Data Processing Agreement
Version 1.0.0Effective July 18, 2026
View the current subprocessor register
DATA PROCESSING ADDENDUM
investordataroom.com
Mikasa Labs LLC
Version 1.0.0
Effective date: 2026-07-18
1. Introduction and Order of Precedence
1.1 This Data Processing Addendum (this "DPA") forms part of the Agreement between Mikasa Labs LLC, a California limited liability company, and the customer entity that accepts or has accepted the Agreement (the "Customer"). This DPA applies to Mikasa Labs LLC's Processing of Customer Personal Data in the course of providing the Service.
1.2 Order of precedence. If there is a conflict among the documents governing the parties' relationship, the following order of precedence applies: (a) where the Standard Contractual Clauses apply to a transfer, the Standard Contractual Clauses prevail to the extent of the conflict, as required by their own terms; (b) this DPA prevails for all matters relating to the Processing of Customer Personal Data; (c) the Platform Terms of Service; (d) the Acceptable Use Policy. Nothing in this Section 1.2 reduces the protections of this DPA.
1.3 This DPA is entered into by the Customer for itself and, where Section 3.3 applies, on behalf of the controller for which the Customer acts.
2. Definitions
2.1 "Agreement" means the investordataroom.com Platform Terms of Service between Mikasa Labs LLC and the Customer, together with the documents the Platform Terms of Service incorporate, including the Acceptable Use Policy and this DPA.
2.2 "Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including, in each case to the extent applicable: (a) the GDPR; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss FADP; (d) the CCPA; and (e) other United States state privacy laws that apply to the Processing, including laws that impose contract requirements between a controller and a processor.
2.3 "CCPA" means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, California Civil Code Section 1798.100 and following, together with its implementing regulations.
2.4 "Controller", "processor", "data subject", "personal data", "processing" (and "Process", "Processed", "Processing"), and "supervisory authority" have the meanings given in the GDPR or, where the GDPR does not apply, the closest equivalent meanings under Applicable Data Protection Law. For the CCPA: "controller" includes a "business", "processor" includes a "service provider", "data subject" includes a "consumer", and "personal data" includes "personal information".
2.5 "Customer Personal Data" means personal data that Mikasa Labs LLC Processes on the Customer's behalf in providing the Service, as described in Annex 1. Customer Personal Data does not include Platform Operations Data.
2.6 "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation). "UK GDPR" has the meaning given in the UK Data Protection Act 2018. "Swiss FADP" means the Swiss Federal Act on Data Protection.
2.7 "Platform Operations Data" means data Mikasa Labs LLC processes for its own limited operational purposes as described in Section 3.4.
2.8 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Mikasa Labs LLC. A Security Incident does not include an unsuccessful attempt or activity that does not compromise the security of Customer Personal Data, such as a blocked intrusion attempt, port scan, or denial-of-service attack that does not result in access to Customer Personal Data.
2.9 "Service" means the investordataroom.com multi-tenant investor data room service provided by Mikasa Labs LLC under the Agreement.
2.10 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2.11 "Subprocessor" means a third party engaged by Mikasa Labs LLC to Process Customer Personal Data on Mikasa Labs LLC's behalf in providing the Service.
2.12 "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, version B1.0, in force 21 March 2022.
3. Roles and Scope of Processing
3.1 Roles. As between the parties, the Customer is the controller of Customer Personal Data and Mikasa Labs LLC is a processor acting on the Customer's behalf. Where the CCPA applies, the Customer is the business (or, where Section 3.3 applies, a service provider) and Mikasa Labs LLC is a service provider.
3.2 Details of Processing. The subject matter, duration, nature and purposes of the Processing, the categories of personal data, and the categories of data subjects are described in Annex 1. In summary: the subject matter is the hosting and operation of the Customer's investor data room on the Service; the duration is the term of the Agreement plus the deletion and retention windows in Section 12; the nature and purposes are storage, retrieval, display and disclosure by transmission to the Customer's authorized users, transactional email notification, access control and authentication, audit logging, and data subject request tooling; the data subjects are the Customer's investors and other individuals the Customer invites to the Service and the Customer's own personnel; and the categories of personal data are those listed in Annex 1 Part B.
3.3 Customer as processor. Where the Customer acts as a processor for a third-party controller, the Customer warrants that: (a) its instructions to Mikasa Labs LLC and its use of the Service are consistent with the controller's instructions and its contract with that controller; (b) the controller has authorized the engagement of Mikasa Labs LLC as a subprocessor; and (c) the Customer will be the sole point of contact for Mikasa Labs LLC, and all instructions and communications required from a controller under this DPA will be given to Mikasa Labs LLC by the Customer.
3.4 Platform Operations Data. Mikasa Labs LLC processes a limited set of data for its own purposes as an independent controller, as described in the platform Privacy Policy: the Customer's own account and business contact information; records of acceptance of Mikasa Labs LLC's platform legal documents; and operational and security records Mikasa Labs LLC is required or permitted to keep for its own legal compliance, security, and the establishment, exercise, or defense of legal claims. Nothing in this Section 3.4 permits Mikasa Labs LLC to use Customer Personal Data for advertising, for sale or sharing, or for any purpose inconsistent with Section 15.
