Privacy notice

This notice explains how personal data is handled when you use a data room or intranet operated on the AdeptIQ platform. It applies to every data room hosted on the platform, whichever organisation invited you — that organisation is named in the data room itself and in your invitation.

1. Who is responsible for your data

Each data room is run by the organisation that invited you (for example, your employer or the company whose sale process you are participating in). That organisation decides what content is published, who is invited, and how long you have access — it is the data controller for the data room.

The controller for this data room is Vitae Investments.

The AdeptIQ platform itself is operated by Castle AgentIQ Ltd (registered in England & Wales, company number 16530178), Linfield House, 27 Clifton Rd, Littlehampton BN17 5TE, United Kingdom ("the operator"), which hosts and secures the platform on the controller's behalf — it acts as the data processor for data room content and usage data.

Contact for privacy matters: privacy@castleagentiq.com.

2. What we collect

Account and identity data — your name and email address (provided by the organisation that invited you), and for external participants, the company you represent.

Access configuration — your role (administrator, staff, or external user), account status, which content packages you have been granted, and for external users the start and end dates of your access window.

NDA acceptance — for external users, the date and time you accepted the non-disclosure agreement and a snapshot of the exact NDA text you accepted.

Security data — your password (stored only as a cryptographic hash by our authentication provider), your two-factor authentication enrolment, and active session data.

Usage and audit data — the platform keeps a per-user audit trail of activity: sign-ins and sign-in attempts, magic-link requests, pages viewed, documents viewed and downloaded, and administrative actions, each with a timestamp. This audit trail exists because data rooms carry confidential material: the organisation running the data room can see who accessed what, and when.

Watermarking — documents you download may be stamped with your identity, the date and time (UTC), and a confidentiality marking. This embeds your identity in the copy you receive.

Technical data — our infrastructure providers process connection metadata (such as IP addresses and request logs) to deliver and secure the service.

We do not use analytics trackers, advertising cookies, or profiling.

3. Why we process it, and on what legal basis

PurposeLegal basis (UK GDPR)
Providing your account and access to the data roomPerformance of a contract / legitimate interests of the controller
Access control, security, two-factor authenticationLegitimate interests (protecting confidential material); legal obligation where applicable
The audit trail and document watermarkingLegitimate interests of the controller in protecting confidential material in a transaction process and evidencing who accessed it
Sending invitation, sign-in, and service emailsPerformance of a contract / legitimate interests
NDA acceptance recordsLegitimate interests / establishment and defence of legal claims

4. Who sees your data

  • The organisation running your data room: its administrators can see your account details, access configuration, NDA acceptance, and your audit trail (what you viewed and when).
  • The operator: for hosting, support, and security administration.
  • Sub-processors (infrastructure suppliers to the operator):
ProviderRoleLocation / transfer safeguard
SupabaseDatabase, authentication, file storageData hosted in the United Kingdom (Supabase's UK region). Supabase's data-processing addendum incorporates the EU Standard Contractual Clauses and the UK ICO Addendum, covering any access from outside the UK
CloudflareHosting, networking, TLS, DNSGlobal edge network. Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework including the UK Extension; its data-processing addendum additionally incorporates the EU SCCs with the UK Addendum
ResendTransactional email (invitations, sign-in links)US provider. Resend's data-processing addendum incorporates the EU Standard Contractual Clauses and the UK Addendum

Embedded video (Vimeo). Where a data room page embeds a video, your browser fetches the player directly from Vimeo. Vimeo then receives your IP address, technical browser data, and the address of the page embedding the video, and acts as an independent controller of that data under its own privacy policy. We never send Vimeo any information about who you are, and our embeds enable Vimeo's "Do Not Track" mode, which disables Vimeo's session tracking and analytics cookies in the player.

We do not sell personal data or share it for marketing.

5. International transfers

Data is primarily stored in the United Kingdom. Where a sub-processor processes personal data outside the UK or EEA, the transfer is protected by the safeguards listed in the table above: Cloudflare's certification under the EU-U.S. Data Privacy Framework (including the UK Extension), and, for each provider, the EU Standard Contractual Clauses together with the UK Addendum incorporated into their data-processing addenda.

6. How long we keep it

  • Account and access data: for the life of your membership, then removed when your account is deleted by the data room's administrator.
  • Audit trail: for the life of the data room. When a data room is closed, its audit trail is included in the closing export delivered to the controller and then deleted from the platform; the controller may retain the exported records for as long as is necessary to evidence access to confidential material — typically up to six years, in line with the limitation period for contractual claims in England and Wales.
  • NDA acceptance records: for the life of your membership in the data room, and thereafter as part of the closing export, retained by the controller for as long as the NDA remains enforceable (typically up to six years from any claim arising).
  • Data room content: controlled by the organisation running the data room; when a data room is closed, its content is exported to the controller and deleted from the platform.

7. Your rights

Under the UK GDPR you have rights of access, rectification, erasure, restriction, objection, and data portability, and the right not to be subject to solely automated decision-making (which we do not carry out). To exercise them, contact the organisation that runs your data room (the controller) or privacy@castleagentiq.com.

You may complain to the Information Commissioner's Office (ico.org.uk). If you are in the EEA, you may also complain to your local supervisory authority — for example, Datatilsynet (datatilsynet.no) in Norway.

8. Cookies

The platform sets only strictly necessary cookies: authentication/session cookies and security tokens. These are exempt from consent requirements (PECR), so no cookie banner is shown. No analytics or third-party cookies are set.

9. Changes

We will update this notice when our practices change and show the date of the current version here.