Data room
Privacy notice
What we collect when you use the data room, why, how long we keep it, and your rights.
PRIVACY NOTICE
Plurel Inc. Data Room · Version 2026-10-05
This notice explains how Plurel Inc. (“Plurel,” “we,” “us”) handles personal information about people who are invited to our private data room at dataroom.plurelinc.com (the “Room”). The Room is used only to share confidential information with prospective investors, banks, processors and other business partners who have been invited individually. For the purposes of the EU and UK General Data Protection Regulation, Plurel is the controller of the personal information described here.
1. What we collect
Information we enter when we invite you: your name, your firm, your email address, the kind of relationship (for example investor or bank), the parts of the Room you can open, and internal notes about our discussions.
Information you give us: the email address you sign in with; and, when you sign the Mutual Nondisclosure Agreement, your printed name, drawn signature, title, the entity you sign for, and the email address you give for notices. Each time you sign in we email you a one-time six-digit code. We store only a keyed, one-way hash of each code, and the code stops working after 10 minutes, after it is used once, or after 5 wrong tries.
Information recorded when you use the Room: the date and time you ask for a sign-in code, sign in, sign out and sign the agreement; each note you read and each document you open; requests you send for restricted items and the message you include; wrong codes entered; your IP address and the approximate country it indicates; and your browser’s user-agent string when you sign in and when you sign.
Information placed in documents: every document you open is marked with your name, firm, email address, a reference code, your IP address and the time it was opened, both visibly and across each page. This lets us trace any copy that leaves the Room.
We do not ask for, and ask you not to provide, sensitive categories of information such as health, biometric or financial-account data. We do not knowingly collect information from anyone under 18.
2. Activity monitoring
Because the Room holds confidential information, we monitor its use. Plurel staff who manage the Room can see which notes and documents you open, when, and from which network. We use this to protect the information, to detect invitations that may have been shared or accounts that may have been compromised, to follow up on your interest, and to enforce the Mutual Nondisclosure Agreement. We do not use it to make automated decisions that produce legal or similarly significant effects about you.
3. Why we use it, and our legal bases
- To give you access and keep the Room secure (sending and checking your sign-in codes, signing you out after inactivity, rate-limiting, preventing and investigating unauthorized disclosure). Legal basis: our legitimate interest in protecting confidential information, and where applicable the performance of our agreement with you.
- To form and keep a record of the Mutual Nondisclosure Agreement. Legal basis: entering into and performing a contract, and establishing, exercising or defending legal claims.
- To evaluate and pursue a business relationship with you and your firm, including answering your requests. Legal basis: our legitimate interest in developing our business.
- To comply with law and respond to lawful requests from authorities. Legal basis: legal obligation.
Where we rely on legitimate interests, we have weighed them against your rights and consider the processing necessary and proportionate given the confidential nature of the Room. You may object at any time (see section 8).
4. Cookies
The Room uses only cookies that are strictly necessary for it to work securely. They are first-party, marked secure and HTTP-only, and never used for analytics or advertising:
__Host-room-login: ties a sign-in code to the browser that asked for it, so a forwarded email can’t be used elsewhere. Expires after 10 minutes, or when you sign in.__Host-room: keeps you signed in. Ends after 30 minutes without activity, after 12 hours at most, or when you sign out.__Host-room-email: remembers the address you signed in with, so next time you only need the code. Expires after 60 days; “Use a different email” removes it immediately.
No analytics, advertising or tracking scripts run in the Room, and it loads nothing from other websites.
5. Who we share it with
We do not sell your personal information and we do not share it for cross-context behavioral advertising. We share it only with:
- Service providers that run the Room for us, under contracts that limit their use of the information to providing their service: Cloudflare (hosting, the Room’s database and file storage, network delivery and security, including determining approximate country from IP address); Loops (sending the emails that carry your sign-in codes, which means it receives your email address, first name and each code); and, if we enable it, Slack (internal notification that you requested access, including your name, firm and the items requested).
- Our professional advisers, such as lawyers and accountants, under a duty of confidentiality.
- Authorities or other parties where required by law, or where necessary to establish, exercise or defend legal claims, including enforcing the Mutual Nondisclosure Agreement.
- A successor in connection with a merger, financing, acquisition or sale of assets, subject to confidentiality obligations.
6. Where it is stored, and international transfers
Plurel is based in Los Angeles, California. We store the Room’s data with Cloudflare in the United States: records in Cloudflare D1, and documents and signatures in Cloudflare R2, encrypted with a key that Plurel holds. Our service providers may process information in the United States and other countries. Where we transfer personal information from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum) or another lawful transfer mechanism. You can ask us for a copy of the relevant safeguards.
7. How long we keep it
We keep your invitation, access records and activity log while your access is active and for as long as the obligations in the Mutual Nondisclosure Agreement survive, which is generally up to five years after it ends. We keep the signed agreement and its execution record for the same period, or longer if needed to establish, exercise or defend legal claims. Security records such as wrong sign-in codes are kept for the same period. After that, we delete or anonymize the information. You can ask us to delete it sooner (see section 8), subject to our need to keep a record of the signed agreement.
8. Your rights
Depending on where you live, you may have the right to: access the personal information we hold about you and receive a copy; correct it; delete it; restrict or object to our use of it, including where we rely on legitimate interests; receive it in a portable format; and withdraw consent where we rely on consent. If you are in the EEA or the UK, you may also complain to your local data protection authority.
California residents: you have the right to know what personal information we collect, use and disclose, to request deletion and correction, and not to be discriminated against for exercising these rights. The categories we collect are identifiers (name, email, IP address), professional information (firm and title), internet activity within the Room, approximate geolocation (country), and your signature. We do not sell or share personal information as those terms are defined in California law, and we do not use sensitive personal information to infer characteristics about you.
To exercise any right, email contact@plurelinc.com from the address we have on file, or ask the person who invited you. We will verify the request and answer within one month (45 days for California requests), and tell you if we need longer. You may use an authorized agent where the law allows.
9. Security
We protect the Room with one-time sign-in codes sent only to your invited address and usable only in the browser that asked for them, sessions that end after 30 minutes without activity and after 12 hours at most, documents encrypted at rest with a key Plurel holds, encrypted connections, strict browser security policies, per-reader watermarks, rate limits, and an audit log of every administrative action. No system is perfectly secure; if we become aware of a breach affecting your personal information, we will notify you and the authorities as the law requires.
10. Changes
If we change this notice, we will update the version above. If a change is material, we will tell you in the Room before it applies to you. This version reflects the Room’s move to Cloudflare and to sign-in by emailed code: Convex and Clerk no longer process information about visitors to the Room.
11. Contact
Plurel Inc., attention: Privacy, Los Angeles, California. Email contact@plurelinc.com.