Privacy Policy
Last updated: 8 August 2026
Deal Room is a fundraising and deal-management platform operated by Roke Weaver LTD (“Roke Weaver”, “we”, “us”, “our”). This policy explains what personal data we collect across deal-room.ai (our marketing site), app.deal-room.ai (the platform used by our clients), and the token-gated investor portal, why we collect it, who we share it with, and the rights you have over it. Roke Weaver is the data controller for the personal data described here, unless we are processing data on behalf of a client organisation (e.g. a fund manager's investor and deal data), in which case that organisation is the controller and we act as its processor.
1. Scope of this policy
This policy applies to everyone who interacts with Deal Room: registered users of the platform (fund managers and their team members), investors and other recipients who access a shared data room or investor portal via a tokenised link, and visitors to our marketing site. It does not cover third-party websites or services we link to, which have their own privacy practices.
2. Information we collect
2.1 Account and identity data
When you register or are invited to Deal Room, we collect your name, work email address, and password or authentication credentials through our authentication provider, Clerk. If you sign in via a third-party identity provider, we receive the profile information that provider shares with us (typically name, email, and profile photo).
2.2 Business and deal data
Deal Room is built to manage fundraising and deal activity. Depending on how a client uses the platform, this can include information about companies, funds, investment firms, individual investors and contacts, deals and fundraises, tasks, pipeline stages, scoring and research notes, and other business records entered by users. Where this data identifies an individual (for example, an investor's contact details or an LP's commitment history), it is personal data and is covered by this policy.
2.3 Documents and data room content
Files uploaded to a data room — pitch decks, financial statements, due-diligence materials, signed agreements, and similar documents — are stored on our infrastructure and, where a client shares a data room with an investor, made available through a tokenised, access-controlled link. We process the contents of these documents only as necessary to store, index, and display them, and to power optional AI features described in section 2.6.
2.4 Connected communications and calendar data
If a user connects a Gmail, Outlook, or LinkedIn account, or a calendar, Deal Room reads that account's emails, messages, contacts, and calendar events and displays them inside the platform so the user can manage deal-related communications in one place. Depending on the account and feature this can also include composing and sending emails and drafts on the user's behalf, moving messages to trash, and creating, editing, and deleting calendar events — including on calendars shared with the user by someone else, not only the user's own primary calendar. We connect to these accounts through our integration providers Unipile and Nylas (Gmail, Outlook, LinkedIn, and calendar) and Nango (Google Drive and OneDrive, letting a user browse and attach files from that account). These connections are opt-in, made directly by the user, and can be disconnected at any time from account settings; disconnecting stops all further access, and any previously synced copy of that account's data held in our systems is deleted within a reasonable period unless retained for a purpose described in section 7. We only mirror an email thread, chat, or file into a client's underlying business records when the user explicitly links it to a deal, project, task, or contact — routine reading, archiving, or starring does not. No Deal Room employee reads the content of a user's connected email or calendar data except: with the user's consent, to investigate suspected abuse or a security incident, to comply with a legal obligation, or as part of a merger, acquisition, or asset transfer, each subject to confidentiality obligations. Our use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.5 Meetings and scheduling
If a user books or manages meetings through our scheduling integration (Cal.eu), we process the attendee names, email addresses, and meeting details necessary to schedule, remind, and (where enabled) generate a meeting brief or summary.
2.6 AI-assisted features
Deal Room uses artificial intelligence to help users draft communications, summarise documents, generate meeting briefs, score and match deals, and answer questions inside an in-app assistant (“Comms Copilot”). This relies on third-party AI model providers — accessed directly or through model-routing/gateway services — and on specialised web research, data-enrichment, and workflow-automation tools, for example to look up publicly available company and contact information, or to connect to other apps and services a user has enabled. Using these features may send relevant content (such as an email thread, a document extract, or a user's prompt) to the relevant provider for processing. Content sent to these providers is used to generate a response to the request that triggered it; it is not used by us to train our own models, and our agreements with these providers prohibit them from using it to train theirs. Certain automated actions that would send a message or post to a third party on a user's behalf require the user to review and approve them before they are sent, unless the user has explicitly enabled an autonomous mode for a narrow, pre-defined set of actions. An up-to-date list of the specific providers we use for these purposes is available on request — see section 12.
2.7 Usage and device data
We automatically collect limited technical and usage information — such as pages viewed, features used, timestamps, browser type, and IP address — to secure the platform, diagnose problems, and understand how it is used. We use a first-party, cookie-free analytics mechanism (a randomly generated session identifier stored in your browser's local storage) rather than third-party advertising or tracking cookies.
2.8 Communications with us
If you email us or otherwise contact us for support, we keep a record of that correspondence, including any information you choose to include in it.
