Legal
Data Processing Addendum
Version and effective date 16 August 2026
This Data Processing Addendum forms part of the agreement between Amafi (HK) Limited, trading as MergerMatch, and the customer identified when an authorised workspace representative accepts it in MergerMatch Rooms. It applies when MergerMatch processes personal data in customer-controlled Rooms content on the customer's behalf.
1. Parties, roles, and scope
The customer is the controller or data user for personal data it places in Rooms and for the disclosure choices it makes. Amafi (HK) Limited is the processor or data processor for that customer-controlled content. Each party remains independently responsible for information it controls for its own purposes. MergerMatch controls account administration, billing, service security, fraud prevention, and legal compliance data as described in the Privacy Policy.
2. Documented instructions
MergerMatch will process customer personal data only to provide, secure, support, maintain, and improve the contracted Rooms service. The customer's documented instructions are this Addendum, the Terms, the applicable order, support instructions, and authorised use of product controls. MergerMatch will notify the customer if an instruction appears to violate applicable data protection law unless law prohibits that notice.
MergerMatch may process or disclose personal data when required by law. When legally permitted, MergerMatch will notify the customer before the disclosure and limit it to what is required.
3. Customer responsibilities
The customer is responsible for lawful and fair collection, notices, permissions, legal basis, accuracy, disclosure decisions, guest instructions, retention instructions, and communications with affected people. The customer must use appropriate groups and permissions and must not upload restricted or highly sensitive data unless it has confirmed that the use is lawful and that the selected Rooms workflow is appropriate.
4. Confidentiality and personnel
MergerMatch will limit access to personnel who need it for their work, are subject to appropriate confidentiality duties, and receive security and privacy instruction appropriate to their role. Access is removed when it is no longer required.
5. Security
MergerMatch will maintain technical and organisational measures appropriate to the risk, including the measures in Schedule 2. Measures may evolve when the overall level of protection is not materially reduced.
Rooms currently uses physical database backups, write-ahead log archiving, and versioned private object storage. Continuous point-in-time database recovery is not included unless an order or written activation record says it is active. No fixed recovery point or recovery time objective applies unless it is stated in an order. Backups reduce risk but do not replace the customer's own export, continuity, and record-keeping responsibilities.
6. Subprocessors
The customer gives general authorisation for the subprocessors in Schedule 3. MergerMatch will impose appropriate data protection duties and remains responsible for their processing to the extent required by applicable law.
MergerMatch will give at least 15 days' advance notice through the service or the customer's account email before adding a subprocessor that will process customer-controlled content. The customer may raise a reasonable documented data protection objection during that period. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may terminate the affected Rooms service. MergerMatch will refund any prepaid fee for the unused terminated period.
7. Individual rights requests
Taking into account the nature of processing, MergerMatch will provide reasonable assistance through product controls and support procedures when the customer must respond to an individual rights request involving customer content. If MergerMatch receives the request directly, it will route it to the customer when the customer is responsible, unless law requires a direct response.
The customer decides the request, verifies authority, communicates with the requester, and gives lawful instructions. Assistance beyond standard product and support functions may be charged at an agreed reasonable rate where law allows.
8. Security incidents
MergerMatch will notify the customer's approved security contact without undue delay after confirming a personal data breach affecting customer-controlled content. Notice may be provided in stages as information becomes available and will describe the known nature, affected data and people, likely consequences, containment, and contact point. Notification is not an admission of fault.
The customer is responsible for its controller notifications. MergerMatch will provide reasonable cooperation and preserve relevant evidence, subject to confidentiality, security, privilege, and other customers' rights.
9. Assessments and audits
MergerMatch will provide information reasonably available about processing and security measures to support a required impact assessment, regulator consultation, or compliance review. The parties will first use current reports, architecture summaries, test summaries, and written responses when available.
If that material is insufficient for a legally required audit, the customer may request one audit each year on reasonable advance notice during business hours. It must minimise disruption, protect other customers and security, use an independent qualified auditor under confidentiality, and avoid production exploitation. The customer bears its audit cost unless the audit finds a material breach by MergerMatch.