3.5 No sale; no tracking. Mikasa Labs LLC does not sell or share Customer Personal Data, does not use Customer Personal Data for advertising or cross-context behavioral advertising, and does not deploy analytics or tracking software development kits in the Service.
4. Customer Responsibilities
4.1 The Customer is responsible for compliance with Applicable Data Protection Law as controller (or as processor for its controller), including: (a) establishing a lawful basis for the Processing; (b) providing all notices to, and obtaining all consents and authorizations from, data subjects that Applicable Data Protection Law requires; (c) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was collected; and (d) ensuring its instructions to Mikasa Labs LLC comply with Applicable Data Protection Law.
4.2 Restricted data. The Customer must not submit to the Service, or instruct or permit its users to submit: (a) the document kinds the Service refuses during the pilot phase, namely passports, visas, I-526 or I-829 immigration petition documents, and documents containing a full United States Social Security number or taxpayer identification number (the Service is designed to refuse these document kinds at creation and at download); (b) payment card data subject to PCI DSS; (c) protected health information; (d) personal data of children under 13 years of age; or (e) special categories of personal data within the meaning of GDPR Article 9, or personal data relating to criminal convictions and offences within the meaning of GDPR Article 10, except to the extent the parties agree otherwise in writing and the Customer has established a lawful basis.
4.3 Tenant legal terms. The Customer's own terms, privacy policy, and offering-related legal documents governing its relationship with its investors are the Customer's sole responsibility. The Service surfaces them as external links provided by the Customer; Mikasa Labs LLC does not author, host, review, or endorse them.
4.4 Customer-controlled security. The Customer is responsible for the security decisions Applicable Data Protection Law and this DPA leave in its control, including managing its administrator accounts and credentials, granting and revoking its users' entitlements through the Service, choosing what data and documents it uploads, and using the multi-factor authentication features available in the Service.
5. Processing on Documented Instructions
5.1 Mikasa Labs LLC will Process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers of personal data to a third country or an international organization, unless required to do otherwise by applicable law; in that case, Mikasa Labs LLC will inform the Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
5.2 The parties agree that the Customer's complete and final documented instructions are: (a) the Agreement and this DPA; (b) the Customer's and its authorized users' configuration and use of the Service's features and controls; and (c) any additional written instructions agreed by both parties in writing. Mikasa Labs LLC is not obliged to comply with an instruction that exceeds, or requires a change to, the Service's functionality unless the parties agree to it in writing.
5.3 Lawfulness pushback. Mikasa Labs LLC will immediately inform the Customer if, in Mikasa Labs LLC's opinion, an instruction infringes the GDPR or other applicable data protection provisions. Mikasa Labs LLC is entitled to suspend performance of the disputed instruction until the Customer confirms or modifies it. Mikasa Labs LLC is not obliged to perform a comprehensive legal review of the Customer's instructions.
6. Confidentiality
6.1 Mikasa Labs LLC will ensure that every person it authorizes to Process Customer Personal Data is bound by a written confidentiality obligation or is under an appropriate statutory obligation of confidentiality, and Processes Customer Personal Data only as needed to provide the Service.
6.2 Access to Customer Personal Data within Mikasa Labs LLC is restricted on a least-privilege basis to persons who need it to provide, secure, and support the Service.
7. Security
7.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk to the rights and freedoms of natural persons, Mikasa Labs LLC implements and maintains the technical and organizational measures set out in Annex 2.
7.2 Mikasa Labs LLC may update the measures in Annex 2 from time to time, provided the update does not materially diminish the overall security of the Service during the term of the Agreement.
7.3 The Customer acknowledges that the measures in Annex 2 describe the Service as designed and operated at the version date of this DPA, and that the Customer, not Mikasa Labs LLC, controls the elements described in Section 4.4.
8. Subprocessors
8.1 General authorization. The Customer grants Mikasa Labs LLC general written authorization to engage Subprocessors to Process Customer Personal Data. The Subprocessors engaged as of the version date of this DPA are listed in Annex 3, which is the current subprocessor register. Mikasa Labs LLC will maintain the register and make its current version available to the Customer. Unless and until Mikasa Labs LLC publishes the register at a public URL, the register is Annex 3 of the then-current published version of this DPA.
8.2 Flow-down. Mikasa Labs LLC will engage each Subprocessor under a written contract imposing data protection obligations that are materially no less protective of Customer Personal Data than the obligations in this DPA, to the extent applicable to the services the Subprocessor provides, including, where the SCCs apply, the obligations required for onward processing. Mikasa Labs LLC remains responsible to the Customer, as provided in the Agreement, for the performance of its Subprocessors' data protection obligations.
8.3 Notice of Mikasa Labs LLC-initiated changes. Mikasa Labs LLC will give the Customer at least 30 days prior written notice of any addition or replacement of a Subprocessor that Mikasa Labs LLC initiates, by email to the Customer's designated administrative contact (as described in Section 20.1) and by update to the subprocessor register. If an addition or replacement is reasonably necessary to address an emergency, an actual or suspected Security Incident, or a Subprocessor's sudden unavailability or termination of service, Mikasa Labs LLC may make the change on shorter notice and will notify the Customer as soon as reasonably practicable; the Customer's objection right under Section 8.5 applies from that notice.
