Institutional Governance

Privacy & Data Protection Policy

Effective Date: September 2026 · Operated by GGAM Advisory & LIFT OS

1. Institutional Commitment & Scope

LIFT ("we," "our," or "the Platform"), operated under GGAM Advisory, provides an enterprise-grade due diligence operating system. This policy governs how financial statements, MCA corporate records, cap tables, intellectual property escrow files, and commercial contracts are ingested, processed, and protected.

We operate strictly as a data processor and fiduciary facilitator for accredited investment committees, verified startup incubators, and participating founders. We never monetize, aggregate, or train public AI models on private deal room data.

2. Data We Ingest and Process

  • Corporate & Cap Table Data: Shareholding structures, MCA filings, founder identification credentials, board resolutions, and ESOP pool allocations.
  • Financial & Tax Records: Audited P&L, balance sheets, GST/tax reconciliation reports, bank statements, and financial projections.
  • Legal & Material Contracts: Employment agreements, intellectual property assignment covenants, vendor master contracts, and non-disclosure instruments.
  • Telemetry & Access Logs: Immutable timestamped logs of document downloads, view durations, and analyst query interactions for compliance audits.

3. Cryptographic Isolation & Security Architecture

All venture files uploaded into the LIFT Startup Data Room (app.lift.business) are immediately encrypted using AES-256 at rest and TLS 1.3 in transit.

Zero Cross-Tenant Leakage

Each venture repository exists inside isolated database partitions and encrypted storage buckets.

Dynamic Watermarking

All document preview renders embed viewer email, IP address, and microsecond timestamps to deter unauthorized leaks.

4. Role-Based Access Control (RBAC) & Disclosure

Access to data room contents is strictly role-governed:

  • Founders: Complete management, revocation privileges, and real-time audit views over who has accessed their documents.
  • Incubator Directors: Cohort readiness benchmarks and aggregated compliance checklists without unauthorized deep file downloads unless explicitly granted.
  • GGAM Advisory Analysts & Partners: Scoped deal room access for investment committee dossier preparation, restricted by multi-factor authentication (MFA).

5. Data Retention & Fiduciary Purge Rights

Upon closing or discontinuation of a diligence workflow, founders and venture leads hold the unilateral right to trigger a cryptographic data purge or escrow transfer. Inactive deal rooms are permanently archived or deleted based on statutory compliance mandates.

6. Regulatory Contact & Data Protection Officer

For inquiries regarding institutional compliance, audit verification logs, or data rights:

Data Protection & Governance Office

GGAM Advisory / LIFT OS Institutional Operations

compliance@lift.business