Back to the portal

Privacy Policy

Version 1.0.0Effective July 18, 2026

PLATFORM PRIVACY POLICY investordataroom.com Version: 1.0.0 Effective date: 2026-07-18 This Privacy Policy explains how Mikasa Labs LLC ("we", "us", "our") collects, uses, discloses, protects, and retains personal data in connection with the investor data room platform available at investordataroom.com and its subdomains, including tenant subdomains (the "Platform"). This Privacy Policy is an informational notice, not a contract. Processing of Customer Personal Data (defined in Section 3) is governed by the Data Processing Addendum between Mikasa Labs LLC and the relevant Tenant. If this Privacy Policy conflicts with the Data Processing Addendum with respect to Customer Personal Data, the Data Processing Addendum controls, followed by the Platform Terms of Service, followed by the Acceptable Use Policy. Please read Section 2 first. It explains which organization is responsible for which data about you, and where to send questions and requests. 1. Who We Are Mikasa Labs LLC is a California limited liability company. We operate the Platform as a neutral software provider. Tenants (defined in Section 3), typically EB-5 regional centers, issuers, and fund managers, use the Platform to share information and documents with their own investors. Mikasa Labs LLC is not a party to any investment, does not author or endorse Tenant content, and provides no investment, legal, immigration, or tax advice. Email: privacy@investordataroom.com Mail: Mikasa Labs LLC, 37010 Dusterberry Way 546, Fremont, CA 94536 2. Our Two Roles: Who Decides How Your Data Is Used The Platform holds two kinds of personal data, and a different organization is responsible for each kind. First, data we collect to run the Platform itself. This includes your account record, your sign-in and security records, your acceptance of legal documents, audit logs, your notification preferences, and email you send to us. For this data, Mikasa Labs LLC decides how and why the data is used. Privacy laws call this being a "controller" (or, under some US state laws, a "business"). This Privacy Policy is the primary notice for this data, which we call Operational Data. Second, data that a Tenant and its investors put into the Tenant's workspace on the Platform. This includes investor identity details a Tenant enters, investment records, documents, document acknowledgment records, and job-creation records. For this data, the Tenant decides how and why the data is used, and Mikasa Labs LLC follows the Tenant's documented instructions. Privacy laws call this being a "processor" or "service provider". We call this data Customer Personal Data. The Tenant's own privacy policy is the primary notice for Customer Personal Data. It is linked at the consent screen shown when you first sign in, and it is available from the Tenant. If you are an investor and your question or request concerns data your Tenant controls (for example, your investment records or documents the Tenant shared with you), the right place to start is the Tenant. Section 11.2 explains how we route such requests. We never author or host Tenant legal documents; the Platform links to them where the Tenant publishes them. 3. Definitions "Customer Personal Data" means personal data that a Tenant or its authorized users submit to the Tenant's workspace on the Platform, or that the Platform generates inside that workspace on the Tenant's behalf, and that the Tenant controls. "DPA" means the Data Processing Addendum between Mikasa Labs LLC and a Tenant. "Operational Data" means personal data Mikasa Labs LLC collects and controls to operate, secure, and administer the Platform, as described in Section 2. "Platform" means the investor data room service available at investordataroom.com and its subdomains, including tenant subdomains. "Tenant" means the organization (for example, an EB-5 regional center, issuer, or fund manager) that has an agreement with Mikasa Labs LLC to use the Platform and that invites its own users, including investors, into its workspace. "You" means any person who uses the Platform, whether an investor, a Tenant administrator, or a platform operator. 4. Personal Data We Collect We collect personal data from three sources: from you directly, from your Tenant, and from your use of the Platform. 4.1 Data you provide directly - Account and identity data: your name (display name), your email address, your role on the Platform, your account status, and the identity of the Tenant workspace your account belongs to. If a Tenant invited you, the Tenant typically provided your name and email address first (see Section 4.2). If a phone number or profile photo is associated with your account in our authentication service, we hold those as well. - Password: processed by our authentication service and stored only in hashed form. We do not store plaintext passwords. - Multi-factor authentication (MFA) enrollment: if you enroll in time-based one-time password (TOTP) MFA, the enrollment record is held by our authentication service. - Notification preferences: your choices about content notification email. - Support correspondence: if you email us, we receive your email address and the content of your message. 