8.4 Notice of upstream-initiated changes. Where a change originates upstream, including a change within an existing Subprocessor's own subprocessor chain, Mikasa Labs LLC receives only the notice the Subprocessor's terms provide (for example, Resend's data processing agreement provides 14 days notice of its subprocessor changes). Mikasa Labs LLC will pass such notice on to the Customer as soon as practicable after Mikasa Labs LLC receives it. Mikasa Labs LLC does not promise a longer notice period for upstream-initiated changes than Mikasa Labs LLC itself receives.
8.5 Objection. The Customer may object to a change noticed under Section 8.3 or Section 8.4 by written notice to Mikasa Labs LLC within 30 days of Mikasa Labs LLC's notice, stating reasonable, documented data protection grounds. The parties will discuss the objection in good faith. Because the Service runs on shared, single-configuration infrastructure, Mikasa Labs LLC cannot deploy different subprocessors for different customers and cannot suspend a change for one customer alone. If the parties do not resolve the objection within 30 days after it is received, the Customer may terminate the Agreement by written notice, as its exclusive remedy for the objection; any fee treatment on such termination is as provided in the Agreement. If the Customer does not object within the 30 day objection window, the change is deemed accepted.
9. Data Subject Requests
9.1 Taking into account the nature of the Processing, Mikasa Labs LLC will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests by data subjects to exercise their rights under Applicable Data Protection Law (including access, rectification, erasure, restriction, portability, objection, and equivalent rights, and rights under the CCPA to know, access, correct, and delete).
9.2 Built-in tooling. The Service provides the primary assistance: the Customer and its authorized users can view records through the Service and correct the records the Service makes editable (including investment, entitlement, and notification preference records), and, on the Customer's documented request, Mikasa Labs LLC will run the Service's data subject tooling for an identified subject: (a) an export of the subject's personal data in a commonly used, machine-readable format, delivered by a time-limited link; and (b) an erasure process that applies the category dispositions described in Annex 1 Part C, using a soft-delete window of 30 days followed by a destructive purge, subject to the retention carve-outs in Section 12.4.
9.3 Direct requests. If a data subject makes a request directly to Mikasa Labs LLC that relates to Customer Personal Data, Mikasa Labs LLC will not respond substantively except to acknowledge receipt and direct the data subject to the Customer, and will forward the request to the Customer promptly, unless applicable law requires Mikasa Labs LLC to respond directly.
9.4 Additional assistance. For assistance materially beyond the built-in tooling, Mikasa Labs LLC will provide reasonable cooperation and may charge a reasonable fee, except where Applicable Data Protection Law requires the assistance to be provided without charge.
10. Security Incidents
10.1 Notification. Mikasa Labs LLC will notify the Customer of a Security Incident without undue delay after becoming aware of it, and in any case within 72 hours of becoming aware. Where California Civil Code Section 1798.82(b) or a materially similar state statute applies to Mikasa Labs LLC as the maintainer of computerized data it does not own, Mikasa Labs LLC's notification to the Customer will follow discovery of the breach consistent with the timing that statute requires. Notification will be made by email to the Customer's designated administrative contact.
10.2 Content. The notification will describe, to the extent then known: the nature of the Security Incident; the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address the Security Incident and mitigate its effects; and a contact point for further information. Information may be provided in phases as it becomes available, and Mikasa Labs LLC will supplement the notification on a rolling basis.
10.3 Allocation of external notifications. As the party with the direct relationship with data subjects and, where applicable, the owner or licensor of the data, the Customer is responsible for deciding on and making any notifications to data subjects, supervisory authorities, regulators, and other third parties, and for the content and timing of those notifications, unless applicable law requires Mikasa Labs LLC to notify a party directly. Mikasa Labs LLC will provide reasonable cooperation and information to support the Customer's notification obligations, including under GDPR Articles 33 and 34 and state breach notification statutes.
10.4 No admission. Mikasa Labs LLC's notification of, or response to, a Security Incident is not an acknowledgment of fault or liability.
11. Impact Assessments and Consultations
11.1 Taking into account the nature of the Processing and the information available to Mikasa Labs LLC, Mikasa Labs LLC will provide reasonable assistance to the Customer with data protection impact assessments under GDPR Article 35, with prior consultations with supervisory authorities under GDPR Article 36, and with comparable risk or impact assessments required by other Applicable Data Protection Law, in each case solely insofar as they relate to Mikasa Labs LLC's Processing of Customer Personal Data. This DPA, its annexes, and the compliance information in Section 13.1 are the primary form of that assistance.
12. Deletion and Return
12.1 During the term. The Service enables the Customer to retrieve Customer Personal Data during the term, including downloading documents and viewing records through the Service's features.
12.2 Export on request. If the Customer requests it in writing within 30 days after termination or expiry of the Agreement, Mikasa Labs LLC will provide an export of Customer Personal Data then held by Mikasa Labs LLC in a commonly used, machine-readable format, within 30 days of the request.
12.3 Deletion. After the export window in Section 12.2 closes (or, if an export was requested, after its delivery), Mikasa Labs LLC will delete Customer Personal Data. The deletion process may use a soft-delete window of up to 30 days followed by a destructive purge. Deletion will be completed no later than 90 days after the effective date of termination or expiry or, if an export was requested and delivered later than 60 days after termination, no later than 30 days after its delivery, in each case except as provided in Section 12.4. On the Customer's written request, Mikasa Labs LLC will confirm completion of deletion in writing.
12.4 Retention carve-outs. Mikasa Labs LLC may retain Customer Personal Data after completion of an erasure process under Section 9.2, or after termination, only: (a) as required by applicable law, for the period and purposes the law requires; (b) to the extent permitted by applicable law, as evidence of compliance and for the establishment, exercise, or defense of legal claims, limited to the following record categories and minimized as described in Annex 1 Part C: consent records (with the hashed IP value removed at purge), document acknowledgment attestations (with hashed identifiers removed at purge), audit log entries (which by design contain no raw personal identifiers beyond account identifiers), investment records as financial records of the relationship, and job-creation allocation snapshots as program evidence; (c) where the data is subject to a documented legal hold, for the duration of the hold; and (d) in backup media, until deleted or overwritten in the ordinary course of Mikasa Labs LLC's backup cycle described in Annex 2. Data retained under this Section 12.4 remains subject to the confidentiality and security obligations of this DPA for as long as it is held and is Processed for no other purpose.
13. Compliance Information and Audits
13.1 Information. Mikasa Labs LLC will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR, consisting of: (a) this DPA and its annexes; (b) the subprocessor register; (c) Mikasa Labs LLC's record of processing activities carried out on behalf of the Customer; (d) the third-party certifications and audit reports covering the infrastructure Subprocessors listed in Annex 3, as and to the extent those vendors make them available (for example, Google publishes ISO 27001 and SOC coverage for the Google Cloud and Firebase services the Service uses); and (e) written responses to a reasonable security and compliance questionnaire from the Customer no more than once in any 12 month period, except following a Security Incident or where a supervisory authority requires more.
13.2 Audits. Where the information in Section 13.1 is insufficient to demonstrate compliance with this DPA, or where an audit is required of the Customer by Applicable Data Protection Law or a competent supervisory authority, Mikasa Labs LLC will allow for and contribute to an audit, including an inspection, conducted by the Customer or an independent auditor mandated by the Customer, on the following terms: at least 30 days prior written notice; no more than once in any 12 month period, except following a Security Incident or where required by a supervisory authority; conducted during normal business hours, remotely where feasible, and in a manner that does not disrupt the Service; the auditor must not be a competitor of Mikasa Labs LLC and must be bound by confidentiality obligations; the scope excludes data of Mikasa Labs LLC's other customers, Mikasa Labs LLC's privileged materials, and the physical facilities of Subprocessors (audit assurance for Subprocessor infrastructure is provided through those vendors' certifications and reports under Section 13.1); and the audit is at the Customer's cost.
13.3 SCC and mandatory audit rights. Where the SCCs apply, Sections 13.1 and 13.2 are applied consistently with Clause 8.9 of the SCCs, and nothing in this Section 13 limits a right the SCCs make mandatory or an information or audit right under Applicable Data Protection Law that the parties cannot lawfully limit.
13.4 Records. Mikasa Labs LLC maintains a record of the categories of processing activities carried out on behalf of the Customer as required by GDPR Article 30(2), where the GDPR applies.
14. International Data Transfers
14.1 Hosting location. The Service is hosted in the United States, in a single United States region. Customer Personal Data at rest is stored in the United States. The Service does not currently offer in-region hosting outside the United States, and Mikasa Labs LLC makes no representation that data subjects' data remains outside the United States. Transactional email is delivered through the Subprocessors described in Annex 3 and may transit the locations those vendors disclose.
14.2 EU transfers. To the extent the Customer's transfer of Customer Personal Data to Mikasa Labs LLC is a transfer of personal data subject to the GDPR to a third country within the meaning of GDPR Chapter V, the parties incorporate the SCCs into this DPA by reference, completed as follows: (a) Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is a processor acting for another controller; (b) in Clause 7, the optional docking clause does not apply; (c) in Clause 9, Option 2 (general written authorisation) applies, with a time period of at least 30 days for prior written notice of changes to the list of Subprocessors in Annex 3 (Annex III of the SCCs), and the register and objection mechanics are those of Section 8 of this DPA; (d) in Clause 11(a), the optional language on independent dispute resolution bodies does not apply; (e) in Clause 17, Option 1 applies and the clauses are governed by the law of Ireland; (f) in Clause 18(b), disputes will be resolved before the courts of Ireland; (g) Annex 1 of this DPA serves as Annex I of the SCCs (Parts A, B, and D corresponding to Annex I.A, I.B, and I.C respectively), Annex 2 of this DPA serves as Annex II of the SCCs, and Annex 3 of this DPA serves as Annex III of the SCCs. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
14.3 UK transfers. To the extent the transfer is subject to the UK GDPR, the parties incorporate the UK Addendum by reference. Tables 1, 2, and 3 of the UK Addendum are completed by reference to the parties, selections, and annexes in Section 14.2 and the annexes of this DPA, and for Table 4 (ending the UK Addendum when the Information Commissioner issues a revised approved addendum), both the importer and the exporter may end the UK Addendum as set out in it.
14.4 Swiss transfers. To the extent the transfer is subject to the Swiss FADP, the SCCs as incorporated above apply with the adaptations recognized by the Swiss Federal Data Protection and Information Commissioner (FDPIC): references to the GDPR are understood to include the Swiss FADP as applicable; the FDPIC is the competent supervisory authority for transfers governed by the Swiss FADP; references to an EU Member State are understood to include Switzerland so that data subjects habitually resident in Switzerland may enforce their rights in Switzerland; and, where the transfer is exclusively subject to the Swiss FADP, the SCCs are governed by Swiss law or the law of a country that allows and grants rights as a third-party beneficiary.
