Effective Date: February 7, 2026
Last Updated: February 2026
DDee.ai, Inc. (“DDee.ai,” “we,” “us,” or “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our commercial real estate due diligence platform and related services (collectively, the “Services”).
By using our Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.
When you authenticate via SSO (Okta, Azure AD, Google Workspace), we receive your name, email, and organizational information as configured by your administrator.
If your employer or organization has a business relationship with us, we may receive your contact information to provision your account.
We use the information we collect for the following purposes:
We do not sell your personal information. We share information only in the following circumstances:
We share information with third-party service providers who perform services on our behalf, including:
| Provider | Purpose | Data Shared |
|---|---|---|
| AWS | Document storage, infrastructure | Uploaded documents |
| Vercel | Application hosting | Application data |
| Neon | Database hosting | Account and deal data |
| Clerk | Authentication | Authentication data |
| OpenAI/Anthropic | AI document analysis | Document content (not retained) |
| Stripe | Payment processing | Payment information |
| Sentry | Error monitoring | Error logs (anonymized) |
For a complete list of subprocessors, see our Subprocessor List.
If you access our Services through an organizational account:
We may disclose information if required by law or if we believe disclosure is necessary to:
In connection with a merger, acquisition, or sale of assets, your information may be transferred. We will notify you of any such change.
We may share information with your consent or at your direction.
When you upload documents, our AI systems:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days |
| Uploaded documents | Duration of service + 30 days |
| Analysis results | Duration of service + 30 days |
| Audit logs | 7 years |
| Payment records | 7 years (legal requirement) |
We implement appropriate technical and organizational measures to protect your information:
For detailed security information, see our Security Whitepaper.
To exercise your rights, contact us at: privacy@ddee.ai
We will respond within 30 days (or as required by applicable law).
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
You may request information about categories of personal information collected, sources, business purposes, and third parties shared with.
You may request deletion of your personal information, subject to certain exceptions.
We do not sell personal information. If this changes, we will provide opt-out mechanisms.
We will not discriminate against you for exercising your privacy rights.
You may designate an authorized agent to submit requests on your behalf.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):
Right to access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making.
Your data may be transferred to the United States. We use appropriate safeguards including Standard Contractual Clauses (SCCs) and Data Processing Agreements.
You have the right to lodge a complaint with your local data protection authority.
We implement appropriate safeguards for international transfers:
Our Services are not intended for children under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected information from a child, we will delete it promptly.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security | Session |
| Functional | Preferences, settings | 1 year |
| Analytics | Usage understanding | 1 year |
We respect Do Not Track signals where technically feasible.
Our Services may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of our Services after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our privacy practices: