What we hold, and for how long

The same rule as in the terms: every clause is written twice, in plain words and in full.

1. Controller

In plain words. The founder is the person responsible for your data.

Grig Kochedykov, trading as Provenance Diligence, sole trader (empresário em nome individual), Torres Vedras, Portugal (identification in the Legal notice). Contact: the form on the home page.

2. What we collect

In plain words. What you type in the form, the listing you send, and payment confirmation — that's it.

  • From the form: your name, email, the listing link/details, and anything you choose to write.
  • From the free numbers tool: the figures you enter run in your browser and reach us only if you press "send" — asking price, rent, stated revenue and owner's earnings, employee count, city, sector, and your email.
  • From the free listing self-check tool: the same rule — everything runs in your browser, and your answers (country, how the listing describes the company, address precision, contact channel, city, and which patterns you ticked) reach us only if you press "send", together with your email. Please do not include a seller's personal details.
  • From the case portal (case.provenancediligence.com): your name, email, the listing link or description, your notes, and the files you choose to upload — see 3.
  • During an engagement: documents you send about the target business (which may contain third-party data — see 6).
  • From payment: confirmation of payment from Stripe. We never see or store your card number.

From this website itself: no advertising trackers, no fingerprinting, no cookies set on your browser. The site keeps a privacy-respecting, first-party visit count to see which pages are read and whether answer-engines cite the site. It is cookieless: your IP address is turned into a one-way hash with a salt that changes every day (so a visitor cannot be re-identified or followed across days), and only the page path, referring site, any utm_source campaign tag and that daily hash are stored — never a raw IP, never a name. This first-party analytics record is not shared with any third party, and there is no advertising or profiling. The hosting provider also keeps standard short-lived security logs, as every host does.

3. The case portal (case.provenancediligence.com)

In plain words. Paid work starts on a case page reached through a private access link. Uploaded files are stored in Cloudflare R2 with EU jurisdiction configured and are deleted no later than 90 days after delivery.

Paid engagements begin on the case portal. When you submit a deal there, we collect your name, email, the listing link or description, any notes you write, and the files you choose to upload. You receive a deal ID and a private case page reached through an access link. There are no accounts and no passwords. Anyone who holds the link can open that page, so treat it like a confidential document: do not post it, and forward it only to people helping you with the deal.

Case records and uploaded files are stored with Cloudflare. Uploaded files are stored in a Cloudflare R2 bucket configured for EU jurisdiction. Case records — your name, email, listing line, notes, deal ID and access-link metadata — are stored separately in Cloudflare KV and are not covered by that R2 EU-jurisdiction setting.

The notification that tells us a new case has arrived is delivered through Formspree, a processor in the United States. It includes your name, email, listing line and the case access link, but not file attachments. Payment, when it opens on your case page after the fit check, happens inside Stripe. If you arrive at the portal from a free first-read report, an opaque reference code may accompany your submission so we can connect the two records. The code does not contain your name, email or report contents.

Before uploading, redact third-party personal data your files do not need to carry. For staff, roles, start dates and salary bands are enough; do not include names, personal IDs or home addresses unless they are needed for the review.

3a. The browser extension

In plain words. Until you link your account, the extension sends us nothing. After you link it, it sends only what you chose to save.

The extension reads the listing page inside your browser. On the eighteen Spanish marketplaces named in its manifest it starts by itself; on any other site it runs only when you press its icon. That press grants it access to that one tab and only for that visit — the extension holds no standing permission to read websites.

Until an account is linked, everything stays on your device: saved listings live in your browser's own storage, and we neither see nor copy them. Remove the extension and that goes with it.

If you press “Keep this list on my other devices”, your browser asks you to grant access to our address, and from then on the extension sends us:

  • the listing cards you chose to save: the link, the title, the price with its currency, the country, the town and the kind of business;
  • when you open a listing you already saved, no more than once a day, what we saw on it: the link, the price and the date the marketplace last pushed it back to the top;
  • once a week, the listings you asked it to watch — up to ten of them.

We do not see the pages you merely opened: only the ones you saved and linked. You can unlink every extension with one button in your account without deleting the list, and deleting the account erases everything.

3b. My list and watching listings

In plain words. You ask for a property to be watched, with a button. We keep the listing address, the price and the check dates — for no longer than a year.