14.5 Data Privacy Framework status. Mikasa Labs LLC is not certified under the EU-US Data Privacy Framework, the UK Extension to it, or the Swiss-US Data Privacy Framework, and does not rely on any of them for transfers under this DPA. The transfer mechanism for transfers to Mikasa Labs LLC is the SCCs as set out in this Section 14. Mikasa Labs LLC's Subprocessors may rely on their own lawful transfer mechanisms for their onward processing, including the EU-US Data Privacy Framework where a Subprocessor is itself certified under it, as reflected in that Subprocessor's terms.
14.6 Importers subject to the GDPR. The parties acknowledge that the SCCs were adopted for data importers not themselves subject to the GDPR, and that the European Commission has announced, but as of the version date of this DPA has not adopted, an additional set of standard contractual clauses for transfers to importers whose processing is subject to the GDPR under Article 3(2). The parties incorporate the existing SCCs as the safeguard available today and will cooperate under Section 14.7 when a new or additional instrument is adopted.
14.7 Replacement mechanisms. If a competent authority or court invalidates a transfer mechanism relied on under this Section 14, or a new mechanism is adopted that must or should replace it, the parties will cooperate in good faith to implement a lawful replacement mechanism promptly, and Mikasa Labs LLC may update this Section by notice to the extent the update does not reduce the protections for Customer Personal Data.
15. CCPA Service Provider Terms
15.1 This Section 15 applies to the extent the CCPA applies to Customer Personal Data. Terms used in this Section 15 that are defined in the CCPA have the meanings given in the CCPA. Mikasa Labs LLC is a service provider to the Customer. This Section is intended to satisfy California Civil Code Section 1798.100(d) and Section 7051 of the CCPA regulations (Cal. Code Regs. tit. 11, Section 7051).
15.2 Limited and specified purposes. The Customer discloses Customer Personal Data to Mikasa Labs LLC only for the following limited and specified business purposes: providing the Service to the Customer as described in the Agreement and Annex 1, namely hosting and operating the Customer's investor data room, including storage, retrieval, display to authorized users, transactional email notification, access control and authentication, audit logging, security and integrity of the Service, debugging and error repair, and data subject request tooling; and the internal uses the CCPA and its regulations permit a service provider.
15.3 Prohibitions. Mikasa Labs LLC will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in Section 15.2, including for any commercial purpose other than those business purposes, or as otherwise permitted by the CCPA and its regulations; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Mikasa Labs LLC and the Customer, except as permitted by the CCPA and its regulations; or (d) combine Customer Personal Data with personal information Mikasa Labs LLC receives from or on behalf of another person, or collects from its own interaction with a consumer, except as permitted by the CCPA and its regulations (for example, to detect security incidents or to protect against fraudulent or illegal activity).
15.4 Certification. Mikasa Labs LLC certifies that it understands the restrictions in this Section 15 and will comply with them.
15.5 Compliance and assistance. Mikasa Labs LLC will comply with the obligations the CCPA makes applicable to service providers, provide the level of privacy protection the CCPA requires of the Customer with respect to Customer Personal Data, and assist the Customer in meeting its CCPA obligations, including responding to verifiable consumer requests (Section 9), implementing reasonable security (Section 7 and Annex 2), and breach notification duties (Section 10).
15.6 Notification of noncompliance. Mikasa Labs LLC will notify the Customer promptly after making a determination that it can no longer meet its obligations under the CCPA.
15.7 Remediation. Upon notice under Section 15.6 or where the Customer reasonably believes Mikasa Labs LLC is using Customer Personal Data in an unauthorized manner, the Customer may take reasonable and appropriate steps, in accordance with the Agreement and this DPA, to stop and remediate the unauthorized use, and Mikasa Labs LLC will cooperate with those steps. The Customer may also take reasonable and appropriate steps to ensure that Mikasa Labs LLC uses Customer Personal Data consistently with the Customer's CCPA obligations, through the mechanisms in Section 13.
15.8 Subcontracting. Mikasa Labs LLC engages Subprocessors under written contracts as described in Section 8.2 and notifies the Customer of Subprocessor engagements as described in Sections 8.3 and 8.4.
15.9 No sale. The parties acknowledge that the Customer's disclosure of Customer Personal Data to Mikasa Labs LLC is not a sale or sharing, and Mikasa Labs LLC provides no monetary or other valuable consideration to the Customer for Customer Personal Data.
16. Other US State Privacy Laws
16.1 This Section 16 applies to the extent a United States state privacy law other than the CCPA applies to the Processing and requires a contract between a controller and a processor (for example, Virginia Code Section 59.1-579(B) and materially similar provisions of other state privacy laws).
16.2 This DPA is that contract. It sets out the Processing instructions (Section 5), the nature and purpose of the Processing, the type of data subject to the Processing, the duration of the Processing (Section 3.2 and Annex 1), and the rights and obligations of both parties.
