Privacy Policy
Last updated: 7 October 2026
This Privacy Policy explains how EchoStream SRL ("Transferify", "we", "us" or "our") collects, uses, shares and protects personal data when you use the Transferify file-transfer service at transferify.ro and transferify.cloud (the "Service"). It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable Romanian data-protection law.
For the purposes of the GDPR, the data controller is EchoStream SRL, a company registered in Romania under CUI RO46964705 and Trade Register no. J12/6242/05.10.2022, with its registered office at Str. Soporului nr. 8, bl. C, sc. 1, ap. 8, 400482 Cluj-Napoca, Romania. You can reach us about privacy at support@transferify.cloud or on +40 736 677 233.
1. How Transferify works (and why it matters for your privacy)
Transferify lets you send files in two different ways, and each handles your data differently:
- Instant peer-to-peer (P2P) transfers. Files stream directly from the sender's device to the recipient's device over WebRTC and are end-to-end encrypted. The file contents are never stored on our servers. Our servers only help the two devices find and connect to each other (signaling) and may relay the encrypted stream if a direct connection cannot be established; we do not retain the file contents.
- Hosted transfers. Files are uploaded to storage in the European Union, with Cloudflare (Cloudflare, Inc.) (restricted to the EU jurisdiction) or with Amazon Web Services (AWS). Files are encrypted in your browser before upload; whether we can decrypt them depends on the key handling explained below. While a hosted upload you start when signed in can still be continued, this browser keeps what continuing it needs, including the file key and your recipients’ addresses; the Cookie Policy lists what is kept and for how long, and signing out deletes it.
Encryption of hosted transfers. Files you send over a hosted link, send to email recipients or groups, or upload in response to a file request are encrypted in your browser before upload. By default we store an encrypted copy of the file key, protected by AWS key management in the European Union. Our service can recover that key and returns it to the recipient's browser after the download checks pass; the browser decrypts the files. We are therefore technically able to decrypt these files. We use that ability only to serve authorized downloads and to meet legal obligations. This default is not an end-to-end encrypted mode and not a Zero-Knowledge mode, and it also applies on paid plans unless you select Zero-Knowledge.
Earlier email, group and file-request uploads. Files sent through the Service to email recipients or groups, and files uploaded in response to a file request, before browser encryption covered those paths may be stored without browser encryption. They remain protected by encryption in transit and at rest, and the same retention and deletion rules apply to them.
Zero-Knowledge. If you select this paid mode for a hosted link, the file key is not sent to us. It is carried in the part of the complete transfer link after #, optionally protected by your password. We cannot decrypt these files without that key. This protects file contents, not the transfer metadata described in the Privacy Policy.
Lost links and recovery. Losing a default hosted link does not itself destroy the file key, but does not guarantee restoration of access. Expiry, deletion and download restrictions still apply. For Zero-Knowledge, keep the complete link and any password: if all copies of the key or the required password are lost, we cannot reconstruct them or restore access to the encrypted files. P2P transfers leave us no stored file copy to recover. Keep your own copies of important files.
2. Personal data we collect
Depending on how you use the Service, we may collect:
- Account and identity data - the email address associated with your sign-in, the user identifier our authentication provider (Google) assigns to your account, and the sign-in provider you used (Google, Microsoft, Yahoo, or Facebook). Microsoft, Yahoo and Facebook each act as an independent controller for the sign-in they perform on their own pages and under their own privacy notice; Google acts as our processor for the sign-in itself (see Section 4). You may also use the Service with an anonymous session, in which case we hold only a temporary anonymous user identifier.
- Transfer and file metadata - information about your transfers such as file names, sizes and types, timestamps, chosen expiry, download limits, whether a transfer is password-protected, recipient email addresses you enter, and delivery status, plus a log of each download and each download-page visit (its time, what was opened or downloaded, the country, the IP address and the browser identifier). For hosted transfers using default key escrow, this also includes the wrapped encryption key. For P2P transfers we do not store the file contents.
- Sender email (optional) - if you choose to add your email address to a transfer, we store it as part of that transfer and show it to the recipients on the download page so they know who sent the files. It is also placed in the reply-to address of the email each recipient receives, and is handed to our email provider for that purpose, so be aware that adding it discloses your address to everyone you send to. Like the rest of the transfer record, it is kept as long as that record (see section 7) and is deleted with it.
