Privacy Policy

Last Updated: December 20, 2024

This Privacy Policy explains how DueReady Collective ("DueReady," "we," "us," or "our") collects, uses, stores, protects, and shares your personal data when you use our website at dueready.com (the "Website"), our Readiness Assessment Tool, and our deal readiness services (collectively, the "Services").

We are committed to protecting your privacy and handling your personal data in a transparent and lawful manner, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are

DueReady Collective is a deal readiness firm that provides specialized consulting and implementation services to startups, helping them prepare their financials, legal documentation, tech stack, and compliance for funding rounds, acquisitions, and enterprise deals.

Our registered address is 3rd Floor, 86-90, Paul Street, London, England, United Kingdom, EC2A 4NE.

We are registered with the Information Commissioner's Office (ICO) under registration number ZB924306.

2. What Personal Data We Collect

We may collect and process various types of personal data, depending on how you interact with our Services:

Identity & Contact Data:

Name, email address, phone number, company name, job title, startup stage, and message content.

Source: Directly from you via contact forms, inquiries, or assessment tool submissions.

Website Usage Data:

Information about how you use our Website, including your IP address, browser type and version, time zone setting, operating system and platform, and other technology on the devices you use to access this Website.

Source: Automatically collected via cookies and analytics tools (e.g., Google Analytics).

Readiness Assessment Data:

All information and answers you provide when using our online Readiness Assessment Tool, which may include sensitive details about your startup's financial practices, legal setup, tech infrastructure, compliance status, business strategy, and personal/company information. This is stored locally in your browser and may be processed to generate customized results.

Source: Directly from you via the assessment tool with explicit consent.

Client Project Data (Highly Sensitive):

If you become a client, we will collect and process highly sensitive personal and business data necessary to provide our deal readiness services. This may include:

  • Detailed financial records (P&L, balance sheets, cap tables, payroll data).
  • Legal documents (contracts, intellectual property assignments, corporate governance records, employee agreements).
  • Technical documentation (system architectures, security policies).
  • Compliance records (GDPR, ISO readiness, HR policies, data breach plans).
  • Personal data of founders, employees, and potentially customers of your startup contained within these documents.

Source: Directly from you, often via a secure Virtual Data Room (VDR).

Collective Member Data:

For individuals who join our "Collective" as independent contractors/consultants, we collect professional profiles, contact details, payment information, vetting documentation (e.g., certifications, references), and project performance data.

Source: Directly from the individual.

Marketing & Communication Data:

Your preferences in receiving marketing from us and your communication preferences.

Source: Directly from you.

3. How We Collect Your Personal Data

We use different methods to collect data from and about you, including:

Direct Interactions:

You provide data directly when you:

  • Fill out forms on our Website (e.g., contact form, Readiness Assessment).
  • Communicate with us via email, phone, or live chat.
  • Sign up for our services as a client.
  • Apply to join our Collective as an expert.

Automated Technologies or Interactions:

As you interact with our Website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. We collect this personal data by using cookies and other similar technologies.

Third Parties or Publicly Available Sources:

We may receive personal data about you from various third parties and public sources, such as analytics providers (e.g., Google Analytics), information providers (e.g., Crunchbase, PitchBook, LinkedIn).

4. How We Use Your Personal Data and Our Legal Bases

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:

Purpose of ProcessingType of Data CollectedLegal Basis for Processing
To provide and manage our ServicesIdentity & Contact Data, Client Project Data, Collective Member DataPerformance of a contract with you (or to take steps at your request before entering into a contract).
To respond to your inquiries and requestsIdentity & Contact Data, Readiness Assessment DataOur legitimate interests (to respond to queries, build relationships, and grow our business).
To process your Readiness Assessment submissionIdentity & Contact Data, Readiness Assessment DataYour consent (when you submit the assessment) and our legitimate interests (to provide you with tailored insights and potentially offer our services).
To process contact form submissionsIdentity & Contact Data (name, email, company, startup stage, message content)Your consent (provided when submitting the form) and our legitimate interests (to respond to inquiries and provide requested information).
To send you marketing communicationsIdentity & Contact Data, Marketing & Communication DataYour consent (where required) or our legitimate interests (for existing clients, to inform them about relevant services). You can opt-out at any time.

5. Data Security

We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered, or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors, and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

6. Data Retention

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

7. Disclosure of Your Personal Data

We may share your personal data with the following parties for the purposes outlined in Section 4:

Members of our Collective:

Specific expert consultants and contractors within the DueReady Collective who are assigned to your project, on a strict need-to-know basis, and subject to robust confidentiality and data processing agreements.

Third-Party Service Providers:

External providers who perform services on our behalf, such as:

  • Virtual Data Room (VDR) providers (Digify)
  • Project management software providers (Notion)
  • Website analytics providers (Google Analytics)
  • Email marketing service providers
  • Payment processors
  • IT and system administration services

Professional Advisors:

Including lawyers, accountants, and insurers who provide consulting, banking, legal, insurance, and accounting services.

9. Your Legal Rights

Under certain circumstances, you have rights under data protection laws in relation to your personal data. These include the right to:

  • Request access to your personal data.
  • Request correction of your personal data.
  • Request erasure of your personal data.
  • Object to processing of your personal data.
  • Request restriction of processing of your personal data.
  • Request transfer of your personal data.
  • Withdraw consent at any time where we are relying on consent to process your personal data.

You have the right to make a complaint at any time to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please contact us in the first instance.

11. Contact Us

If you have any questions about this Privacy Policy or our data protection practices, please contact us at:

Email: hello@dueready.com

Postal Address: 3rd Floor, 86-90, Paul Street, London, England, United Kingdom, EC2A 4NE