In most founders’ minds, due diligence sits near the end of the round as an inspection to be endured; on the investor’s side, the process is the decision about the company itself. The data room — in practice now always a virtual data room — is the file the founder submits towards that decision, and how it is built carries as much of a message as what it holds. A scattered, incomplete room filled the night before is a finding in its own right, independent of any defect in the documents: this company cannot manage its records.
The most productive approach is to start building the data room not at the start of the round but before a round is even on the horizon. When every general assembly resolution, every contract and every trademark registration lands in the right folder on the day it is signed, due diligence preparation stops being an archaeological dig that consumes weeks. This piece walks through that folder structure with a lawyer’s eye: where the investor’s counsel looks first, which gap turns into a bargaining chip, and how to manage the red flags.
A data room is a narrative, not a warehouse
A good data room tells the company’s story through documents: incorporation, the evolution of the shareholding, the birth of the product and its intellectual property, the team, the contracts, compliance. The first task is therefore a labelled, numbered index; the request lists coming from the investor side generally follow the same main headings. Documents should be uploaded in dated, final versions, and drafts must never be mixed with signed originals.
The technical features of a virtual data room should be used deliberately. Access is granted in layers that widen as the round progresses: summary information at the first stage, the full set after exclusivity, and the most sensitive trade secrets only to a narrow team. The Q&A module replaces sprawling email chains with a single recorded channel; and the access logs, which answer the question of who saw what and when, are the company’s best defensive evidence if a dispute over the representations arises later.
The commercial contracts folder is part of the narrative too, and deserves its own pre-screening. The investor’s counsel looks for three things here: clauses giving the counterparty a termination right on a change of control, exclusivity and non-compete restrictions, and unusual assumptions of liability. A founder who reads the ten largest customer and supplier contracts through those three lenses in advance can see, before the round begins, which contract will need consent before closing; the same screening also produces the first draft of the third-party consents section of the closing checklist.
Corporate books and the cap table: the first place they look
The first stop for the investor’s counsel is the corporate layer: the trade registry records, the current text of the articles, the general assembly and board resolution books, the share register and the signature circulars. What is sought here is not polish but consistency: the capital shown at the registry, the increases in the resolution books, the entries in the share register and the story the shareholders tell must all be the same. Missing resolution books, unrecorded transfers and resolutions adopted without a meeting are the regulars of this folder, and usually the last gaps anyone notices. Most of these gaps cause trouble not when they are noticed but when someone tries to document them: putting on paper today a transfer that in fact happened years ago requires the signatures of the shareholders of that day, and sometimes the cooperation of people who can no longer be reached. Keeping the corporate layer current after every transaction is therefore not a matter of tidiness but a matter of cost.
The second stop is the cap table, and the question here is singular: does everyone who could claim a right over the company’s shares appear on it? Oral promises of equity, advisor shares pledged by email, forgotten SAFEs and undocumented option commitments love to surface in the middle of a priced round. The pre-DD task is to reduce every promise to a written instrument or to settle it away explicitly; the disasters these ghosts cause are a story of their own.
Where does the IP chain break?
In a technology company the carrier of value is intellectual property, and the most unforgiving question of due diligence is this: do the code, the designs and the brand actually belong to the company? Under the Turkish copyright regime, the exercise of economic rights in works created by employees within the scope of their duties belongs as a rule to the employer; but that rule does not cover the code a founder wrote before the company existed, the freelancers engaged from outside, or the agencies. These are precisely where the chain breaks most often: pre-incorporation assets never assigned to the company, a freelancer contract with no assignment clause, a logo still owned by an agency.
The cure is a written intellectual property assignment agreement with every contributor, and separate transfer instruments for pre-incorporation assets. The data room should also hold the trademark and any patent registrations, the domain name records and the software’s dependency list; a licence inventory of open source components, particularly where copyleft licences are involved, is a standard question in the investor’s technical review. Completing missing assignments before closing is a typical condition precedent; the cost of obtaining a signature from a departed and embittered co-founder compounds with every passing month.
Employment files and the KVKK: risk in both directions
The employment folder is read with two separate eyes. The first looks at employment law: written contracts, confidentiality and intellectual property clauses, non-compete undertakings from key staff, the ESOP plan if there is one, and the records of options granted. Options promised but never attached to a plan are the employee version of cap table ghosts and deserve the same clean-up. The second eye looks at compliance: whether the company meets its obligations under the KVKK — privacy notices, the data processing inventory, VERBİS registration where required, processor agreements — is by now a standard section of every legal review list.
The point that escapes attention is that the data room is itself a personal data processing activity. Uploading employment contracts, payroll details and customer lists as they stand can generate a fresh KVKK breach in the middle of preparing for the round. Good practice is to mask or summarise personal data wherever possible, to open name-level review only on a reasoned request and with narrow access, and to check the confidentiality clauses in customer contracts before anything is disclosed. Adding an express term to the confidentiality agreement signed with the investor, confirming that personal data in the data room will be used solely for the purposes of the transaction, completes the contractual side of that balance.
Framing the red flag, not hiding it: the disclosure plan
Every company’s file contains defects; the purpose of due diligence is not to find a flawless company but to price the risk. The founder’s strategic decision is this: will the findings be discovered by the investor’s counsel, or presented by the company? A pending lawsuit, a tax exposure, a missing IP assignment or a change-of-control clause in a critical contract reads as a sign of managerial maturity when the founder raises it early and in context; discovered by the lawyers, it becomes both a bargaining chip and a question of trust.
The contractual counterpart of that narrative is the disclosure mechanism: disclosures made against the representations and warranties are documented, depending on the deal, in a disclosure letter or in disclosure schedules, and a matter properly disclosed cannot, as a rule, ground a later indemnity claim. For the founder this is one of the rare mechanisms in which honesty is legally rewarded: the earlier and more precisely you disclose, the smaller your post-closing liability surface. Serious findings are resolved through one of three routes: cure before closing, a price adjustment, or a specific indemnity. Which route is chosen depends on the nature of the finding: what can be cured is cured, what can be measured is priced, and what remains uncertain is tied to a specific clause that allocates the liability openly. The founder’s bargaining strength here comes from having been the one who told the story first.
In short: the data room is a tool for making the company governable, not merely for persuading an investor, and it is at its best when it is kept permanently current. Corporate books that match the cap table, an IP chain closed link by link with written assignments, an employment and KVKK file that is clean both in content and in how it is uploaded, and red flags presented through the company’s own narrative and tied into the disclosure mechanism — these four habits turn due diligence from an examination into a negotiating advantage. And once the round closes, do not close the room: the next round will open exactly where you left it today.
This article is provided for general information only and does not constitute legal advice. Please seek legal support for an assessment of any specific matter.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro call