Privacy policy
Last updated: 2026-07-19
What data we collect, why, and what you can do about it. Without the legal fog.
1. Data controller
The controller of your personal data is Infinity Team, operator of DealRoom. For anything data-related: contact@infinityteam.io.
2. The demo version — what changes
In the current demo version there are no user accounts and no user database. Anything you type into the demo (a room, a message) stays in your browser's memory and disappears on refresh — it never reaches our server and nobody else sees it.
So at this stage the only personal data that actually reaches us is what you send us yourself — for example an email address when applying to the beta.
3. What we collect and on what basis
Beta applications / email contact — your email address and message. Basis: our legitimate interest in responding, and steps prior to entering a contract (Art. 6(1)(f) and (b) GDPR). Retained for up to 24 months from last contact.
Account and profile (once the full version launches) — name, email, professional details in your profile and, for investors, information needed for verification (e.g. LinkedIn profile, firm, experience). Basis: performance of the service contract (Art. 6(1)(b) GDPR). Retained while the account exists and up to 12 months after deletion.
Content published in rooms — messages, reactions, interest signals. Public by nature. Basis: performance of the contract (Art. 6(1)(b) GDPR).
Technical data — server logs and basic device information needed for security and operation. Basis: legitimate interest (Art. 6(1)(f) GDPR).
4. Cookies and browser storage
We use no marketing or profiling cookies and no third-party tracking tools.
We use browser localStorage solely to remember your interface language. That is strictly necessary data — it requires no consent and cannot identify you.
5. Who we share data with
We use trusted providers who process data only on our instructions:
- Vercel Inc. — hosting and delivery of the Service,
- Supabase — database and authentication (in the full version),
- our email provider — handling correspondence.
Some of these may process data outside the European Economic Area. Where that happens, transfers rely on Standard Contractual Clauses approved by the European Commission.
We do not sell personal data and do not share it with data brokers.
6. Your rights
You have the right to:
- access your data and receive a copy,
- rectify inaccurate data,
- erasure (“the right to be forgotten”),
- restriction of processing,
- data portability,
- object to processing based on legitimate interest,
- withdraw consent at any time where processing relies on it.
To exercise any of these, email contact@infinityteam.io. We respond within 30 days.
You may also lodge a complaint with the Polish supervisory authority (Prezes UODO, ul. Stawki 2, 00-193 Warsaw) or your local one.
7. The public nature of content
One point is specific to DealRoom: room conversations are public by design. What you publish there — along with your name and profile — is publicly visible and may be indexed by search engines or archived by third parties, which we cannot control.
So please: do not publish anything in rooms you would not want disclosed. Keep confidential financial detail outside the Service.
8. Security and changes
We use encrypted connections (HTTPS), limit data access to those who need it, and rely on providers with appropriate safeguards.
We announce material changes to this policy in the Service and, for account holders, by email. The last-updated date appears at the top of the page.