Legal

MergerMatch Rooms Terms

Effective and last updated 17 August 2026

These product terms govern access to and use of MergerMatch Rooms by customers, workspace members, and invited guests. They supplement the MergerMatch Terms of use. The Privacy Policy explains how we handle personal information. The Data Processing Addendum applies when Amafi (HK) Limited processes customer-controlled personal data in Rooms.

Acceptance and eligibility

You must be at least 18, legally able to enter these terms, and authorised to use Rooms for a professional transaction purpose. Each workspace member and invited guest must personally accept the current version before receiving room access. Do not accept for another person or share an individual account, invitation, password, or verification code.

An owner or administrator who accepts the customer agreement confirms authority to bind the named customer. That customer acceptance is separate from each person's acceptance and incorporates the current Data Processing Addendum. Electronic acceptance records may include the account or invited email, document versions, time, IP address, and browser details.

Roles and customer control

The customer controls its workspaces, rooms, members, guest groups, invitations, document publication, and access permissions. Owners and administrators must assign the least access reasonably needed, review the intended disclosure, keep recipient details current, and promptly revoke access that is no longer authorised.

A workspace role or product control does not prove a person's identity, authority, professional status, or suitability. The customer remains responsible for verifying recipients and deciding what information to disclose.

What Rooms provides

Rooms provides self-service software for organising and sharing M&A due diligence materials. The standard service includes workspace roles, room and folder management, private document storage, selected guest access, permission controls, document activity records, and transaction Q&A. Features and capacity remain subject to the plan, order, technical limits, and product controls shown in the service.

Uploaded files are held in private encrypted object storage and pass through automated malware and processing checks before they become available. Clean original files can be downloaded when permission allows. In-browser preview is currently limited to PDFs that pass the required file-signature and processing checks. Other file types are download-only.

An Inactive room can be prepared by entitled workspace members, but invited guests cannot enter it and staged guest invitations are not released until an authorised member makes the room Active. Activity and acceptance records are support tools. They are not notarisation, certification, or conclusive proof of identity, authority, receipt, review, or legal effect.

What Rooms does not provide

Rooms does not verify the completeness, accuracy, authenticity, ownership, legality, or suitability of customer content. It does not verify a user's identity, authority, professional status, sanctions status, or background beyond the account, invitation, and verification controls shown in the service. Customers must perform the checks required for their transaction and law.

Rooms does not provide a transaction-specific NDA, legal hold, regulated-data compliance programme, records-management policy, escrow service, electronic signature service, notarisation, due diligence opinion, valuation, transaction advice, or closing service. The customer must arrange each item it needs.

Malware scanning, access restrictions, watermarks, download controls, and audit records reduce risk but do not eliminate it. We do not promise that a file is harmless or that an authorised recipient cannot photograph, capture, copy, retain, or redistribute information after viewing or downloading it. Customers must use suitable confidentiality agreements and disclosure procedures.

Invited guests

A guest may access room content only for the transaction purpose stated or reasonably understood from the invitation. A guest must follow the room permissions, protect confidential content with at least reasonable care, and disclose it only to people authorised by the customer and bound by suitable confidentiality duties.

The Rooms Terms are not a transaction-specific non-disclosure agreement. A customer may require a separate confidentiality acknowledgement or NDA. The customer is responsible for providing suitable transaction terms and deciding whether they are required. A guest must comply with each applicable agreement.

Confidential material and authorised use

Room content may include trade secrets, personal information, financial records, contracts, and other sensitive material. You may view, download, copy, or share content only as the room permissions and transaction purpose allow. A download permission does not transfer ownership or create a right to use the content for another purpose.

Do not upload or disclose content unless you have the rights, notices, permissions, and lawful basis needed for the intended use. Do not upload malicious code, unlawful material, secrets unrelated to the transaction, or regulated information that requires controls the customer has not arranged.