16.3 Mikasa Labs LLC will: (a) ensure each person Processing Customer Personal Data is subject to a duty of confidentiality (Section 6); (b) at the Customer's direction, delete or return Customer Personal Data as and when provided in Section 12, unless retention is required or permitted by law as described there; (c) on the Customer's reasonable request, make available the information in Mikasa Labs LLC's possession reasonably necessary to demonstrate compliance with the Customer's obligations under such laws (Section 13.1); (d) allow and cooperate with reasonable assessments as provided in Section 13.2, or, where such law permits, satisfy an assessment request by providing a report or the compliance materials described in Section 13.1; and (e) engage subcontractors only under written contracts meeting the requirements of such laws, as provided in Section 8.
17. LIMITATION OF LIABILITY
17.1 TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS DPA, TOGETHER WITH ITS TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT, IS SUBJECT TO THE LIMITATIONS AND EXCLUSIONS OF LIABILITY SET OUT IN THE AGREEMENT, INCLUDING THE AGGREGATE CAP STATED THERE. THE CAP AND EXCLUSIONS APPLY IN THE AGGREGATE ACROSS THE AGREEMENT AND THIS DPA COMBINED. THIS DPA DOES NOT CREATE A SEPARATE OR ADDITIONAL CAP, AND A CLAIM UNDER THIS DPA COUNTS TOWARD THE SAME SINGLE AGGREGATE CAP.
17.2 Nothing in this Section 17 or the Agreement: (a) limits or excludes a data subject's rights against a party under the SCCs where the SCCs apply, including under Clause 12 of the SCCs; or (b) limits or excludes any liability that cannot be limited or excluded under Applicable Data Protection Law.
18. Term and Survival
18.1 This DPA takes effect on the effective date stated above (or, if later, when the Customer accepts the Agreement) and remains in force for as long as Mikasa Labs LLC Processes Customer Personal Data.
18.2 Sections 6, 10, 12, 14 (with respect to data still held), 17, and any other provision that by its nature should survive, survive termination or expiry of the Agreement until Mikasa Labs LLC has ceased Processing Customer Personal Data and completed the deletion required by Section 12.
19. Governing Law
19.1 This DPA is governed by the law governing the Agreement (the law of the State of California, without regard to conflict of laws principles), except that: (a) the SCCs are governed by the law selected in Section 14.2; (b) the UK Addendum and the Swiss adaptations are governed as their terms and Section 14.4 provide; and (c) where Applicable Data Protection Law requires that a matter be governed by a different law, that law applies to that matter.
20. Notices
20.1 Notices to the Customer under this DPA will be sent by email to the Customer's designated administrative contact (the email address of record for the Customer's administrator account) and are effective as provided in the Agreement.
20.2 Notices to Mikasa Labs LLC under this DPA must be sent by email to legal@investordataroom.com and, for legal notices, also in writing to: Mikasa Labs LLC, 37010 Dusterberry Way 546, Fremont, CA 94536.
21. Changes to this DPA
21.1 Mikasa Labs LLC may update this DPA as provided in the Agreement's amendment provisions. Each published version of this DPA is identified by a version number and effective date. If an update materially diminishes the protections for Customer Personal Data under this DPA, Mikasa Labs LLC will give the Customer at least 30 days advance notice by email to the Customer's designated administrative contact before the update takes effect. Changes to Annex 3 are governed by Section 8, and changes to Annex 2 are governed by Section 7.2.
22. Miscellaneous
22.1 Severability. If a provision of this DPA is held invalid or unenforceable, the remainder remains in effect, and the provision will be enforced to the maximum extent permitted; this Section does not apply to the SCCs, which are severable only as their own terms allow.
22.2 Third-party beneficiaries. Except for data subjects to the extent the SCCs give them third-party beneficiary rights, this DPA creates no third-party beneficiary rights.
22.3 Electronic acceptance. This DPA may be accepted electronically, including by clickwrap acceptance of the Agreement that incorporates it, and an electronic record or signature satisfies any requirement of a writing or signature to the extent permitted by the federal E-SIGN Act and applicable state electronic transactions law.
22.4 Disputes. Disputes arising out of or relating to this DPA are resolved as the Agreement provides, except where the SCCs or Applicable Data Protection Law require otherwise.
ANNEX 1: DESCRIPTION OF PROCESSING
This Annex 1 also serves as Annex I of the SCCs where the SCCs apply (Part A as Annex I.A, Part B as Annex I.B, and Part D as Annex I.C).
Part A. List of parties
Data exporter: the Customer identified in the Agreement or in Mikasa Labs LLC's account records for the Customer's tenancy. Role: controller (or processor for a third-party controller, per Section 3.3). Contact: the Customer's designated administrative contact. Activities: operating an investor data room for the Customer's investors on the Service.
Data importer: Mikasa Labs LLC, a California limited liability company. Role: processor. Contact: privacy@investordataroom.com; postal address 37010 Dusterberry Way 546, Fremont, CA 94536. Activities: providing the Service as described in this DPA.
Part B. Description of the processing and transfer
Categories of data subjects: the Customer's investors and other individuals the Customer invites to access the Service (including their authorized representatives where the Customer invites them), and the Customer's personnel and other authorized users who administer the Customer's tenancy.
Categories of personal data:
- Identity and account data: email address, display name, role, tenant association, account status, and notification preferences; the hosted authentication service may also hold a phone number and profile photo where set.
- Authentication data: credentials handled by the hosted authentication service, and time-based one-time-password multi-factor enrollment data.
