Skip to content

Legal notice and privacy policy

This English translation is provided for convenience only. The French version (« Mentions légales ») is the sole authoritative and legally binding version.

1. Legal notice

Site publisher

The diligeo.com website is published by:
Hugues Schaap, sole trader (French entrepreneur individuel) operating under the trading name Diligeo
Address: 62 rue du Faubourg Poissonnière, 75010 Paris
SIRET: 106 190 465 00018 (SIREN: 106 190 465)
APE code: 70.22Z (business and other management consultancy activities)
VAT not applicable, Article 293 B of the French General Tax Code
Director of publication: Hugues Schaap
Email: contact@diligeo.com
Website: https://diligeo.com

Hosting provider

Vercel Inc.
340 S Lemon Ave #4133, Walnut, CA 91789, USA
Website: https://vercel.com

2. Privacy policy

This policy describes how Diligeo collects, uses and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).

2.1 Data controller

Diligeo · contact@diligeo.com

No data protection officer (DPO) has been appointed at this stage: such an appointment is not mandatory for an organization of this size. The point of contact for any question relating to your data is contact@diligeo.com.

2.2 Data collected

The /onboarding form collects the following categories of data, depending on the branch selected (buyer case or sourcing case):

  • Identity and contact details: name, email address, telephone number.
  • Professional experience: primary role, background sectors, years of experience, largest team managed.
  • Acquisition profile: mode (solo, team, fund), rank (first acquisition, second, serial), training completed.
  • Personal financial capacity: personal equity contribution, target bank leverage, any cash reserve.
  • Target criteria: sectors sought, target revenue, target headcount, geographic area, accepted procedures (solvent sale, court-supervised restructuring (redressement judiciaire, RJ), court-ordered liquidation (LJ)).
  • Position on the case (buyer branch): stage of progress, any offer deadline, cases pursued in parallel, indication of whether a chartered accountant or a lawyer has been engaged.
  • Search constraints (sourcing branch): area mode, sale horizon, reason for acquisition, free-form notes.
  • Document: CV (optional PDF, 4 MB maximum).
  • Free text: comment or free-form notes (optional).
  • Technical metadata: consent timestamp, internal case reference generated by Diligeo, partial IP address (for anti-spam rate limiting).

The fields marked as mandatory in the form are necessary to process your request: without them, Diligeo can neither contact you nor scope the engagement. The other fields are optional and their absence does not prevent your request from being taken into account.

The home page and the other public pages collect no personal data (no tracker, no analytics cookie). Diligeo only keeps aggregate, anonymous visit counters, described in section 3.

2.3 Purposes of processing

Your data is collected in order to:

  • Respond to your request and contact you within 48 business hours;
  • Define the scope of the engagement (data-room analysis or sourcing pack);
  • Prepare a quote or commercial proposal suited to your profile;
  • Produce the requested deliverable (analysis report or target pack).

Legal basis: performance of pre-contractual measures taken at your request (Article 6(1)(b) GDPR), supplemented by your explicit consent (Article 6(1)(a) GDPR) ticked when the form is submitted. For the public data of legal entities and their directors used in the Sourcing deliverable, the legal basis is legitimate interest (Article 6(1)(f) GDPR).

2.4 Processors and recipients

The processing of your data involves the following technical processors, each strictly limited to its function:

  • Vercel Inc. (United States): website hosting and execution of server functions. Traffic encrypted over HTTPS. See postal address in section 1.
  • Resend (Boundary Mountain, Inc.) (United States): email delivery (confirmation emails, team alerts). Resend does not durably store the content of emails beyond its technical logs.
  • Upstash Inc. (United States, regional infrastructure in Europe): temporary storage (48 hours maximum) of the double opt-in token and anti-spam rate-limiting counters. No personal data within the meaning of the GDPR is stored there for more than 48 hours.
  • Svix Inc. (United States): cryptographic verification of Resend webhooks (HMAC signature). Does not receive or store your data.
  • Infomaniak Network SA / SwissTransfer (Switzerland): secure transfer of data-room documents. See section 2.4.2.
  • Anthropic, PBC (United States): automated processing by the Claude artificial-intelligence models of the documents and data entrusted, solely for the purpose of producing the requested extraction and analysis. The data submitted is not used to train the models.

Transfers outside the European Union: the US processors cited are bound by the European Commission's Standard Contractual Clauses (SCCs) or an equivalent mechanism under Article 46 GDPR (EU-US Data Privacy Framework certification where applicable), which govern the international transfer of personal data. Switzerland is recognized by the European Commission as offering an adequate level of protection (Decision 2000/518/EC).

Under no circumstances is your data sold, rented or transferred to third parties for commercial purposes.

2.4.1 Buyer case form

The data listed in section 2.2 and collected via the /onboarding form in the Buyer branch is processed in the context of pre-contractual measures taken at your request (Article 6(1)(b) GDPR), so that the Diligeo team can contact you regarding your acquisition project and produce the requested analysis. For the Target search and Preliminary review (pre-LOI) branches, the data processed includes: identity, contact details, professional profile, financing capacity, scoping elements of the contemplated transaction (valuation provided, shareholder current accounts, timetable) and the description of the available documents. When you identify a target, the data relating to its directors (identity, role) provided by you or obtained from public registers is processed on the basis of legitimate interest (Article 6(1)(f) GDPR), strictly to the extent necessary for the pre-audit; those persons have a right to object by writing to contact@diligeo.com.

