Skip to content
STRATON Datenraum

Security, hosting and data protection

A data room contains particularly sensitive documents relating to a transaction: leases, purchase price data, expert reports, corporate documents, personal data of tenants and employees. On this page we describe how the STRATON Data Room is operated, which technical and organisational measures lie behind it and where the limits of what we undertake lie. The information on this page is a self-declaration by the provider. You can review the technical and organisational measures in the course of a customer audit under Article 28(3)(h) GDPR.

Principle

You remain the controller, we are the processor

As a rule you are the controller within the meaning of the GDPR. We process the contents of your data room exclusively on your instructions as a processor. We do not decide which documents are uploaded, who sees them and how long they remain available. We implement what you determine, and we document it. A data processing agreement under Article 28 GDPR is concluded for every data room before the first file is uploaded.

If you set up the data room for a third party – for example as a broker, asset manager or service KVG (German investment management company) for the owner or the fund assets – you are yourself a processor and we become a sub-processor under Article 28(4) GDPR. For this we provide a version of the agreement that passes your obligations under the main agreement on to us unchanged; you obtain the controller's authorisation. If you act as an insolvency administrator, we clarify responsibility for debtor data and insolvency estate data in writing before set-up.

The data room is not a bought-in licence and not a resold cloud. It is our own application, which we operate on our own infrastructure in a data centre in Germany. No US cloud platform is used, there is no parent company and no shareholders outside the EU, and no content is transferred to third countries. The server location alone would not be a robust argument – what is decisive is that support, maintenance, backup and operation also remain within the same jurisdiction.

We state parameters, procedures and responsibilities instead of security adjectives. We do not display any test seals, quality marks or certificate logos. Where a statement could not be substantiated, we do not make it – not even where it is common practice in the market.

No system is free of risk. Security in a data room arises from the interplay of technology, disciplined permissions management and the conduct of those involved. The critical point is rarely the technology, but the handling of permissions: rights defined too broadly, a folder opened too early, an access right not withdrawn after an adviser has left. That is precisely where our support comes in.

Technical and organisational measures

What is actually implemented

The following measures form part of the TOM documentation under Article 32 GDPR, which is attached as an annex to the data processing agreement. It carries a version status and date.

Encryption in transit

Access is exclusively via HTTPS with TLS 1.2 and TLS 1.3. Older protocol versions and outdated cipher suites are disabled on the server side. The configuration in use is set out in the TOMs documentation and can be verified externally. An unencrypted request is redirected to the encrypted connection.

Encryption of data at rest

Documents and database content are stored encrypted at storage level with AES-256; backups are encrypted as well. Key management rests with the operator. We therefore deliberately do not speak of end-to-end encryption: that term would only be accurate if we ourselves had no access to the keys.

Separation of clients

Each data room is logically separated. Assignment is checked on the server side with every request, not in the interface. File storage is also separate for each data room; files are not delivered via directly callable paths, but only after server-side verification of the permission.

Roles and permissions concept

Permissions are allocated per data room, folder and document, separately for viewing, downloading, printing, uploading and administration. The basis is the need-to-know principle: a user sees only what is required for their role in the process. Bidder groups are screened off from one another; bidders see neither the names nor the activities of other bidders.

Two-factor authentication

Two-factor authentication using time-based one-time passwords (TOTP in accordance with RFC 6238) is available for all accounts and is mandatory for administrator accounts. For individual data rooms it can be enforced for all users. Passwords are stored exclusively as hashes.

Session and device management

Sessions expire after a configurable period of inactivity and are terminated on the server side. Active sessions are visible in the user administration and can be terminated immediately, either individually or for an entire account. Withdrawal of an access takes effect immediately, not only at the next attempt to log in.

Activity log

Every login, every view, every download, every upload and every change of permissions is logged with a time stamp, user ID and action. The log is kept in write-only form (append-only); entries cannot be changed or deleted through the application. Export as PDF and CSV, also per user, folder or period.

Release and visibility history

In addition to access, availability is recorded: which folders and documents, in which version, were visible to which bidder group from which point in time, including subsequent additions and changes of version. The history can be exported and forms part of the data room archive.

