Geren Corporate
Client Data Room Privacy Notice
Effective: 29 September 2026
Who is responsible
Ali Geren, operating through Geren Corporate, is responsible for the Client Data Room account administration, authentication, service operation, security, access control, audit and related service communications. Questions and privacy requests may be sent to support@gerencorporate.mt.
For personal data contained in client documents or secure messages, Geren Corporate's legal role depends on the professional engagement. Geren Corporate may act as controller for its own professional or regulatory purposes and may act as processor where data is handled solely on a client's documented instructions. The applicable engagement terms govern that relationship.
What the portal processes
The Data Room may process account and contact details, authentication and MFA state, invitation records, client and Workspace access assignments, document content and version/integrity metadata, malware-scan status, secure-message content and attachment references, audit/security records including technical access information, and recovery/backup data.
Why information is processed
Information is processed to provide and secure the professional service, authenticate users, enforce need-to-know access, exchange and retain professional records, communicate securely, investigate security events, maintain accountability and meet legal or regulatory obligations where applicable.
Depending on the activity and engagement, the lawful basis may include performance of a contract, compliance with a legal obligation and legitimate interests in securely operating and evidencing the professional service. Consent is not used as the routine basis for Data Room account administration or security processing.
Service providers and locations
The live Data Room uses Microsoft Azure services including App Service, Blob Storage, Key Vault, Relay, Azure Communication Services, Defender for Storage, Event Grid and monitoring services. Primary Data Room Azure resources are configured in West Europe, while the dedicated SQL database is hosted in Geren Corporate's Malta office environment through an outbound-only Azure Relay connection.
Microsoft's data-protection terms, subprocessor framework and applicable international-transfer safeguards govern Microsoft cloud processing. Resource-region information alone is not treated as proof that no international transfer can occur.
The one-off Google Drive recovery-evidence copy created before live client onboarding is not a recurring live-client backup destination. New live-client data must not be copied there unless a separate provider, transfer and lifecycle review is completed and approved.
Retention
Company Services records are retained for at least five years after termination where the applicable MFSA recordkeeping rule applies, and longer where law or a competent authority requires it. Other account, security, audit, diagnostic and service records are retained according to their purpose, applicable engagement terms and legal requirements. Retention expiry is subject to human review; the Data Room does not automatically purge client records merely because a period has elapsed.
Security and access
Access is invitation-only. MFA is mandatory. Client, Workspace and document permissions are enforced server-side. Client Administrator and Geren Support roles do not receive document access merely because of their role, and secure-message participation does not grant document access. Documents are private, versioned and malware-scanned before normal availability.
Your rights
Depending on the applicable GDPR role and circumstances, individuals may have rights of access, rectification, erasure, restriction, objection, portability and complaint to the competent supervisory authority. Some rights may be limited by legal or regulatory recordkeeping duties. Where Geren Corporate acts as processor, a request may need to be handled in cooperation with the relevant controller.
Engagement-specific review
Before a client is invited, Geren Corporate records the applicable controller/processor role, expected data categories, retention position and any engagement-specific privacy or processor terms. Processing that materially changes the initial risk profile, including large-scale special-category or criminal-offence data, systematic profiling or another likely high-risk activity, requires renewed privacy/DPIA screening before that expanded use begins.