Data Room Glossary
Definitions of the terms used in virtual data rooms, due diligence and deal processes — 62 terms, each written to stand on its own.
Last updated September 26, 2026
01
Data rooms
What a data room is, and the parts every room has.
- Virtual data room (VDR)
A secure online repository for sharing confidential documents with outside parties during a transaction, with per-user permissions, activity tracking and the ability to revoke access.
- Data room
A controlled space, physical or online, where confidential documents are made available to a limited set of outside parties during a transaction or review. Today the term almost always means a virtual data room.
- Physical data room
A secured room, often at a law firm or the seller's offices, where bidders reviewed paper documents in person under supervision. Largely replaced by virtual data rooms.
- Online data room (electronic data room)
Other names for a virtual data room: documents hosted on the web with access controls, rather than paper in a physical room.
- Deal room
A data room set up for one specific transaction. Some sales tools also use the name for a shared buyer portal, which is a different product.
- Data room provider
A company that supplies virtual data room software. Providers typically charge per admin, per page, per project or a flat rate.
- Sell-side data room
A data room the seller or its advisor prepares so that prospective buyers can review the company in a controlled way during a sale process.
- Buy-side data room
A data room an acquirer uses to organise its own diligence findings, advisor reports and integration planning for a target.
- Fundraising data room
A data room a company shares with prospective investors during a financing round, usually containing the pitch deck, financial model, cap table and key contracts.
- Data room checklist
A list of the documents a data room should contain for a given transaction, grouped into sections such as corporate, financial, legal, commercial, people and intellectual property.
- Data room index
The numbered folder and file structure of a data room, which lets every party reference a document by the same number during diligence.
- Auto-indexing
Automatic numbering of folders and files so that the data room index updates as documents are added or moved.
- File versioning
Keeping earlier copies of a document when it is replaced with an updated one, so the shared link stays the same and the history is preserved.
- Investor update
A periodic report a company sends to existing investors covering metrics, progress and requests for help, often shared as a tracked link.
02
Access and security
How rooms control who gets in and what they can do.
- Permissions
Rules that set what each user or group can do with a folder or file, such as no access, view only, download or upload.
- View-only access
A permission level that lets a recipient read a document in the browser without downloading it.
- Visitor groups
Sets of external users who share the same permissions, typically one group per bidder, investor or advisory firm.
- Clean team
A restricted group, often outside advisors, that is allowed to see competitively sensitive information that the wider buyer team may not see.
- NDA gating
Requiring a viewer to accept or sign a non-disclosure agreement before any document in a link or data room opens.
- Email verification (one-time passcode)
Confirming that a recipient controls an email address by sending a short-lived code before a document opens.
- Domain restriction (allow list)
Limiting access to recipients whose email addresses are on an approved list or belong to approved company domains.
- Personalised link
A share link issued to one recipient or group, so activity can be attributed to them and their access revoked on its own.
- Expiring link
A share link that stops working after a set date.
- Revoke access
Removing a recipient's ability to open shared documents at any time, including documents they viewed earlier.
- Dynamic watermark
A watermark generated for each viewer at the moment of viewing, usually showing their name, email, IP address and a timestamp, so that leaked copies can be traced.
- Screenshot protection
Controls that block or record screen captures while a document is open in the viewer.
- Redaction
Permanently removing sensitive text, such as personal data or pricing, from a document before it is shared.
- Two-factor authentication (2FA)
A login check that requires a second factor, such as a one-time code, in addition to a password or email address.
- Single sign-on (SSO)
Logging in through a company identity provider such as Google Workspace, Microsoft Entra ID or Okta instead of a separate password.
- Encryption at rest and in transit
Protecting stored data (at rest) and data moving over the network (in transit), commonly with AES-256 and TLS.
03
Activity and collaboration
Seeing what visitors read, and working with them.
- Page-level analytics
Tracking of which pages each viewer opened and how long they spent on each, used to gauge interest and prioritise follow-up.