Security and access evidence

We use access controls, private object storage, encryption in transit and at rest, verification measures, and audit records to support controlled diligence. Customers and users must use available security features, keep devices and email accounts secure, and notify us promptly of suspected unauthorised access.

Rooms may record sign-ins, acceptances, invitations, document activity, downloads, permission changes, IP addresses, and browser details. Customers may receive or export relevant audit records for security, compliance, transaction administration, and dispute handling. Technical controls reduce risk but cannot guarantee that authorised recipients will not misuse information.

Availability, recovery, and independent copies

Rooms is provided as available and does not include a service-level agreement, fixed recovery point, or fixed recovery time unless an order expressly says otherwise. Continuous point-in-time database recovery is not included unless an order or written activation record says it is active.

The current standard recovery baseline uses daily physical database backups, write-ahead log archiving, and versioned private object storage. If recovery from the latest usable physical database backup is required while continuous point-in-time recovery is not active, recent database changes may be lost. The potential recovery gap can be up to approximately 24 hours. Object and database recovery are separate processes and a successful recovery is not guaranteed.

Backups, versioning, and recovery procedures reduce risk but do not make Rooms the customer's sole archive or system of record. Customers must keep independent copies of material and records needed for a legal obligation, retention requirement, closing, filing, or critical transaction deadline.

Privacy and processing

The customer decides why customer-controlled room content is processed and who may receive it. Amafi (HK) Limited processes that content to provide, secure, support, and maintain Rooms as described in the Data Processing Addendum. Customers are responsible for required notices, lawful bases, disclosure instructions, retention decisions, and responses to rights requests.

Subscriptions and service limits

A Rooms order or checkout states the applicable price, billing period, storage limit, active room limit, and renewal terms. Access may be limited or suspended for non-payment, expiry, a security risk, unlawful activity, or a material breach. The customer should export required records before cancellation or the end of an agreed retrieval period.

A plan described as having unlimited members or guests has no ordinary per-seat charge or stated seat cap. It does not provide unlimited storage, rooms, bandwidth, automated traffic, processing, email, or support. We may apply documented plan limits and reasonable technical or security controls to protect the service and other customers. We will not use those controls to avoid providing ordinary good-faith use of the purchased plan.

No transaction or professional advice

Rooms is document and workflow software. Amafi (HK) Limited does not act for a transaction party, decide whether disclosure is appropriate, verify room content, perform due diligence, or provide legal, tax, accounting, valuation, financial, or investment advice. Each party remains responsible for its advisers, decisions, disclosures, and compliance with applicable law.

Suspension, termination, and retained evidence

We may suspend or restrict access when reasonably necessary to protect the service, a customer, another user, or confidential information, or to comply with law. When practical, we will give notice and an opportunity to correct a remediable issue. Urgent security or legal risks may require immediate action.

Deletion and return of customer-controlled data follow the Data Processing Addendum and applicable order. We may retain limited acceptance, billing, security, and audit evidence when reasonably necessary for legal compliance, fraud prevention, security, or establishing and defending legal claims.

Relationship with the general terms

The disclaimers, intellectual property terms, liability limits, indemnity, governing law, dispute terms, and general provisions in the MergerMatch Terms of use apply to Rooms. If these Rooms Terms directly conflict with the general Terms of use, these Rooms Terms control for use of Rooms. An applicable signed order controls only to the extent it expressly states a different term.

These descriptions allocate responsibilities and explain the service boundary. They do not exclude any duty, warranty, remedy, or liability that applicable law does not allow us to exclude. Any disclaimer, indemnity, exclusion, or liability cap applies only to the maximum extent permitted by law and remains subject to the express exceptions in the Terms of use.

Changes to these Rooms Terms

We may update these terms when Rooms, our providers, our business, or the law changes. We will post the new version and effective date. We will request renewed acceptance before further access when the version requires it. A change does not retroactively alter rights or duties that already accrued.

Contact

Amafi (HK) Limited
MergerMatch legal team
Email contact@mergermatch.ai

You can also use our contact page. Include Legal in the subject or message.