Personalised watermarks

When documents are viewed in the browser and when PDFs are downloaded, a watermark showing the user ID, the time and the data room is generated for each retrieval. For original files in other formats – for example spreadsheets containing tenancy schedules or cash flow models, or plans in CAD format – a watermark is not technically possible. For these files we control access through the download permission and the PDF output; the log identifies the retrieval by individual user.

Controlled download

Downloading and printing are separate permissions and can be enabled per role and per folder independently of read access. In the view without download permission, the document is delivered in rendered form, not as the original file. Bulk downloading can be blocked or limited to individual roles.

Backup and recovery

Daily backup of the database and the document holdings, stored separately from the production system and encrypted. The retention period and the run-off period of the backups are set out in the data processing agreement. Restoration is tested at regular intervals and the result is documented.

Checking of uploads

Uploaded files are scanned for malware before they are made available; the detection patterns are updated continuously. Files flagged as suspicious are not released but placed in quarantine and reported to the person responsible for the data room.

Hardening and updates

Services and ports that are not required are deactivated; administrative access is available only via secured connections. We install security updates for the operating system, runtime environment and application regularly, and security-critical updates at short notice. We document changes to the system.

Hosting

Operated on our own infrastructure in Germany

The data room runs on servers that we operate and administer ourselves, in a data centre in Germany. We name the operator and the location of the data centre in the data processing agreement, giving company name and address; on request we will also name them in advance. It is not a rented platform belonging to a hyperscaler, nor a resold product of another provider.

The data room is operated by STRATON Real Estate Advisory UG (haftungsbeschränkt) & Co. KG, with its registered office in Wörth and registered with the Amtsgericht München (Munich Local Court). There is no US parent company, no US subsidiary and no controlling investors outside the EU. On the question of the US CLOUD Act, see the frequently asked questions at the end of this page.

Support, maintenance, monitoring and backup are performed by us in Germany. Every service provider engaged is listed with its company name, registered office, service and place of processing in the list of sub-processors that forms part of the data processing agreement. We notify changes in advance; you may object. No external fonts, no external analytics services and no external content delivery networks are embedded in the application.

Administrative access to the systems is limited to a small number of named individuals, takes place via personal accounts with two-factor authentication and is logged. Content of a data room is accessed exclusively on your instruction, for example during set-up, bulk upload or a fault analysis.

Where you are subject to professional secrecy obligations – for example as a lawyer, insolvency administrator, auditor or tax adviser – we additionally place the persons deployed under an obligation of secrecy pursuant to Section 203(4) StGB and instruct them on the associated criminal liability; we provide the declarations of commitment. In such cases we engage further processors only with your separate consent.

  • Data centre in Germany; the operator and location are named.
  • Our own servers, our own application, our own administration – no hyperscaler, no resale.
  • Operating company domiciled in Germany, with no shareholder or group parent outside the EU.
  • Support, maintenance, monitoring and back-up are carried out by us in Germany.
  • No transfer of content to third countries.
  • No external fonts, analytics services or content delivery networks in the application.
  • Complete list of the sub-processors with company name, registered office, service and place of processing.
  • Administrative access limited to a small number of named individuals, with two-factor authentication and logging.
  • Obligation under Section 203(4) StGB, in so far as you are subject to professional secrecy.
  • Separate environments for production and testing; test systems contain no live data.
Data protection

Processing on behalf of a controller, redaction, deletion

A data processing agreement is concluded for every data room. It covers all the points of Article 28(3) GDPR; the details are set out in the following section. It may be concluded in electronic form under Article 28(9) GDPR. We provide a template before the contract is concluded so that your legal department can review it in advance.

The technical and organisational measures pursuant to Article 32 GDPR are documented as an annex to the agreement, with a date and version status. We maintain a record of processing activities pursuant to Article 30(2) GDPR. We review the effectiveness of the measures at defined intervals and document the outcome. Tobias Streckel, Managing Director, is responsible for this.

Real estate data rooms regularly contain personal data: tenant names in leases, tenancy schedules and arrears lists, contact details and bank details, surety bonds and credit reports, evidence of deposits, extracts from the Grundbuch (land register) showing owners, rights holders and holders of land charges, Erbbaurecht agreements, the Teilungserklärung (declaration of division) with the list of owners and the minutes of the owners' meetings, extracts from the register of Baulasten (public-law building encumbrances), documents on site personnel including the particulars under Section 613a BGB, and anti-money-laundering documents on the beneficial owner. Occasionally special categories of personal data under Article 9 GDPR occur. We draw attention to such documents separately before any release is granted.

We therefore work with redaction and pseudonymisation. In the first phase of a bidding process, personal data are as a rule made illegible or replaced by identifiers; the complete version is only released once the field of bidders has been narrowed. Redaction is destructive: the content concerned is removed from the document, not covered over. The redacted version is newly generated, and the search index is built exclusively from that version. The unredacted original file remains separate and is not released. Before every release to a bidder group we check on a sample basis that the text layer and the search index no longer contain any redacted content. You take the decision on scope and timing; we prepare it and point out the document classes concerned.

Release to a bidder is a transfer: the bidder becomes a controller in its own right for the data received. The legal basis and the balancing of interests lie with you; you govern the bidder's confidentiality and deletion obligations in the confidentiality agreement. We provide the basis for this: an overview of the document classes released per phase and bidder group, together with evidence of what was actually available.

We support you in the case of requests from data subjects under Articles 15 to 22 GDPR – you fulfil the rights as controller, not us. If we become aware of a personal data breach, we notify you without undue delay in accordance with Article 33(2) GDPR; notification of the supervisory authority is a matter for you.

Once the project has been completed, you decide how the documents are to be dealt with: complete deletion, return as a structured export, or handover of a closed data room archive including the index, Q&A trail, log extract and the release and visibility history. The periods for deletion and for the run-off of the backups are quantified in the contract. Statutory retention obligations remain unaffected (Article 28(3)(g) GDPR); we identify the affected data before deletion. On request, you receive a complete data export in open file formats before deletion.

  • A data processing agreement under Article 28 GDPR for every data room; a template is available in advance.
  • Contract version for the case in which we become a sub-processor under Article 28(4) GDPR.
  • Documentation of the technical and organisational measures (TOMs) under Article 32 GDPR with date and version status as an annex to the agreement.
  • A record of processing activities under Article 30(2) GDPR is maintained.
  • Destructive redaction, regeneration of the file, search index built solely from the redacted version.
  • Overview of the released document classes for each phase and bidder group.
  • Support with data subject rights pursuant to Article 28(3)(e) GDPR.
  • Notification of personal data breaches to you without undue delay after becoming aware, Article 33(2) GDPR.
  • Deletion or return after the end of the engagement within a contractually agreed period, subject to statutory retention obligations.
  • Data export in open file formats before any deletion.
Contract content

What the data processing agreement covers

The agreement covers all the points set out in Article 28(3) GDPR:

  • Subject matter, nature, purpose and duration of the processing as well as the type of personal data and the categories of data subjects.
  • Processing solely on documented instructions, including the provisions governing transfers.
  • Confidentiality undertaking from the personnel deployed and, for members of professions bound by secrecy, additionally under Section 203 (4) StGB.
  • Technical and organisational measures under Article 32 GDPR as a dated annex.
  • Use of further processors, a list stating registered office and place of processing, advance notification and a right to object.
  • Support with data subject rights under Articles 15 to 22 GDPR.
  • Assistance with notification obligations, data protection impact assessments and prior consultation.
  • Return or deletion after the end of the engagement, with a set period and a run-on period for backups; statutory retention obligations remain unaffected.
  • Evidence obligations and audit and inspection rights under Article 28(3)(h) GDPR.
Regulated entities

Outsourcing and regulatory law

For supervised undertakings, procuring a data room is generally an outsourcing or a contract for ICT third-party services. Depending on the institution, the relevant provisions are Section 25b KWG together with MaRisk AT 9, Section 32 VAG, Section 36 KAGB and, since 17 January 2025, Articles 28 et seq., in particular Article 30 DORA (Regulation (EU) 2022/2554).