4.2 Data your Tenant provides about you (Customer Personal Data) - Identity and contact details the Tenant enters to invite you and manage your access. - Investment and entitlement records: investment amounts, currency, commitment dates, project memberships, and access levels. - Documents concerning you: the Platform supports project documents shared with a Tenant's investors, investor-private documents, and tax documents. Tenant-submitted documents may contain sensitive information, such as financial and tax details. We process document contents only as the Tenant's processor and do not use them for any purpose of our own. - Pilot data minimization: the Platform currently refuses to accept or serve documents identified as a passport, a visa, an immigration petition (for example Form I-526 or Form I-829), or a record of a full Social Security number or taxpayer identification number. These categories are excluded from the Platform at this time. 4.3 Data generated by your use of the Platform - Legal acceptance records: when you accept the Platform legal documents or a Tenant's legal documents, we record the document type, the version accepted, the time, and a keyed cryptographic hash of your IP address. Raw IP addresses are never stored in these records. We handle your IP address transiently to create that hash and to serve your connection, as any web service must. - Document acknowledgment records: when you acknowledge a document, we record a checksum of the exact file you acknowledged, the time, and a keyed cryptographic hash of your IP address. - Audit logs: security-relevant actions on the Platform (for example sign-in events, role changes, document downloads, and administrative actions) are recorded with the action, the account identifier, the Tenant, the time, and limited technical detail. Audit logs are designed to contain no raw IP addresses and no document contents. - Job-creation allocation records: for EB-5 program tracking, the Platform generates job-allocation snapshots tied to investment records. These are Customer Personal Data. - Security signals: our anti-abuse system (Firebase App Check with reCAPTCHA Enterprise, operated by Google) collects browser attestation signals when you use the Platform. When you set a password, we also screen it against known-breached password lists using the privacy-preserving method described in Section 6.1. - Session data: a session cookie keeps you signed in (see Section 7). We do not collect precise geolocation, biometric information, or advertising identifiers, and the Platform contains no analytics or tracking software development kits. 5. How We Use Personal Data and Our Legal Bases We use Operational Data to: - Provide and operate the Platform: create and administer accounts, authenticate you, maintain your session, and respond to your support email. - Secure the Platform: enforce tenant isolation and access controls, verify device and browser attestation, screen breached passwords, rate-limit abusive requests, and keep audit logs. - Meet legal obligations and manage legal risk: keep evidence of legal acceptance, respond to privacy requests, meet breach notification duties, retain records required by law, and establish or defend legal claims. - Communicate about the service: send transactional email such as invitations, password reset messages, security notices (for example when MFA is enabled on your account), and content notifications. We send no marketing email. You can turn off content notifications in your notification preferences or with the unsubscribe link in the email; service and security messages are sent for as long as you hold an account. For people in the European Economic Area or the United Kingdom, our legal bases for Operational Data are: - Performance of a contract (GDPR Article 6(1)(b)): providing the Platform to you under the Platform Terms of Service. - Legitimate interests (GDPR Article 6(1)(f)): keeping the Platform and the data on it secure, preventing fraud and abuse, operating the service in ways you would reasonably expect, and establishing or defending legal claims. Our security processing is deliberately narrow: attestation, breached-password screening, rate limiting, and audit logging. - Legal obligation (GDPR Article 6(1)(c)): record-keeping, responding to lawful requests, and breach notification duties. - Consent (GDPR Article 6(1)(a)): we do not currently rely on consent as the legal basis for any processing described in this Privacy Policy. If we ever do, we will ask you clearly at the point of collection, and you will be able to withdraw consent at any time. Providing the account data described in Section 4.1 is a practical requirement of using the Platform, not a statutory one: without an email address and an account record, we cannot provide you access. For Customer Personal Data, we process only on the Tenant's documented instructions under the DPA. The Tenant is responsible for establishing its own legal basis and for its own privacy notice. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. We do not sell personal data, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising. 6. How We Disclose Personal Data We disclose personal data only as described in this Section 6. 