GDPR & EU Compliance

Built for European data protection.

Dataroom is operated from the EU, hosted in the EU, and designed around the General Data Protection Regulation.

Our commitments

EU data residency

Your documents and personal data never leave the European Union. Hosting: [PROVIDER], [COUNTRY]. No international transfers — all processing happens inside the EU/EEA.

Data minimisation

We collect only what the service needs: name, email address, and the activity records required for the audit trail. No profiling, no advertising data, no trackers.

Purpose limitation

Your data is used solely to provide the data room service. It is never sold, shared or used for marketing without consent.

Privacy by design

Access control, encryption and audit logging are core product features, not add-ons — as required by Art. 25 GDPR, data protection by design and by default.

Your rights under GDPR

Every user can exercise the rights granted by Articles 15–21 GDPR: access to their personal data, rectification, erasure (“right to be forgotten”), data portability, and restriction or objection to processing.

Requests: [privacy@YOURDOMAIN] — answered within 30 days as required by law.

For business customers

Data Processing Agreement

We sign a DPA (Art. 28 GDPR) with every business customer, defining our role as processor and your instructions as controller.

Subprocessors

Current list: [HOSTING PROVIDER], [COUNTRY] — nothing else. Customers are notified before any change.

Breach notification

In the unlikely event of a personal data breach, affected customers are informed without undue delay and within 72 hours (Art. 33 GDPR).

Data retention & deletion

When a data room is deleted, its documents are permanently removed from our servers [and rotated out of backups within X days].

Cookies

The application uses one strictly necessary cookie to keep you signed in. No tracking cookies, no analytics, no third-party cookies — which is why you won't find a cookie banner here.

Supervisory authority. Our lead supervisory authority is [AUTHORITY OF YOUR EU COUNTRY]. You also have the right to lodge a complaint with your local data protection authority at any time.