Privacy Policy
Last updated 22 July 2026
This Privacy Policy explains how DataRooms collects, uses, and protects personal data when you use our website at datarooms.be and the DataRooms platform (the "Service"). We handle personal data in accordance with the EU General Data Protection Regulation (GDPR) and Belgian data protection law.
1. Who we are
DataRooms ("we", "us", "our"), located at Kattendijkdok-Westkaai 61/1202, 2000 Antwerp, Belgium, is the controller of the personal data described in this policy, except where we act as a processor (see "Our two roles" below). For any privacy question, contact us through our contact form.
2. Our two roles
Account and website data. When you sign up and use DataRooms as a founder or visitor, we act as the controller of your account and usage data.
Data you upload and the people you invite. When you upload documents and invite investors to your data room, you decide what is uploaded and who can access it. For that content and for the personal data of the investors you invite, you act as the controller and we act as your processor, handling it on your behalf and under your instructions. You are responsible for having a lawful basis to upload and share that information.
3. Personal data we collect
- Account data: your name, email address, and authentication details when you create an account.
- Billing data: your plan, subscription status, and transaction details. Payments are processed by Revolut, and we do not store full card numbers.
- Content you provide: documents and materials you upload, and the questions and messages exchanged with the AI assistant. These may contain personal data that you choose to include.
- Data room access data: when you invite investors, we process the email addresses and access credentials needed to gate access, and we record access to your data room.
- Usage and analytics data: how you interact with the Service, including pages viewed, documents opened, approximate location, and device and browser information, collected in part through analytics tools and cookies.
- Communications: messages you send us, for example by email or through the Service.
4. How we use personal data and our legal bases
- To provide the Service (performance of our contract with you): creating and managing your account, hosting and processing your content, running the AI assistant, gating data room access, and providing engagement analytics to founders.
- To process payments and manage subscriptions (contract and legal obligation).
- To secure and improve the Service, prevent abuse, and develop new features (legitimate interests).
- To communicate with you about the Service, including service updates and support (contract and legitimate interests).
- To send newsletters or marketing where you have subscribed (consent); you can unsubscribe at any time.
- To comply with legal obligations and to establish, exercise, or defend legal claims (legal obligation and legitimate interests).
5. How the AI features process your documents
When you use the AI assistant, we extract text from your documents, split it into segments, generate vector embeddings, and store them so the assistant can retrieve relevant passages and answer questions grounded in your materials.
AI processing is performed using OpenAI's API. Content sent to the OpenAI API is not used to train OpenAI's models. This processing happens only for data rooms configured to use the AI features.
6. Providers that process personal data
We rely on a small set of trusted providers to run the Service. They process personal data on our behalf under appropriate data protection terms:
- Supabase — database, authentication, and file storage.
- OpenAI — AI model processing for the assistant and embeddings.
- Revolut — payment processing and billing.
- PostHog — product analytics.
- Resend — transactional and notification email.
We may also use infrastructure hosting and error-monitoring providers to operate and maintain the Service. We do not sell your personal data.
7. International transfers
Some of our providers are located outside the European Economic Area, including in the United States. Where personal data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses so that your data receives an adequate level of protection.
9. Data retention
We keep account and billing data for as long as your account is active and as needed to provide the Service, and afterwards as required to comply with legal, accounting, or reporting obligations.
Content you upload is retained until you delete it or close your account. After account closure we delete or anonymize personal data within a reasonable period, unless we must keep it to meet a legal obligation or to resolve disputes.
10. Security
We use technical and organizational measures to protect personal data, including encryption in transit, access controls, and isolation of each customer's data. Sensitive credentials, such as API keys, are stored encrypted. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.
11. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. Where processing is based on consent, you may withdraw it at any time without affecting processing carried out beforehand.
To exercise your rights, contact us through our contact form. If your request concerns data that a founder uploaded to their data room (where we act as processor), we may refer you to, or act on the instructions of, that founder as the controller.
You also have the right to lodge a complaint with your local supervisory authority. In Belgium this is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Rue de la Presse 35, 1000 Brussels.
12. Data room visitors and investors
If you access a data room as an investor, the founder who created that room decides what documents to share and controls access. Your access, including views and document opens, may be recorded and shown to that founder as part of engagement analytics. For questions about how a particular founder uses your data, please contact them directly; for questions about our platform, contact us.
13. Children
The Service is intended for businesses and professionals and is not directed to children. We do not knowingly collect personal data from anyone under 18.
14. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify you, for example by email or through the Service. The "Last updated" date above shows when this policy was last revised.
15. Contact
For any question about this policy or your personal data, contact us through our contact form or write to DataRooms, Kattendijkdok-Westkaai 61/1202, 2000 Antwerp, Belgium.