This notice explains how personal data is processed when you use CELLAR, the operational due-diligence platform operated by Armagnac Consulting. Please read it before you continue. It applies to you as a user and to the personal data you and your delegates enter into the platform.
Who is responsible
Your firm is the data controller for the personal data processed through CELLAR. Armagnac Consulting acts as data processor on its behalf, under a written agreement. Where Armagnac Consulting determines the means and purposes itself, for example platform security and audit logging, it acts as a controller for those limited purposes.
What data we process
Identification and contact data: names, professional email addresses, job titles.
Account and usage data: sign-in events, IP address, and browser information, used for security and audit.
Due-diligence content: the questionnaire answers, ratings, comments and documents you and your delegates submit, which may contain personal data of third parties.
Why we process it (lawful basis)
Performance of the contract between your firm and Armagnac Consulting.
Legitimate interests: securing the platform, maintaining an audit trail, and improving the service.
Legal and regulatory obligations, including CSSF Circulars 18/698 and 22/806 record-keeping requirements.
Where data is stored
Data is hosted in the European Union. CELLAR relies on a small number of sub-processors: Netlify (hosting and storage, Frankfurt), Google (document storage), and Resend (transactional email). Each is bound by a data-processing agreement.
How long we keep it
Personal data is retained for the duration of the engagement and for the period required by CSSF record-keeping obligations (up to ten years), after which it is deleted or anonymised.
Your rights
Subject to applicable law, you may request access to, rectification of, or erasure of your personal data, as well as restriction of or objection to processing, and data portability. You may also lodge a complaint with the Luxembourg supervisory authority (CNPD).
Applies to: all CSSF-supervised entities, including IFMs / management companies.
The master Luxembourg outsourcing regime: governance, a materiality / criticality assessment, pre-outsourcing due diligence, written contracts, an outsourcing register, control of sub-outsourcing, ongoing monitoring and a documented exit strategy. Prior notification for critical or important functions.
Substance and own-funds requirements, plus the conditions for delegating portfolio / risk management and administrative functions — the IFM must keep effective oversight and never become a letter-box entity.
Applies to: alternative investment fund managers (AIFMs).
Delegation of AIFM functions only on objective reasons, to delegates of sufficient quality, with prior notification to the regulator and no delegation to the extent the AIFM becomes a letter-box entity.
Delegation conditions for UCITS ManCos: prior information to the regulator, qualified delegates, continued monitoring and no hollowing-out of the management company.
Applies to: financial entities, including IFMs, for their ICT arrangements.
ICT third-party risk management: mandatory contractual provisions, a register of information on all ICT arrangements, concentration-risk assessment and oversight of critical ICT providers.
Applies to: banks / payment & e-money institutions — the EU blueprint behind CSSF 22/806.
The EU baseline for outsourcing governance, materiality assessment, registers and contractual content that CSSF 22/806 transposes into Luxembourg practice.
Applies to: any controller outsourcing personal-data processing.
Processors must offer sufficient guarantees; a written data-processing agreement and controlled sub-processing are mandatory.
Send DDQ invitations
Add a recipient and click VALIDATE to add them to your authorized recipients. Tick the ones to invite, choose which questionnaire to send, and click Send. Each ticked recipient receives their own activation email.
List of authorized recipients
No recipients yet. Add one above and click VALIDATE.
Reuse a previous questionnaire
Send a renewal DDQ to a delegate that already responded. The new questionnaire is pre-filled with the previous cycle’s answers and conclusion, so the recipient only edits what changed.
Loading…
Sent invitations
Loading…
DD Reviews
Open a submitted DDQ to rate each answer, add comments and page references, then validate to produce the formal DD report.
Loading…
Loading…
0 / 0 questions rated
Enter audited figures (€ thousands) for up to 3 financial years. FY'N is mandatory; if no audited report is available, leave zeros. Totals and 12 ratios compute live. You can rename any row or change its slot type — click the small ⋯ next to the row label.
