DealStrand Privacy Notice
Effective August 29, 2026 · Version 1.1
Effective date: August 29, 2026
This Privacy Notice explains how Kerja Group LLC dba DealStrand ("DealStrand", "we", "us"), a Florida limited liability company, collects, uses, shares, and protects personal information in connection with the DealStrand website (dealstrand.com), the DealStrand hosted platform, and related support and marketing (together, the "Service").
DealStrand is a business-to-business software platform. This Notice covers three groups of people, and different sections apply to each:
- Visitors — anyone who browses dealstrand.com or contacts us.
- Customers — the businesses and individuals who subscribe to DealStrand, and their team members.
- Portal Users and Data Subjects — people whose information a Customer stores in its DealStrand workspace (clients, buyers, sellers, investors, lenders, contractors, referrers, attorneys, and other contacts), including people the Customer invites to a client portal.
1. Our two roles: controller and processor
1.1 When we are the controller. For Visitors, for Customer account and billing information, and for the operation and security of the Service, we decide how and why personal information is used. We are the "controller" (GDPR/UK GDPR) or "business" (US state privacy laws). Sections 2–9 apply.
1.2 When we are the processor. Everything a Customer uploads to or creates in its workspace — contacts, deal records, documents, files, portal-user accounts, signatures, messages — is Customer Data. The Customer decides what to collect and why. For Customer Data, the Customer is the controller and we are the Customer's processor (or "service provider"). We process Customer Data only on the Customer's instructions, as described in our Data Processing Addendum. Section 10 applies.
If you are a Portal User or a contact in a Customer's workspace and want to access, correct, or delete your information, contact the Customer that invited you or holds your records. We will assist that Customer as required by law, and will refer requests we receive directly to them.
2. Information we collect as controller
2.1 Information you provide
- Account and profile: name, business name, email address, phone, job title, timezone, password (hashed), avatar.
- Workspace setup: chosen subdomain, edition, brand name and logo, legal-identity details you enter for document generation (entity name, entity type, tax ID, registered address, signer name and title).
- Billing: plan, billing cycle, billing address, tax ID. Payment card details are collected and stored by Paddle, our Merchant of Record, not by us. We receive the last four digits, card brand, and transaction records.
- Communications: support requests, emails, feedback, survey answers, and demo or trial signup form entries.
2.2 Information collected automatically
- Usage data: pages and features used, actions taken, timestamps, referring URLs, error logs.
- Device and connection data: IP address, browser type, operating system, screen size, language, approximate location derived from IP.
- Cookies and similar technologies (see Section 7).
- Security data: login attempts, session identifiers, bot-protection signals (Cloudflare Turnstile), audit logs.
2.3 Information from third parties
- Paddle: order confirmations, payment status, tax determination, refund and chargeback events.
- Service providers: email delivery events (delivered, bounced, opened) from our transactional email provider; uptime and security alerts.
- Public and business sources where you provide a business domain or license number, to verify a business account.
We do not collect personal information from children, and the Service is not directed to anyone under 18.
3. How we use information (controller)
| Purpose | Examples | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Provide the Service | Create and run your workspace, authenticate you, deliver features, provide support | Contract |
| Billing | Process subscriptions through Paddle, send invoices and renewal reminders, prevent failed payments | Contract; legal obligation |
| Security and abuse prevention | Detect fraud, bots, unauthorized access; enforce the Terms | Legitimate interests; legal obligation |
| Improve the Service | Analyze feature usage, fix bugs, plan the roadmap, aggregated statistics | Legitimate interests |
| Communicate | Service notices, trial and renewal reminders, security alerts, responses to your requests | Contract; legitimate interests |
| Marketing | Product updates and offers to Customers and people who requested information; you can opt out at any time | Legitimate interests; consent where required |
| Legal | Comply with law, respond to lawful requests, establish or defend legal claims | Legal obligation; legitimate interests |
We do not sell personal information and we do not use Customer Data or your personal information to train artificial-intelligence models.
