Legal

Last updated: July 29, 2026

Data Processing Agreement

Draft summary for legal review. A standard DPA is available to any customer on request during the design-partner phase. Email legal@pe-dealroom.com and we will send the signed template. The summary below is not a substitute for the signed DPA.

Last updated below.

1. Parties and roles

  • Controller: the customer firm.
  • Processor: PE Dealroom.
  • The processor acts solely on the documented instructions of the controller, as set out in the Terms of Service, the order form, and this DPA.

2. Subject matter and duration

  • Subject matter: provision of the PE Dealroom service.
  • Duration: for the term of the order form, plus the retention period set out in the Privacy Policy.

3. Nature and purpose of processing

Hosting, transmitting, storing, retrieving, displaying, indexing, and generating derivative artefacts (summaries, dossiers, plans) from Customer Data, to provide the Service.

4. Types of personal data

  • Contact and account data of the controller's users and, where uploaded, its counterparties, advisors, and portfolio-company personnel.
  • Business content (deal records, fund and LP records, documents, notes, portfolio KPIs).

5. Data subjects

The controller's employees and authorised users, and individuals referenced in Customer Data (for example, counterparties, advisors, portfolio-company executives).

6. Subprocessors

We engage subprocessors for hosting, storage, email delivery, and AI inference. The current list is available on request; a public list is coming. We will give the controller prior notice of changes and an opportunity to object on reasonable grounds.

7. Security measures

  • Row-level tenant isolation and org-scoped access-control policies.
  • Encryption of Customer Data in transit and at rest.
  • Private document storage buckets with per-workspace access rules.
  • Role-based access control and least-privilege service credentials.
  • Per-workspace audit log of key data changes.
  • Regular review of access, dependencies, and configuration.

8. Assistance to the controller

We will provide reasonable assistance to the controller to respond to data subject requests, and to comply with security, breach notification, data protection impact assessment, and prior consultation obligations, taking into account the nature of processing and the information available to us.

9. Personal data breach

We will notify the controller without undue delay after becoming aware of a personal data breach affecting Customer Data, with the information we have at that point and follow-up updates as it becomes available.

10. International transfers

Where Customer Data is transferred outside the controller's region, we rely on appropriate safeguards, including the Standard Contractual Clauses, incorporated by reference into the DPA.

11. Return and deletion

On termination or expiry, the controller may export Customer Data. We will delete Customer Data within 30 days of termination, unless retention is required by law.

12. Audit

Once per year and on reasonable prior notice, the controller may request information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and to protecting other customers' data.

13. Order of precedence

If there is a conflict between this DPA, the Terms of Service, and the order form, the DPA prevails on data-protection matters.

14. Contact