ModernDataRoom
Privacy Policy
Last updated: September 23, 2026
This policy explains how ModernDataRoom (“ModernDataRoom”, “we”, “us”) collects, uses, shares and protects personal information when you use our websites, applications and services (the “Service”). The Service lets organizations (“Operators”) build and share virtual data rooms with people they invite (“Visitors”).
1. Our role
For content an Operator uploads to a data room, and for information about the Visitors an Operator invites, we act as a service provider (processor) on the Operator’s behalf and follow the Operator’s instructions. For account, billing and website information about our own customers, we act as the controller. If you are a Visitor with questions about a data room, contact the Operator who invited you.
2. Information we collect
- Account information: name, email address, workspace name, role and sign-in records.
- Customer content: documents, pages, messages, brand assets, scripts and other material Operators add to the Service.
- Visitor activity: which rooms, sections and documents a Visitor opens, for how long, questions asked of the room assistant, and access requests. This is shown to the Operator who invited the Visitor.
- Voice information: if an Operator enables voice features, spoken questions and generated answers, and, only with the speaker’s recorded consent, voice samples used to create a voice clone. Consent can be withdrawn, after which the clone is deleted at our voice provider.
- Connected accounts: if you connect a third-party account (for example Google Drive, Gmail, Google Calendar, a CRM or accounting system), we access only the data needed for the features you use, under the permissions you grant.
- Billing information: plan, subscription and invoice records. Card details are collected and stored by our payment processor, Stripe; we do not store full card numbers.
- Technical information: IP address, browser and device information, and logs needed to operate and secure the Service.
3. How we use information
- To provide, maintain and secure the Service, including its AI features.
- To authenticate users, enforce access controls and prevent abuse.
- To process payments and manage subscriptions.
- To send service messages such as invitations, notifications and receipts.
- To provide support and respond to requests.
- To comply with law and enforce our Terms of Service.
We do not sell personal information, and we do not use customer content or connected account data to train generalized AI models.
4. AI features
The Service uses AI models to answer questions about a room, draft content and prepare media. Content is sent to the model provider only to perform the requested task, under terms that prohibit using it to train their models. Actions that send, publish, change settings or spend money require the Operator’s approval, and AI-generated content is labelled.
5. Google user data
ModernDataRoom’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the features you request (for example importing files into a room or scheduling a meeting), we do not use it for advertising, we do not sell it, and people at ModernDataRoom do not read it except with your permission, for security, or as required by law.
6. How we share information
We share personal information only:
- With the Operator whose room or workspace the information belongs to, and with the people the Operator chooses to share a room with.
- With service providers that host, process or support the Service on our behalf, such as cloud hosting and database providers, AI model providers, voice and video providers, email delivery, payment processing, integration and background-job providers. They may use the information only to provide their services to us.
- When required by law, or to protect the rights, safety and security of others.
- In connection with a merger, acquisition or sale of assets, with notice to you.
7. Retention
We keep information for as long as the Operator’s account is active or as needed to provide the Service, then delete or anonymize it, except where we must keep it longer to meet legal obligations, resolve disputes or enforce agreements. Operators control the retention of room content and some visitor records.
8. Security
We use encryption in transit and at rest, tenant isolation enforced in the database, access controls, audit logging and monitoring. No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.
9. Where information is processed
Our primary database is hosted in Canada. Some service providers process information in other countries, including the United States. Where required, we use appropriate safeguards for international transfers.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, contact us at the address below. If your information is in a data room, we may refer your request to the Operator. You may also complain to your local data protection authority.
11. Children
The Service is for business use and is not directed to anyone under 16.
12. Changes
We may update this policy. We will post the new version here with its date and, for material changes, notify account holders.
13. Contact
Questions or requests: privacy@moderndataroom.com.
See also our Terms of Service.