Corporate development deals put your most sensitive material in front of outside parties: acquisitions, divestitures, carve-outs, joint ventures and strategic investments. The counterparty is often a competitor, several bidders may be in the process at once, and advisors on every side need different slices of the room. A leaked customer list or pricing model can hurt the business even if the deal never closes.
This guide walks through the Papermark data room controls that matter most for corporate development, in the order you would set them up.
| Feature | How to set it up |
|---|---|
| Team roles and Data Room Member | Manage team roles |
| SAML SSO and SCIM | Set up SSO and SCIM |
| Email verification | Require email verification |
| Allow list | Create an allow list |
| Block list and global block list | Create a global block list |
| NDA agreement | Require an NDA before viewing |
| Groups and granular permissions | Groups and granular permissions |
| Default permissions for new documents | Set default permissions |
| Dynamic watermark | Add a dynamic watermark |
| Screenshot protection and confidential view | Screenshot protection |
| Disable printing | Disable printing |
| Download permissions | Allow downloads from a data room |
| OTP-verified bulk downloads | Bulk downloads with OTP |
| Link expiration | Set an expiration date |
| AI redaction | AI redaction |
| Q&A conversations | Q&A conversations |
| Request list | Use the request list |
| Data room analytics | Detailed data room analytics |
| Audit logs | Audit logs |
| Storage region | Choose your storage region |
| Freeze data room | Freeze a data room |
Corporate development rooms often hold material that most of your own company should not see, such as target valuations, synergy models or a planned divestiture.
Turn on email verification on every link. Visitors receive a one-time code by email before the room opens, so a forwarded link is useless to anyone without access to that inbox. Every view in your analytics and audit log is then tied to a verified person, not just a typed-in address.
@acquirer.com and @theirbank.com, so nobody outside those firms can get in even with the link.When someone is denied access, Papermark notifies you, so you see attempted access instead of guessing.
Attach your confidentiality agreement to the link with NDA agreements. Each visitor must accept it before viewing, and the acceptance is recorded with their verified email and a timestamp. This matters when bidders join at different stages and you need proof of who agreed to what. See also how to add agreements and one-click NDA.
Never share one link with every party. Create a group for each bidder, and one for each workstream on their side (legal, financial, commercial, technical). Then use granular file permissions to decide, folder by folder:
A typical setup shares the teaser and management presentation in the first round, adds financials and contracts for the shortlist, and opens the most sensitive folders (customer contracts, employee data, IP) only to the final bidder's named advisors. Set default permissions for new documents so files you add later stay hidden until you share them on purpose. Read more on granular permissions.
Enable a dynamic watermark on every link. Papermark stamps each page as it is viewed with the details you choose: the viewer's email, the date and time, the link, or their IP address, for example Confidential {{email}} {{date}}. If a page leaks, the watermark shows whose copy it was. See dynamic watermarking.
For the documents a competitor would value most, such as customer lists, pricing and product roadmaps:
These settings make bulk capture harder, and the watermark still identifies anyone who photographs the screen.
Keep downloads off by default, and allow them only for the groups that need offline copies, usually the final bidder's legal and financial advisors. See how to allow downloads from a data room.
If you allow bulk downloads, OTP-verified bulk downloads send a one-time password to the visitor's verified email before the ZIP is built. A forwarded link cannot be used to pull the whole room.
Give each link an expiration date that matches the phase of the process, for example the end of the first-round bid deadline. Bidders who drop out lose access automatically, without you having to remember to revoke it. You can also disable a link at any time.
Employee files, customer contracts and HR records carry names, emails and account numbers that the counterparty rarely needs before signing. Use AI redaction to find and black out personal data before documents go into the room. This reduces GDPR exposure and lowers the stakes if anything leaks. See also GDPR compliance.
Use Q&A conversations so bidders ask questions next to the document they are about, instead of over email. Questions and answers stay inside the room's access controls, and you have a complete record when the deal closes. To collect documents from the other side, use the request list.
If the transaction involves EU entities or your legal team requires data residency, pick your storage region before you upload anything.
When the deal signs, closes or is abandoned, freeze the data room. Freezing permanently ends all visitor access, archives every link and generates an archive of the documents, the full audit log and all Q&A, with a SHA-256 hash so you can prove later that the record has not been changed.
| Phase | Who gets access | Settings |
|---|---|---|
| Teaser and NDA | All approached parties | Email verification, NDA, watermark, no downloads, short expiry |
| First round | Bidders who signed the NDA | One group per bidder, allow list by domain, screenshot protection on sensitive folders |
| Confirmatory due diligence | Shortlisted bidder and advisors | Workstream groups, downloads only for named advisors, OTP bulk downloads, Q&A |
| Signing and close | Deal team only | Expire bidder links, export audit logs, freeze the room |
Some controls depend on your plan. See pricing for what each plan includes.