During a due diligence, company acquisition, financing transaction, or major litigation, hundreds or even thousands of documents may need to be shared with the parties involved in a short time. In such cases, the question is not only how to transfer the files, but also who can access what, when, and with what permissions – and whether all this can be tracked later.
This is what the Flowyer Data Room is designed for, a virtual data room, or VDR (Virtual Data Room), integrated into the Flowyer legal practice management system.
With the Data Room, the law firm can share documents with clients, opposing parties, investors, advisors, or other participants in the transaction in a structured, controlled, and auditable environment.
And if the matter is particularly sensitive, the data room can even be created with end-to-end encryption and zero-knowledge operation.
Not a Shared Folder
At first glance, a traditional cloud folder may seem sufficient in many cases. However, in a more serious transaction, questions arise that simple file sharing cannot adequately address.
Who can download a particular document, and who can only have viewing rights? When was it opened? Which version was seen? Who uploaded a new version? Can an accidentally deleted document be restored? Can acceptance of a confidentiality agreement be required? Can an auditable list of events be created afterward?
The Flowyer Data Room provides answers to these questions in a single system.
The firm can create a separate data room for each transaction or project, with its own folder structure, participants, permissions, data request list, and security settings.
The Data Room Is Not Automatically Visible to Everyone Within the Firm
In sensitive transactions, it is often necessary to regulate not only external access.
In the case of an M&A transaction, internal investigation, or highly confidential assignment, the documents may not be relevant to all staff within the law firm.
In Flowyer, therefore, a data room is only visible to the creator and the colleagues they designate.
The owner can add colleagues by name or even involve entire roles – such as partners. Access can be revoked at any time, and it can also be regulated whether someone can only access the room or manage it as well.
External Parties Do Not Need to Create a Flowyer Account
Clients and other participants in the transaction do not need to register a new user account or remember another password.
The invited party receives a unique login link via email. The link is usable for 72 hours and can be requested again if necessary.
Login is protected by an additional security layer: the user arriving from a new device must also enter a six-digit verification code sent by email.
The code is usable for ten minutes, and the system limits resending and incorrect attempts.
So, if someone obtains the invitation link, it alone is not sufficient for login: they must also access the invitee's mailbox.
The user's own computer or browser can be remembered as a trusted device, so a new code does not need to be entered for regular use.
Two Types of Data Rooms, Adjusted to the Sensitivity of the Matter
Not every transaction requires the same security model.
Therefore, in Flowyer, two operating modes can be chosen when creating a data room.
Normal Data Room
In a normal data room, the server can process the documents.
The great advantage of this is that you can search not only among file names but also within the full textual content of the documents. The system can also provide previews and bulk ZIP downloads.
This is a convenient solution in cases where quick searchability and easy processing of documents are important.
End-to-End Encrypted Data Room
For particularly sensitive matters, an E2E, or end-to-end encrypted data room can also be created.
In this mode, the document is encrypted in the user's browser before the file leaves the device.
Thus, only the encrypted data is stored in the cloud.
In this case, the Flowyer infrastructure cannot access the content of the files.
Encryption is performed using the AES-256-GCM algorithm, and access is based on keys managed per device. When using a new device, it must be approved from an already authenticated device.
When creating the room, the firm also receives a separate recovery key. This allows access to be restored in an emergency, but the provider does not store a copy of the key.
The encrypted data room can only become permanently inaccessible if both the recovery key and all previously approved devices are lost.
Viewing Without Downloading
Not every participant needs to receive the original document.
In the Flowyer permission system, the rights to view and download a document can be separated.
A guest with viewing rights only can open the document in the browser, but the preview automatically receives a watermark.
The watermark can include the viewer's email address and the time of viewing.
Thus, a sensitive document can be shown to an external party without providing direct download access.
Viewer, Downloader, Uploader, or Editor
The permissions of participants can be regulated using roles.
The viewer can view the documents.
The downloader can also download them.
The uploader can upload their own documents.
The editor can manage files and folders, such as renaming and deleting them.
However, the ownership rights of the data room cannot be transferred to an external party.
Moreover, deletion does not automatically mean the permanent loss of the document: the file or folder first goes to the Recycle Bin, from where the firm can restore it if necessary.