6.1 Service providers (subprocessors) We use a small number of service providers to run the Platform. Each is bound by contract to process personal data only to provide its service to us. - Google LLC (United States). Cloud infrastructure for the entire Platform: application hosting, database, file storage, authentication, serverless computing, secret management, security attestation (Firebase App Check with reCAPTCHA Enterprise), server-side map image rendering, domain name services, and operational logging. All personal data processed on the Platform is hosted on Google Cloud in the United States. - Resend Inc. (United States). Transactional email delivery. Resend receives the recipient email address, display name, and the links the message contains (for example a set-password link or an unsubscribe link), and delivers mail through its upstream carrier, Amazon Web Services (Amazon Simple Email Service). Notification email is designed to omit document names and document contents. - Have I Been Pwned. When you set a password, we send only the first five characters of a cryptographic hash of the password to this breached-password service and compare the results on our side (a k-anonymity technique). Your password, your identity, and the full hash never leave our systems, and no personal data leaves in identifiable form. 6.2 Video platforms, only when a Tenant embeds video If a Tenant embeds a video from YouTube or Vimeo in an update, the video player loads from that provider when you open the page. The provider can see your IP address and browser information and may set its own cookies inside its player frame. This happens only on pages where a Tenant has embedded a video. The Platform sends nothing else to these providers. 6.3 Your Tenant Customer Personal Data is available to your Tenant and the users the Tenant authorizes. That is the purpose of the Platform. We do not sell or license Operational Data to Tenants; a Tenant can see activity records connected to its own workspace (for example, whether its investors have acknowledged a document). 6.4 Professional advisers We may disclose personal data to our lawyers, auditors, accountants, and insurers under confidentiality obligations, where needed for audits, insurance, or legal advice. 6.5 Legal process and protection We may disclose personal data where we believe in good faith that disclosure is required by law or valid legal process, or is necessary to protect the rights, property, or safety of Mikasa Labs LLC, our users, or others. Where a request concerns Customer Personal Data, we will, where legally permitted, direct the requester to the Tenant and notify the Tenant. 6.6 Business transfers If Mikasa Labs LLC is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal data may be transferred as part of that transaction. We will require the recipient to honor this Privacy Policy or to provide notice and any legally required choices before handling your personal data in a materially different way. 6.7 What we never do - We do not sell personal data. - We do not share personal data for cross-context behavioral advertising. - We do not use or disclose personal data for targeted advertising. - The Platform contains no analytics or tracking software development kits, no advertising networks, and no data brokers. 7. Cookies, Local Storage, and Similar Technologies The Platform's use of browser storage is deliberately minimal. This is the complete inventory: - One first-party cookie: a session cookie named __Host-session. It keeps you signed in. It is HttpOnly (page scripts cannot read it) and Secure, and it lasts up to 8 hours or until you sign out. It is strictly necessary: the Platform cannot keep you signed in without it. - Theme preference: your light-or-dark theme choice is stored in your browser's localStorage. It never leaves your browser. - Authentication state: our sign-in library stores authentication state in your browser's IndexedDB storage. It is strictly necessary for sign-in to work. - Security attestation state: our anti-abuse library keeps its current attestation token in your browser's IndexedDB storage so the security check does not have to re-run on every request. It is used for security purposes only. - Library service records: the Google client libraries the Platform is built with keep small records in your browser's IndexedDB storage listing the library versions in use and the dates they were used. These records accompany the Platform's requests to Google's services as diagnostic information; they contain no name, email address, or account identifier. - reCAPTCHA Enterprise (Google): our anti-abuse protection loads Google scripts and an iframe in your browser, and Google may set its own cookies in that context. This is used for security and anti-abuse purposes only. The Platform sets no analytics, advertising, or tracking cookies of any kind. For more detail, see the Platform Cookie Policy, published alongside this Privacy Policy. Global Privacy Control and Do Not Track: some browsers can send opt-out preference signals. We do not sell personal data and do not share it for cross-context behavioral advertising, for any user, so there is no sale or sharing for such a signal to opt out of. Our practices are the same whether or not your browser sends one. 8. How Long We Keep Personal Data We keep personal data no longer than needed for the purposes described in this Privacy Policy, plus any period required by law. While your account exists, we keep the data that operates it. The schedule below describes what happens to each category at end of life, including after a verified deletion request (see Section 11.1): - Account profile and notification preferences: kept while your account is active. After a verified deletion request, identifying fields (email, name, phone number, photo, preferences) are permanently removed at the end of the deletion window described in Section 11.1. An internal account identifier and administrative fields (role and workspace assignment) are