TermsroomLegal
  • Terms of service
  • Privacy notice
  • Refunds
  • Acceptable use
  • Disclaimers
  • Sub-processors

Effective 22 September 2026

Privacy notice

How Termsroom handles personal information, under PIPEDA and the British Columbia Personal Information Protection Act.

1. The short version

  • We collect the minimum needed to run a negotiation: who you are, which rooms you are in, and what you did.
  • We do not store your organisation’s documents. They live in your own storage.
  • Your actions are logged, and records we issue ourselves, such as the record of a sitting, carry a code identifying the copy and who it went to. This is deliberate and is explained in section 5.
  • Where you point a costing at a payroll file, we read it and do not keep it. Section 5A is about that, and it is the section to read if you are an employee or a member rather than a user.
  • We do not sell personal information, and we do not use it to train models.

2. Who is responsible for what

For the personal information of your people inside a negotiation, your organisation is the controlling party and we act on its instructions as a service provider. For the information we need to run our own business, meaning your contact details, billing records and support conversations, we are responsible ourselves.

Subscriptions are sold through Paddle, which acts as merchant of record. Paddle is responsible for the payment, invoicing and sales tax information it collects from you under its own terms and its own privacy notice.

3. What we collect

CategoryExamplesWhy
IdentityName, job title, organisation, phone numberTo create your account and attribute actions
AuthenticationPhone number, one-time verification codesTo sign you in securely
ActivityRooms joined, versions tabled, risks raised, documents opened, browserTo keep the audit record both parties rely on
Network addressHeld by our hosting and database providers in their own request logs, not written into our audit recordTo operate and secure the service
Content you typeRisk titles, mitigations, commentsBecause it is the product
Distribution registerWho was sent which version, when they first opened it, when they acknowledged itTo keep the record of what each side was given
Document structureClause numbers, their depth and order, a hash of each clause, and what changed between two versions. Not the wording of any clauseTo compare two versions without reading either of them
Storage pointers and fingerprintsThe location of a file in your own storage, its SHA-256, its size and its typeTo find a document you tabled, and to prove it has not changed since
Roster facts, not the rosterWhere a payroll file sits in your storage, its SHA-256 and the number of rows in it. Never the file, and never any row of itTo cost an offer against a real population. Section 5A
Grievance recordsThe reference the parties use for a case, the articles relied on, the remedy sought, and the dated events in it. The person grieving is held as a reference the two sides agree, such as an employee number, and never as a nameTo run the steps and the deadlines both sides are held to
Your own working materialYour mandate and its limits, your costing assumptions and cost lines, your risks. Held for your organisation alone and never disclosed to the other partyBecause it is the product, and because it is the half of it that must stay sealed
Credentials you give usFor S3 compatible storage, the access key and secret you supply, held encrypted while the connection is active. For a Teams channel, the notification address. For SharePoint, no credential at allTo read and write in the storage you connected
BillingBilling contact name and email, subscription and invoice recordsTo sell and renew a subscription, through Paddle as merchant of record

We do not collect document content, and we do not hold card numbers. There is no column in our database that is permitted to hold the content of a document, and an attempt to add one fails. See termsroom.com/trust for the full inventory of what is stored, column by column.

3A. If you write to us before you are a customer

Two forms on this site can be used by somebody with no account: the request for a quotation on the purchasing page, and the request for our evidence pack on the trust page. Both record what you typed, and this notice did not previously say so. It does now.

Each records your name, the organisation you are asking for, an email address and, if you give one, a telephone number and your role. It records what you asked for, and anything you wrote in the free text box. It does not record your network address; that sits in our providers’ request logs, on the same footing as every other page you visit here.

We use it to reply to you, and we count what was asked for so we know what buyers and reviewers actually gate on. We do not use it for anything else, we do not add you to a mailing list, and we do not sell or share it. Nobody signed in to Termsroom can read it: every access policy on both tables is a plain refusal, and a standing assertion runs daily against our production database asserting that this is still true.

