Data Room, Inc. (US)
United States · New York
English

Privacy Policy

Last updated: October 7, 2026. This policy now says what our payment provider receives when a host on our GPU marketplace sets up payouts, and that on the GPU marketplace the host of a machine you are claimed to have damaged may be given your name and an address for you (who receives your personal information). Since October 6, 2026 it also lists who receives your personal information, the legal grounds we rely on, how to exercise your rights and what we keep about a visit that began with one of our advertisements.

We respect your privacy.

Server Room complies with all applicable regulations and laws relating to the protection of personal data. Each Server Room user is in control of their data. Server Room does not make use of it freely. Personal data is dealt with transparently, confidentially and securely. Server Room is engaged in a continuous process of protecting the data of its users, in accordance with the General (EU) Data Protection Regulation of 27 April 2016 (hereinafter "GDPR").

Our fundamental principles:

  • We ask only for the personal information we need for the purposes described in this policy;
  • Your personal information is disclosed only to the recipients listed under Who receives your personal information;
  • In particular, we do not publish any of the information that you provide us with, including the websites that you create with Data Room, Inc.;
  • In accordance with applicable data-protection law and the GDPR, you have the right to access, modify, rectify and delete data concerning yourself. You can exercise this right by contacting our support team or by addressing a letter to our head office.

Data Room, Inc. manages the services serverroom.net and reserves the right to create other services. With all of its services, Data Room, Inc. is committed to applying the same privacy policy.

Visitors

Like the majority of websites, Data Room, Inc. records information such as the IP address, browser type, language preference, source site, the pages requested and the date and time of each visit in its server logs. These logs are used to operate and secure the website, and to measure, in aggregate, how each page performs: how visitors find it, whether it leads to an order, and which of two wordings of a page works better while we test them. For these statistics the IP address and browser are turned into a salted one-way code. Separately, for a visit that reaches us from an advertisement or a campaign link, we keep a record of the visit (the IP address, the pages opened and for how long, the search terms where the advertising platform gives them, whether the visit led to a chat, the creation of an account, a login or a payment and, for a visitor who signed in, the customer number) and assess how engaged it was, to judge our advertising and to choose which visits we report to the advertising platform. These visit records are kept for up to 90 days from the visit. We do not sell this information or share it with advertising or analytics companies, with one exception: a click on one of our advertisements that leads to an engaged visit, the creation of an account or a first payment is reported to the advertising platform it came from (see Who receives your personal information). Nothing is stored on your device for this purpose. The server logs are kept for three years.

Relevance of Data

In order to best follow the interest of Server Room's prospects and customers, the file collects all information of visitors of the website serverroom.net relating to their identity and professional information. We do not ask you for information about racial or ethnic origin, political, philosophical or religious opinions, trade union membership, health or sexual life (sensitive data) for our own purposes. Where an identity check is needed, our identity verification provider compares a photo of your face with your identity document. What you store on a server or write to our support is your own choice.

Lawfulness of processing and conditions of consent (art.6 and art.7 of the GDPR)

We process personal data on different legal grounds, depending on the purpose:

  • to create your account, provide the services you order, bill you and answer your requests: performance of our contract with you (GDPR art. 6(1)(b)) or, where you act for a company that is our customer, our legitimate interest in providing the service to it (art. 6(1)(f));
  • for invoices, accounting and tax records, and to answer authorities where the law requires us to: a legal obligation where the law of the European Union or of one of its member states imposes it on us (art. 6(1)(c)), and otherwise our legitimate interest in meeting the law that applies to us (art. 6(1)(f));
  • to keep the services secure, prevent fraud and abuse, keep server logs, improve the services and measure the results of our advertising (the report to an advertising platform described under Who receives your personal information): our legitimate interest (art. 6(1)(f)); you can object to this processing at any time (art. 21);
  • for a newsletter and other messages you asked for: your consent (art. 6(1)(a)), which you can withdraw at any time without affecting what was done before.

Accepting our terms is not consent to advertising.

Who receives your personal information

It is received only by:

  • companies that provide services to us and use it for us, on our instructions: the providers of our email, telephone and messaging, of the automated assistants that answer chat and calls, and the data centers and network carriers our servers use;
  • our accountants, auditors and legal advisers, who act under their own professional duties;
  • our payment and identity verification providers, the card networks and the banks involved in a payment, which also use it under their own legal duties, for example to prevent fraud and to handle a disputed payment;
  • our affiliated companies, which run the services with us;
  • advertising platforms (Google, LinkedIn, Reddit and X): when a click on one of our advertisements leads to an engaged visit (one in which the site was really used), the creation of an account or a first payment, we report an event to the platform the click came from, to measure our advertising and to help the platform's bidding. The report holds the identifier the platform itself put on the click, which can let it connect the event to the person who clicked; the time; which of the platform's conversion actions the event is filed under; a token we generate for the event, which does not show your account or customer number; and, where one is sent, a value and its currency. Reddit also receives the address of our site's home page. Except for account creations reported to Google, which have an action of their own, these reports are filed under the platform's purchase action and do not say which of the three kinds the event was. For an engaged visit or an account creation, a value, where one is sent, is an estimate we assign to help the platform's bidding and not money paid. We send them no email address, phone number or other contact detail, and no lists of customers;
  • on the GPU marketplace, the host of a machine you rent: its machine receives the public access key you rent with and holds what you put on the rental. That is encrypted while it is stored, which does not stop a host who administers the machine from reaching it while it is in use. And, in the one case section 9 of the Marketplace terms describes, the host of a machine you are claimed to have damaged may be given your name and an address for you that we have checked;
  • courts, authorities and other persons, where a judicial order or other valid legal process requires it, or where we need it to bring or answer a legal claim.