4. How we share information
We share personal information only as described here:
4.1 Service providers (sub-processors). Companies that process data on our behalf under contracts that restrict their use of it:
| Provider | Purpose | Location |
|---|---|---|
| Paddle.com Market Limited | Merchant of Record: checkout, payment, tax, invoicing, refunds | United Kingdom / EU / US |
| IONOS | Virtual private server hosting for Customer workspaces | United States (EU region where offered) |
| Ploi (a WebBuilds B.V. product) | Server provisioning, management, and deployment control plane | Europe (exact country not published); application content remains on DealStrand-hosted servers, while Ploi stores account and server-management data |
| Cloudflare, Inc. | CDN, DNS, TLS, DDoS protection, bot protection (Turnstile) | Global edge network; US |
| Resend | Transactional email delivery (notifications, signature requests, reminders) | United States |
| Anthropic, PBC | AI features (document triage, copilot, form fill, drafting) | United States |
| Backup storage provider | Encrypted off-site backups | United States |
| Support and analytics tools | Help desk, product analytics, error monitoring | United States |
A current list of sub-processors is available on request at privacy@dealstrand.com. We will notify Customers at least 15 days before engaging a new sub-processor that processes Customer Data, as described in the Data Processing Addendum.
4.2 AI providers. When you use an AI feature, the relevant text (for example the content of a document you ask the Service to triage, deal facts, or a prompt you type) is sent to Anthropic's API for processing and a response is returned. Under our agreement, Anthropic does not use this data to train its models and retains it only as needed to provide the service and for abuse monitoring. If a Customer connects its own AI provider key ("bring your own key"), the Customer's agreement with that provider governs, and we are not a party to that processing.
4.3 Integrations you choose. If you connect webhooks, automation platforms, a CRM, accounting software, or a custom domain, data flows to those services under your instructions and their privacy terms.
4.4 Legal and safety. We may disclose information to comply with law, court orders, or lawful government requests; to enforce our Terms; or to protect the rights, property, or safety of DealStrand, our Customers, or the public.
4.5 Business transfers. If Kerja Group LLC or the DealStrand business is involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to this Notice.
4.6 With your direction. For example when you share a document, invite a Portal User, or ask us to share information with a third party.
5. International transfers
We are based in the United States and our primary hosting is in the United States. If you are in the EU, EEA, UK, or Switzerland, your information is transferred to the US. For such transfers we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), supplemented by technical measures such as encryption, and, where a provider is certified, the EU-US Data Privacy Framework. Customers who require EU data residency should contact us about EU-region hosting availability before subscribing.
6. Retention
- Account and billing records: for the life of the account and for 7 years afterward as required for tax and accounting.
- Customer workspaces: for the life of the subscription. After a trial expires without conversion, 14 days; after a paid subscription ends, 30 days; then permanently deleted.
- Backups: encrypted backups are retained for no more than 90 days; data deleted from production is purged from backups within that period.
- Support communications: 3 years.
- Security and access logs: 12 months.
- Marketing data: until you opt out or after 24 months of inactivity.
We may retain information longer where required by law or to resolve disputes.
7. Cookies and tracking
We use:
- Strictly necessary cookies — login sessions, security tokens, Cloudflare bot protection, load balancing. These cannot be disabled.
- Functional cookies — remembering your theme, language, and workspace preferences.
- Analytics — privacy-respecting usage analytics to understand how the site and product are used.
- Paddle checkout cookies — set by Paddle when you open checkout, for fraud prevention and to complete your order.
We do not use third-party advertising cookies on the Service. Where the law requires consent for non-essential cookies (for example in the EU/UK), we ask for it through a cookie banner, and you can change your choice at any time via the cookie settings link in the footer. Your browser can also block or delete cookies; blocking necessary cookies will prevent login.
8. Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy.
- Correct inaccurate information.
- Delete your information, subject to legal retention requirements.
- Restrict or object to certain processing, including direct marketing (you can also use the unsubscribe link in any marketing email).
