Privacy Policy

Analysis by Oscar Windermere
Updated May 10, 2026
Reading 3 min read

Effective Date: January 1, 2024

1. Introduction

The Due Diligence Federation (“DD-Federation”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. As an independent oversight organization specializing in financial investigations, open-source intelligence (OSINT), and anti-fraud analytics, confidentiality is the cornerstone of our operations.

This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you visit our website (dd-federation.org) or utilize our reporting and audit request services. To understand our core mission, ethical standards, and why we process certain financial data, please read more about our compliance experts and zero-tolerance policy.

2. Information We Collect

We only collect information that is strictly necessary for our investigative purposes and website functionality. This includes:

  • Information You Voluntarily Provide: When you use the “File a Report” or “Request Audit” features, you may provide your name, email address, and specific details regarding financial transactions, broker communications, or digital assets.
  • Automated Device Data: For security and anti-DDoS purposes, we automatically collect basic log data, including IP addresses, browser types, operating systems, and access timestamps.
  • Cookies and Tracking: We use minimal, privacy-focused cookies essential for website security and anonymous traffic analysis. We do not use third-party advertising trackers.

3. How We Use Your Information

Your data is processed under the legal basis of legitimate interest and user consent. We utilize the information to:

  • Conduct independent Due Diligence on financial entities, brokers, and cryptocurrency platforms.
  • Communicate with you regarding the status of a fraud report you have submitted.
  • Update our Verified Blacklist to protect the broader retail investor community.
  • Maintain the technical security, integrity, and performance of our digital infrastructure.

4. Data Sharing and Disclosure

We do not, under any circumstances, sell, rent, or trade your personal data to marketing agencies, brokers, or third-party corporations.

We may only share your information in the following strictly controlled scenarios:

  • Law Enforcement & Regulators: If legally compelled by a valid court order or official request from recognized financial authorities (e.g., FCA, SEC, FINMA) to assist in ongoing criminal investigations.
  • Anonymized Case Studies: We may publish investigation reports on our website based on user submissions. However, all personally identifiable information (PII) is strictly redacted and anonymized before publication.

5. Data Security Measures

We implement institutional-grade security protocols to protect your submitted data. This includes end-to-end encryption for report submissions, secure SSL/TLS server configurations, and restricted access control. Our investigative team processes sensitive financial data in isolated, offline environments.

6. Your Data Protection Rights (GDPR & CCPA)

Regardless of your geographic location, DD-Federation extends the highest standard of data rights to all users:

  • The Right to Access: You may request copies of your personal data.
  • The Right to Erasure (“Right to be Forgotten”): You may request that we permanently delete your personal information and any submitted case files from our active servers.
  • The Right to Rectification: You may request correction of any inaccurate information.

7. Third-Party Websites

Our website contains links to external regulatory bodies, financial registries, and potentially harmful entities (within our Blacklist reports). We are not responsible for the privacy practices of external domains. Always exercise caution and perform your own OSINT checks before interacting with third-party sites.

8. Contact Information

If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to contact our Data Protection Officer (DPO), please reach out to us securely via email or written correspondence:

Due Diligence Federation (DD-Fed)
Compliance & Legal Department
Hermiankatu 8, Hermia Technology Centre
33720 Tampere
Finland

Email: desk@dd-federation.org