- Recipient email addresses supplied by senders - when a sender sends you files, or asks you to upload files, they type your email address into the Service. We did not obtain that address from you, so Section 5 sets out separately where it came from, what we do with it, who it goes to and how to stop the emails.
- Email preferences and consent evidence - your account's current email-marketing choice and a history of recorded choices, including the verified address an explicit grant covers, the decision and recording times, the notice version and language, and the source of the choice. A short-lived server-time receipt lets a choice made before login be ordered against a later unsubscribe. These account records are separate from the anonymous decision totals in Section 11.
- Optional feature data - if you use them: contacts you save, share links you email, reminders, and settings for password protection, download limits and link expiry.
- Payment and billing data - when you buy anything through the Service (a plan, a one-off purchase, a free trial with an amount reserved on your card, or an advertising booking), Stripe collects your postal address at every checkout (Stripe labels it a shipping address, although nothing is shipped to it), together with your payment card and the billing details used for invoicing and tax: your billing address, VAT/tax identification number and company name. Stripe collects the postal address only at checkout, on its own hosted checkout pages and in the payment forms it shows inside the Service; it collects the billing details there and on its Customer Portal pages; and it keeps the addresses on your Stripe customer record. Stripe uses the postal address to work out which payment methods it can offer you and where VAT is due. Depending on the purpose, Stripe acts as our processor or as an independent controller, as described in Section 4. We do not collect or store these addresses, billing details or your full card number on our own systems; on our side we retain only Stripe reference identifiers (such as your Stripe customer and subscription ids) and subscription metadata (plan, billing status and subscription period) needed to manage your plan.
- Technical, device and usage data - your IP address, browser and device type, operating system, and how you interact with the Service. This includes product-analytics data measured for us by Google, which is only collected where you have consented (see Section 10, Cookies and analytics).
3. Why we use your data, and our legal bases
Under the GDPR we must have a legal basis for each use of your personal data. We rely on the following:
- To provide the Service - creating your account, authenticating you, accepting uploads, delivering transfers, enforcing expiry, download limits and password protection, and managing your subscription. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- To keep the Service secure and working - preventing abuse and fraud, debugging, ensuring reliability, and understanding aggregate demand. Legal basis: our legitimate interests (GDPR Art. 6(1)(f)), balanced against your rights.
- To take payment and issue invoices - processing payments for plans, one-off purchases, trials and advertising bookings through Stripe; having Stripe collect your postal address at every checkout, so that it can work out which payment methods it can offer you and where VAT is due; and having Stripe collect the billing address, VAT/tax id and company name needed to issue tax-compliant invoices. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) and compliance with our legal obligations (GDPR Art. 6(1)(c)) under applicable VAT, tax and accounting law.
- Product analytics - measuring how the Service is used so we can improve it, via Google. Under this purpose we also keep a record of how your first visit reached us: the coarse channel it came from (for example a paid advertisement, an unpaid search result, a link on another website or a direct visit) and the page you first landed on. Where a link on another website brought you (an ordinary site, a social network or an AI assistant), the record also holds that website's domain, for example
blog.example.org, but never the page you were reading there or anything else in its address. Once you have an account, the record is kept against it for at most 365 days. Legal basis: your consent (GDPR Art. 6(1)(a)). You can withdraw this consent at any time. - Advertising measurement - measuring which advertising campaigns bring people to Transferify, so we do not keep paying for advertising that does not work. Where you arrived from a Google or Reddit advertisement, this includes six events reported to Google: that an account was created, that it sent its first transfer, that a plan limit stopped one of its requests, that a checkout was started, with its amount, that a subscription payment was made, with its amount, and that a one-off purchase was made, with its amount. Where it was a Google advertisement, the events also carry the click identifier its link carried (
