Privacy Policy
Dataroom.pro
Operated by Quokka S.àr.l.
Effective Date: June 25, 2026
1. Introduction
Quokka S.àr.l. (“Company,” “we,” “us,” or “our”), a société à responsabilité limitée duly incorporated and registered in the Grand Duchy of Luxembourg under register number B280011 (VAT: LU35321866), with its registered office at 58 Boulevard Marcel Cahen, L-1311 Luxembourg, operates the Dataroom.pro platform (the “Platform”).
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you access or use the Platform. It applies to all users of the Platform, including Startup Clients and Investor Clients, as well as visitors to our website at https://dataroom.pro.
We are committed to protecting your privacy and processing your personal data in compliance with Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”) and applicable Luxembourg data protection legislation.
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. This Privacy Policy forms an integral part of our Terms of Service and should be read in conjunction with them.
2. Data Controller
For the purposes of the GDPR, the data controller responsible for your personal data is:
Quokka S.àr.l.
58 Boulevard Marcel Cahen, L-1311 Luxembourg, Grand Duchy of Luxembourg
Register Number: B280011
VAT: LU35321866
Email: legal@dataroom.pro
If you have any questions or concerns regarding the processing of your personal data, or if you wish to exercise any of your rights under the GDPR, please contact us at the address above.
3. Personal Data We Collect
The categories of personal data we collect depend on how you interact with the Platform and whether you are a Startup Client, Investor Client, or visitor.
3.1 Data Collected During Account Registration
When you create an account on the Platform, we collect:
Your full name;
Your email address;
Account credentials (where you register directly via email); and
Session tokens (where you authenticate via a third-party identity provider such as Google or GitHub).
Where you register or log in through a third-party identity provider, we receive only the information listed above from that provider. We do not request or receive access to any other data held by that provider beyond what is strictly necessary for account creation.
3.2 Data Collected from Startup Clients
In addition to registration data, we collect the following categories of information from Startup Clients:
Company profile information voluntarily submitted by you, including but not limited to company name, investment stage, aggregate capital raised, industry classification, and product category;
Usage data and behavioural analytics generated through your interaction with the Platform; and
Payment and billing information as required for the processing of subscription fees.
We may expand the scope of profile information collected in the future to enhance user profiles and improve discoverability for Investor Clients. Any such expansion will be reflected in an update to this Privacy Policy.
3.3 Data Collected from Investor Clients
In addition to registration data, we collect the following categories of information from Investor Clients:
Company profile information voluntarily submitted by you, including but not limited to entity name, investment focus, mandate parameters, and jurisdiction of incorporation;
Engagement analytics relating to your interactions with Startup Client data rooms on the Platform, which includes specific pages or documents viewed, frequency of access, and related interaction metrics;
Payment and billing information; and
General usage analytics pertaining to your interaction with the Platform.
Important: By accessing any Startup Client’s data room on the Platform, you acknowledge and consent to the collection and disclosure of your engagement analytics to the relevant Startup Client, as more fully described in Section 5 of this Privacy Policy.
3.4 Document Storage
Users may upload documents to data rooms hosted on the Platform. Such documents are stored on our infrastructure solely for the purpose of making them accessible to you and to parties you designate. We do not access, review, or process the substantive content of uploaded documents except where you expressly initiate AI-assisted services pursuant to the Terms of Service. Documents may contain commercially sensitive or confidential information, and you are solely responsible for ensuring that you have the right to upload and share such materials.
3.5 Automatically Collected Data
When you access the Platform, we automatically collect certain technical and usage data, including:
- your IP address;
- your browser's user-agent string, which identifies your browser type and version, and your operating system;
- the date and time of each access;
- the pages, documents, and features you access within the Platform — including the data rooms and documents you open, preview, or download, and how often;
- the referring URL (the address of the page that directed you to the Platform), where available; and
- the specific URLs and requests you make to the Platform.
We do not collect the duration of your sessions, your precise geographic location, or any device fingerprint or persistent device identifier.
3.6 Document and Activity Analytics
- The Platform records when a user views, previews, or downloads a document inside a data room. When you access a data room operated by a startup or other host, that host can see analytics about your activity in their data room — including which of their documents you opened and the date and time you did so. We provide this information to hosts so they can understand engagement with the materials they share.
3.7 Cookies and Local Storage
- We do not use cookies. To operate the Platform, we store a limited amount of data in your browser's local and session storage — for example, to keep you signed in, remember your display preferences, and complete sign-up or invitation flows. This data stays on your device and is cleared when you sign out (except non-identifying display preferences such as your theme choice).
- We do not use any third-party analytics, advertising, session-replay, or tracking technologies, and all fonts and other assets are served from our own servers.
