Draft — to be reviewed by counsel before launch. Not legal advice.
Controller
[Vessio AS, Norway] is the controller for account and service data. For files sent in end-to-end encrypted mode we process ciphertext only and cannot read the content.
What we process, why, how long
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Email address, passkeys, sessions | Your account and sign-in | Contract | Account lifetime; 30 days after deletion |
| Files (Standard mode: readable; E2EE: ciphertext) | Delivering your transfer | Contract | Until the expiry you chose (max. 90 days) |
| Recipient email addresses you enter | Notifications, per-recipient links | Legitimate interest of you and the recipient | With the transfer |
| IP addresses on sign-in, upload, download, report | Abuse prevention, security | Legitimate interest | 30 days, then removed; country kept |
Device cookie (vd) |
Limiting repeated trial abuse | Legitimate interest | 400 days |
| Billing data | Payment via Paddle (merchant of record) | Contract, legal obligation | Per accounting law |
| Abuse reports, takedown records | Notice and action (DSA) | Legal obligation | 12 months after closing |
| Audit log (metadata only) | Security, accountability | Legitimate interest | 12 months |
Where
All data is stored and processed in the EU/EEA by the providers listed on the sub-processor page. No transfers outside the EEA.
Your rights
Access, rectification, erasure, restriction, portability and objection: write to the address on the imprint. You may complain to Datatilsynet (Norway) or your local authority. Account deletion is self-service on the account page.
Cookies
Only first-party, functional cookies: session, locale, device id, and short-lived sign-in challenges. No analytics, no advertising cookies.