Your data stays yours.
This policy explains what we process when you use DataRoom One and the choices available to you. Effective August 19, 2026.
1. Who we are
DataRoom One is an online secure data-room service. We act as controller for account and service data, and as processor for content customers place in their rooms under their instructions.
2. Data we process
- Name, email, account, and team details.
- Documents, folders, and room settings you upload.
- Sign-in, viewing, download, and audit events.
- Device, browser, IP address, and error diagnostics.
- Support requests and notification preferences.
- Website interactions and campaign-attribution data when you consent.
- Billing status. Stripe processes card details; we do not store complete card numbers.
3. Why we use it
We process data to provide the service, secure accounts, enforce permissions, show activity, manage billing, deliver requested alerts, resolve issues, and meet legal obligations. Our legal bases include contract, legitimate interests, consent, and legal obligation.
4. Sharing and providers
We do not sell personal data. We share data only with infrastructure, database and storage, payment, email, messaging, error-monitoring, and consented measurement providers needed to run the service, and with authorities when legally required. Key providers include Supabase, Stripe, Resend, Twilio, Google, and Meta.
Google Identity Services loads on the sign-in page to provide the optional Google sign-in button. This authentication traffic is separate from optional analytics and advertising measurement.
5. Retention and deletion
We retain account and room content while needed to provide the service. Room owners can delete content. After account closure, limited copies may remain for security, backup, fraud prevention, and legal obligations before deletion or anonymization.
6. International transfers
Our providers may process data in different countries. Where required, we rely on adequacy decisions, the European Commission's Standard Contractual Clauses, or equivalent legal safeguards.
7. Your rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or objection. California residents may also have rights to know, correct, delete, and opt out of sale or sharing. DataRoom One does not sell personal data. We do not discriminate for exercising privacy rights.
8. Security and cookies
We use encrypted connections, private storage, server-side permission checks, short-lived access links, and audit records. Necessary cookies and local storage support sessions, security, and language selection. If you consent, Google and Meta analytics and advertising cookies measure visits, registrations, checkout starts, trials, and campaign results. You can accept, reject, or later change your optional-cookie choice.
9. Contact
For privacy requests, email privacy@dataroom.one.