gclid,gbraidorwbraid). When you have an account and have granted this purpose, we also send Google a one-way hash (SHA-256) of your account email address with each of these events, so Google can match the event to the advertisement you clicked when the click identifier is missing or has expired. Google compares the hash with the hashes of its own signed-in accounts and keeps the match only for that measurement; we do not send the address itself or anything about your files. The recipient is Google Ireland Limited; section 4 below says in which role it acts for each step. Granting this purpose also lets Google and, on transferify.ro and the Romanian pages of transferify.cloud, Meta put your browser in advertising audiences they hold for us, so that we can stop advertising to people who already subscribe to Transferify and advertise again to people who looked at Transferify without buying a plan; a membership lasts at most 540 days with Google and 180 days with Meta from your last visit. Third-party vendors, including Google, show our advertisements on websites and apps across the internet, and use cookies and device identifiers to do so based on your past visits to Transferify; you can opt out of that kind of advertising on Google’s Ads Settings page, on the Network Advertising Initiative opt-out page or in your device’s advertising settings, as well as by withdrawing this purpose in Cookie Settings. Where you arrived from a Reddit advertisement, the link carries Reddit's click identifier (rdt_cid), which we treat the same way, and where you arrived on transferify.ro and the Romanian pages of transferify.cloud through a link from Facebook or Instagram (an advertisement or a post), the link carries Meta's click identifier (fbclid), which we treat the same way too. From ANY of these networks' links we also keep the three labels we put on our own advertisements - which network it was, which campaign, and which version of the advertisement (utm_source,utm_campaignandutm_content) - where the link carried them. Those name our campaign rather than you, and they are kept and deleted on exactly the same terms as the click identifier. We report two events to Reddit: that an account was created, and that a purchase was completed, with the amount paid. Reddit matches these events to the ad click using a one-way hash (SHA-256) of your account identifier and of your email address, which we send to Reddit only if you granted this consent; we never send anything about your files. On transferify.ro and the Romanian pages of transferify.cloud, Meta's measurement tag in your browser reports the pages you view, a sign-up and a purchase. Once it has started there, it also reports the pages you go on to open in the same visit and records the buttons you click and the titles of those pages, including inside your account after you sign in, never the content of your files. Our servers also report six events to Meta for accounts that accepted advertising under this wording: that an account was created, that it sent its first transfer, that a plan limit stopped one of its requests, that a checkout was started, with its amount, that a subscription payment was made, with its amount, and that a one-off purchase was made, with its amount. To match them to an ad, Meta receives the click identifier, an identifier Meta's tag set in your browser, details of the browser you used, a reference number for your account and for each event, and a one-way hash (SHA-256) of your email address and of the country recorded for your account; never the address itself or anything about your files. For visitors who accepted advertising, Meta's tag may also read contact details typed into our forms while it runs, including the addresses of the people you send files to, and hashes them before sending. Legal basis: your consent (GDPR Art. 6(1)(a)) and, for storing and reading information on your device, § 25(1) TDDDG in Germany and art. 4 alin. (5) of Legea nr. 506/2004 in Romania. We read the click identifier only after you have granted this consent, and we keep it for at most 365 days. You can withdraw this consent at any time; withdrawing does not affect the lawfulness of what we did before it (GDPR Art. 7(3)). - Advertising audiences built from your email address - where you accept advertising cookies, or switch on “Use my email for Transferify ads on Google” in your account settings, sending Google a one-way hash (SHA-256) of your account email address so that Google can hold you in advertising audiences it keeps for us: to stop showing you our advertisements while you hold a subscription, to show them to you again if you have not bought a plan, and to tune what we bid for advertising. Google matches the hash against its own signed-in accounts and never receives the address itself. The recipient is Google Ireland Limited; section 4 says in which role it acts for each step. Legal basis: your consent (GDPR Art. 6(1)(a)). Two things grant it, and either one is enough: accepting the advertising purpose on the cookie banner, which says so where you press, or the switch in your account settings. Nothing is read from or written to your device for this use itself, and agreeing to receive our email is not permission for it. Neither route is on until you choose it. Switching it off in either place withdraws it and asks Google to remove you, which usually takes about a day; withdrawing does not affect the lawfulness of what we did before it (GDPR Art. 7(3)).
- Anonymous statistics counted without consent - keeping two aggregate totals: how visitors answer the cookie banner, and the coarse acquisition channel a visit came from. Section 11 sets out exactly what each total holds and what is never collected for it. The totals themselves are aggregate statistics rather than personal data and need no legal basis; the personal data on that path does - your IP address, and the session token the channel category accompanies. Legal basis: our legitimate interests (GDPR Art. 6(1)(f)), in knowing how many visits each source sends us and whether our own measurements are representative, and in keeping an endpoint anyone can call usable.
