Privacy Policy
DealGauge — Privacy Policy
Last Updated: June 16, 2026
Version: 1.0
Provider: Edenbrook Technologies, Inc., a Delaware corporation doing business as "DealGauge" ("Edenbrook," "DealGauge," "Company," "we," "us," or "our").
Product: DealGauge, an AI-assisted business-valuation production platform operated at https://dealgauge.ai (the "Service").
1. Introduction
This Privacy Policy describes how DealGauge collects, uses, shares, and protects information about you when you interact with the Service, our website, or any related product or communication. It also describes the choices you have about how we use that information and the rights you have under applicable U.S. state privacy laws.
This Privacy Policy applies in addition to, and is incorporated by reference into, the DealGauge Terms of Service. Defined terms used here and not defined have the meaning set out in the Terms of Service.
2. Who This Policy Applies To
DealGauge has three categories of users, and parts of this Privacy Policy apply differently to each:
- Firm Customers — professional services firms that subscribe to the Service. Where we collect personal information about a Firm Customer's employees, contractors, or principals in connection with their account (such as billing contacts, account administrators, and Analyst Users), we are acting as the controller of that information.
- Analyst Users — individuals who access the Service under a Firm Customer's seat. Where we collect personal information about an Analyst User in connection with their access, we are acting as the controller of that information.
- Business Owner Sub-Users — individuals who interact with the Service because a Firm Customer has invited them to participate in a valuation engagement. Some of the information Business Owner Sub-Users provide is processed on behalf of the Firm Customer (we are the processor); other information collected about Business Owner Sub-Users (such as account credentials, communications with us, and technical access logs) is collected by us as the controller.
In addition to these three categories, this Privacy Policy applies to website visitors — anyone who browses dealgauge.ai or our marketing pages without signing in or interacting with the Service.
3. Our Role as Processor for Firm Customer Engagement Data
A substantial portion of the information processed through the Service consists of financial documents, tax returns, addback explanations, discovery-questionnaire responses, and related materials about a Firm Customer's underlying client (the business being valued). For this category of information — which we refer to as Engagement Data — the Firm Customer is the controller and DealGauge is the processor. The Firm Customer determines what Engagement Data is uploaded, how it is used in the engagement, how long it is retained for the Firm Customer's own purposes, and what is communicated to the underlying client.
If you are an individual whose information appears in Engagement Data and you wish to exercise privacy rights (such as access, deletion, or correction) with respect to that information, you should generally direct your request to the Firm Customer that controls the engagement, rather than to DealGauge. We will support the Firm Customer's lawful response to your request as described in Section 16.
This Privacy Policy primarily addresses the information for which DealGauge is the controller. To the extent we process Engagement Data as a processor, our processing is governed by the Terms of Service and any applicable agreement between DealGauge and the Firm Customer.
4. Information We Collect
We collect the following categories of information.
A. Information You Provide Directly
Account information: When a Firm Customer signs up or an account administrator provides an Analyst User, we collect business name, contact name, business email address, phone number (where provided), job title or role, and credentials (such as a password, which we store in hashed form).
Subscription and billing information: Plan selection, seat count, billing address, payment method details (which are processed by our payment provider; we do not store full payment card numbers), tax identification information where required, and Order Form contents.
Communications: Information you submit when contacting us by email, support form, or another channel, including your name, contact information, and the substance of the communication.
Sub-user identification: When a Firm Customer invites a Business Owner Sub-User through a portal link or sponsored sub-user account, we collect the Business Owner Sub-User's name, email address, and (where SMS verification is used) phone number. These data points are collected to provide access to the portal and to authenticate the Business Owner Sub-User.
Engagement Data submitted through portals: Where a Business Owner Sub-User submits addback explanations, questionnaire responses, financial documents, or other content through a portal, that information becomes part of the Engagement Data processed on behalf of the Firm Customer.
B. Engagement Data Uploaded by Firm Customers
Firm Customers upload Engagement Data on behalf of their underlying clients. Engagement Data may include:
- federal and state tax returns;
- financial statements (including income statements, balance sheets, and cash-flow statements);
- bank statements and other financial records;
- corporate, ownership, and capitalization information;
- addback explanations and supporting documentation;
- discovery questionnaire responses;
- AI Outputs produced through the Service (extracted financial data, normalization suggestions, valuation calculations, narrative reports, financial models, slide decks, and audio narrations); and
- any other documents or content a Firm Customer chooses to upload.
