M&AI
M&AI Privacy Policy
Status, scope, and responsibility
This privacy policy is effective as of the date shown above. It was published under the authority of the M&AI service operator so that CurtisWiltse can review it in the live service. CurtisWiltse or legal review may amend it after publication.
The Dean's List LLC, a Utah limited liability company doing business as CurtisWiltse Merger and Acquisition Experts (CurtisWiltse), determines why M&AI handles Client Data and personal information. Allied Code operates M&AI on CurtisWiltse's documented instructions and does not independently determine those purposes or acquire ownership of Client Data.
This policy governs M&AI's handling of personal information and confidential deal content. It does not replace confidentiality obligations, deal agreements, law, or a valid legal hold.
Information, content, and uses
M&AI handles only the information and content needed to operate a private deal workspace:
- Administrator and invited buyer identity, contact, authentication, and session information.
- Access decisions, security events, and activity metadata.
- Authorized deal documents, document metadata, extracted content, chunks, embeddings, and indexes.
- Buyer questions, answers, summaries, citation identifiers, citation excerpts, and conversation records.
- Limited operational metadata used to secure, support, audit, and maintain the service.
- M&AI uses these categories to authenticate and authorize users, operate approved deal corpora, deliver grounded answers, prevent misuse, investigate security or operational issues, and meet applicable legal or contractual duties.
Service providers and data-use limits
When activated for the service, Cloudflare provides application hosting and Workers logging; Supabase provides Auth, Postgres, access controls, and private storage; Trigger.dev and AWS may provide durable processing; OpenAI API may provide embeddings and grounded-answer processing; and Fastmail may provide transactional authentication email. Provider locations, retention, and support access are governed by the applicable provider terms and the operator's dated control records.
M&AI does not sell personal information, use personal information for targeted advertising, or knowingly permit use by children under 13. It does not use Client Data to train generally available models. Application Responses requests are designed to use store: false, while provider abuse-monitoring or other provider-controlled copies may remain subject to the provider's terms and approved account controls.
Access revocation and deletion trigger
CurtisWiltse or its authorized operator disables an administrator, buyer, or invite promptly when instructed or when access must end. Revocation prevents future access; it does not by itself delete retained information.
For each deal corpus, the retention clock begins on the earlier of recorded deal closure or withdrawal and an authorized deletion instruction. Active corpus content is retained for 90 days after that trigger. The operator then completes the active-system purge within the following 30 days, subject only to a relevant legal hold, active security investigation, law, or contractual obligation.
Corpus and substantive-derived-content deletion
The corpus-deletion clock applies together to all substantive deal content and derivatives: original documents, document metadata that reveals content, extracted content, chunks, embeddings, indexes, questions, answers, summaries, citation excerpts, conversation content, temporary extraction artifacts, and operator-controlled provider copies. These categories are not retained as seven-year audit records.
The operator clears active application systems first, records provider-specific purge, expiry, or transfer status using metadata-safe evidence, and treats incomplete provider control as an unresolved control rather than a completed deletion. The deletion procedure also covers transient workspaces, queues, cache entries, and exports created for the corpus.
Audit-safe metadata retention
For seven years after the related deal closure or account relationship end, whichever is later, CurtisWiltse may retain only audit-safe non-content metadata needed to demonstrate authorized operation, security, and deletion handling. The allowed record is limited to internal identifiers, actor role or pseudonymous actor identifier, timestamps, policy version and hash, system or provider name, action type, bounded status or error code, count, retention deadline, legal-hold reference, and a location pointer that does not reveal content.
The seven-year record must not contain document text, filenames, questions, answers, summaries, citation excerpts, raw URLs, credentials, identity-document copies, correspondence, console captures, or other substantive Client Data.
Legal holds and security investigations
A written legal hold or active security investigation pauses deletion only for the relevant information and stated purpose. The hold record identifies its authority, scope, start, review cadence, access restriction, and release condition without copying underlying content.
When the hold or investigation ends, the operator records release and resumes the applicable deletion workflow. A hold does not authorize ordinary use, broad retention, or a permanent exception.
Provider-native backup and recovery
The production M&AI project is hosted in the CurtisWiltse Supabase organization on the Pro plan. Supabase provides automatic daily Postgres and Auth backups retained for seven days; dated operator evidence must be refreshed after a material plan, project, or backup-control change.
Supabase database backups do not include private Storage object bytes, bucket settings, or source assets. Successfully ingested deal originals are not reopened for live buyer Q&A, which uses published Postgres-derived chunks, embeddings, and citations. CurtisWiltse retains authoritative deal originals and re-uploads them when recovery needs them; Allied Code then performs re-ingestion, validation, and republication before restored content is made available.
Active site assets remain runtime Storage dependencies. CurtisWiltse retains and approves site-asset source files and performs or expressly authorizes their upload; Allied Code verifies that the restored application serves the approved assets.
The operator performs an isolated recovery exercise using synthetic or non-production data where practicable. The exercise verifies database and Auth restoration, application integrity, pending-deletion replay before access resumes, source-file re-upload and republication where applicable, served-asset integrity, and cleanup of the isolated environment. The initial exercise remains an operational follow-up after publication and repeats at least annually and before a material migration or handoff. The seven-day provider backup window is separate from the active-system deletion schedule and seven-year metadata-only retention stated above.
Privacy requests
A person may contact CurtisWiltse at info@curtiswiltse.com or 11650 South State Street, Suite 200, Draper, UT 84020 to request access, correction, deletion, or information about handling. CurtisWiltse verifies the requester's identity and authority before acting and protects the request record from substantive content and identity-document copies.
CurtisWiltse substantively responds within 45 days of a verified request. If reasonably necessary, it may use one additional 45-day extension after giving an explained notice within the initial period. A response may be limited only where information must remain for a relevant legal hold, security investigation, law, contract, confidentiality duty, or valid backup-rotation process.
Termination, incidents, and material changes
Before an approved transfer or termination, CurtisWiltse provides the agreed export through an authorized channel and coordinates access revocation, retention, deletion, provider-native backup recovery controls, and provider controls. Incident handling uses metadata-safe records and escalates to CurtisWiltse where Client Data, access, retention, or deletion may be affected.
CurtisWiltse reviews this policy and its controls before any material service, jurisdiction, provider, legal-applicability, or contractual change takes effect. A material revision requires a new canonical artifact, hash, approval record, effective date, and applicable operational evidence.