- Port your information to another provider in a structured, machine-readable format.
- Withdraw consent where processing is based on consent.
- Opt out of "sales" or "sharing" and of targeted advertising under US state laws — we do not do either.
- Not be discriminated against for exercising your rights.
- Lodge a complaint with your data-protection authority (for example your national authority in the EU, the ICO in the UK, or the Federal Trade Commission or your state attorney general in the US).
To exercise these rights, email privacy@dealstrand.com from the email address associated with your account, or write to the address in Section 12. We will verify your identity and respond within 30 days (45 days under some US state laws, extendable where permitted). You may authorize an agent to make a request on your behalf; we will require proof of that authorization.
Portal Users and contacts in a Customer's workspace: your request should go to that Customer, who controls your data. If you contact us, we will identify the Customer and forward your request, and assist the Customer as required.
Customers: you can access, correct, export, and delete most account and workspace data yourself in Settings, and can close your account in Settings → Billing.
9. Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including: isolated workspace and database per Customer; TLS encryption in transit; encryption of backups at rest; role-based access controls and least-privilege administrative access; hashed passwords; bot protection and rate limiting; audit logs for sensitive actions; private, non-web-accessible storage for identity and financial documents; and regular patching and backups. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal information we will notify you and any regulator as required by law, and will notify affected Customers without undue delay and no later than 72 hours after becoming aware, so they can meet their own obligations.
10. Customer Data: our role as processor
This Section applies to Customer Data, where we act as processor for the Customer.
- Instructions. We process Customer Data only to provide the Service, as instructed by the Customer through the product and the Data Processing Addendum, and as required by law.
- What may be included. Customers use the Service to store business and personal information about their clients and counterparties, which may include names, contact details, structured addresses, roles, communications, deal and property records, financial documents, loan and investor information, identity documents, tax forms, licenses, signatures, and audit trails. Customers are responsible for having a lawful basis to collect this information and for providing notices to the individuals concerned.
- Portal Users. When a Customer invites you to its client portal, you create login credentials with us on that Customer's workspace. We use your credentials and activity solely to operate the portal for that Customer and to secure the Service.
- AI processing. AI features process Customer Data as described in Section 4.2, only when the Customer or its users invoke them.
- Confidentiality. Our personnel are bound by confidentiality obligations and access Customer Data only for support, security, and maintenance, on a need-to-know basis, and where possible with the Customer's knowledge.
- Deletion and return. Customers can export Customer Data at any time and it is deleted on the schedule in Section 6.
- Sub-processors. Listed in Section 4.1.
11. Additional notices
11.1 California (CCPA/CPRA). In the preceding 12 months we collected the categories of personal information described in Section 2 (identifiers, commercial information, internet activity, professional information, and inferences drawn for product analytics) for the purposes in Section 3, and disclosed them to the service providers in Section 4.1. We do not sell or share personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. California residents may exercise the rights in Section 8, including the right to know, delete, correct, and limit use of sensitive personal information.
11.2 Other US states. Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights in Section 8 and may appeal a decision by replying to our response; we will explain the appeal outcome and how to contact your state attorney general.
11.3 EU/EEA/UK/Switzerland. Our legal bases are stated in Section 3. We have not appointed an EU or UK representative; contact privacy@dealstrand.com for GDPR matters. Transfers are covered in Section 5.
11.4 Do Not Track. We do not respond to browser Do Not Track signals but do honor Global Privacy Control signals as an opt-out of sale/sharing where applicable (we do neither).
12. Contact us
Kerja Group LLC dba DealStrand Attn: Privacy 386 South Atlantic, 59Ormond Beach, Florida 32176, United States Email: privacy@dealstrand.com
Billing and payment questions: Paddle.com Market Limited, Merchant of Record — paddle.net · Paddle's privacy policy: paddle.com/legal/privacy
13. Changes to this Notice
We will post any changes here and update the effective date. For material changes we will notify Customers by email or in-product notice at least 30 days in advance.