Engagement Data may incidentally contain personal information about individuals (such as the underlying client's owner, principals, employees, family members, customers, or counterparties). As described in Section 3, we process Engagement Data as a processor on behalf of the Firm Customer.
C. Information Collected Automatically
When you use the Service or visit our website, we automatically collect certain information about your device and your interactions with the Service, including:
- IP address and approximate location (derived from IP);
- browser type, operating system, and device characteristics (which may include device fingerprint signals derived from a combination of browser, hardware, and configuration attributes used to recognize a device across sessions for account-integrity and fraud-prevention purposes);
- log data, including pages accessed, features used, files uploaded or downloaded (metadata only, not content), timestamps, and session identifiers;
- cookies and similar tracking technologies (see Section 10); and
- error and crash reports.
D. Information from Third Parties
We may receive information about you from third parties, including:
- identity-verification, fraud-prevention, and account-integrity providers;
- payment processors (transaction confirmations, fraud signals);
- third-party data providers from whom we license Benchmark Data and comparable-transaction data (this information does not generally include personal information about Service users, but may include information about businesses);
- our communications providers Resend and, where used, our SMS delivery provider);
- our advertising and marketing partners, who may share information about how you interacted with our advertisements on Meta, LinkedIn, Google, or other platforms; and
- Firm Customers, who may provide information about Business Owner Sub-Users when issuing portal invitations. 5. How We Use Information We use information for the following purposes:
- Providing the Service: Operating, maintaining, and improving the Service; provisioning accounts; processing uploaded documents; generating AI Outputs; supporting Firm Customer engagements; sending operational notifications.
- Authentication and security: Verifying user identity, preventing fraud and unauthorized access, monitoring for misuse, investigating suspected violations of these Terms or applicable law.
- Billing and account management: Processing subscription payments, issuing invoices and receipts, managing renewals and cancellations, calculating applicable taxes, and managing seats.
- Communications: Responding to support requests, sending product updates and service notifications, sending billing communications, and (where you opt in) sending marketing communications.
- Improvement and analytics: Understanding how the Service is used, identifying defects, evaluating product performance, and improving the Service. We may use aggregate, anonymized, and de-identified data derived from operation of the Service for these purposes.
- Legal compliance and protection: Complying with applicable law, responding to legal process, enforcing the Terms of Service, protecting the rights, property, and safety of DealGauge, our users, and third parties.
- Marketing and advertising (for our own website and marketing pages — not the logged-in Service). Measuring and improving our advertising campaigns, identifying prospective customers, and managing remarketing audiences.
6. AI and Automated Processing
The Service uses artificial-intelligence systems to process Engagement Data, including extracting financial data from uploaded documents, suggesting normalizations and addbacks, performing valuation calculations, generating narrative content, building financial models, producing slide deliverables, and (optionally) generating audio narration. AI Outputs are subject to the limitations described in the DealGauge Terms of Service, including the requirement that the Firm Customer's credentialed professional review, modify, and approve AI Outputs before relying on them or delivering them to any third party.
The AI providers we currently use to deliver these functions are listed in Section 9 (Subprocessors). Each AI provider has its own terms governing the handling of inputs and outputs, including its position on whether inputs may be used to train models. Our current configurations and provider relationships are described, and will continue to be updated, in our Subprocessor List on the DealGauge website. The Service uses multiple AI providers, each assigned to one or more of the operations described above (extraction, analysis, narrative and presentation generation, and text-to-speech). The active provider for each operation is determined by the Service's configuration and may be changed from time to time by authorized administrators through the Service's settings. Engagement Data is transmitted only to the provider(s) actively configured for the relevant operation; the Service does not automatically route Engagement Data to providers that are not the active configured provider for that operation.
Automated processing of Engagement Data through the Service does not constitute a "solely automated decision" that produces legal or similarly significant effects on a natural person within the meaning of applicable U.S. state privacy laws, because the Firm Customer's credentialed professional is required to review and approve AI Outputs before any reliance or delivery.
7. Cookies and Tracking Technologies — Website and
Marketing Pages Our website and marketing pages at dealgauge.ai use cookies and similar tracking technologies for the following purposes:
- Strictly necessary cookies — required to operate the website and the logged-in Service (session management, security, load balancing).
- Functional cookies — remember user preferences, language settings, and prior interactions to improve experience.
- Analytics cookies — measure how visitors interact with our website (for example, through Google Analytics) so that we can improve our content and conversion paths.
- Advertising and marketing cookies — measure the effectiveness of our paid advertising on Meta, LinkedIn, and Google, and support remarketing to visitors who have previously engaged with our content. These cookies include the Meta Pixel, the LinkedIn Insight Tag, and Google Ads conversion tracking, among others.