retained so the records described below stay consistent; they no longer include your name or contact details. - Legal acceptance records: the record of which document version you accepted, and when, is retained as legal proof of acceptance. On deletion, the hashed IP value is removed and the proof fields are kept. - Document acknowledgment records: the attestation (document checksum and time) is retained as legal proof. On deletion, hashed identifiers are removed and the attestation is kept. - Investment and entitlement records: retained as the financial record of the investment relationship, including after account deletion. - Job-creation allocation records: retained as program records. - Audit logs: retained for security, dispute resolution, and record-keeping obligations. - Investor-private and tax documents that belong to you: permanently deleted after a verified deletion request, unless a specific document is under a legal hold, in which case that document is retained until the hold ends and the rest are deleted. - Privacy export files (see Section 11.1): automatically deleted from our systems within 7 days of creation. - Session records: the session cookie expires after at most 8 hours. - Customer Personal Data generally: retained and deleted per the Tenant's instructions and the DPA. Deleted data can persist for a short additional period in residual copies in routine backups of our datastore. Backup copies are deleted or overwritten in the ordinary course of the backup cycle and are not used to restore deleted data except for disaster recovery. Where law requires us to preserve specific records (for example under a legal hold or a statutory retention duty), we retain them for as long as the requirement applies and continue to protect them as described in Section 9. 9. How We Protect Personal Data The Platform is designed with security as the first requirement. Measures in place today include: - Attestation on every data path: every connection from the application to our database, file storage, and server functions must present a valid attestation token (Firebase App Check with reCAPTCHA Enterprise). - Default-deny access rules: our database and file storage rules deny all access unless a rule explicitly allows it, and tenant isolation is enforced and tested so one Tenant's users cannot read another Tenant's data. - Multi-factor authentication: administrator accounts must enroll in MFA before they can use the Platform, and opening an investor-private or tax document requires a fresh MFA verification (step-up). - Short-lived download links: document downloads use signed links valid for about 60 seconds, are rate limited, and are recorded in the audit log. - IP address protection: where a record needs IP evidence, we store a keyed cryptographic hash (HMAC-SHA256) computed with a secret key, never the raw IP address. - Encryption: data is encrypted in transit (TLS) and at rest on Google Cloud. - Secret management: application secrets are stored in a dedicated secret manager, not in code or configuration files. - Append-only audit logs: security-relevant actions are recorded in audit logs designed to be append-only. No system is perfectly secure. If a breach affects Customer Personal Data, we notify the affected Tenant, and the Tenant, as controller, notifies individuals and regulators as required. If a breach affects Operational Data, we notify affected individuals and authorities as required by law. 10. International Data Transfers The Platform is operated from the United States and stores all data in a single United States region. If you use the Platform from outside the United States, your personal data is transferred to and processed in the United States, whose data protection laws may differ from those of your home jurisdiction. Platform users may be located outside the United States. For Customer Personal Data that is subject to European Economic Area or United Kingdom data protection law, the transfer is addressed contractually in the DPA between Mikasa Labs LLC and the Tenant, including through the European Commission's Standard Contractual Clauses where they apply. Mikasa Labs LLC is not certified under the EU-US Data Privacy Framework and does not rely on it for any transfer. 11. Your Privacy Rights 11.1 How to make a request and what happens next Send privacy requests to privacy@investordataroom.com, from the email address associated with your account where possible. We verify your identity before acting on a request: at minimum we match the request to the account email, and we may ask you to confirm control of the account (for example by signing in or replying from the account email) or to provide additional information where the law allows. We respond within the time required by the law that applies to your request. We do not charge a fee for a reasonable request. If we cannot honor a request, we will tell you why, and you may appeal as described in Section 11.4 or complain to a supervisory authority as described in Section 11.3. - Access and portability: on a verified request, we produce an export of your personal data held on the Platform in a machine-readable format (JSON). The export is delivered as a secure download link valid for 15 minutes, and the export file itself is automatically deleted from our systems within 7 days. The export includes your profile, preferences, legal acceptance records, investment records, metadata about your own documents (not the file contents), acknowledgment