A request sits with us for two years unless you ask us to remove it sooner, which you may do at any time by quoting the reference you were given. Nothing deletes these on a schedule today, and section 7 says so rather than implying a job that does not exist.

4. Why we may collect it

To provide the service you or your organisation asked for; to keep the service secure and detect misuse; to keep records we or you are required to keep; and to comply with law. We rely on your organisation’s agreement with us, and on your consent where consent is required.

5. Logging and the distribution record (please read this one)

Termsroom records who did what. It also records who was sent which version of a document, when they first opened it, and when they acknowledged receiving it. Records that Termsroom itself produces, such as the record of a sitting, carry a code identifying that copy and the person it was issued to.

This is monitoring of identifiable individuals, and we would rather you heard it from us plainly. It exists because both sides of a negotiation need to trust that confidential material is traceable, not because we are interested in what any individual is doing. The record is available to your own organisation and to the other party where it concerns shared material; it is not used for any other purpose.

What we do not do. Termsroom does not hold your documents, so it does not stamp them and cannot trace a leaked page of one back to a recipient. Per-recipient watermarking of documents is on the roadmap at termsroom.com/trust and is not in the product today. If it ships, this notice will say so before it is switched on.

5A. Payroll rosters, and the people who are in one

This section is for a different reader from the rest of this notice. If you are an employee or a member whose pay appears in a file your employer or your union used to cost an offer, you are not a Termsroom user, you never agreed to anything with us, and you should still be told what happens to that file.

What happens. The organisation points Termsroom at a payroll file sitting in its own storage. Our software opens it once, computes a fingerprint of it, counts how many rows it has, and reads one column of earnings figures in order to run each person against the annual contribution ceilings that Canadian statutory deductions impose. It then discards everything it read.

What is kept. Where the file sits, its fingerprint, the number of rows, and the resulting totals for the whole group: headcount, payroll before and after, and statutory cost before and after. No row, no name, no individual figure and no identifier is retained, and no column other than the single earnings column is parsed at all.

Who is responsible. The organisation that pointed us at the file is the controlling party for it. It decided what to put in the file and whether it was entitled to use it that way. We act on its instruction, and we are responsible for handling it as described here and for nothing wider.

Why we do it this way. An accurate costing needs the shape of a real population, because statutory ceilings apply per person and a total divided by a headcount gives the wrong answer. It does not need the population itself to be uploaded to us, so it is not.

If you believe a file about you has been used this way and you want to know more, the request goes to your employer or your union, because it is their file and their instruction. Section 8 explains why, and we will help them answer it.

6. Who we share it with

WhoWhat they getWhere
The other party in your negotiationYour name and role in the shared room, and what you tabled there. Never your private room.n/a
The other party’s own storageA version you tabled at the shared table, where you instruct us to place a copy of it there. Only what you tabled, and only on your instructionTheir tenant
SupabaseThe record: accounts, membership, findings, audit trailCanada
VercelRequests in transit; no persistent storageRequests served from the region nearest the caller
TwilioYour phone number, to send a verification codeUnited States
Paddle, payments and merchant of recordBilling contact, payment and tax detailsAs per Paddle’s own terms
MicrosoftYour own tenant, which your documents never leaveYour tenant

Cross-border note: phone verification is processed by Twilio in the United States, which means your phone number is disclosed outside Canada and may be accessible to US authorities under US law. Billing and tax information is processed by Paddle in the locations set out in its own terms, which may be outside Canada. Everything else is processed in Canada. If your organisation cannot accept that, tell us before you sign. We are assessing a Canadian alternative for phone verification.

We do not sell personal information to anyone, in any circumstances.

7. How long we keep it

Each entry says whether it happens on its own or only when somebody asks. We would rather publish that distinction than let you assume a scheduler exists that does not. A job runs daily against these periods and records what is due; the entries marked as counted are ones it can see but is not yet permitted to act on, and we would rather say that than describe a deletion that has not happened.