Balance Sheet (€ thousands)
Profit & Loss (€ thousands)
12 ratios · 4 families
Each family has an auto-suggested band based on FY'N values. The reviewer's pick below feeds the Financial dimension score.
Edit row caption
Notes
Stickers stay on this DD until you validate it; they are never printed or shared.
Points of Attention
DD Register
All validated due diligences for this client. Click a row to open the DD report.
Show DDQs that are
Loading…
PURPOSE
The purpose of the due-diligence process is to assess the delegation risk associated with a specific delegate across four key risk dimensions:
Operational
Legal
Reputational
Financial
Each required document and question is linked to one or several of these risk dimensions.
Example #1: a question such as "Please provide information about the professional track record of the members of the management / governing body and the senior management, in particular regarding their experience in dealing with the services that you provide" may simultaneously carry operational, legal, and reputational risk implications.
RISK RATING
Each document and question is reviewed and assigned a risk rating of:
LOW
MEDIUM
HIGH
Example #2: a "Certificate of incorporation (dated ≤ 3 months from request)" is required, but the delegate provides a certificate older than 3 months. The risk rating for this document is MEDIUM.
SCORING
Illustrative. Each risk rating corresponds to a numerical score (configurable per client; the values shown are the ones currently set):
LOW = 0
MEDIUM = 1
HIGH = 2
The values must always be equally spaced, so each step is the same size (for example 0 / 1 / 2, or 1 / 2 / 3). MEDIUM is always the midpoint between LOW and HIGH.
If a question is linked to multiple risk dimensions, its score is multiplied by the number of occurrences.
Example #3: a question associated with Operational, Legal and Reputational risks is rated HIGH. Score = 2 × 3 = 6.
An overall score per risk dimension is then calculated:
Sum of all LOW + MEDIUM + HIGH scores for Operational Risk ÷ Total number of Operational Risk occurrences = Overall Operational Risk Score
RISK BANDS
A risk band is a numerical interval that groups a range of scores into a single qualitative risk level.
Supported scales:
3-tier: LOW / MEDIUM / HIGH
4-tier: LOW / MEDIUM-LOW / MEDIUM-HIGH / HIGH
5-tier: LOW / MEDIUM-LOW / MEDIUM / MEDIUM-HIGH / HIGH
Each band has a customisable numerical interval.
Example #4 (3-tier default):
LOW: 0.00 → 0.67
MEDIUM: 0.67 → 1.33
HIGH: 1.34 → 2.00
Thresholds can be customised below.
FINAL DELEGATION RISK ASSESSMENT
The Overall Delegation Risk Score is a weighted average of the four risk-dimension scores:
(Operational Score × Operational Occurrences ÷ Total Occurrences) + (Legal Score × Legal Occurrences ÷ Total Occurrences) + (Reputational Score × Reputational Occurrences ÷ Total Occurrences) + (Financial Score × Financial Occurrences ÷ Total Occurrences) = Overall Delegation Risk Score
The final score falls into one of the predefined risk bands, which determines the frequency of future due-diligence reviews.
Example #5: if the Overall Delegation Risk Score falls into the LOW band, the next due-diligence review is scheduled 3 years after the validation date.
Process supervision
Five-phase guided workflow for running a DD on a delegate. Hover any dot for a short explanation of that stage; click the dot to jump to the relevant tab and do the work.
StartReview and validate the structure and content of the DDQ
1. Start by reviewing the structure and content of the DDQ
- Review the list of all required documents
- Review the structure of all sections
- Review all questions
2. Add or remove documents / sections / questions
3. Allocate a risk dimension (Operational, Legal, Reputational, Financial) to each document and question
4. Save the DDQ
SetSet the methodology
Choose the number of risk ratings and the values associated with each of them for calculating the score per risk dimension and the overall score.
