Data processing, clearly defined.
This Data Processing Addendum explains how we process customer content on your behalf. Effective August 13, 2026.
1. Scope and roles
This DPA forms part of the Terms where DataRoom One processes personal data for a customer. The customer is controller and DataRoom One is processor. Customer affiliates using the service may participate as authorized users.
2. Instructions
We process data only to provide, secure, and support the service and follow your documented instructions. If we believe an instruction violates data-protection law, we will inform you unless legally prohibited.
3. Confidentiality and security
People with access are bound by confidentiality. We maintain appropriate technical and organizational measures including encrypted transport, private storage, authentication, server-side authorization, access revocation, audit records, backups, and incident response controls.
4. Sub-processors
You grant general authorization to use sub-processors to provide the service. Key providers are Supabase (database, authentication, storage), Stripe (billing), Resend (email), and Twilio (WhatsApp alerts). We bind sub-processors to appropriate data-protection obligations and remain responsible for their processing. We will provide reasonable notice of material changes.
5. Assistance
Taking account of the processing and information available to us, we provide reasonable assistance with data-subject requests, security, breach notices, impact assessments, and regulatory consultation. If a data subject contacts us directly, we redirect the request to the customer.
6. Personal-data breach
After becoming aware of a confirmed personal-data breach affecting customer data, we notify the customer without undue delay and provide available details, likely consequences, and mitigation steps.
7. Transfers
Where personal data is transferred to a country without an adequacy decision, the current European Commission Standard Contractual Clauses are incorporated using the appropriate module. Swiss or UK adaptations apply where required.
8. Return and deletion
At the end of the service, we return or delete customer data at the customer's choice. Copies subject to legal retention remain protected and are not used for other purposes. Backup copies are removed through normal deletion cycles.
9. Audit
We provide reasonable information needed to demonstrate compliance. Where documentation is insufficient and justified cause exists, we allow a reasonable audit subject to confidentiality and security conditions. The customer will first use available reports and avoid unnecessary disruption.
Annex A — Processing details
- Subject: provision of a secure data-room service.
- Duration: account term and post-termination deletion period.
- People: customer personnel, advisers, investors, buyers, and guests.
- Data: identity and contact, business information, room content, usage and audit events.
- Operations: collection, storage, organization, display, transmission, securing, and deletion.
Contact
For DPA or sub-processor questions, email legal@dataroom.one.