Legal
Privacy Policy
Last Updated: January 2026
1. Introduction
This Privacy Policy describes how Dealdrive AS, a Norwegian limited company with organization number 934 150 937, with registered address at Arbins gate 2, 0253 Oslo, Norway ("Dealdrive," "we," "us," or "our"), collects, uses, and protects personal data in connection with the Dealdrive virtual data room platform (the "Service").
This Policy applies to all users of the Service, including Customers, Authorized Administrators, and Invited Users. It covers data collected through the Service, our website at dealdrive.co, and related communications.
Our Role: Dealdrive is the data controller for personal data we collect about users (such as account and usage data). For personal data within Customer Content uploaded to Data Rooms, the Customer is the data controller and Dealdrive acts as a data processor under our Data Processing Agreement at dealdrive.co/legal/dpa.
2. Personal Data We Collect
2.1 Account Information
When you register, we collect: name, email address, contact details, organization name and role, login credentials (stored encrypted), and two-factor authentication information where enabled.
2.2 Billing Information
For Customers, we collect: billing contact details, payment method information (processed by our payment providers), and transaction history.
2.3 Usage Data
We automatically collect: access logs (IP addresses, device information, browser type, access times), activity within Data Rooms (documents viewed, downloaded, printed), feature usage patterns, and error logs.
2.4 Communications
When you contact us, we collect: communication content, attachments, and associated metadata.
2.5 Customer Content
Users may upload documents containing personal data. Dealdrive processes this on behalf of the relevant data controller (Customer or Invited User's principal) under our DPA. We do not access or use such data except to provide the Service or as required by law.
2.6 AI Feature Data
When you use AI features, we process submitted content to generate analyses and insights. This is governed by the terms regarding Customer Content.
3. How We Use Personal Data
We use personal data to:
Provide the Service: Create and manage accounts, provide Data Room access, process payments, authenticate users, generate audit trails, and provide support.
Improve the Service: Analyze usage to improve functionality, identify and fix issues, develop new features, and monitor performance and security.
Communicate: Send service notifications, security alerts, billing notices, feature updates, respond to inquiries, and send marketing communications (with your consent).
Maintain Security: Detect and prevent security incidents, unauthorized access, fraud, and abuse; enforce our terms.
Comply with Law: Meet legal obligations, respond to lawful requests, establish or defend legal claims, and protect rights and safety.
Create Anonymized Data: We may create anonymized, aggregated data that cannot identify individuals, which we may use without restriction for analytics, research, and product development.
4. Legal Bases
Under GDPR, we process personal data based on:
Contract Performance: Processing necessary to provide the Service, manage your account, process payments, and provide support.
Legitimate Interests: Processing for service improvement, security, fraud prevention, analytics, and service communications, balanced against your rights.
Legal Obligations: Processing to comply with tax, accounting, and other legal requirements.
Consent: Processing for marketing communications or optional features, which you may withdraw at any time.
5. Sharing Personal Data
We share personal data with:
Service Providers: Third parties assisting with hosting, payments, analytics, support, and security, bound by data protection obligations.
Customers and Administrators: For Invited Users, your Data Room activity (documents viewed, downloaded, printed) may be visible to the Controlling Party. Audit trails are a core Service feature.
Other Users: Your name and contributions to collaborative features may be visible to other authorized Data Room users.
Legal Requirements: Where required by law or valid legal process, with notice where permitted.
Business Transfers: In connection with merger, acquisition, or asset sale, with notice of any changes.
We do not sell personal data or share it with third parties for their independent commercial purposes.
6. International Transfers
Dealdrive is based in Norway and primarily processes data within the European Economic Area ("EEA"). Where data is transferred outside the EEA, we ensure appropriate safeguards including adequacy decisions, Standard Contractual Clauses, or other recognized mechanisms.
Our sub-processors and their locations are listed at dealdrive.co/legal/subprocessors.
7. Data Security
We implement appropriate technical and organizational measures including: encryption in transit and at rest, access controls and authentication, regular security assessments, employee training, incident response procedures, and physical security at data centers.
You are responsible for maintaining credential confidentiality and enabling available security features such as two-factor authentication.
In the event of a breach likely to risk your rights, we will notify you without undue delay as required by law.
8. Data Retention
Account Data: Retained while your account is active and for a reasonable period afterward to handle inquiries or disputes.
Billing Records: Retained as required by tax and accounting regulations, typically five (5) years.
Usage Logs: Retained in accordance with service documentation and legal requirements.
Customer Content: Retained for thirty (30) days following subscription termination, then deleted unless law requires retention. Customers may export content before termination.
When no longer required, data is deleted or anonymized according to our retention procedures.
9. Your Rights
Under GDPR, you have rights to:
- Access your personal data and information about its processing
- Rectification of inaccurate or incomplete data
- Erasure in certain circumstances (e.g., data no longer needed, consent withdrawn)
- Restriction of processing in certain circumstances
- Data Portability to receive your data in machine-readable format
- Object to processing based on legitimate interests
AI Features: Our AI features are assistive tools and do not make automated decisions with legal or similarly significant effects.
To exercise your rights: Contact [email protected]. We will respond within one (1) month, extendable by two (2) months for complex requests. We may verify your identity before fulfilling requests.
Complaints: You may lodge complaints with a supervisory authority. In Norway: Datatilsynet at datatilsynet.no.
10. Cookies
We use cookies and similar technologies:
Essential Cookies: Required for Service functionality, authentication, and security.
Functional Cookies: Enable enhanced functionality and personalization.
Analytics Cookies: Help us understand Service usage to improve performance.
Marketing Cookies: Used for relevant advertising (only with consent).
You can manage preferences through browser settings or our cookie consent mechanism. Disabling certain cookies may affect functionality.
11. Children's Privacy
The Service is for business use and not directed at individuals under 18. We do not knowingly collect data from children. If we learn we have collected such data without parental consent, we will delete it.
12. Changes
We may update this Policy to reflect changes in practices, law, or the Service. Material changes will be notified by posting the revised Policy and, for significant changes, by email or through the Service. Changes are effective on the posted date. Continued use constitutes acceptance.
13. Contact
Questions about this Policy or our data practices:
Dealdrive AS Email: [email protected] Website: dealdrive.co Address: Arbins gate 2, 0253 Oslo, Norway
For data protection matters, you may also contact Datatilsynet at datatilsynet.no.
© 2026 Dealdrive AS. All rights reserved.