We reflect the contractual content required for this: information, access and audit rights for you, your internal audit function, your auditors and the competent supervisory authority; rules on onward subcontracting to further service providers; termination and exit rights with an orderly return of data; notification of incidents to you; and the details for your outsourcing register or register of information, with a description of the services, the processing locations and the sub-processors.

The regulatory classification, the materiality determination and the risk analysis are carried out by you. We provide the information and answer your service provider questionnaire. We do not give any legal or regulatory assessment.

  • Information, access and audit rights for you, internal audit, the auditor and the supervisory authority.
  • Rules on onward subcontracting, with prior notification and a right to object.
  • Termination and exit rights with return of data in open file formats.
  • Notification of incidents to you, by a contractually defined route and contact person.
  • Details for your outsourcing register or register of information: service, places of processing, sub-processors.
  • Your service provider questionnaire answered by a dedicated contact person.
Self-imposed limits

What we deliberately do not do

Some undertakings consist in refraining from doing something. The following points are expressly agreed in the data processing agreement.

No analysis of the content

We do not analyse the documents in your data room for our own purposes – neither in terms of content nor statistically. There is no market database into which rents, purchase prices or property data from client projects are fed. Content is accessed only on your instruction, for example during set-up, structuring or fault analysis, and is logged.

No training of AI models with client data

Your documents are not used to train or improve language or analysis models and are not passed to external model providers. Text-processing functions such as full-text search and optical character recognition run on our own infrastructure; the content processed does not leave the data room environment.

No third-party access for advertising purposes

No analytics, tracking or advertising services are integrated into the application. No cookies are set for advertising purposes and no usage profiles are created. User data is not used for approaches of our own and is not passed on to third parties – not even for the purposes of our advisory activities.

No disclosure of metadata

Metadata are confidential as well: project designation, property addresses, names of the parties involved, the number and composition of the bidder groups, times of access. We do not pass this information on and do not use it as a reference. Without your express written release we name no project and no client.

No dual role without disclosure

Before set-up we check whether a conflict of interest exists with a current advisory or valuation engagement, and we disclose it. The individuals who look after a data room are named for the duration of the process. Any involvement in a competing engagement on the opposing side is excluded by contract. On request we name individuals to run the data room who are not working on the advisory engagement.

Permissions

Permissions by role

The table shows a customary initial allocation. It is not a fixed scheme: every permission can be granted differently for each data room, folder and document. "Optional" means that the permission exists and is deliberately enabled or blocked in the permissions concept. We propose the allocation; it is released by you. The last row does not denote a permission but a condition attached to output to the relevant role.

ActionAdministratorProject teamBidderRead-only
Viewing documents within the applicationyesyesyes, once the phase has been releasedyes
Download documentsyesyesoptionaloptional
Print documentsyesyesoptionaloptional
Uploading and replacing documentsyesyesnono
Changing the folder structure, deleting documentsyesoptionalnono
Inviting users and allocating permissionsyesoptionalnono
Ask questions in the Q&Ayesyesyesno
Answering questions and releasing answersyesoptionalnono
Viewing and exporting the activity logyesoptionalnono
Generating the index export and the data room archiveyesoptionalnono
Condition: output with a personalised watermarkoptionaloptionalyesyes
Frequently asked questions

Questions on security and evidence

Are you certified to ISO 27001 or BSI C5?

No. There is neither a certification to ISO/IEC 27001 nor an attestation under BSI C5, SOC 2 or a comparable audit. Nor do we hold out any inspection seals or certificates of the data centre operator as our own. Article 28(5) and Article 32(3) GDPR name approved certification procedures as one factor for providing evidence, not as an obligation. We therefore provide the evidence differently, namely in a verifiable form. You receive the documents listed in the margin column of the section on hosting, together with the option of a customer audit under Article 28(3)(h) GDPR. This information is a self-declaration by the provider. We state this openly, because a professional auditor will recognise the difference in any event.

Is the activity log audit-proof?