10. Return, deletion, and legal holds
During an entitled subscription period, the customer may export supported content through available product controls. On a verified lawful instruction or after the service ends, MergerMatch will delete or return customer-controlled personal data in accordance with the Terms and Privacy Policy unless law permits or requires retention. A verified account deletion process is targeted for completion within 30 days.
Deletion from active systems does not immediately erase isolated physical backups or noncurrent object versions. Those copies remain access-restricted, are not used for ordinary processing, and expire through the applicable backup or storage lifecycle. Noncurrent Rooms object versions can remain for up to seven years unless an approved deletion process removes them earlier. If a backup is restored after a valid deletion, the deletion record is used to prevent the data from returning to active use.
A documented legal hold may preserve the minimum necessary data for a legal duty, dispute, fraud matter, confidentiality issue, or claim. MergerMatch will restrict ordinary use and record the reason and review point.
11. International transfers
Customer content is processed in the locations in Schedule 3. Each party will comply with transfer requirements that apply to it. Before initiating a restricted transfer from the EEA or United Kingdom that requires an approved safeguard, the customer must contact MergerMatch so the parties can complete the applicable transfer documents and assessment.
Where appropriate, the parties will complete the European Commission Standard Contractual Clauses issued under Decision 2021/914 using Module Two, or the current Information Commissioner's Office International Data Transfer Addendum or International Data Transfer Agreement. The parties will also complete the required appendix details and transfer assessment. Accepting this Addendum does not by itself complete those customer-specific transfer documents or authorise a restricted transfer.
12. Priority, liability, and duration
If this Addendum conflicts with the Terms or an order about processing customer personal data, this Addendum controls for that conflict. The liability allocation in the Terms applies to this Addendum unless applicable law requires otherwise. This Addendum lasts while MergerMatch processes customer personal data and any term that must continue to protect retained data remains effective.
Schedule 1. Processing details
| Subject matter | Hosting and operation of a private virtual data room for transaction due diligence |
|---|---|
| Duration | The service period plus approved deletion, evidence, legal hold, and backup cycles |
| Nature and purpose | Collection, storage, organisation, encryption, malware scanning, preview generation, access control, disclosure, download, Q&A, audit, support, backup, recovery, export, and deletion |
| Personal data | Identity and professional details, email, permissions, access and audit events, transaction documents and their contents, Q&A, support records, and technical identifiers |
| People | Customer personnel, advisers, invited bidders and guests, employees, contractors, clients, counterparties, and people described in uploaded documents |
| Sensitive data | Not intentionally required. The customer must confirm authority, necessity, legal basis, and workflow suitability before uploading sensitive or restricted data |
Schedule 2. Security measures
- Separate product access, workspace membership, guest access, and billing authorisation layers.
- Tenant-scoped PostgreSQL row-level security and server-side authorisation checks.
- Private Amazon S3 storage with versioning, KMS encryption, public-access blocking, and short-lived authorised URLs.
- TLS, restrictive browser security headers, protected sessions, and multi-factor authentication support.
- Email verification, expiring guest sessions, invitation revocation, disclosure revisions, and permission-aware downloads.
- Malware scanning before document availability and fail-closed processing states.
- Immutable published versions, audit events, controlled exports, and closing evidence.
- Least-privilege runtime roles, secrets management, webhook verification, WAF controls, monitoring, alerts, and retained security logs.
- Physical database backups, write-ahead log archiving, S3 object versions, incident procedures, and recovery validation.
- Dependency, source, configuration, authorisation, integration, and first-party security testing.
Schedule 3. Current subprocessors
| Provider | Function | Expected processing location |
|---|---|---|
| Supabase, Inc. and listed subprocessors | Authentication and PostgreSQL platform | Singapore production region, with provider support processing under its terms |
| Amazon Web Services, Inc. and applicable affiliates | Rooms compute, document storage, encryption, security, logs, alerts, and transactional email | Singapore for compute and storage, Australia for transactional email, with provider support processing under its terms |
Stripe handles Rooms billing information under its own terms and the roles described in the Privacy Policy. It does not receive customer-controlled room documents through the ordinary product workflow.
Contact
Amafi (HK) Limited
MergerMatch privacy team
Hong Kong Special Administrative Region
Email contact@mergermatch.ai