4. How We Use Your Personal Data
We process your personal data for the following purposes and on the following legal bases:
| Purpose | Categories of Data | Legal Basis (GDPR) |
|---|---|---|
| Account creation and authentication | Name, email, session tokens | Performance of contract (Art. 6(1)(b)) |
| Providing Platform services (data room hosting, document storage, sharing) | User Content, profile data, usage data | Performance of contract (Art. 6(1)(b)) |
| AI-assisted document processing (upon user request) | User Content transmitted to AI providers | Consent (Art. 6(1)(a)) |
| Investor engagement analytics (disclosed to Startup Clients) | Investor interaction data with specific data rooms | Consent (Art. 6(1)(a)) / Legitimate interest (Art. 6(1)(f)) |
| Platform improvement and development | Usage analytics, operational metadata (without any third-party analytics tools) | Legitimate interest (Art. 6(1)(f)) |
| Payment processing and billing | Payment information, transaction history | Performance of contract (Art. 6(1)(b)) |
| Compliance with legal obligations | Account data, transaction records | Legal obligation (Art. 6(1)(c)) |
| Security and fraud prevention | IP addresses, access logs, authentication data, User-Agent / browser strings | Legitimate interest (Art. 6(1)(f)) |
Additionally, real-time messaging functionality and document-to-PDF conversion runs on our own infrastructure (hosting provider is described in section 5.3 below); document content processed for previews does not leave our servers.
5. Disclosure and Sharing of Personal Data
5.1 No Sale of Data
We do not sell, rent, trade, or otherwise commercially disclose your personal data to third parties under any circumstances.
5.2 Investor Engagement Analytics
The provision of investor engagement analytics to Startup Clients constitutes a core feature of the Platform’s services and does not constitute a sale or commercial disclosure of personal data. Investor engagement analytics are generated through the investor’s interaction with a specific Startup Client’s own data room and are disclosed solely to that Startup Client in connection with the Platform’s services. The analytics shared are limited to data relating to the investor’s engagement with that specific Startup Client’s materials and do not include information about the investor’s activity in any other data room or on any other part of the Platform.
5.3 Service Providers and Third-Party Disclosures
We may share your personal data with third-party service providers who assist us in operating the Platform, subject to appropriate contractual safeguards. These providers are authorised to use your personal data only as necessary to provide services to us and are contractually obligated to protect your data in accordance with applicable data protection law. Categories of third-party service providers include:
Hosting and infrastructure – Digital Ocean, where all Platform data is stored, including your account details and the documents uploaded to data rooms.
Email delivery — Mailgun (EU region): receives recipient email addresses and the contents of account, security, and notification emails.
Payment processing — Stripe: receives your name, email, billing details, and any tax identifier you provide. We do not store full payment-card numbers ourselves; card data is handled by Stripe.
AI document analysis — Anthropic (with OpenAI as a fallback): when you use the document analysis feature, the text extracted from the relevant document is sent to our AI provider to generate the analysis. Under the provider's API terms, this content is not used to train its models.
Sign-in providers — Google and GitHub: if you choose to sign in with one of them, we receive your email address, name, and profile picture. Their handling of your data is governed by their own privacy policies.
5.4 Legal and Regulatory Disclosures
We may disclose your personal data where required to do so by applicable law, regulation, legal process, or governmental request, or where we believe in good faith that such disclosure is necessary to: (a) comply with a legal obligation; (b) protect and defend the rights or property of Quokka S.àr.l.; (c) prevent or investigate possible wrongdoing in connection with the Platform; or (d) protect the personal safety of users of the Platform or the public.
5.5 Business Transfers
In the event of a merger, acquisition, reorganisation, sale of assets, or similar corporate transaction involving Quokka S.àr.l., your personal data may be transferred as part of that transaction. We will notify you via email or prominent notice on the Platform of any such change in ownership or control of your personal data.
6. International Data Transfers
6.1 Storage Within the European Union
Your personal data is stored on servers located within the European Union. Backup copies of your data may be maintained at multiple locations within the EU to ensure service continuity and resilience. We do not store your data outside the European Economic Area (“EEA”) as part of our standard operations.
6.2 Transfers to Third-Country AI Service Providers
When you initiate AI-assisted services through the Platform, your data may be transmitted to third-party AI service providers whose processing infrastructure is located outside the European Economic Area, including in the United States. Such transfers occur only at your express request and solely for the purpose of fulfilling the specific AI-assisted service you have initiated.
Where personal data is transferred to a third country that has not been the subject of an adequacy decision by the European Commission, we ensure that appropriate safeguards are in place to protect your data, including:
Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR, executed between Quokka S.àr.l. and each relevant sub-processor;
Supplementary technical and organisational measures to protect data in transit and at rest, including encryption, access controls, and data minimisation; and
Assessment of the legal framework in the recipient country to evaluate whether it provides an adequate level of protection, and implementation of additional safeguards where necessary.
We conduct transfer impact assessments in accordance with guidance issued by the European Data Protection Board (“EDPB”) to evaluate the adequacy of protections afforded to transferred data. Where a third country has been the subject of an adequacy decision by the European Commission, transfers to that country may proceed without additional safeguards.
7. Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required by applicable law. The following retention periods apply:
| Data Category | Retention Period |
|---|---|
| Account data (name, email, profile) | Retained for the duration of your account. Within 30 days of an account-deletion request, account data is permanently deleted or irreversibly anonymised. |
| User Content (uploaded documents) | Retained for the duration of your account. Within 30 days of an account-deletion request, uploaded content is permanently deleted |
| Payment and transaction records | Retained for the period required by applicable Luxembourg tax and commercial law (typically 10 years), independently of account deletion. Card data is held by our payment processor (Stripe), not by us. |
| Usage analytics and metadata | Retained for up to 24 months from collection, then automatically deleted. |
| Investor engagement analytics | Retained for up to 24 months from collection, then automatically deleted. |
| Support feedback | Retained for up to 90 days from collection, then automatically deleted. |
| Technical and security logs | Application access and authentication logs: 30 days. In-app audit logs (document-analysis and activity logs): up to 24 months, then automatically deleted. Session records expire after a period of inactivity. |
Following the expiration of the applicable retention period, personal data is securely deleted or irreversibly anonymised. Anonymised data, from which you can no longer be identified, may be retained indefinitely for the purposes of Platform improvement and aggregate statistical analysis.
7.1 Account deletion
When you ask us to delete your account, we deactivate it and remove your profile, profile picture, and sign-in credentials. Records that are tied to other users — for example, the fact that a document in another company's data room was viewed — may be retained where we have a legitimate or legal reason to keep them. To request erasure of your personal data, contact us at support@dataroom.pro.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration. These measures include, but are not limited to:
Encryption of data in transit using industry-standard TLS/SSL protocols;
Encryption of data at rest on our servers;
Access controls restricting data access to authorised personnel on a need-to-know basis;
Regular security assessments and vulnerability testing; and
Secure data backup procedures within the European Union.
While we take all reasonable measures to protect your data, no method of electronic transmission or storage is entirely secure. We cannot guarantee absolute security, and you acknowledge that you transmit data to the Platform at your own risk.
9. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we shall, in accordance with Article 33 of the GDPR, notify the competent supervisory authority (the Commission Nationale pour la Protection des Données, or “CNPD”) without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of affected individuals, we shall, in accordance with Article 34 of the GDPR, communicate the breach to affected users without undue delay, providing information on the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
10. Your Rights Under the GDPR
As a data subject under the GDPR, you have the following rights with respect to your personal data:
Right of access (Art. 15): You have the right to request confirmation as to whether your personal data is being processed and, if so, to obtain a copy of that data together with information about the processing.
Right to rectification (Art. 16): You have the right to request the correction of inaccurate personal data or the completion of incomplete personal data.
Right to erasure (Art. 17): You have the right to request the deletion of your personal data where, among other grounds, the data is no longer necessary for the purposes for which it was collected, or where you withdraw consent.
Right to restriction of processing (Art. 18): You have the right to request the restriction of processing of your personal data in certain circumstances, such as where you contest the accuracy of the data.
Right to data portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to object (Art. 21): You have the right to object to the processing of your personal data where such processing is based on legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds.
Right to withdraw consent (Art. 7(3)): Where processing is based on consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
Right to lodge a complaint (Art. 77): You have the right to lodge a complaint with the competent supervisory authority. The supervisory authority for Luxembourg is the Commission Nationale pour la Protection des Données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, Luxembourg (https://cnpd.public.lu).
To exercise any of these rights, please contact us at legal@dataroom.pro. We will respond to your request within thirty (30) calendar days, or such longer period as is permitted by applicable law. We may request verification of your identity before processing your request.
11. Children’s Privacy
The Platform is not directed at individuals under the age of eighteen (18), and we do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected personal data from an individual under the age of 18, we shall take reasonable steps to delete such data promptly. If you believe that a minor has provided personal data to us, please contact us at legal@dataroom.pro.
12. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy at any time. Material changes will be communicated to you by publication of the revised Privacy Policy on the Platform and by updating the “Effective Date” at the top of this document. Where required by applicable law, we will obtain your consent to material changes before they take effect. Your continued use of the Platform following publication of an amended Privacy Policy constitutes your acceptance of the revised terms.
We encourage you to review this Privacy Policy periodically to remain informed about how we protect your data.
13. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Grand Duchy of Luxembourg. Any disputes arising in connection with this Privacy Policy shall be resolved in accordance with the dispute resolution provisions set forth in the Terms of Service.
14. Language
This Privacy Policy has been drawn up in the English language. The English language version shall be the authoritative version for the purposes of interpretation and construction. In the event of any conflict between the English version and any translation, the English version shall prevail.
Contact Information
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us at:
Quokka S.àr.l.
58 Boulevard Marcel Cahen, L-1311 Luxembourg, Grand Duchy of Luxembourg
Register Number: B280011
VAT: LU35321866
Privacy and Data Protection Enquiries: legal@dataroom.pro
Website: https://dataroom.pro