We do not use the term. It is an industry term, not a legal one. The law requires records to be unalterable (Section 146(4) AO, Section 239(3) HGB) and ties that requirement to the interplay of system, process documentation and the processes actually practised by the user; in any event, these provisions do not apply to the access logs of a transaction data room. We therefore do not say “audit-proof” but describe what the log does: see the section on the measures. For your evidential documentation of which documents were available to, and retrieved by, which bidder group at which point in time, we recommend drawing the log extract and the release and visibility history at closing and filing them together with the data room archive. Whether this satisfies a duty of disclosure or establishes evidence in an individual case depends on the purchase agreement and on the case law. That is for you and your advisers to assess, not for us.

Can US authorities access our data?

The US CLOUD Act obliges companies subject to US law, and their subsidiaries, to hand over data irrespective of where it is stored. The connecting factors do not apply to us: no US parent company, no US subsidiary, no controlling investors outside the EU, no US service providers, no processing outside Germany. On that basis we do not see any connecting factor under US law. This does not constitute legally binding advice; the assessment in an individual case remains a matter for your legal department. You can verify the details stated and use them as a basis for your own assessment. Requests for information from authorities under German or European law remain unaffected; in such a case we will inform you to the extent that we are legally permitted to do so.

Who within your organisation is technically able to read our documents?

We answer this without glossing over it. Because key management lies with the operator, administrative access to the content exists at system level. It is limited to a small number of named individuals who are bound to confidentiality, and it is logged. It is used only on your instructions – during set-up, bulk upload, structuring or fault analysis. We do not use any procedure that technically excludes this access. Full-text search, optical character recognition (OCR) and server-side watermarks require server-side access to the plain text. If a provider assures you that it has no technical access to content, ask for an explanation of where the search index, optical character recognition and watermarks are generated.

How do you ensure that one bidder cannot see what another bidder sees?

Bidders are assigned to groups that are sealed off from one another. Folders that have not been released do not appear in the structure; they are not merely shown as blocked. The names and activities of other bidders cannot be viewed. In the Q&A module you decide for each answer whether it goes only to the person asking or to all groups. Which group was able to see which folder, and when, is shown by the release and visibility history. On the technical separation, see the section on the measures.

What happens to the data room after closing?

You have three options, and the decision is yours. First: complete deletion after the period set out in the contract, with a defined run-on period for the backups and written confirmation. Second: return of the data as a structured export in open file formats, with the folder structure preserved and the index as a table. Third: handover of a closed data room archive. The holdings are frozen and handed over as a self-contained, navigable archive, including the index, the Q&A trail, a log extract and the release and visibility history. The archive contains a checksum (SHA-256) for each file and a signature covering the overall index; this makes it possible to verify afterwards that the holdings handed over are complete and unaltered. It does not involve a qualified electronic signature or a qualified time stamp under eIDAS. The archive replaces the handover on DVD or USB media that used to be customary and can be opened without our application. Statutory retention obligations remain unaffected (Article 28(3)(g) GDPR); we identify the holdings concerned before deletion. In transactions we recommend making provision for the archive to be retained until the contractual limitation periods have expired and for deletion to be triggered only thereafter; who keeps the archive and who may access it is determined by the parties in the purchase agreement. For property owners (long-term holders), the data room alternatively remains in place as a permanent data room and is updated on an ongoing basis.

Contact person

Who responds on our side

Questions on security, hosting and data protection are answered by Tobias Streckel, Managing Director. He is also responsible for reviewing the measures, for service provider questionnaires and for audit requests. In every project you speak to the same people; there is no chain of tickets.

STRATON Real Estate Advisory UG (haftungsbeschränkt) & Co. KG, Schmiedweg 5, 85457 Wörth. Telephone +49 (0)8123 88 300 10, e-mail contact@realestate-advisory.de. Documents such as model contracts, the TOMs documentation and the list of sub-processors are made available on request before the contract is concluded.

STRATON Datenraum

Your data room is ready within a few days

Tell us the occasion, the size of the property or portfolio and the timetable. You will receive a response and a fixed-price offer within one working day – without obligation.

Reply within one working day Operated in a data centre in Germany A data processing agreement for every data room Confidentiality, NDA on request