- Consent and acknowledgment records: document type and scope, tenant association, document version, timestamps, and a salted keyed hash of the IP address; raw IP addresses are never stored.
- Documents and document metadata: files uploaded to the Customer's tenancy in the project, investor-private, and tax categories, and their metadata (titles, categories, checksums, ownership).
- Investment and entitlement records: investor identifier, project, access level, status, commitment and funded amounts, and queue position for job attribution.
- Job-creation allocation snapshots keyed to investments.
- Audit log entries: action, actor identifier, tenant, timestamp, and metadata that by design contains no raw personal identifiers beyond account identifiers.
- Transactional email data: recipient email address, display name, action links (set-password or portal sign-in), and tokenized unsubscribe links; notification emails omit document names and content by design.
Sensitive data: none intended. The Service is not intended for special categories of personal data within the meaning of GDPR Article 9, and Section 4.2 prohibits submitting them. During the pilot phase the Service refuses the most sensitive identity document kinds at creation and at download: passports, visas, I-526 or I-829 immigration petition documents, and documents containing a full United States Social Security number or taxpayer identification number. Tax and investor-private documents may contain financial information and are protected by the step-up controls described in Annex 2.
Frequency of the transfer: continuous, for the duration of the Agreement.
Nature of the processing: hosting; storage; organization; retrieval; display and disclosure by transmission to the Customer's authorized users; transmission of transactional notification email; access control and authentication; audit logging; export; erasure and deletion.
Purpose of the transfer and further processing: provision of the Service to the Customer under the Agreement, on the Customer's behalf and documented instructions. No advertising, no sale or sharing, no tracking, and no automated decision-making producing legal or similarly significant effects concerning a data subject.
Period for which the personal data will be retained: the term of the Agreement plus the windows in Section 12, subject to the category dispositions in Part C below and the carve-outs in Section 12.4.
Transfers to subprocessors: as described in Annex 3; the subject matter, nature, and duration of that onward processing are cloud infrastructure hosting and transactional email delivery for the duration of the Agreement plus the deletion windows.
Part C. Category dispositions on erasure and at end of term
- User profile: personal fields (email, display name, phone number, photo, preferences) are removed at purge; a minimal attributable shell (account identifier, role, tenant association, creation record) is retained for referential integrity of retained records.
- Consent records: retained as proof of acceptance (document type, scope, tenant association, version, timestamp); the hashed IP value is removed at purge.
- Document acknowledgment attestations: the checksum-pinned attestation and timestamp are retained as evidence; the hashed IP value is removed at purge.
- Documents owned by a data subject (investor-private and tax): metadata and the stored file bytes are deleted, unless subject to a documented legal hold.
- Investment records: retained as the financial record of the relationship; entitlement status is set to revoked.
- Job-creation allocation snapshots: retained as program evidence.
- Audit log entries: retained; they contain no raw personal identifiers beyond account identifiers by design.
Part D. Competent supervisory authority
Where the SCCs apply, the competent supervisory authority is determined in accordance with Clause 13 of the SCCs: where the data exporter is established in an EU Member State, the supervisory authority of that Member State; where the data exporter is not established in an EU Member State but has appointed a representative under GDPR Article 27, the supervisory authority of the Member State in which the representative is established; otherwise, the supervisory authority of a Member State in which the data subjects whose personal data is transferred are located. For transfers subject to the UK GDPR, the Information Commissioner's Office. For transfers subject to the Swiss FADP, the Federal Data Protection and Information Commissioner.
ANNEX 2: TECHNICAL AND ORGANIZATIONAL MEASURES
This Annex 2 also serves as Annex II of the SCCs where the SCCs apply. The measures below describe the Service as designed and operated at the version date of this DPA.
1. Encryption in transit and at rest. All traffic to the Service is encrypted in transit using TLS, with HTTP Strict Transport Security enforced. Data at rest is encrypted by the underlying Google Cloud infrastructure using Google's default encryption at rest.
2. Access control and authorization. User roles and tenant association are set only by server-side code and carried in verified authentication claims; they are never accepted from client input. Every tenant-scoped record is isolated by tenant, enforced by default-deny security rules. Project-level access for investors is resolved from server-managed entitlement records. Sessions are revoked on entitlement change, so access changes take effect immediately. Sessions are bound to HttpOnly, Secure cookies with a maximum lifetime of 8 hours.
3. Multi-factor authentication. Time-based one-time-password multi-factor authentication is required for administrator roles and available to investors. Opening an investor-private or tax document additionally requires a step-up: a second factor verified within the previous 5 minutes.
4. Anti-abuse attestation. App Check attestation backed by reCAPTCHA Enterprise is enforced on database, storage, and callable-function access. Enforcement is never disabled in deployed environments.
5. Tenant isolation assurance. Security rules are default-deny, and cross-tenant and per-project isolation is verified by an automated test suite at 100 percent branch coverage as a release gate. Security rules deploy before dependent server code.
6. Document access controls. Document downloads are served only through signed URLs valid for 60 seconds, minted after per-request authorization checks, rate limited per user, and every download is recorded in the audit log. A code-defined pilot allowlist refuses the most sensitive identity document kinds (passports, visas, I-526 or I-829 immigration petitions, full Social Security or taxpayer identification numbers) at creation and at download.
