Skip to content
DealRoom

Privacy Policy

Last updated: 19 August 2026

This policy explains how personal data is handled in the DealRoom mobile application (the "app") and on the website at thedealroomapp.com (the "website"). It applies to everyone who uses either of them.

1. Who we are

DealRoom is a trading name of Aerovest Holdings Ltd, a company registered in England and Wales with company number 15581204. Our registered office is 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Aerovest Holdings Ltd is the data controller for the personal data described in this policy.

For any privacy or data-protection matter, contact privacy@thedealroomapp.com.

2. Age requirement

DealRoom is a tool for commercial transactions and is not intended for children. You must be at least 16 years old to create an account or take part in a room. We do not knowingly collect data from anyone under 16. If you believe an account has been created by someone younger, email privacy@thedealroomapp.com and we will delete it.

3. The app: what we collect

A DealRoom room is created and administered by one person, usually the broker, introducer or adviser, who invites the other participants. In the app we handle:

  • Account details — your name, email address, telephone number where you give one, and your password credentials.
  • Room identity — the alias, party label, side colour and custom tag set for you by the room administrator. This is what other participants see, in place of your personal contact details.
  • Messages and attachments you send in a room, including the automated detection that identifies and blocks telephone numbers and email addresses in message content.
  • Documents and signature records — files shared in a room, their versions and approval status, and the record of agreements you sign, including the time and the account that signed.
  • Room membership and invitations — whether you were invited by email address or by a unique join code, when you joined, your permissions, and the required actions assigned to you.
  • Device and technical data — device type, operating system version, app version, IP address, and sign-in and session records, used to keep accounts secure and the service reliable.

We do not sell personal data, we do not use it to build advertising profiles, and we do not use the contents of rooms for advertising.

4. The app: why we use it, and our lawful basis

  • To provide the service — creating your account, running rooms, delivering messages, sharing documents, recording signatures and tracking actions. Lawful basis: performance of a contract with you.
  • To keep the service secure — authentication, session management, abuse prevention, contact-detail blocking and protecting the integrity of the transaction record. Lawful basis: our legitimate interests in securing the service and protecting our users.
  • To support you — answering questions and investigating problems you report. Lawful basis: performance of a contract, and our legitimate interests in supporting users.
  • To improve the app — diagnostic and reliability information, used in aggregate. Lawful basis: our legitimate interests in maintaining and improving the product.
  • To meet legal obligations — retaining records where the law requires it and responding to lawful requests. Lawful basis: compliance with a legal obligation.

5. Who can see what inside a room

Other participants see your alias, party label, side colour and tag, and anything you post in the room. They do not see your name, email address or telephone number through the app, and the app blocks messages in which contact details are detected. There is no participant-to-participant direct messaging and no user search.

The room administrator has oversight of the room they run. They set aliases and permissions, control invitations, and can see the room's messages, documents, signatures and history. This is deliberate: someone has to be accountable for the transaction record. Choose carefully whose room you join, and treat anything you post in a room as visible to that room's administrator.

Aerovest Holdings Ltd staff do not read room contents as a matter of routine. Access is limited to the small number of people who need it, and only where it is necessary to investigate a reported fault, a security incident, a serious breach of our acceptable use policy, or a legal requirement.

6. Who we share data with

We share personal data with service providers who process it on our instructions, under written terms, and only for the purposes we set. The categories are:

  • Cloud hosting, database and file storage providers who run our infrastructure.
  • Email delivery providers, used to send invitations, notifications and replies.
  • Analytics and error-reporting providers, used to measure usage and diagnose faults.
  • Apple and Google, in their capacity as app store operators, where you install or pay through their stores. Their own privacy terms apply to that relationship.

We also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. If our business is restructured or transferred, data may pass to the acquiring entity under the same protections. We do not share personal data with third parties for their own marketing.

7. International transfers

Our providers may process data outside the United Kingdom. Where they do, we rely on UK adequacy regulations or on the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with appropriate technical and organisational safeguards.

8. Security

Data is encrypted in transit using TLS and encrypted at rest by our infrastructure providers. Access to production systems is restricted, authenticated and logged. Room contents are separated by room, and permissions are enforced per room, per party and per participant. Sessions can be revoked, and a deletion request revokes all of your active sessions immediately.

Room confidentiality is administrator-controlled rather than participant-only end-to-end encrypted, by design, so the room owner retains oversight of the transaction record. We say so plainly rather than claim otherwise. No system is completely secure, and we do not promise that it is.

9. Retention and deletion

We keep account data for as long as your account is open. When you request deletion, your account and the personal data that is not part of a transaction record are removed within 30 days, and all active sessions are revoked.

Transaction evidence — messages, documents, signed agreements, required actions and room history — is retained for as long as the room's administrator keeps the room open, because it is a shared record the other parties rely on. A closed and unused room is deleted after six years. Legal holds and regulatory obligations take precedence over these periods.

Step-by-step instructions are on our account deletion page.

10. This website

The website collects personal data only when you choose to submit one of its forms — early access, contact, a demo request or a broker enquiry. The fields are limited to your full name, email address, telephone number (optional), company name (optional), a free-text message (optional), and which page the enquiry came from with the date and time.

These submissions are stored privately in the website's backend database. They are not published, are not visible to other visitors and are not readable through any public interface. We use them only to answer your enquiry and, where you asked us to, to contact you about launch and product updates. Where you asked to hear from us we rely on your consent; where we are answering an enquiry you sent us we rely on our legitimate interest in replying properly. Submitting a form does not create a DealRoom account — accounts are created in the app.

For the cookies and third-party tools the website uses, see our Cookie Policy.

11. Your rights

Under UK GDPR you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to our processing of it, to receive it in a portable format, and to withdraw consent where our processing relies on consent. You can export your data and request deletion from the Privacy and account data screen in the app, or by emailing privacy@thedealroomapp.com.

We respond within one month. Where a right is limited — for example, because transaction evidence must be retained for the other parties or by law — we will tell you which data is affected and why. If you are unhappy with our response you can complain to the UK Information Commissioner's Office at ico.org.uk.

12. Changes to this policy

We update this policy when the app or the website changes. The "last updated" date above shows when it was last revised, and we will notify users in the app of any change that materially affects them.

13. Contact

Aerovest Holdings Ltd, 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Privacy enquiries: privacy@thedealroomapp.com. General enquiries: hello@thedealroomapp.com. Support: support@thedealroomapp.com.