Draft 9 August 2026
Privacy notice
How Termsroom handles personal information, under PIPEDA and the British Columbia Personal Information Protection Act.
1. The short version
- We collect the minimum needed to run a negotiation: who you are, which rooms you are in, and what you did.
- We do not store your organisation’s documents. They live in your own storage.
- Your actions are logged, and documents you download are watermarked with your name. This is deliberate and is explained in section 5.
- We do not sell personal information, and we do not use it to train models.
2. Who is responsible for what
For the personal information of your people inside a negotiation, your organisation is the controlling party and we act on its instructions as a service provider. For the information we need to run our own business, meaning your contact details, billing records and support conversations, we are responsible ourselves.
3. What we collect
| Category | Examples | Why |
|---|---|---|
| Identity | Name, job title, organisation, phone number | To create your account and attribute actions |
| Authentication | Phone number, one-time verification codes | To sign you in securely |
| Activity | Rooms joined, versions tabled, risks raised, documents opened, IP address, browser | To keep the audit record both parties rely on |
| Content you type | Risk titles, mitigations, comments | Because it is the product |
| Copy register | Who was issued which watermarked copy, when | To make leaks traceable |
We do not collect document content. See termsroom.com/trust for the full inventory of what is stored.
4. Why we may collect it
To provide the service you or your organisation asked for; to keep the service secure and detect misuse; to keep records we or you are required to keep; and to comply with law. We rely on your organisation’s agreement with us, and on your consent where consent is required.
5. Logging and watermarking (please read this one)
Termsroom records who did what, and stamps every document copy with the name of the person it was issued to, their organisation, the time and a code unique to that copy. A leaked page can therefore be traced to one recipient.
This is monitoring of identifiable individuals, and we would rather you heard it from us plainly. It exists because both sides of a negotiation need to trust that confidential material is traceable, not because we are interested in what any individual is doing. The record is available to your own organisation and to the other party where it concerns shared material; it is not used for any other purpose.
6. Who we share it with
| Who | What they get | Where |
|---|---|---|
| The other party in your negotiation | Your name and role in the shared room, and what you tabled there. Never your private room. | n/a |
| Supabase | The record: accounts, membership, findings, audit trail | Canada |
| Vercel | Requests in transit; no persistent storage | Configurable |
| Twilio | Your phone number, to send a verification code | United States |
| Microsoft | Your own tenant, which your documents never leave | Your tenant |
Cross-border note: phone verification is processed by Twilio in the United States, which means your phone number is disclosed outside Canada and may be accessible to US authorities under US law. Everything else is processed in Canada. If your organisation cannot accept that, tell us before you sign. We are assessing a Canadian alternative.
We do not sell personal information to anyone, in any circumstances.
7. How long we keep it
- Account information: while your account is active, then 90 days.
- The audit record: for the life of the negotiation plus 7 years, because it is evidence both parties may need. Your organisation can ask for a different period.
- Support conversations: 2 years.
8. Your rights
You may ask what we hold about you, ask us to correct it, and complain if you think we have got something wrong. Where your information sits inside your organisation’s negotiation, we will usually direct your request to them, because it is their record.
Contact privacy@termsroom.com. We respond within 30 days. If you are not satisfied you may complain to the Office of the Privacy Commissioner of Canada or, in British Columbia, to the Office of the Information and Privacy Commissioner for BC.
9. Security
Encryption in transit and at rest; access controlled at the database level rather than by application logic; an append-only, tamper-evident audit record; and no storage of your documents at all. The detail, including what we have not yet certified, is at termsroom.com/trust.
We will tell your organisation without undue delay, and within 72 hours of becoming aware, of any breach affecting your material, and will report to regulators where required.
10. Cookies
We use a session cookie to keep you signed in. We do not use advertising or third-party tracking cookies, and we do not run analytics that identify individuals.
11. Children
Termsroom is a business product and is not directed at anyone under 18.
12. Changes
We will post changes here with a new date, and tell your organisation directly if a change is significant.
13. Contact
Privacy Officer, [LEGAL ENTITY NAME], [ADDRESS], British Columbia, Canada.
privacy@termsroom.com