My list is a separate free service with its own sign-in. You sign in with your email address and a password. The password is stored only as an irreversible hash. The address is kept for signing in and for the confirmation and password-reset emails. The property card holds what the extension read from the listing: the link, the country, the town, the kind of business and the price.

Watching is not a default behaviour but your explicit request: every property has a button, and without it the property simply sits in the list. For a property under watch we look at the listing once a week and record an observation: the address, the date of the check and the price. Through the listing address such records also touch the seller — which is why they carry a hard limit: observations older than a year are erased, and observations of deleted properties are erased at once. We send no emails about changes — you see them when you come into the list.

Deleting the account erases everything: the list, the observations and the links to extensions. You can unlink every extension without deleting anything, with one button.

This promise is not the same as the extension promise in clause 3a, and we deliberately keep them apart. The extension does not report the pages you merely open; it speaks to us only about the listings you saved after linking the account yourself. Watching concerns only the properties you saved to the list yourself and put under watch yourself.

4. Why, and the lawful basis

In plain words. We use your data to answer you and to produce your memo. Nothing else.

To assess whether your deal is a fit and reply (pre-contractual steps at your request, Art. 6(1)(b) GDPR); to deliver the memo you purchased (performance of a contract, Art. 6(1)(b)); to keep invoices and tax records (legal obligation, Art. 6(1)(c)); and to keep delivered memos for the defence of legal claims (legitimate interest, Art. 6(1)(f)). No marketing use, no profiling, no automated decisions about you.

5. Processors and recipients

In plain words. Only the services that run the shop touch your data — form, payment, hosting. Nobody gets it for marketing. Ever.

Form handling and case notifications (Formspree, a processor in the United States), transactional service email (Brevo), payment (Stripe), and website hosting and case-file storage (Cloudflare; case files under EU jurisdiction) — each under its own data-processing terms. Formspree, Brevo and Stripe may process data outside the EEA under their data-processing terms, including standard contractual clauses where required. Page typography is currently fetched from Google Fonts and Fontshare; when your browser requests those font resources, those providers receive ordinary request metadata such as your IP address and browser user-agent. We do not sell or share personal data for marketing, and there are no third-party advertising or analytics services on this site.

6. Third-party data in the research (Art. 14 GDPR notice)

In plain words. Research about the business you're buying concerns other people too — we use only public sources for that, and the same care.

A risk screen necessarily processes information about the target business and the people publicly connected to it (owners, directors) — drawn from official public registers and public sources only (commercial registries, insolvency registers, published court decisions, licence censuses), on the lawful basis of legitimate interest (Art. 6(1)(f)), assessed and documented. Because informing each person individually would be disproportionate for a confidential one-off report and could prejudice its purpose, this section serves as the public information notice under Art. 14(5)(b) GDPR: categories = identification and role data as published in the registers named above; recipients = the instructing client only; retention = as in section 7; rights = as in section 8, exercisable by anyone via the form. Criminal-conviction data is not collected; references to insolvency or court records are limited to what the official public register itself publishes, cited to its source. The information stays inside the client's memo, is never published, and public samples are anonymised so no business or person is identifiable.

7. Retention

In plain words. Enquiries: gone in months. Delivered work: kept as long as the law and honest self-defence require, then gone.

Enquiries that don't become engagements: deleted within 6 months — the same rule covers portal cases that never become engagements. Files uploaded to the case portal: deleted no later than 90 days after delivery. Delivered memos and their working files: kept for the legal limitation period applicable to professional-service claims, then deleted. Invoices: kept for the period Portuguese tax law requires. Nothing is kept "just in case" beyond those schedules.

8. Your rights

In plain words. You can see, fix or delete your data — and complain to the regulator if we get it wrong.

Access, rectification, erasure, restriction, portability and objection — exercised via the form, answered within one month. You can also complain to the Portuguese supervisory authority, the CNPD (Comissão Nacional de Proteção de Dados, cnpd.pt), or to your own country's authority.

What this site deliberately doesn't do

  • No advertising trackers, no analytics cookies, no cookie banner — because there's nothing to consent to
  • No marketing emails — we don't build a list; you hear from us only about your own deal
  • No data sales, no "partners", no lookalike audiences
  • No storing of card numbers — payment stays inside Stripe