Privacy Policy
1Data Controller
The controller responsible for data processing within the meaning of the GDPR is:
2Data We Collect
We process the following personal data:
- Account Data: Name, email address, encrypted password, organization name
- Client Data: Client names, email addresses, and company names you create
- Upload Metadata: File name, file size, MIME type, upload timestamp, status
- Uploaded Files: Files transferred by your clients via upload links
- Usage Data: IP address, browser type, access times for security purposes
- Payment Data: Billing is processed through Stripe; we do not store complete credit card data
3Purposes of Processing
We process your data for the following purposes:
- Provision and operation of the platform
- Management of customer accounts and upload links
- Storage and provision of uploaded files
- Notifications about upload activities
- Billing and payment processing
- Security and abuse prevention
- Compliance with legal obligations
4Legal Basis
Processing is based on the following legal grounds:
- Art. 6(1)(b) GDPR: Performance of the contract for the use of the platform
- Art. 6(1)(f) GDPR: Legitimate interests in the security of the platform
- Art. 6(1)(c) GDPR: Compliance with legal obligations (e.g., retention requirements)
5Data Processing
When you use SendMeSafe to receive files from your clients, we act as a data processor for this client data. You are the data controller for your clients' data.
Upon request, we will provide you with a Data Processing Agreement (DPA) in accordance with Art. 28 GDPR. Contact us at support@sendmesafe.com
6Recipients and Service Providers
We use the following service providers:
- Hetzner Online GmbH (Germany): Server hosting and infrastructure
- S3-compatible Object Storage (EU): File storage
- Stripe, Inc.: Payment processing (with Standard Contractual Clauses for US transfers)
- Email Service Provider (EU): Transactional emails
Data processing agreements are in place with all service providers.
7Storage Location and Data Transfers
Your data is stored on servers in the European Union (EU).
Should data transfer to a third country be required in individual cases (e.g., for Stripe), this will only occur using appropriate safeguards such as Standard Contractual Clauses (SCC) pursuant to Art. 46 GDPR.
8Data Retention
We store your data as long as your account is active and as required to fulfill our contractual and legal obligations.
- Account Data: Until account deletion plus statutory retention periods
- Uploaded Files: Until deletion by you or according to your plan
- Billing Data: 10 years in accordance with commercial and tax law requirements
- Security Logs: 90 days for abuse detection
9Your Rights
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR): You may request information about your stored data.
- Rectification (Art. 16 GDPR): You may request the correction of inaccurate data.
- Erasure (Art. 17 GDPR): You may request the deletion of your data, provided there are no retention obligations.
- Restriction (Art. 18 GDPR): You may request the restriction of processing.
- Data Portability (Art. 20 GDPR): You may receive your data in a machine-readable format.
- Objection (Art. 21 GDPR): You may object to processing based on legitimate interests.
To exercise your rights, please contact: support@sendmesafe.com
10Right to Complain
You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.
The competent supervisory authority in Germany depends on your place of residence or the location of the alleged violation. A list of supervisory authorities can be found on the website of the Federal Commissioner for Data Protection.
11Cookies
We use only technically necessary cookies for authentication and security of the platform. These cookies are required for the operation of the platform and cannot be disabled.
We do not use advertising or tracking cookies. We do not sell personal data to third parties.
12Security
We implement technical and organizational measures to protect your data:
- 256-bit TLS/SSL encryption for all data transfers
- Encrypted storage of sensitive data
- Regular security audits
- Access controls and logging
- ISO 27001 certified information security management
13Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you by email of any material changes. The current version is always available on this page.