Dataroom is operated from the EU, hosted in the EU, and designed around the General Data Protection Regulation.
Your documents and personal data never leave the European Union. Hosting: [PROVIDER], [COUNTRY]. No international transfers — all processing happens inside the EU/EEA.
We collect only what the service needs: name, email address, and the activity records required for the audit trail. No profiling, no advertising data, no trackers.
Your data is used solely to provide the data room service. It is never sold, shared or used for marketing without consent.
Access control, encryption and audit logging are core product features, not add-ons — as required by Art. 25 GDPR, data protection by design and by default.
Every user can exercise the rights granted by Articles 15–21 GDPR: access to their personal data, rectification, erasure (“right to be forgotten”), data portability, and restriction or objection to processing.
Requests: [privacy@YOURDOMAIN] — answered within 30 days as required by law.
We sign a DPA (Art. 28 GDPR) with every business customer, defining our role as processor and your instructions as controller.
Current list: [HOSTING PROVIDER], [COUNTRY] — nothing else. Customers are notified before any change.
In the unlikely event of a personal data breach, affected customers are informed without undue delay and within 72 hours (Art. 33 GDPR).
When a data room is deleted, its documents are permanently removed from our servers [and rotated out of backups within X days].
The application uses one strictly necessary cookie to keep you signed in. No tracking cookies, no analytics, no third-party cookies — which is why you won't find a cookie banner here.