SendDelegate outreach
Designate the contacts at the delegates that will be sent the DDQ, select the type of DDQ to send, and send invitations. Review which invitations have been sent, are pending, or have been revoked, and which DDQs have been submitted.
ReviewDD Reviews
Have an overview of all DDs, who they were shared with, date of submission, and their status. Open any submitted DD to rate answers, add comments and page references, request follow-ups, and validate the review.
RegisterDD Register
Have an overview of all validated DDs, by type, by country, by risk, by date of validation, by next due, and by days remaining. Filter and sort across all delegates.
ReportGovernance
Track ExCo and Board validation dates per delegate, and generate a single governance pack PDF combining all validated DDs into one document for the next committee meeting.
Completed Current stage Ended workflow
Open DD Processes
No open DD process. Click + Create new DD process to start tracking one.
Closed DD Processes
DD processes for which every step has been completed.
No closed DD process yet.
Compare
Compare up to 5 delegates across risk dimensions.
Search results
Pick a criterion and click Validate to see matching delegates.
Comparison list (0 of 5)
Pick a delegate from the search results and click + to add (max 5).
Governance
All validated DDs. Add ExCo + Board validation dates as they happen; "Save all to PDF" builds a single governance pack that opens with a period summary, then one delegate per page.
Loading…
Ongoing monitoring
Supervised delegates at a glance (CSSF 22/806, ongoing oversight). Each line is an active delegation: its current risk rating, when the next due diligence is due, and how close it is. Document freshness, issues and periodic reviews are added in the next steps.
Loading…
My account
Subscription
Client—
Signed in as—
Package—
Total DDs in package—
Users in package—
Other users—
DDs used—
Questionnaires opted in
—
Documents
My GDPR
Privacy notice and consent record.
My Contract
The agreement signed between Armagnac Consulting and your firm.
Send selected questions back to recipient
Tick the questions you'd like the recipient to re-answer with more detail. They'll receive an email with a follow-up form showing only the ticked questions; their original answers stay in the record.
Loading questions…
Import questionnaire from Excel
Bring your existing questionnaire into Cellar. Upload an Excel file, or paste rows copied from Excel or a Word table. Sections and questions are added to the DDQ as custom items - your required documents are left untouched. Nothing is sent anywhere until you click Add to DDQ.
Review and edit the questionnaire below before adding it. Each bulleted line is a question; click ← to turn a question into a section heading (its bullet is removed and it becomes bold), or → to turn a section back into a question. Edit any text inline.
The reviewer has asked you to provide additional detail on the questions below. Your original answers stay in the record — what you write here is added alongside them.
If your counterparty already uses Cellar, request their existing DD pack instead of sending a blank questionnaire. Enter their email address and click on submit passport. They approve your request and choose which pack to release; you then ingest it as a reviewable DD (it still passes your own review and validation).
Your counterparty already uses Cellar and requests your existing DD pack: approve to share your pack in one click, or decline if it is not applicable. Fill your DD once, reuse it for everyone. Click on "submit your passport."
This questionnaire is organised into 12 common sections + up to 8 delegate-specific sections (Fund Administrator, Depositary, Investment Manager, Broker, Distributor, IT Firm, Legal Firm, Corporate Secretary). Plus a checklist of supporting documents. Answer the common sections, then complete only the delegate sections relevant to the services you provide. You can press SAVE at any time, your draft is kept locally in this browser. Press SUBMIT when complete.
What you need to do
Start by reviewing the structure and content of the DDQ
Review the list of all required documents
Review the structure of all sections
Review all questions
Add or remove documents, sections or questions
Allocate a risk dimension (Operational, Legal, Reputational, Financial) to each document and question
Save the DDQ
Customisation mode. You can add questions to any section (+ Add question at the bottom of each section), remove existing questions or sections using the − button next to them, and undo any change. Edits save automatically. Respondents see the questionnaire reflecting your latest saved version.