You can manage cookie preferences through our cookie consent banner, through your browser settings, and through the opt-out mechanisms each advertising network provides. We honor recognized Global Privacy Control (GPC) browser signals as opt-out signals where applicable U.S. state privacy law treats them as such.
For the logged-in Service itself (the application where Firm Customers and users actually work on engagements), we use only strictly necessary and functional cookies. We do not run advertising or third-party marketing trackers inside the logged-in Service.
8. How We Share Information
We share information only as described in this Section.
Service providers and subprocessors: We share information with third-party service providers who help us operate the Service, including hosting providers, AI model providers, document extraction providers, communications providers, payment processors, identity-verification providers, customer-support tools, and analytics and marketing providers. These service providers are listed in our Subprocessor List (Section 9) and are bound to use information only as needed to provide their services to us.
With Firm Customers and their authorized users: Engagement Data and AI Outputs produced through the Service are accessible to the Firm Customer that conducts the engagement and to the Analyst Users assigned by that Firm Customer. Business Owner Sub-User submissions through portals are shared with the inviting Firm Customer.
Legal compliance, law enforcement, and protection: We may share information to comply with applicable law, court orders, subpoenas, regulatory requests, and other legal process, or to protect the rights, property, or safety of DealGauge, our users, or third parties — including for fraud prevention, security, and the enforcement of our Terms.
Business transfers: We may share information in connection with a merger, acquisition, financing, sale of all or substantially all of our assets, corporate restructuring or reorganization, or analogous transaction, including during diligence. Where we do so, we will require the recipient to honor the commitments in this Privacy Policy, or we will notify affected users of any material changes. With your consent: We may share information for purposes you specifically authorize.
We do not sell personal information: DealGauge does not sell personal information for monetary consideration. To the extent advertising-related sharing through technologies like the Meta Pixel, LinkedIn Insight Tag, and Google Ads conversion tracking constitutes a "sale" or "share" of personal information under applicable state law (such as the CCPA's expanded definition of "share" for cross-context behavioral advertising), you may opt out as described in Sections 7 and 13.
9. Subprocessors
We maintain a current list of subprocessors — third-party service providers that process personal information or Engagement Data on our behalf — on the DealGauge website at https://dealgauge.ai/subprocessors (or such other URL as we may designate). The categories of subprocessors we currently use include:
- Cloud hosting and storage — DigitalOcean.
- Large language model and vision providers —
- Anthropic (Claude API) — default provider for document reading and extraction, analysis, and report generation.
- Google (Gemini API) — default provider for presentation and slide-script generation; selectable as an alternative extraction provider.
- OpenAI — default provider for text-to-speech narration; selectable as an alternative extraction and analysis provider.
- ElevenLabs — optional premium text-to-speech provider; used only when explicitly enabled in account settings.
- Text-to-speech audio narration — ElevenLabs.
- Communications — Resend for email delivery; our SMS delivery provider for SMS messages where used.
- Payment processing — Stripe.
- Identity verification and account integrity — our identity-verification provider.
- Analytics — our analytics provider.
- Advertising and marketing measurement (for the website and marketing pages only) — Meta, LinkedIn, Google Ads, and similar advertising platforms.
We may update subprocessors from time to time. Material changes to subprocessors that affect the processing of Engagement Data will be reflected in updates to our Subprocessor List. 10. Data Retention We retain information for as long as needed to provide the Service, fulfill the purposes described in this Privacy Policy, comply with our legal and recordkeeping obligations, enforce our Terms of Service, resolve disputes, prevent fraud, and protect our legitimate interests.
In general:
- Account information is retained for the duration of the account, plus a period thereafter to support reactivation, legal recordkeeping, and dispute resolution.
- Billing and tax records are retained for the period required by applicable tax and accounting laws.
- Engagement Data is retained for the duration of the Firm Customer's subscription, plus any post-termination period agreed in the Order Form or required by law. The Firm Customer determines the retention of Engagement Data for the Firm Customer's own purposes; we delete or return Engagement Data following termination as described in the Terms of Service and any applicable subprocessor or data-processing arrangement with the Firm Customer.
- Communications with our support and sales teams are retained for as long as reasonably necessary for service quality, training, and dispute resolution.
- Technical and security logs are retained for the period necessary for fraud prevention, security monitoring, audit, and investigation.