records, job-creation records tied to your investments, and audit records of your own actions. - Correction: we correct inaccurate Operational Data on request. For Customer Personal Data, we route the request to your Tenant (see Section 11.2). - Deletion: on a verified deletion request, access to the account is revoked when we action the request, and the data enters a deletion window of 30 days. At the end of the window, personal data is permanently deleted or reduced as described in Section 8. Records we must keep (proof of acceptance, financial records, audit logs, and documents under legal hold) are retained as Section 8 describes. - Objection and restriction: you may object to processing based on legitimate interests, or ask us to restrict processing, and we will assess the request under applicable law. Security processing is often necessary to keep providing the service at all; where that is the case, we will explain it. Authorized agents: where the law allows an authorized agent to submit a request for you (for example in California), we require proof of the agent's authority, and we will still verify your identity with you directly where permitted. 11.2 Requests about Tenant-controlled data If your request concerns Customer Personal Data (for example, investment records or documents your Tenant manages), the Tenant is the controller and is responsible for responding. When we receive such a request, we forward it to your Tenant without undue delay and assist the Tenant as the DPA requires. The Tenant's own privacy policy, linked at the consent screen and available from the Tenant, describes the Tenant's practices and your rights against the Tenant. 11.3 European Economic Area and United Kingdom If EEA or UK data protection law applies to you, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. You also have the right to lodge a complaint with a supervisory authority: in the EEA, the data protection authority of your member state; in the UK, the Information Commissioner's Office. 11.4 California and other US states California residents have rights under the California Consumer Privacy Act, as amended: to know and access the personal information we collect, to correct it, to delete it, to receive it in a portable format, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we do not use or disclose sensitive personal information for purposes beyond those the law permits for providing the service and maintaining security, so there is no use to limit), and not to receive discriminatory treatment for exercising these rights. Residents of a number of other US states have similar rights under their state privacy laws, and we honor them through the same process (see Section 11.1). Categories of personal information for California: in the preceding 12 months (or since the Platform launched, if shorter) we have collected identifiers (name, email address); customer records (account details); commercial information (investment records, processed for Tenants as a service provider); internet or other electronic network activity information (audit records of Platform actions); professional information (your role and Tenant affiliation); and sensitive personal information limited to account log-in credentials used for authentication, plus the contents of Tenant-submitted documents (which may include financial or tax details), processed only as the Tenant's service provider. We collect these categories from you, from your Tenant, and from your use of the Platform, for the purposes in Section 5, and we disclose them for business purposes to the service providers listed in Section 6.1. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing the personal information of anyone under 16 years of age. Appeals: if we decline your request and your state's law gives you a right of appeal, reply to our decision stating that you appeal. We will review the appeal and respond within the time your state's law requires, including telling you how to contact your state attorney general if the appeal is denied. 11.5 Canada If Canadian federal privacy law (PIPEDA) applies, you may request access to your personal information, challenge its accuracy, and withdraw consent subject to legal and contractual restrictions, using the process in Section 11.1. You may also complain to the Office of the Privacy Commissioner of Canada. 12. Children The Platform is a professional investment data room. It is not directed to minors under 18, and we do not knowingly collect personal data from anyone under 18. If you believe a minor's personal data has been provided to the Platform, contact us at privacy@investordataroom.com and we will delete it as required by law. 13. Changes to This Privacy Policy Each version of this Privacy Policy is published to an append-only version ledger with its version identifier, effective date, and a summary of changes. The current version and its effective date appear at the top of this document. If we make a material change, the Platform will present the new version for acceptance at your next sign-in before you continue using it. Non-material corrections may be published without re-acceptance; the ledger records every version either way. 14. How to Contact Us Mikasa Labs LLC 37010 Dusterberry Way 546, Fremont, CA 94536 Email: privacy@investordataroom.com For requests about data controlled by your Tenant, contact your Tenant first (see Section 11.2). Section 2 explains the two roles, and the DPA governs the processing of Customer Personal Data.