Privacy Policy
Last updated: April 30, 2026
DFV LLC (“DFV”, “we”) operates dfv.llc. This policy describes the personal information we collect through this site and how we use it. We do not sell personal information. We comply with the California Consumer Privacy Act (“CCPA”) and California Privacy Rights Act (“CPRA”) as updated for 2026, and where applicable the EU General Data Protection Regulation (“GDPR”).
1. Information we collect
- Contact form & credentials request: name, email address, organization, stated purpose, and the body of your message. Optional: LinkedIn URL.
- Career applications: name, email, role sought, optional LinkedIn URL, and the text of your pitch.
- Server logs: IP address, user agent, referrer, timestamps for the duration needed to operate the service. We do not maintain advertising trackers.
- Cookies: session cookies are used only on the operations cockpit at x.dfv.llc, which is auth-gated. Public pages do not set tracking cookies.
2. How we use it
- To respond to inquiries, applications, and credential requests.
- To verify counterparty status before sending sensitive documents.
- For internal record-keeping, audit, and security.
- We do not sell, rent, or trade your personal information.
3. Retention
Form submissions and inquiries are retained for up to 36 months unless we have a continuing business reason to retain longer (e.g. ongoing engagement, audit obligation). Career applications are retained for 12 months unless you ask us to delete them sooner. Server logs are retained for 90 days.
4. Your rights (CCPA/CPRA, GDPR)
You have the right to request access to your personal information, correction, deletion, and (where applicable) portability. California residents may request a list of the categories of personal information we collect, the purposes for collection, and confirm we do not sell personal information. EEA/UK residents have the additional right to object to processing and to lodge a complaint with a supervisory authority.
To exercise any of these rights, email info@dfv.llc with the subject line “Privacy request”. We will respond within 45 days (CCPA/CPRA standard) or 30 days (GDPR standard), whichever is sooner.
5. Security
We use TLS in transit, encrypted storage at rest via our database providers, role-based access, and audit logs for sensitive operations. No system is perfectly secure; please do not transmit credentials, financial statements, or other sensitive documents through the public credentials request form — instead, request a secure encrypted exchange and we will reply with instructions.
6. Sharing
We do not share personal information with third parties except: (a) infrastructure providers strictly necessary to operate the site (Supabase, Vercel, Cloudflare, their respective subprocessors); (b) where legally required by valid subpoena or court order; (c) in the event of a business transfer, to the acquiring entity under equivalent or stricter terms.
7. Changes
We may update this policy. The “Last updated” date at the top reflects the most recent revision. Material changes will be summarized at the top of this page for at least 30 days.
8. Contact
DFV LLC · Missouri · info@dfv.llc