7. Pseudonymization and data minimization. IP addresses are hashed with a keyed HMAC-SHA256 and a secret salt held in a secret manager before storage; raw IP addresses are never persisted. Notification emails omit document names and content by design. Audit log metadata excludes raw personal identifiers, IP addresses, and secrets by schema contract. The Service contains no analytics, advertising, session-replay, or tracking software development kits, and the only first-party cookie is the session cookie.
8. Secrets management and supply chain. Secrets are stored in Google Secret Manager and bound to server code at deploy time; no credentials or keys are committed to source control. Continuous integration deployments are keyless, using workload identity federation.
9. Logging and audit. An append-only audit log, writable only by privileged server code, records privileged administrative actions, role and entitlement changes, document downloads, sensitive writes, and consent events.
10. Data subject tooling. Export bundles are delivered by signed URL valid for 15 minutes, and the underlying export object is automatically deleted from storage after 7 days. Erasure uses a soft-delete window of 30 days followed by a destructive purge executed by a scheduled job, applying the dispositions in Annex 1 Part C. A continuous-integration-enforced coverage map keeps the export and erasure tooling aligned with the data model as it evolves.
11. Availability and backup. The Service runs on Google Cloud managed infrastructure, and Customer Personal Data is stored in replicated, durable managed storage. Daily automated backups of the production datastore are maintained with a 7 day retention cycle. Residual copies in backup media are deleted or overwritten in the ordinary course of the backup cycle.
12. Physical and environmental security. Physical security of the data centers is provided by Google as the infrastructure operator, under the certifications and audit reports Google publishes for Google Cloud and Firebase services (including ISO 27001 and SOC coverage). Mikasa Labs LLC does not itself hold independent security certifications as of the version date of this DPA.
13. Incident response. Security-relevant events are surfaced through platform logging, audit records, and infrastructure provider notifications. Incidents are assessed, contained, and notified to the Customer as provided in Section 10.
14. Personnel. Access to production systems is restricted to authorized persons bound by confidentiality, on a least-privilege basis.
15. Change management. Changes to security rules, privileged server code, and the data model require tests and review before deployment, with tenant-isolation tests as a release gate.
16. Data residency. The Service is hosted in a single United States region; Customer Personal Data at rest is stored in the United States (see Section 14.1).
17. Assistance to the data exporter. The measures in items 9 and 10, together with Sections 9 through 11 of this DPA, are the specific measures by which Mikasa Labs LLC provides assistance to the Customer (and, for Module Three transfers, to the Customer's controller).
ANNEX 3: SUBPROCESSORS
Mikasa Labs LLC engages the following Subprocessors to Process Customer Personal Data. This list is current as of the version date of this DPA and is maintained as described in Section 8.1. Changes are notified as described in Sections 8.3 and 8.4.
1. Google LLC
- Services provided: cloud infrastructure for the Service, comprising authentication (Firebase Authentication, including multi-factor enrollment), primary database (Cloud Firestore), object storage (Cloud Storage), serverless compute and hosting (Cloud Functions, Firebase App Hosting), secret management (Secret Manager), DNS and operational logging (Cloud DNS, Cloud Logging), and anti-abuse attestation (Firebase App Check with reCAPTCHA Enterprise).
- Data categories: all categories of Customer Personal Data listed in Annex 1 Part B.
- Processing location: Customer Personal Data at rest is stored in United States regions selected by Mikasa Labs LLC. Google's service operations, support, and its own subprocessors are as disclosed by Google.
- Terms and transfer safeguards: Google Cloud Data Processing Addendum, https://cloud.google.com/terms/data-processing-addendum . Google's subprocessor disclosures: https://cloud.google.com/terms/subprocessors .
2. Resend Inc.
- Services provided: transactional email delivery for the Service (administrator and investor invitations, password reset links, portal sign-in action links, security notices such as multi-factor enrollment confirmations, and new update and new document notifications), delivered through Resend's upstream carrier, Amazon Web Services (Amazon Simple Email Service).
- Data categories: recipient email address, display name, action links, and tokenized unsubscribe links. Notification emails omit document names and document content by design.
- Processing location: as disclosed by Resend in its data processing agreement and subprocessor list.
- Terms and transfer safeguards: Resend Data Processing Agreement, https://resend.com/legal/dpa . Resend's subprocessor disclosures: https://resend.com/legal/subprocessors .
Services that are not Subprocessors
The following services interact with the Service but are not engaged by Mikasa Labs LLC to Process Customer Personal Data on its behalf, and are listed for transparency:
- Have I Been Pwned (Pwned Passwords): during password screening, the Service sends only a 5-character prefix of a one-way password hash (a k-anonymity technique); no personal data in identifiable form leaves the Service, and no password or full hash is transmitted.
- Google Maps Static API: the Service's server requests a map image for a project's location using project coordinates or an address line, which is the Customer's business data about a project; no investor personal data is sent, and the request is made server-side.
- YouTube and Vimeo: if a Customer administrator embeds a video from one of these providers in a project update, the viewer's browser loads the embed directly from that provider when the update is viewed, and the provider then receives the viewer's IP address and browser information as an independent party under its own terms. This conditional exposure is disclosed in the platform Cookie Policy. These providers are not Mikasa Labs LLC's Subprocessors.
- GitHub and the npm registry: build-time software supply chain only; they receive no Customer Personal Data at runtime.
Version history
- 1.0.0: Initial publication.