This data is intended for the Diligeo team only and is not shared with any third party (apart from the technical processors cited in section 2.4, strictly within the limits of their function). It is retained for 24 months after the last contact, then deleted.

You have the rights of access, rectification, erasure and objection with respect to this data. To exercise them, write to contact@diligeo.com.

2.4.2 Transfer of the data room

To preserve the confidentiality of your data-room documents, they never pass through direct email or our web form. We use the SwissTransfer service (Infomaniak Network SA, Switzerland), which is GDPR-compliant and provides:

  • end-to-end AES-256 encryption of the transfer;
  • mandatory password protection, transmitted through a separate channel (telephone);
  • a limited lifetime for the link (30 days maximum);
  • automatic deletion from the servers after download or expiry.

The downloaded documents are stored on the professional workstations of the Diligeo team, with restricted access (strong authentication, disk encryption), and deleted at the latest 12 months after delivery of the analysis report, or immediately upon your written request to contact@diligeo.com.

Apart from the technical processors listed in section 2.4 (each strictly within the limits of its function), no data-room document is disclosed to a third party or used for any purpose other than the requested analysis.

2.4.3 Sourcing case form

The data listed in section 2.2 and collected via the /onboarding form in the Sourcing branch is processed in the context of pre-contractual measures taken at your request (Article 6(1)(b) GDPR), in order to qualify sale opportunities within your scope and to provide you with a corresponding deliverable.

This data is intended for the Diligeo team only and is not shared with any third party (apart from the technical processors cited in section 2.4, strictly within the limits of their function). It is retained for 24 months after the last contact, then deleted.

The public data of legal entities and their directors used to produce the Sourcing deliverable is collected from the French public registers (INSEE SIRENE, INPI RNE, DILA BODACC) and processed on the basis of legitimate interest (Article 6(1)(f) GDPR). An objection procedure is available by email at contact@diligeo.com.

You have the rights of access, rectification, erasure and objection with respect to your personal data. To exercise them, write to contact@diligeo.com.

2.5 Retention period

Your data submitted via the /onboarding form is retained for 24 months after your last contact with the Diligeo team, then deleted. The data-room documents transferred via SwissTransfer follow a distinct cycle specified in section 2.4.2 (deletion at the latest 12 months after delivery of the report, or immediately upon written request).

The technical double opt-in token stored at Upstash has a lifetime of 48 hours maximum and is automatically purged after use (single-use).

2.6 Your rights

In accordance with the GDPR, you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: request the deletion of your data
  • Right to restriction: restrict the processing of your data
  • Right to portability: receive your data in a structured format
  • Right to object: object to the processing of your data
  • Right to withdraw your consent: at any time, without affecting the lawfulness of processing based on consent carried out before that withdrawal

To exercise these rights, contact us at: contact@diligeo.com

In the event of a dispute, you may lodge a complaint with the CNIL (the French data-protection authority): www.cnil.fr

2.7 Security

Diligeo implements the following technical and organizational measures to protect your data:

  • Encryption in transit: all communications with the site and the processors use HTTPS (TLS 1.2 or higher). The HSTS preload header is enabled.
  • Email double opt-in: your form submission triggers a confirmation email. Until you have clicked on that link, your address is not considered verified. This prevents impersonation by third parties and constitutes proof of consent.
  • Rate limiting: limits per IP address and per email prevent massive automated submissions and spam.
  • Anti-bot honeypot: a hidden form field detects and silently rejects bot submissions.
  • File validation: uploaded CVs are validated (strict PDF format, size limited to 4 MB, rejection of PDFs containing automatic actions such as embedded JavaScript or external Launch).
  • Restricted internal access: the workstations of the Diligeo team are protected by strong authentication and disk encryption.
  • Strict Content Security Policy (CSP): the site only executes scripts served from its own domain; no third-party script, no tracker.

3. Cookies and local storage

The diligeo.com website uses no cookies for tracking, analytics, audience measurement or advertising. No third-party cookie (Google Analytics, Meta Pixel, etc.) is set.

Anonymous visit counting: the site keeps aggregate counters (number of clicks on the journeys offered on the home page, number of views of the journey pages, number of clicks on action buttons), incremented by a request to the diligeo.com domain itself. This counting uses no cookie, no local storage, no identifier, and records neither your IP address nor your browser's characteristics: only monthly totals per page and per language are kept, for at most 25 months, with no personal data. Your truncated IP address serves solely as an anti-abuse safeguard at the time of the request and is not kept beyond that technical window (one hour at most), like the rest of the rate limiting described in section 2.7.

Browser-side local storage (localStorage): the /onboarding form saves a draft of your answers in your browser's local memory, under the key diligeo:onboarding:draft, so that you can resume your entry if you close the tab by mistake. This data:

  • is never transmitted to the Diligeo servers until you have explicitly submitted the form;
  • remains accessible only to your browser, on your device;
  • is automatically purged after 7 days;
  • can be erased at any time via your browser settings (the key diligeo:onboarding:draft in the domain's local storage).

Fonts: the site's fonts are self-hosted on the diligeo.com servers. No request is made to Google Fonts or to any other third-party service when pages load: your IP address is not transmitted to any third party through the mere consultation of the site.

4. Intellectual property

All the content of the diligeo.com website (text, graphics, logo, structure) is the property of Diligeo and is protected by intellectual-property law. Any reproduction, even partial, is prohibited without prior authorization.

5. Update

This page was last updated on July 3, 2026.