[Verification pending: a documented, enforced data-retention schedule covering each category above is in development. Once verification is complete, the specific retention periods will be reflected in this Privacy Policy.]
We may retain information beyond these periods where required by law, legal hold, regulatory process, or ongoing dispute.
11. Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, use, or disclosure. These safeguards include encryption of data in transit, access controls on production systems, logging of administrative activity, periodic review of our security practices, and contractual commitments from our subprocessors.
No information system can be made completely secure. We do not warrant that our security measures will be effective against every threat, and we cannot guarantee the security of information transmitted to or stored within the Service. You are responsible for using a strong password, safeguarding your credentials, and notifying us promptly of any suspected unauthorized access.
[Verification pending: documented access controls, permissions, audit logging, and breach-response procedures are in development. Once verification is complete, the specific commitments will be reflected in this Privacy Policy and in our Trust / Security page.]
12. Geographic Scope (United States Only)
The Service is offered exclusively to residents and entities of the United States. All personal information and Engagement Data we process are processed within the United States by our U.S.-based personnel and our subprocessors operating from the United States. We do not transfer Engagement Data to personnel or service providers outside the United States.
This Privacy Policy and the Service are not directed at, and are not intended to comply with the data-protection laws of, the European Economic Area, the United Kingdom, Switzerland, Canada, or other non-U.S. jurisdictions. If you are located outside the United States, please do not use the Service.
13. Your Privacy Rights — U.S. State Privacy Laws
Depending on the state in which you reside, you may have specific privacy rights under applicable U.S. state privacy laws. The sections below summarize those rights and explain how to exercise them. Where DealGauge is the processor (for Engagement Data uploaded by a Firm Customer), you should generally exercise privacy rights with respect to that data by contacting the Firm Customer.
A. California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we have collected about you, including categories, sources, purposes, and recipients;
- Access a copy of the specific pieces of personal information we have collected about you in the past twelve (12) months;
- Delete personal information we have collected from you, subject to applicable exceptions;
- Correct inaccurate personal information we maintain about you;
- Opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising;
- Limit the use and disclosure of sensitive personal information, where applicable;
- Be free from discrimination for exercising your privacy rights.
To exercise these rights, see Section 13.H. We honor the Global Privacy Control (GPC) as an opt-out preference signal for the "sale" and "sharing" of personal information for cross-context behavioral advertising.
B. Virginia (VCDPA)
If you are a Virginia resident, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects.
C. Colorado (CPA)
If you are a Colorado resident, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of solely automated decisions producing legal or similarly significant effects. Colorado residents may also use a recognized universal opt-out mechanism (such as GPC) to opt out of the sale of personal data and targeted advertising.
D. Connecticut (CTDPA)
If you are a Connecticut resident, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of solely automated decisions producing legal or similarly significant effects. E. Texas (TDPSA)
If you are a Texas resident, you have the right to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of (i) targeted advertising, (ii) the sale of personal data, and (iii) profiling in furtherance of solely automated decisions producing legal or similarly significant effects.
F. Utah (UCPA)
If you are a Utah resident, you have the right to access and delete your personal data, to obtain a portable copy of your personal data, and to opt out of targeted advertising and the sale of personal data.
G. Nevada (NRS 603A)
If you are a Nevada resident, you have the right to opt out of the sale of certain "covered information." DealGauge does not sell covered information as defined under Nevada law; however, you may still submit a verified opt-out request using the contact information in Section 13.H.
H. Exercising Your Rights
To exercise any of the rights described above, you may contact us at Support@dealgauge.ai with the subject line "Privacy Rights Request" or use the privacy request mechanism made available in your account settings (where applicable).
When you submit a request, we will:
- Verify your identity before responding, using account information, email confirmation, or other reasonable verification appropriate to the nature of the request and the sensitivity of the information involved;
- Confirm receipt within ten (10) business days where required by applicable law;
- Respond substantively within forty-five (45) days, with a possible extension of an additional forty-five (45) days where reasonably necessary and permitted by applicable law.
We do not discriminate against you for exercising your privacy rights. We may decline a request, in whole or in part, where applicable law permits or requires us to do so (for example, where granting the request would interfere with our legal obligations, would compromise the privacy or rights of another person, or where we cannot verify your identity). If we deny a request, you may have the right to appeal that decision by replying to our response with a written explanation of why you believe the denial was incorrect. We will respond to appeals as required by applicable law.
I. Authorized Agents
You may designate an authorized agent to submit a privacy rights request on your behalf. We may require the authorized agent to provide proof of authority and may require you to verify your own identity directly with us before responding.