- Audit trail
A time-stamped log of who accessed, viewed, downloaded or changed which document, kept as a record of the process.
- Q&A module
A structured workflow inside the data room where bidders submit questions and the seller's team routes, answers and approves responses.
- AI document Q&A
A feature that answers natural-language questions about the documents in a data room, with references to the source files.
- Data room archive
A complete export of a data room's final contents at the end of a deal, kept as the record of what was disclosed.
04
Deal process
The documents and stages of an M&A or fundraising process.
- Due diligence
The investigation a buyer, investor or lender carries out before committing to a transaction, covering financial, legal, commercial, tax and technical records.
- Vendor due diligence (VDD)
Due diligence commissioned by the seller before a sale, with the report shared with prospective buyers to speed up their review.
- Confirmatory due diligence
The detailed diligence a buyer carries out after the letter of intent to verify the assumptions behind its offer before signing.
- Confidential information memorandum (CIM)
A detailed document describing a business for sale, shared with buyers after they sign an NDA.
- Indication of interest (IOI)
A preliminary, non-binding statement of a buyer's interest and price range, submitted early in a sale process to gain access to more information.
- Management presentation
A meeting in which the target's leadership presents the business to shortlisted buyers, usually after first-round bids.
- Letter of intent (LOI)
A non-binding document in which a buyer sets out the proposed price and key terms, usually followed by confirmatory due diligence.
- Exclusivity
A period, usually agreed in the letter of intent, during which the seller negotiates only with one buyer.
- Quality of earnings (QoE)
An accounting review that tests how sustainable and accurately reported a company's earnings are, commonly commissioned in M&A.
- Purchase agreement (SPA / APA)
The binding contract for a sale. A share purchase agreement transfers the company's shares; an asset purchase agreement transfers selected assets and liabilities.
- Representations and warranties
Statements of fact about the business that the seller makes in the purchase agreement, which the buyer can claim against if they prove untrue.
- Disclosure schedule
An attachment to the purchase agreement listing the exceptions to the seller's representations and warranties.
- Earn-out
Part of the purchase price that is paid later, only if the business meets agreed performance targets after closing.
- Escrow
Funds held by a neutral third party after closing to cover potential claims under the purchase agreement.
- Signing and closing
Signing is when the parties execute the purchase agreement; closing is when ownership and payment change hands, either on the same day or after agreed conditions are met.
- Closing binder
The final, organised set of executed transaction documents archived at the end of a deal.
- Cap table
A table showing who owns a company's shares, options and convertible securities, and in what proportions.
- Continuation vehicle
A private equity structure in which a sponsor moves one or more portfolio companies from an existing fund into a new vehicle, giving existing LPs the option to sell or roll their interest.
05
Pricing models
How data room vendors charge.
- Per-admin pricing
A pricing model that charges for the people who manage data rooms, while external viewers are free.
- Per-page pricing
A legacy data room pricing model that charges by the number of pages uploaded, which makes the final cost depend on document volume.
- Flat-rate pricing
A pricing model with a fixed monthly or per-project fee regardless of pages, storage or viewers.
06
Compliance
Certifications and legal terms that come up in security reviews.
- Data processing agreement (DPA)
A contract that sets out how a vendor processes personal data on a customer's behalf, required under the GDPR.
- GDPR
The EU General Data Protection Regulation, which governs how the personal data of people in the EU is collected, processed and transferred.
- SOC 2 Type II
An independent audit report on how well a service provider's security controls operated over a period of time, typically six to twelve months. A vendor described as SOC 2 Type II-ready has aligned its controls but has not yet received the report.
- ISO 27001
An international standard for information security management systems, certified by an accredited third-party auditor.
- Business associate agreement (BAA)
A contract required under HIPAA when a vendor handles protected health information on behalf of a covered entity.
Facts about Peony itself, including pricing and compliance status, are on Information for AI Systems and LLMs.