  • Storage credentials: deleted from the vault at the moment you disconnect the connection, in the same transaction. Automatic today. A retired connection that still pointed at a credential would be reported by our owntr_orphaned_credentials check, which runs on every change to the database.
  • Channel addresses: a Teams webhook address is deleted when you unlink the channel, on the same basis. Automatic today.
  • Account information: while your account is active, then 90 days. Applied on request. This page previously said it would become automatic from 31 January 2027. That commitment is withdrawn rather than quietly missed. Deciding on our own that an account had gone quiet would mean guessing at a bargaining team between rounds, and for a product used on a cycle that is most of the year, so the organisation tells us instead.
  • The audit record: for the life of the negotiation plus 7 years, because it is evidence both parties may need. Your organisation can ask for a different period.
  • Discussion written in a room: retained and readable by the parties until 90 days after the negotiation is confirmed closed, and purged then. It is working conversation rather than evidence, and the audit record of who acted and when is untouched by it. You can also ask us to purge it sooner, or purge it yourself if you lead a party. Counted daily, not yet deleted automatically. The job that does it runs and records what is due; it is not yet permitted to act, and this page will say so until it is. Ninety days rather than on the day of closure because the closing record is issued at closure and usually read some days later, and a deletion has no undo.
  • Roster facts: the pointer, fingerprint and row count live as long as the costing they belong to. The file itself was never kept, so there is nothing else to delete.
  • Enquiries from people who are not customers: a request for a quotation or for the evidence pack, kept 2 years. Applied on request. Nothing deletes these on a schedule; ask, quoting your reference, and we will remove it. See section 3A.
  • Grievance records: kept for the life of the negotiation they belong to, and deleted with it by the database rather than on a schedule of their own. Deleted with the negotiation. Nothing deletes a negotiation on a schedule either, so in practice this takes effect when the negotiation is deleted rather than on a date, and we would rather say so than imply a timer that does not exist. The person grieving is held as a reference the parties agree rather than as a name, so what is deleted here is a case file and not an identity.
  • Support conversations: 2 years. Applied on request. They are held outside this database, so nothing here can count them or delete them.
  • Billing records: 7 years, because tax law requires it. Held by our payment processor as merchant of record.

8. Your rights

You may ask what we hold about you, ask us to correct it, and complain if you think we have got something wrong. Where your information sits inside your organisation’s negotiation, we will usually direct your request to them, because it is their record.

Contact privacy@termsroom.com. We respond within 30 days. If you are not satisfied you may complain to the Office of the Privacy Commissioner of Canada or, in British Columbia, to the Office of the Information and Privacy Commissioner for BC.

9. Security

Encryption in transit and at rest; access controlled at the database level rather than by application logic; an append-only, tamper-evident audit record; and no storage of your documents at all. The detail, including what we have not yet certified, is at termsroom.com/trust.

You do not have to take the audit record on trust. Your organisation can export its own record and check it on its own machine with a program that never contacts us, published at termsroom.com/verify.mjs. If any entry had been altered or removed, that check fails and names the entry.

We will tell your organisation without undue delay, and within 72 hours of becoming aware, of any breach affecting your material, and will report to regulators where required. We will do that by telephoning and texting the mobile number your organisation administrator verified when they created the account, because that is the channel Termsroom actually operates. Termsroom sends no email today. Email notification is being added by 31 January 2027 and this page will name it when it exists.

10. Cookies

We use a session cookie to keep you signed in. We do not use advertising or third-party tracking cookies, and we do not run analytics that identify individuals.

11. Children

Termsroom is a business product and is not directed at anyone under 18.

12. Changes

We will post changes here with a new date, and tell your organisation directly if a change is significant.

13. Contact

Privacy Officer, MarkR Management Inc., Suite 315, 1627 Fort Street, Victoria, British Columbia, Canada.
privacy@termsroom.com

Termsroom · termsroom.com · support@termsroom.com · Effective 22 September 2026