ModernDataRoom

Privacy Policy

Last updated: September 23, 2026

This policy explains how ModernDataRoom (“ModernDataRoom”, “we”, “us”) collects, uses, shares and protects personal information when you use our websites, applications and services (the “Service”). The Service lets organizations (“Operators”) build and share virtual data rooms with people they invite (“Visitors”).

1. Our role

For content an Operator uploads to a data room, and for information about the Visitors an Operator invites, we act as a service provider (processor) on the Operator’s behalf and follow the Operator’s instructions. For account, billing and website information about our own customers, we act as the controller. If you are a Visitor with questions about a data room, contact the Operator who invited you.

2. Information we collect

3. How we use information

We do not sell personal information, and we do not use customer content or connected account data to train generalized AI models.

4. AI features

The Service uses AI models to answer questions about a room, draft content and prepare media. Content is sent to the model provider only to perform the requested task, under terms that prohibit using it to train their models. Actions that send, publish, change settings or spend money require the Operator’s approval, and AI-generated content is labelled.

5. Google user data

ModernDataRoom’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you request (for example importing files into a room or scheduling a meeting), we do not use it for advertising, we do not sell it, and people at ModernDataRoom do not read it except with your permission, for security, or as required by law.

6. How we share information

We share personal information only:

7. Retention

We keep information for as long as the Operator’s account is active or as needed to provide the Service, then delete or anonymize it, except where we must keep it longer to meet legal obligations, resolve disputes or enforce agreements. Operators control the retention of room content and some visitor records.

8. Security

We use encryption in transit and at rest, tenant isolation enforced in the database, access controls, audit logging and monitoring. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.

9. Where information is processed

Our primary database is hosted in Canada. Some service providers process information in other countries, including the United States. Where required, we use appropriate safeguards for international transfers.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at the address below. If your information is in a data room, we may refer your request to the Operator. You may also complain to your local data protection authority.

11. Children

The Service is for business use and is not directed to anyone under 16.

12. Changes

We may update this policy. We will post the new version here with its date and, for material changes, notify account holders.

13. Contact

Questions or requests: privacy@moderndataroom.com.

See also our Terms of Service.