On the GPU marketplace, where the software on a host's machine and its hardware support it, the software reads the state of the hardware before and after a rental: the versions and settings of the GPU's firmware, its error counters, the drive's wear figures and how much the rental wrote. It reads nothing of what you store or run. We keep these readings and do not delete them automatically; the host can see the readings of its own machine, which also keeps those of its last 20 rentals. You can ask our support for the reading of your own rental.

Data Retention

We keep personal data for the purposes described in this policy:

  • Your account, services, orders, invoices and payments, your messages to us (support tickets, emails, live chat and the transcripts of phone calls) and the records of your requests to our dashboard and API: we do not delete these automatically. We keep them so that we have the history of your services, of what we provided and of what you paid, and we delete them when you ask us to (see Individual Rights). Invoices and payment records are kept for at least seven years in any case, a period we choose so that it covers what US tax rules require; DATA ROOM SRL keeps its accounting documents for at least five years from 1 July of the year after the financial year, as Romanian accounting law requires.
  • Our websites' server logs: three years.
  • Records of payment attempts with our payment processors: one year.
  • Records of calls answered by our voice assistant: one year. The working records of our automated chat assistant: 30 days.

When you ask us to delete your personal data, we delete it, except what the law requires us to keep and what we need to establish, exercise or defend a legal claim.

Your privacy rights (art. 12 to 22 of the GDPR)

In accordance with the GDPR and applicable data-protection law, all individuals can exercise their right of access, rectification, opposition, limitation of processing, deletion and portability of data concerning them by email to support@serverroom.net, preferably sent from the email address of your account, or by letter to the head office of Data Room, Inc. We ask for more information to confirm your identity only where we have a reasonable doubt about who is asking.

You can object at any time to the use of your data for direct marketing, and we then stop using it for that. You can also object to other processing that rests on our legitimate interest; we then stop unless we have compelling grounds that the law accepts.

You also have the right to complain to a data protection authority; if you live in the European Union, to the authority of the country where you live. If you are in the United Kingdom, you can complain to us at support@serverroom.net: we acknowledge a complaint within 30 days and tell you its outcome without undue delay. You can also complain to the Information Commissioner's Office (ico.org.uk).

Data security and processing (art. 32 of the GDPR)

The data collected on the website serverroom.net and associated processing, are hosted by the company Data Room, Inc.. Only individuals linked to the technical, marketing and commercial department of Data Room, Inc. and its subcontractors have access to the information collected on the website serverroom.net, via a personal and unique identifier to the Server Room platform.

Payouts to marketplace hosts

When a host on our GPU marketplace sets up payouts, the information asked for (identity, address, bank account and, where required, identity documents and taxpayer number) is sent from the host's browser directly to our payment provider, Stripe, which uses it to verify the host and to pay them; we do not store it. We keep the tax certification the host signs for us (the name and the country of tax residence it gives, and its signature), the host's country, whether it is an individual or a company, and the state of the payout setup. When you provide personal data in connection with payouts on Server Room, Stripe receives that personal data and processes it in accordance with Stripe's Privacy Policy.

Data breach and communication within 72 hours (art. 33 and art. 34 of the GDPR)

If the security of personal data we are responsible for is breached, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to put people's rights and freedoms at risk (art. 33). Where the risk to the people concerned is high, we also tell them without undue delay (art. 34). Where we process data on behalf of a customer, we tell that customer without undue delay.

Cookies

Server Room does not set its own cookies. We do not place cookies on your device to identify you, track your activity, or serve analytics or advertising. Where the website needs to remember something in order to work properly — for example, to keep you signed in to your account — it uses your browser's local storage, which stays on your device and is not used to track you across other websites. Page statistics and tests of page wording are worked out from our own server logs, as described above, without cookies or local storage. Certain third-party tools we embed, such as our live-chat widget and our payment processor, may set their own strictly necessary cookies when you use those specific features; any such cookies are controlled by those providers under their own privacy policies, not by Server Room.

External Links

The website serverroom.net points to many other websites. Server Room can in no way be held responsible for the content and privacy policy of these websites. Server Room cannot be held responsible for any direct or indirect damage that may result from their use: in particular access to these websites and websites linked to these websites, and non-limiting damage, financial or commercial prejudice, operating loss, data loss, even if we were able to be notified beforehand.