Privacy Notice
The short version: I collect the minimum the service needs, share it only with the processors that make the service run, track you with nothing, and delete on schedule. The full version is below — written twice, like the Terms.
I'm the person responsible for your data.
1. Controller
Grig Kochedykov, trading as Provenance Diligence, sole trader (empresário em nome individual), Torres Vedras, Portugal (identification in the Legal notice). Contact: the form on the home page.
What you type in the form, the listing you send, and payment confirmation — that's it.
2. What I collect
- From the form: your name, email, the listing link/details, and anything you choose to write.
- From the free numbers tool: the figures you enter run in your browser and reach me only if you press "send" — asking price, rent, stated revenue and owner's earnings, employee count, city, sector, and your email.
- From the free listing self-check tool: the same rule — everything runs in your browser, and your answers (country, how the listing describes the company, address precision, contact channel, city, and which patterns you ticked) reach me only if you press "send", together with your email. Please do not include a seller's personal details.
- From the case portal (case.provenancediligence.com): your name, email, the listing link or description, your notes, and the files you choose to upload — see 3.
- During an engagement: documents you send about the target business (which may contain third-party data — see 6).
- From payment: confirmation of payment from Stripe. I never see or store your card number.
- From this website itself: no advertising trackers, no fingerprinting, no cookies set on your browser. The site keeps a privacy-respecting, first-party visit count to see which pages are read and whether answer-engines cite the site. It is cookieless: your IP address is turned into a one-way hash with a salt that changes every day (so a visitor cannot be re-identified or followed across days), and only the page path, referring site, any
utm_sourcecampaign tag and that daily hash are stored — never a raw IP, never a name. This first-party analytics record is not shared with any third party, and there is no advertising or profiling. The hosting provider also keeps standard short-lived security logs, as every host does.
Paid work starts on a case page reached through a private access link. Uploaded files are stored in Cloudflare R2 with EU jurisdiction configured and are deleted no later than 90 days after delivery.
3. The case portal (case.provenancediligence.com)
Paid engagements begin on the case portal. When you submit a deal there, I collect your name, email, the listing link or description, any notes you write, and the files you choose to upload. You receive a deal ID and a private case page reached through an access link. There are no accounts and no passwords. Anyone who holds the link can open that page, so treat it like a confidential document: do not post it, and forward it only to people helping you with the deal.
Case records and uploaded files are stored with Cloudflare. Uploaded files are stored in a Cloudflare R2 bucket configured for EU jurisdiction. Case records — your name, email, listing line, notes, deal ID and access-link metadata — are stored separately in Cloudflare KV and are not covered by that R2 EU-jurisdiction setting.
The notification that tells me a new case has arrived is delivered through Formspree, a processor in the United States. It includes your name, email, listing line and the case access link, but not file attachments. Payment, when it opens on your case page after the fit check, happens inside Stripe. If you arrive at the portal from a free first-read report, an opaque reference code may accompany your submission so I can connect the two records. The code does not contain your name, email or report contents.
Before uploading, redact third-party personal data your files do not need to carry. For staff, roles, start dates and salary bands are enough; do not include names, personal IDs or home addresses unless they are needed for the review.
I use your data to answer you and to produce your memo. Nothing else.
4. Why, and the lawful basis
To assess whether your deal is a fit and reply (pre-contractual steps at your request, Art. 6(1)(b) GDPR); to deliver the memo you purchased (performance of a contract, Art. 6(1)(b)); to keep invoices and tax records (legal obligation, Art. 6(1)(c)); and to keep delivered memos for the defence of legal claims (legitimate interest, Art. 6(1)(f)). No marketing use, no profiling, no automated decisions about you.
Only the services that run the shop touch your data — form, payment, hosting. Nobody gets it for marketing. Ever.
5. Processors and recipients
Form handling and case notifications (Formspree, a processor in the United States), transactional service email (Brevo), payment (Stripe), and website hosting and case-file storage (Cloudflare; case files under EU jurisdiction) — each under its own data-processing terms. Formspree, Brevo and Stripe may process data outside the EEA under their data-processing terms, including standard contractual clauses where required. Page typography is currently fetched from Google Fonts and Fontshare; when your browser requests those font resources, those providers receive ordinary request metadata such as your IP address and browser user-agent. I do not sell or share personal data for marketing, and there are no third-party advertising or analytics services on this site.
Research about the business you're buying concerns other people too — I use only public sources for that, and the same care.
6. Third-party data in the research (Art. 14 GDPR notice)
A risk screen necessarily processes information about the target business and the people publicly connected to it (owners, directors) — drawn from official public registers and public sources only (commercial registries, insolvency registers, published court decisions, licence censuses), on the lawful basis of legitimate interest (Art. 6(1)(f)), assessed and documented. Because informing each person individually would be disproportionate for a confidential one-off report and could prejudice its purpose, this section serves as the public information notice under Art. 14(5)(b) GDPR: categories = identification and role data as published in the registers named above; recipients = the instructing client only; retention = as in section 7; rights = as in section 8, exercisable by anyone via the form. Criminal-conviction data is not collected; references to insolvency or court records are limited to what the official public register itself publishes, cited to its source. The information stays inside the client's memo, is never published, and public samples are anonymised so no business or person is identifiable.
Enquiries: gone in months. Delivered work: kept as long as the law and honest self-defence require, then gone.
7. Retention
Enquiries that don't become engagements: deleted within 6 months — the same rule covers portal cases that never become engagements. Files uploaded to the case portal: deleted no later than 90 days after delivery. Delivered memos and their working files: kept for the legal limitation period applicable to professional-service claims, then deleted. Invoices: kept for the period Portuguese tax law requires. Nothing is kept "just in case" beyond those schedules.
You can see, fix or delete your data — and complain to the regulator if I get it wrong.
8. Your rights
Access, rectification, erasure, restriction, portability and objection — exercised via the form, answered within one month. You can also complain to the Portuguese supervisory authority, the CNPD (Comissão Nacional de Proteção de Dados, cnpd.pt), or to your own country's authority.
What this site deliberately doesn't do
- No advertising trackers, no analytics cookies, no cookie banner — because there's nothing to consent to
- No marketing emails — I don't build a list; you hear from me only about your own deal
- No data sales, no "partners", no lookalike audiences
- No storing of card numbers — payment stays inside Stripe