Acceptable Use Policy
Effective Date: 2 October 2026
Last Updated: 2 October 2026
Version: 2026-10-02
1. Purpose and scope
This Acceptable Use Policy ("Policy") applies to every Customer and every Authorised User of MandateRoom, and forms part of our Terms of Service. Rooms are private, and we do not routinely read what is in them. This Policy exists to protect the people whose information is in a room, other users, third parties, our infrastructure providers and the Service itself. Words defined in the Terms of Service have the same meaning here.
2. Your responsibility
A Customer is responsible for everything uploaded to its Rooms and for the conduct of every person it invites. Use the Service only for lawful business purposes. If you are not sure whether something may be uploaded or done, ask us at hello@mandateroom.com first.
3. What you must not upload without our prior written agreement
| Category | Why it is restricted | What to do instead |
|---|---|---|
| Protected health information (patient, treatment or health-plan records about identifiable people) | Health-privacy laws such as HIPAA require a specific contract and safeguards that we do not offer | De-identify or redact it before upload. Medical, dental, veterinary and pharmacy practices are often sold through data rooms: tell us before you upload anything of this kind |
| Technical data controlled under export-control laws (for example ITAR-controlled technical data or EAR-controlled technology above the lowest control level), classified information, and controlled unclassified information | Giving a foreign person access can be an unlicensed export, and the person who administers the Service works in India | Do not upload it |
| Payment-card data (full card numbers, security codes) | Card-industry rules apply to it | Mask it or leave it out |
| Data that the law forbids you to move out of its country of origin, or that is a state secret or restricted "important data" in its home country | Unlawful transfer exposes you and others | Upload it only if you have the legal authority to transfer it |
| Material you have no right to share, including another person's confidential information that you are bound not to disclose | Breach of contract, confidence or copyright | Obtain the right first |
4. Personal data and sensitive deal material
You must have a lawful basis to disclose personal data in a transaction and must have given any notice the law requires. Share only what the purpose needs. Employee, customer and patient-adjacent information, such as government identification numbers, payroll records, bank-account details and immigration status, should be removed, masked or aggregated in early rounds and shared only with the people and at the stage that truly need it. Use disclosure stages, permissions and NDAs for that purpose.
Rooms may hold material non-public information about listed companies and privileged communications. You, and not we, are responsible for insider-dealing, market-abuse, competition and privilege rules. Competitively sensitive information should be shared between competing bidders only under the clean-team and visibility controls the law requires. We do not provide legal advice on any of this.
5. What you must not do
- Break the law or another person's rights. Do not use the Service for anything unlawful, defamatory, infringing or fraudulent, or to launder money, or to evade sanctions or export controls.
- Upload abusive or criminal material. Child sexual abuse material is never permitted and is reported to the authorities. The same applies to material that promotes terrorism or violence, stolen data and credentials, and malware, ransomware or phishing content.
- Deceive. Do not impersonate a person or organisation, create a "deal room" to defraud someone, run advance-fee or payment-redirection scams, or use invitations and notifications to phish or harass.
- Attack or bypass the Service. Do not probe, scan, test or attack the Service outside our vulnerability disclosure policy; bypass or disable watermarking, permissions, NDA steps, the audit ledger or any other control; use automated tools to collect content or data outside the published API; reverse-engineer the Service; or share credentials.
- Misuse invitations. Invite only people with a genuine reason to be in the Room, at the right addresses, and do not send invitations in bulk to people who have not been told to expect them.
- Copy what you see, if you are a viewer. An Authorised User must not photograph, record, copy or pass on material they view, except as the Room's administrator permits in writing.
- Compete or resell. Do not benchmark the Service for a competitor, build a competing service from it, or resell access.
- Overload the Service. Do not use it in a way that degrades it for others.
6. What we do
We do not routinely monitor the content of documents. We do not yet scan uploaded files for malware, and we will update this Policy and our sub-processor list on the day we start. We may look at specific content, to the minimum extent needed, where it is necessary to investigate abuse, a security threat or unlawful content, to respond to a valid legal request, or because the Customer asks. Material that appears to be child sexual abuse material is not opened by our staff beyond what the law requires; it is isolated, preserved as the law requires and reported to the competent authorities, and we may do so without notice to the Customer where the law requires or allows. We tell the affected Customer when we act on a Room, unless the law prevents us.
7. Enforcement
If we reasonably believe this Policy has been broken, we may remove content, suspend or end an Authorised User's or a Customer's access, and report the matter to the authorities. We will give notice and a chance to put things right where we can safely and lawfully do so, but we may act immediately where there is a threat to the Service, to other people or to the law. A breach of this Policy is a breach of the Terms of Service and does not entitle you to a refund.
8. Reporting abuse and copyright complaints
To report abuse, write to hello@mandateroom.com with "Abuse report" in the subject line, giving the Room or account involved, if you know it, what you saw, when, and how to reach you. Do not send the material itself.
To complain that a document in a Room infringes your copyright, send a notice to the same address, with "Copyright notice" in the subject line, that includes: a description of the work you say is infringed; where the material is, as precisely as you can; your name, address, telephone number and email address; a statement that you believe in good faith that the use is not authorised by the owner, its agent or the law; a statement that the information in the notice is accurate and that you are the owner or authorised to act for the owner; and your signature, which may be electronic. We will tell the affected Customer, and we may remove or disable access to the material. If the Customer believes the notice is mistaken, it may send us a counter-notice with its contact details, a description of the material and a statement of its reasons, and we may then restore access unless you tell us that you have started legal proceedings. We close the accounts of repeat infringers in appropriate circumstances.
9. Changes
We may update this Policy in the way the Terms of Service describe for changes to the Terms. The current version is always on our website.