Privacy Policy
Last updated: August 12, 2025
1. Introduction
Welcome to H1.io VDR ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our virtual data room service, including our website, applications, and related services (collectively, the "Service").
We are committed to protecting your personal information and your right to privacy. If you have any questions or concerns about this privacy policy or our practices with regard to your personal information, please contact us at privacy@h1.io.
When you use our Service and more generally, use any of our services, you trust us with your personal information. We take your privacy very seriously. In this privacy policy, we seek to explain to you in the clearest way possible what information we collect, how we use it and what rights you have in relation to it.
2. Information We Collect
Personal Information You Provide
We collect personal information that you voluntarily provide to us when you register on the Service, express an interest in obtaining information about us or our products and services, when you participate in activities on the Service, or otherwise when you contact us.
- Names and contact data (first name, last name, email address, phone number)
- Credentials (passwords, password hints, and similar security information)
- Payment information (credit card numbers, banking information, billing address)
- Professional information (company name, job title, professional email)
- Communication data (the content of messages you send us)
Information Automatically Collected
We automatically collect certain information when you visit, use or navigate the Service. This information does not reveal your specific identity but may include:
- Device and Usage Information (IP address, browser type, operating system)
- Location Information (country, state, city based on IP address)
- Log and Analytics Data (pages viewed, time spent, clicks, search terms)
- Cookies and Similar Technologies (tracking pixels, web beacons)
Information from Third Parties
We may receive information about you from other sources, including:
- Business partners and affiliates
- Social media platforms (if you connect your account)
- Payment processors and financial institutions
- Analytics providers
3. How We Use Your Information
We use personal information collected via our Service for a variety of business purposes described below:
- To provide and maintain our Service – Including to monitor the usage of our Service and provide customer support
- To manage your account – To manage your registration as a user of the Service and provide you with access to functionalities
- To process your transactions – To process payments and deliver the purchased services
- To send administrative information – Such as updates to our terms, conditions, and policies
- To enforce our terms and for safety – To prevent fraud, unauthorized access, and other illegal activities
- To respond to legal requests – To comply with applicable laws and legal processes
- For business transfers – In connection with any merger, sale of company assets, or acquisition
- To send marketing communications – With your consent, to send promotional materials
- To improve our Service – To understand how users interact with our Service and enhance user experience
- To protect our Service – To identify and prevent security threats and technical issues
4. Sharing Your Information
We may share or transfer your information in the following situations:
- With Service Providers: We share your data with third-party vendors who perform services for us (payment processing, data analysis, email delivery, hosting services)
- For Business Transfers: We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition
- With Your Consent: We may disclose your personal information for any other purpose with your consent
- With Business Partners: We may share your information with our business partners to offer you certain products, services or promotions
- For Legal Purposes: We may disclose your information where required to comply with applicable law, governmental requests, judicial proceedings, court orders, or legal processes
- To Protect Rights and Safety: We may disclose your information to protect the rights, property or safety of our company, our users or the public
- With Other Users: When you share personal information or interact with other users in data rooms, such information may be viewed by all users of those data rooms
5. Data Security
We have implemented appropriate technical and organizational security measures designed to protect the security of any personal information we process. These measures include:
- Encryption of data in transit using industry-standard TLS/SSL protocols
- Encryption of sensitive data at rest using AES-256 encryption
- Regular security assessments and penetration testing
- Access controls and authentication mechanisms
- Regular backups and disaster recovery procedures
- Employee training on data protection and security practices
- Incident response procedures for potential data breaches
However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure. We cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.
6. Data Retention
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy policy, unless a longer retention period is required or permitted by law. Specifically:
- Account information is retained for as long as your account is active
- Transaction records are kept for 7 years for tax and accounting purposes
- Communication records are retained for 3 years or as required by law
- Usage data is aggregated and anonymized after 24 months
- Data room content is retained according to your specified retention policies
- After account termination, personal data is deleted within 90 days unless retention is required by law
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information:
European Union (GDPR)
- Access: Request access to your personal data
- Rectification: Request correction of inaccurate personal data
- Erasure: Request deletion of your personal data
- Restriction: Request restriction of processing your personal data
- Portability: Request transfer of your personal data
- Object: Object to processing of your personal data
- Automated Decision Making: Not be subject to decisions based solely on automated processing
California (CCPA)
- Right to know what personal information is collected
- Right to know whether personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to delete personal information
- Right to non-discrimination for exercising privacy rights
To exercise any of these rights, please contact us at privacy@h1.io. We will respond to your request within 30 days.
8. International Data Transfers
Your information may be transferred to and maintained on computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.
If you are located outside Denmark and choose to provide information to us, please note that we transfer the data, including Personal Data, to Denmark and process it there.
We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
9. Children's Privacy
Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your child has provided us with Personal Data, please contact us.
If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our Service and store certain information. Tracking technologies used include:
- Cookies: Small files placed on your device to track usage and remember preferences
- Web Beacons: Small electronic files that count users and track usage
- Local Storage: Technology that stores information locally on your device
- Analytics: Third-party analytics services to understand Service usage
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
11. Third-Party Services
Our Service may contain links to other websites that are not operated by us. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
We may use third-party Service Providers to facilitate our Service, including:
- Payment processors (Stripe)
- Cloud storage providers (AWS, Vercel)
- Analytics services (Tinybird)
- Email service providers (Resend)
- Authentication services (NextAuth, Hanko)
12. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
For material changes, we will provide a more prominent notice (including, for certain services, email notification of Privacy Policy changes).
13. Contact Us
If you have any questions about this Privacy Policy, please contact us:
H1.io VDR
Email: privacy@h1.io
Phone: +45 XX XX XX XX
Address: Amaliegade 22, 1.
1256 København K
Denmark
Data Protection Officer:
Email: dpo@h1.io