Privacy Policy

Vergence — Effective March 26, 2026

Information We Collect

When you create an account or use Vergence, we collect the following categories of information:

  • Account information — your email address, full name, and organizational affiliation provided at signup.
  • Company profiles and product metadata — content you or your organization creates and publishes on the platform.
  • Uploaded documents — files attached to company or product listings, including technical specifications and capability statements.
  • Usage analytics — page views, search queries, document interactions, and feature engagement to improve the platform.
  • Communication data — direct messages and workspace notes created within the platform.

How We Use Your Information

We use the information we collect for the following purposes:

  • Operating and delivering the Vergence platform, including authentication and access control.
  • Powering search and discovery features that connect companies with government and VC audiences.
  • Generating platform analytics and capability intelligence reports.
  • Monitoring security, detecting abuse, and maintaining system integrity.
  • Communicating with you about your account, updates, and platform changes.

Information Sharing

Vergence shares information only in the following limited ways:

  • With other platform users — company profiles and products are shared with the audiences you configure in your discoverability settings (Government, Venture Capital, or other Companies).
  • Within your organization — your profile and activity are visible to other members of your organization on the platform.
  • We do not sell your data — your personal information is not sold, rented, or traded to third parties. See Your Rights Under CCPA/CPRA below.
  • Service providers — we use AWS infrastructure (S3, Aurora PostgreSQL, OpenSearch) to operate the platform under data processing agreements.

Data Security

Vergence implements industry-standard security controls to protect your data:

  • Encryption at rest using AES-256 on Amazon S3 and Amazon Aurora PostgreSQL.
  • Encryption in transit using TLS 1.2 or higher for all connections.
  • Role-based access control — each user can only access data their organizational role permits.
  • Organizational data isolation — VC pipeline notes, government audit trails, and company data are strictly separated and never cross organizational boundaries.
  • Audit logging of sensitive operations including data exports and account deactivations.

Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access — request a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data about you.
  • Right to erasure — request deletion of your personal data ("right to be forgotten").
  • Right to data portability — receive your data in a machine-readable format.
  • Right to restriction — request that we limit how we use your data.
  • Right to object — object to processing based on legitimate interests.

To exercise these rights, use Settings > Data Export (for portability) or Settings > Account Deactivation (which triggers data anonymization per our retention policy). You may also contact us at privacy@northfieldgroup.us.

Your Rights Under CCPA/CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:

  • Right to know — the categories of personal information we collect and how we use it.
  • Right to delete — request deletion of your personal information.
  • Right to opt out of sale or sharing — you may direct us not to share your personal information with third parties for cross-context behavioral advertising or analytics.
  • Right to non-discrimination — we will not discriminate against you for exercising your CCPA rights.

To opt out of the sale or sharing of your personal information, use the Do Not Sell toggle in Settings > Data Sharing, or click the Do Not Sell or Share My Personal Information link. You may also contact us at privacy@northfieldgroup.us.

Data Retention

  • Active accounts — your data is retained while your account is active and for a reasonable period after.
  • Deactivated accounts — personal information is anonymized upon account deactivation per our data erasure policy.
  • Analytics events — retained per our data lifecycle policy and subject to the data partitioning schedule.
  • Compliance audit logs — retained for the legally mandated period regardless of account status.

Cookies and Tracking

Vergence uses cookies and similar tracking technologies only as necessary:

  • Essential cookies — authentication session tokens required to keep you signed in. These cannot be disabled.
  • Analytics (optional) — usage tracking to improve platform performance. You are prompted for consent on first visit and can change your preference at any time.

Contact

For privacy-related inquiries, data subject requests, or CCPA opt-out requests, contact us at:

privacy@northfieldgroup.us

Northfield Group — Vergence Privacy Team

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. The effective date at the top of this page reflects the date of the most recent update. We encourage you to review this policy periodically.