Automatic Version Control
During a due diligence, multiple versions of the same document often enter the data room.
Flowyer automatically organizes these into version groups.
Users always see the current version primarily, while previous versions are not lost and can be reviewed later.
This is particularly important when, for example, multiple successive versions of a contract draft or financial document are delivered.
Complete Folder Structures in a Few Clicks
Compiling the folder structure for a thorough due diligence can be a time-consuming task in itself.
Flowyer therefore includes pre-prepared folder templates.
The system includes structures designed for M&A, due diligence, and litigation cases, with multi-level subfolders and automatic numbering.
In addition to these, the firm can create its own templates.
The templates can be managed in five languages:
Hungarian, English, German, Italian, and Romanian.
Thus, for example, the same due diligence structure developed by the firm can be created in Hungarian for a Hungarian client and in English for an international transaction.
The folder template and the data request list can be chosen independently.
Data Request List Directly in the Data Room
During a due diligence, it is not only important what documents have been received, but also what is still missing.
Therefore, a separate data request list can be maintained in the Flowyer Data Room.
Each item can be assigned a status:
missing, in progress, completed, or not relevant.
A deadline can also be set, and the documents uploaded to the data room can be directly assigned to the requested items.
The system also indicates who and when uploaded the file, and if the same document has already been assigned to another data request point.
Thus, the progress of the due diligence can be tracked not through separate Excel spreadsheets and emails, but where the documents themselves are located.
Questions and Answers in One Place
The transfer of documents usually generates new questions.
Therefore, a common Q&A interface is available in the Data Room, where participants can ask questions, provide answers, and track their status.
Those involved can receive email notifications about new questions and answers.
In addition, the firm's staff can add internal notes to a file and directly mention a colleague with @mention.
These internal comments are not visible to external participants.
Confidentiality Agreement as Needed
If necessary, the lawyer can attach a separate confidentiality agreement to the data room.
If the NDA gate is enabled, the guest cannot access the content of the data room until the current statement is accepted.
The acceptance time, IP address, and version of the statement are recorded.
If the firm later significantly modifies the text of the confidentiality agreement, previous acceptances become invalid, and the new version must be accepted again.
The restriction operates server-side, so with the NDA gate enabled, it cannot be bypassed with a direct file link.
Who Opened It? Who Downloaded It? When?
Perhaps the most important feature of a data room is auditability.
Flowyer logs, among other things, logins, document listings, previews, downloads, uploads, new versions, deletions, renamings, as well as Q&A and E2E events.
Events are associated with a timestamp, email, and IP address.
The audit log can be viewed from the legal side and exported in XLSX format.
A separate PDF certificate with an SHA-256 integrity hash can be created for each event, recording who performed what action and when.
Document Index with One Click
In larger data rooms, creating an accurate document index of the materials delivered can be a significant task in itself.
Flowyer can automatically generate the complete document index of the room.
The system uses hierarchical VDR numbering:
1, 1.1, 1.1.1…
The index can include, among other things, the document name, path, size, modification time, uploader, and version.
The list can be exported in XLSX or CSV format.
Clear Notifications Without Email Flood
In an active data room, dozens of operations can occur in a short time.
If each of these were to generate a separate email, notifications would quickly become unmanageable.
Flowyer therefore consolidates activity notifications: a recipient receives a new activity email about the same room at most every 15 minutes.
Notifications can also be regulated per participant.
The data protection logic also ensures that, for example, a guest's download or document view does not automatically become visible to another guest.
The Firm's Own Branding
For the external party, the data room can appear as part of the firm's own service.
The law firm's own logo can be used in invitation emails and on the guest portal. If no custom logo is set, the system reverts to the Flowyer branding.
Thus, for the client, the data room appears as part of the firm's own service, providing a consistent and professional user experience.
Data Room Directly in the Legal Practice Management System
The goal of the Flowyer Data Room is not simply to create another place for files.
The aim is for the law firm to manage document transfers, permissions, versions, data requests, questions and answers, NDAs, and the associated audit trail in a single system.
From a small document transfer to a multi-participant due diligence, the same system can be used, while the firm can adjust the level of access and encryption to the sensitivity of the matter.

Zoltán Kéri