3. How we use personal data, and our legal bases
We use personal data to:
- Create and administer accounts, and authenticate users (performance of a contract);
- Provide the core functionality of the platform — data rooms, pipeline and task management, communications, scheduling, and AI-assisted features (performance of a contract);
- Operate the investor portal and record who has viewed or engaged with shared materials, on behalf of the client who shared them (performance of a contract / legitimate interests);
- Send transactional and account-related emails, such as verification, password resets, and task or meeting reminders (performance of a contract / legitimate interests);
- Maintain the security, integrity, and availability of the platform, including monitoring for abuse and diagnosing errors (legitimate interests);
- Improve and develop the platform (legitimate interests);
- Comply with our legal obligations, including responding to lawful requests from authorities; and
- Where you have given it, act on any specific consent you provide (for example, to receive marketing communications), which you may withdraw at any time.
We do not sell personal data, and we do not use personal data for third-party advertising.
4. Who we share data with
We share personal data with the following categories of recipients, only as needed to provide the service:
- Your own organisation. If you are an investor or contact interacting with a shared data room, the client who invited you (e.g. the fund manager) can see your engagement with the materials they shared.
- Sub-processors. Vendors we rely on to run the platform, listed in section 5 below. Each is bound by a data processing agreement requiring appropriate confidentiality and security safeguards.
- Professional advisers and successors. If required to obtain advice, or in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations.
- Authorities. Where required by law, regulation, legal process, or governmental request.
5. Sub-processors we use
The table below lists the categories of infrastructure and service providers that may process personal data on our behalf. We add or change providers from time to time as the platform evolves; contact us using the details in section 12 for the current list.
| Provider | Purpose |
|---|---|
| Clerk | Authentication and account/session management |
| Railway | Application database and hosting infrastructure |
| Vercel | Application hosting and delivery |
| DataGol | Internal CRM and business-data platform |
| Unipile | Gmail, Outlook, LinkedIn, and calendar connections (opt-in) |
| Nylas | Gmail, Outlook, and calendar connections (opt-in) |
| Nango | Google Drive and OneDrive connections (opt-in) |
| AI model providers (accessed directly or via routing/gateway services) | AI-assisted drafting, summarisation, scoring, and the Comms Copilot assistant |
| Web research, data-enrichment, and workflow-automation tools | Public company/contact research and enrichment; connecting to other apps and services a user enables |
| Cal.eu | Meeting scheduling |
| DocuSeal | Electronic signature processing |
| Resend | Transactional email delivery |
| Cloudflare | File storage and content delivery |
| Meilisearch | Search indexing within the platform |
| Sentry | Error monitoring and diagnostics |
| Slack | Optional team notifications, only if a client enables this integration |
6. International data transfers
We and our sub-processors operate globally, which means personal data may be transferred to and processed in countries outside the United Kingdom or European Economic Area, including the United States. Where we transfer personal data internationally, we rely on appropriate safeguards recognised under UK and EU data protection law, such as the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, or transfers to jurisdictions benefiting from an adequacy decision.
7. Data retention
We retain personal data for as long as an account is active and as needed to provide the service. After an account is closed, we retain data for a reasonable period to allow for reactivation, comply with legal or contractual obligations (for example, financial and audit records), resolve disputes, and enforce our agreements, after which it is deleted or anonymised. You can request earlier deletion as described in section 9, subject to any legal retention requirements.
8. Security
We apply technical and organisational measures designed to protect personal data, including encryption in transit, access controls and role-based permissions, row-level security on our databases, and webhook/API signature verification for inbound integrations. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Your rights
If you are located in the UK or EEA, you have the right to: access the personal data we hold about you; request correction of inaccurate data; request erasure of your data; restrict or object to certain processing; request a portable copy of data you provided to us; and withdraw consent where processing is based on consent. You also have the right to complain to your local data protection authority (in the UK, the Information Commissioner's Office).
If you are a California resident, you have rights under the CCPA/CPRA to know what personal information we collect and how it is used and shared, to request access to or deletion of that information, to correct inaccurate information, and to opt out of the sale or sharing of personal information — though as noted above, we do not sell or share personal information for cross-context behavioural advertising. We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, contact us using the details in section 12. If your data was provided to us by one of our clients (for example, because you are an investor they invited into a data room), we will generally direct you to that client, as they control the data; we will assist them in responding to your request.
10. Cookies and similar technologies
Our authentication provider, Clerk, sets essential cookies needed to keep you signed in and maintain session state; these cannot be disabled without breaking sign-in. We do not use third-party advertising or tracking cookies. As described in section 2.7, our own usage analytics rely on a first-party identifier stored in local storage rather than a cookie.
11. Children
Deal Room is a business-to-business platform intended for professional use and is not directed at, or knowingly used by, individuals under 18. We do not knowingly collect personal data from children.
12. Contact us
If you have questions about this policy or how we handle personal data, or want to exercise any of the rights above, contact:
Roke Weaver LTD
team@rokeweaver.com
13. Changes to this policy
We may update this policy from time to time to reflect changes to our practices or for legal, operational, or regulatory reasons. We will update the “Last updated” date above and, for material changes, notify users by email or an in-app notice. Continued use of Deal Room after a change takes effect constitutes acceptance of the updated policy.