert interview transcripts, reviewer notes, and investment committee drafts.
As between Underlying and your organization, you retain full ownership and control over your data. Underlying processes customer data solely to perform requested diligence analyses, manage evidence linkages, and support contracted workflows.
02.Information We Collect & Sources
Depending on your interactions with Underlying, we may collect information across the following categories:
- Account Credentials & Contact Information: Name, work email address, company affiliation, title, and authentication tokens when you request pilot access or log in.
- Website Enquiries: Contact details and workflow context submitted through our demo and contact forms are processed via Formspree to respond to your request. Please do not submit confidential transaction documents through public website forms.
- Meeting & Calendar Bookings: When scheduling a demo or other conversation, appointment details are processed via Cal.com under Cal.com’s privacy policy.
- Audit & Review Logs: Timestamped records of analyst citations, approvals, flags, and reviewer overrides generated during workspace operations to maintain inspectable diligence defensibility.
- Website Telemetry: Aggregated, privacy-preserving usage statistics (e.g. via Vercel Analytics) to monitor page performance and CTA interactions. We do not track personal identifying information in web analytics.
03.Third-Party Foundation Models & Infrastructure
Underlying utilizes enterprise foundation model APIs and secure cloud infrastructure to execute extraction, comparison, and draft generation.
Model-provider processing, retention, and training terms are confirmed for the selected endpoints in the applicable deployment agreement and security schedule. That schedule also identifies the cloud hosting region and encryption configuration.
04.Security & Data Residency
Underlying uses organization and Deal Room membership controls and role-based authorization to limit access to customer data. Encryption in transit and at rest, together with the applicable configuration, is documented for the proposed deployment.
Specific geographic data boundaries, hosting arrangements, and infrastructure requirements are assessed and agreed before customer data is processed in the selected environment.
05.Data Retention & Disposal
Customer diligence data retention is governed by the engagement agreement. Deletion requests, source files, analysis artifacts, caches, backups, and any required retention exceptions are handled according to the agreed deletion procedure and schedule.
Any required audit-record export and access arrangements are agreed before workspace decommissioning.
06.Privacy Rights & Inquiries
Depending on your jurisdiction, you may have statutory rights under the GDPR, UK GDPR, or CCPA/CPRA to access, correct, export, or delete personal data held about you. Because Underlying generally acts as a processor on behalf of customer firms, end-user requests regarding matter records should be directed to your organization's workspace administrator.
Questions about security or data protection?
Contact our privacy and security team to request our detailed security architecture review or schedule a compliance call.