J. Engagement Data and Firm Customer Requests
If you are an individual whose information appears in Engagement Data uploaded by a Firm Customer, the Firm Customer is the controller of that information. You should generally exercise your privacy rights with respect to that information by contacting the Firm Customer that conducts the engagement. We will support the Firm Customer's lawful response to your request as a processor.
14. Sensitive Information
Some Engagement Data and other information we process may include "sensitive personal information" or analogous categories under applicable U.S. state privacy laws (for example, financial account information, tax identification information, and, in some cases, information that reveals racial or ethnic origin or other protected characteristics where present in uploaded documents).
We process sensitive information only for the purposes described in this Privacy Policy — including providing the Service, generating AI Outputs, complying with law, and protecting rights and security — and only to the extent necessary for those purposes. We do not use sensitive personal information to infer characteristics about an individual for advertising or marketing purposes.
California residents may exercise the right to limit the use and disclosure of their sensitive personal information as described in Section 13.A. 15. Children's Privacy The Service is not directed to children under the age of 18. We do not knowingly collect personal information from children under 18. If you become aware that a child under 18 has provided us with personal information, please contact us at Support@dealgauge.ai and we will take reasonable steps to delete that information.
16. Engagement Data Deletion and Correction Requests
If you provided information through a Business Owner Sub-User portal or other engagement-related interface and you wish to delete or correct that information, you should first contact the Firm Customer that invited you to the Service. The Firm Customer determines how Engagement Data is used and retained for the purposes of the engagement.
We will support the Firm Customer's lawful response to your request, including by enabling deletion or correction of the relevant data through our administrative tools, as required by applicable law and by our agreement with the Firm Customer. [Verification pending: deletion and correction capabilities that propagate through DealGauge's own storage systems and backups are in development. Once verification is complete, the specific deletion capabilities and timeframes will be reflected in this Privacy Policy. Retention by AI Subprocessors is addressed separately in Section 6 and Section 9 and is governed by each provider's data-processing terms.]
If you are unable to resolve your request with the Firm Customer, or if you have a complaint about the handling of your information, you may also contact us using the information in Section 21.
17. Marketing Communications
We may send marketing communications (newsletters, product announcements, event invitations, and similar messages) to Firm Customers, Analyst Users, and other persons who have opted in to receive them. You may opt out of marketing communications at any time by:
- Clicking the "unsubscribe" link in any marketing email;
- Replying STOP to a marketing SMS (where SMS marketing is used);
- Updating your communication preferences in your account settings; or
- Contacting us at Support@dealgauge.ai.
Opting out of marketing communications does not affect operational communications (such as account, billing, security, and Service notifications), which are necessary to provide the Service.
18. Third-Party Websites and Links
Our website and the Service may contain links to third-party websites, products, and services. This Privacy Policy does not apply to those third parties; their data practices are governed by their own policies. We are not responsible for the content or privacy practices of third parties.
19. Notice of Security Incidents
If we become aware of a security incident that materially affects the confidentiality, integrity, or availability of personal information we maintain about you, we will notify you and, where applicable, regulators in accordance with applicable law. Where we process Engagement Data as a processor on behalf of a Firm Customer, we will notify the Firm Customer in accordance with our agreement with the Firm Customer; the Firm Customer is then responsible for notifying affected individuals to the extent required by applicable law.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, technology, legal requirements, and other factors. When we make material changes, we will update the "Last Updated" date at the top of this Privacy Policy and, where reasonably practicable, notify you by email, by an in-Service notification, or by posting a notice on our website. Continued use of the Service after the effective date of changes constitutes acceptance of the updated Privacy Policy.
In particular, we expect to update this Privacy Policy in the near future to reflect verified commitments regarding (i) the use of Engagement Data with our AI service providers, (ii) personnel access controls applicable to Engagement Data, (iii) data deletion capabilities and timeframes, and (iv) data retention schedules. The placeholders marked [Verification pending] in this Privacy Policy will be replaced with specific commitments once verification is complete.
21. Contact Us
For questions about this Privacy Policy or about our information practices, or to exercise your privacy rights, please contact us at:
Edenbrook Technologies, Inc. d/b/a DealGauge
- Privacy and rights requests: Support@dealgauge.ai (subject line: "Privacy Rights Request")
- General inquiries: Support@dealgauge.ai
If you are a Business Owner Sub-User and your request relates to information you provided in connection with a Firm Customer's engagement, please contact the Firm Customer that invited you to the Service. We will support the Firm Customer's lawful response as a processor.