Privacy Policy
1. Information We Collect
We collect minimal personal data: email, account name, and encrypted metadata (e.g., file size, timestamps). No content is stored in plaintext. All data is pseudonymized via salted SHA-256 hashing. We never collect biometric data, location, or browsing history.
2. Legal Basis for Processing (GDPR Art. 6)
- Performance of contract (account creation, service delivery)
- Legal obligation (e-discovery, subpoenas with notice)
- Legitimate interest (security logs, fraud prevention)
3. Data Subject Rights
Users may exercise rights under GDPR (Art. 15-22), CCPA (CCR ยง999.312), and LGPD (Art. 18). Requests are processed within 30 days. We provide a dedicated portal for DSARs. Right to deletion excludes records retained for legal hold or audit requirements.
4. Data Retention & Erasure
Account data retained for duration of subscription plus 90 days. Deleted files are cryptographically shredded within 24 hours. Backup tapes are overwritten quarterly. We comply with industry retention guidelines (ISO 27001, NIST SP 800-88).
5. Third-Party Data Processors
We retain a current list of sub-processors: AWS GovCloud (infrastructure), Cloudflare (DDoS mitigation). All processors sign DPAs compliant with SCCs under GDPR Art. 46. We perform annual vendor risk assessments.
6. International Transfers
Data may be transferred to US data centers with EU-US Data Privacy Framework certification. For other transfers, we utilize Standard Contractual Clauses or Binding Corporate Rules.