- To email you our own product offers - occasional messages about Transferify plans and discounts, sent to account holders only. We send them if you explicitly permit promotional email, or where the existing-customer exception applies. Explicit permission relies on your consent (GDPR Art. 6(1)(a) and the applicable email-marketing rules). Accepting analytics or advertising-measurement cookies alone is not email permission. The separate email choice is optional and initially off; it applies to your verified account address only after it is saved against that account. The alternative is the existing-customer exception under Article 13(2) of the ePrivacy Directive, as implemented in Romania by Law 506/2004 and Germany by section 7(3) UWG, only when all its conditions are satisfied. For the German existing-customer route we additionally require a prior successful payment; explicit email consent can qualify without a purchase. Where Article 13(2) applies, no separate GDPR Article 6 condition is required (CJEU, C-654/23, 13 November 2025). You can stop promotional email through your account settings or each message's unsubscribe link. Saving the email choice off also stops both routes. A later deliberate email opt-in or the new, clearly described Accept all can resubscribe you. We do not sell your address or send another company's advertising; account safety and applicable country restrictions still apply.
- To suggest a plan inside the app - when you are signed in, the send screen may show you one of our own plan suggestions, chosen from how you have used your account recently: for example how large your transfers have been, whether you keep sending to the same address, or whether a transfer was refused for its size and not paid for. Only you see it, it is decided from your own account data, and it changes nothing about the Service you get. If you have granted analytics, your browser reports that it qualified for a suggestion of that kind and which of the two test groups it was in, by the route in Section 10 and under the random analytics identifier only; the report never carries your account, a file, an address or a size. Legal basis: our legitimate interests (GDPR Art. 6(1)(f)) in offering our own plans to the people who may need them, balanced by using only your own usage with us, keeping no profile of it, and showing each suggestion sparingly. You can object to these suggestions at any time and without giving reasons, in your account settings or by email; Section 8 explains the right. Closing a suggestion with "Not now" takes it away for that visit; the Cookie Policy says what your browser keeps so it does not repeat it.
- To communicate with you about your own account - service messages about your account, your transfers and your subscription. Legal basis: performance of a contract (GDPR Art. 6(1)(b)) for messages the Service owes you, and our legitimate interests (GDPR Art. 6(1)(f)) for security and operational notices you did not specifically ask for.
- To email the recipients a sender chooses - delivering the download link, or a file request, to the email addresses the sender entered, and recording whether that delivery succeeded so we do not send it twice. Towards the sender this is performance of a contract (GDPR Art. 6(1)(b)): sending the email is the service they asked for. The recipient has no contract with us, so towards them we rely on our legitimate interests and the sender's (GDPR Art. 6(1)(f)) in delivering a transfer that was deliberately addressed to them - balanced by sending only what delivery requires, by not using the address for marketing or profiling, and by the one-click opt-out described in Section 5.
- To honour an opt-out - keeping a suppression record of every address that has unsubscribed, so no later transfer can email it again. Legal basis: compliance with our legal obligations (GDPR Art. 6(1)(c)), because Art. 21 obliges us to stop and we cannot stop reliably without remembering who asked us to, and our legitimate interests (GDPR Art. 6(1)(f)) in not contacting people who have told us not to.
Whether you have to provide this data. Your email address is needed to enter into the contract with us: without it we cannot create your account or deliver transfers to you, so we cannot provide the Service. A postal address is needed to complete any checkout: without it Stripe cannot complete the payment, so the purchase cannot be made. A billing address and a VAT identification number are required by tax law only where an invoice must be issued. Everything else is optional.
No automated decision-making. We make no decision about you that produces legal effects or similarly significantly affects you based solely on automated processing, including profiling (GDPR Art. 22). The abuse limits described in Section 11 restrict the request rate of a network and decide nothing about you.
4. Who we share your data with
We do not sell your personal data. We share it only with service providers and other recipients that help us run the Service, under contract and only as needed:
- Google (Google Ireland Limited) - for account sign-in (authentication) and, where you consent, product analytics (usage measurement), advertising measurement and advertising audiences. For advertising measurement it receives the click identifier your link carried and, once you have an account, a one-way hash (SHA-256) of your account email address; never the address itself or anything about your files. For sign-in, for analytics and for matching that hash to the advertisement you clicked Google acts as our processor; for the matched conversion and for audiences Google acts as an independent controller of the data it receives, under its own terms. If you accept advertising cookies, or switch on “Use my email for Transferify ads on Google” in your account settings, Google also receives that same one-way hash of your account email address so it can hold you in advertising audiences for our own advertisements on Google’s services; it is our processor for matching the hash against its own signed-in accounts and an independent controller for the audience itself. Neither route is on until you choose it, and switching it off in either place asks Google to remove you, which usually takes about a day.
- Microsoft, Yahoo and Facebook - each acts as an independent controller for the sign-in it performs on its own pages and under its own privacy notice, and only if you choose that provider; we send nothing to a provider you did not choose, and from the one you chose we receive only your identifier and email address, through Google as our processor.
- Reddit (Reddit, Inc.) - where you consent to advertising measurement, for measuring whether our Reddit advertisements lead to sign-ups and purchases, through a measurement tag in your browser and matching event reports our servers send to Reddit. Reddit receives the click identifier of the ad you arrived through, a one-way hash (SHA-256) of your account identifier and email address, and the event itself (sign-up, or purchase with the amount paid). Reddit acts as an independent controller of the data it receives, under its own terms.
- Meta (Meta Platforms Ireland Limited) - where you consent to advertising measurement on transferify.ro and the Romanian pages of transferify.cloud, for measuring whether our Facebook and Instagram advertisements lead to sign-ups and purchases and for the advertising audiences described in section 3, through a measurement tag in your browser and event reports our servers send to Meta, as described in section 3. For collecting this data with the tag and sending it to Meta, we and Meta are joint controllers; Meta acts as an independent controller for what it does with the data afterwards, under its own terms.
- Cloudflare (Cloudflare, Inc.) - our processor for hosted-file storage (restricted to the EU jurisdiction), for the network that carries connections to our API (Cloudflare terminates the TLS connection at its edge and forwards the request to our servers), and for relaying encrypted peer-to-peer streams when a direct connection cannot be established (TURN). Cloudflare cannot read the file contents of a P2P transfer.
- Amazon Web Services (AWS) - our processor for encryption-key management, for running our servers and database, and for storing hosted files - all in the European Union - and for delivering our website through its content delivery network.
- Stripe - acts as our processor when it processes payment and subscription data, including the addresses you enter at checkout, on our instructions. Stripe acts as an independent controller for purposes it determines itself, including fraud prevention, security, and compliance with legal and regulatory obligations; its own privacy notice applies to that processing.
- Mailjet SAS (a Sinch company) - our email delivery processor. Every email the Service sends - transfer deliveries, file requests, account activation, sign-in codes and service notices - is handed to Mailjet for delivery, over an authenticated, encrypted connection. Mailjet delivers on our instructions only and does not use the addresses for its own purposes. Sign-in and transaction emails are sent without open or click measurement. Offer emails contain an invisible open pixel and measured links only if you have turned on "Measure opens and link clicks in my offer emails" in your account settings; this setting is off by default and independent of whether you receive offer emails. When it is on, our email provider Mailjet, acting as our processor, records each open or click, its time, the clicked link, your IP address and the country derived from it, and the identifier of your email program. Mailjet keeps them in its statistics for 90 days. You can turn the setting off at any time; this applies to emails sent after the change, and emails already delivered keep the measurement elements they were sent with. Blocking remote images in your email program can limit open measurement, but not reliably: some email services load images automatically or through proxies, so a recorded open does not always mean the email was read. Separately from this setting, when you use a personal offer link from one of our emails, our systems record that and when the link was used so the offer can be applied, and the request appears, like any visit, in our server logs.
We may also disclose personal data where required by law, to respond to lawful requests from public authorities, or to protect our rights, users and the Service. A current list of processors can be provided on request at support@transferify.cloud.
5. If someone sent you files: your address as a recipient
This section is for people who receive a Transferify email without ever having signed up. We did not get your email address from you, so this is the information we owe you under GDPR Art. 14. Where we send you a file request, that email carries a short first-layer version of this notice as well.
- Where your address came from. A Transferify sender - the person or organization sending you files, or asking you to upload files - typed it into the Service. That sender is the only source. We never buy, rent, scrape or otherwise acquire recipient addresses, and we do not add you to any mailing list.
- What we process about you. Your email address; whether the message to you was accepted for delivery, and the retry state if it was not; and the transfer metadata needed to deliver it - the transfer's identifier, its download link, its expiry and any download limit. If the sender chose to add their own email address, that travels with the message so you can see who sent it and reply to them. For a file request, the requester's name, email address and the note they wrote are the content of the email you receive.
- What is deliberately NOT in a transfer-delivery email. The sender's free-text message, the file names, the number of files and the file sizes are not put in the email and are not handed to our email provider. They stay behind the download link.
- Why we email you, and on what legal basis. To deliver the transfer or request the sender addressed to you, and nothing else. The bases are set out in Section 3: GDPR Art. 6(1)(b) towards the sender, whose instruction it is, and GDPR Art. 6(1)(f) towards you, on our and the sender's legitimate interest in delivering a transfer that was deliberately addressed to you. We do not use your address for marketing, advertising, profiling or automated decision-making.
- Who else sees it. Only Mailjet SAS, our email delivery processor (Section 4), Amazon Web Services as the host of the systems that store the transfer record, and Cloudflare, whose network carries the sender's connection to our Service. Other recipients of the same transfer never see your address: we send each recipient their own message, and the visible "To" line carries only our own sending address.
- How long we keep it. Your address is part of the transfer record and is deleted with it - see Section 7. If you unsubscribe, we do not keep the address itself: we store a one-way cryptographic fingerprint of it on a suppression list, for as long as the opt-out stands, purely so that no later transfer can email you. The fingerprint lets us check a new transfer against your opt-out, but it cannot be turned back into your address or used to list who has unsubscribed. Your opt-out outlives the sender: if the account that emailed you is later deleted, the suppression entry stays, because forgetting it is the one thing that would let a new transfer reach you again.
- How to stop the emails. Every transfer email and file request we send carries an unsubscribe link, and email clients that support one-click unsubscribe can act on it directly. Confirming it stops file-transfer email to your address from every Transferify sender, not just the one who wrote to you. This is also how you exercise your right to object under GDPR Art. 21; as a matter of policy we honour it unconditionally, without asking you for a reason. The unsubscribe page needs the signed link from the email, so it cannot be reached by typing the address; if you no longer have the email, write to support@transferify.cloud and we will record the opt-out for you - and we will remove it again if you later change your mind.
- If you have already unsubscribed. We still hold the fingerprint of your address on the suppression list and still check new transfers against it - that is the only way to keep the emails stopped - but you will not receive the notice above again, because we send you no email. You received it with the message that led you to unsubscribe.
Your other rights - access, rectification, erasure, restriction, portability and complaint to a supervisory authority - are in Section 8, and apply to you exactly as they do to account holders. The controller is EchoStream SRL, contactable at support@transferify.cloud.
6. International data transfers
Hosted files are stored in the European Union: with Cloudflare, in storage restricted to the EU jurisdiction, or with AWS. For default hosted transfers, AWS's key-management service in the European Union protects the stored encrypted file keys; Zero-Knowledge keys are not held by us. Cloudflare, Inc. and Amazon Web Services are companies based in the United States. Cloudflare may process technical connection and log data (such as IP addresses) for a limited period in the United States as well. Some of our providers - in particular Google and Stripe - may process certain data (such as authentication, analytics, or payment and billing/tax details) outside the European Economic Area, including in the United States. For Cloudflare we rely on its certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, as a fallback, on the European Commission's Standard Contractual Clauses (SCCs) contained in its data processing agreement. For AWS we rely on the SCCs contained in its data processing agreement and, where it applies, on AWS's certification under the same framework. For Google we rely on its certification under the EU-U.S. Data Privacy Framework (European Commission adequacy decision of 10 July 2023) and, as a fallback, on the SCCs contained in its data processing terms; we do not rely on your consent as the basis for that transfer. Other transfers are covered by the SCCs together with any applicable adequacy decision. Stripe is responsible for its own transfers when acting as an independent controller.
Email delivery. Our email processor Mailjet SAS is a French company and part of the Sinch group. Sinch publishes a data-processing agreement that incorporates the European Commission's Standard Contractual Clauses (controller-to-processor module) with the Sinch entity as data importer, and a sub-processor list which states that Mailjet's data centres are provided by Google Cloud France SARL inside the EU (Germany and Belgium), while several sub-processors listed against Mailjet process in the United States as well as the EU - Mailgun Technologies, Inc. for support, deployment and service provisioning, Atlassian Corporation for support ticketing and incident management, and Stripe Payments Europe, Limited for billing. Sinch's own privacy notice states that a customer's platform is hosted from data centres in the United States or Europe depending on the deployment the customer selected, so the region is a fact about our account rather than about Mailjet in general. Wherever a processing leg falls outside the European Economic Area, it is covered by the EU Standard Contractual Clauses incorporated in Sinch's published data-processing agreement for Mailjet; you can request a copy of the applicable safeguards by writing to support@transferify.cloud.
7. How long we keep your data (retention)
- Hosted files. The download link stops working at the expiry the sender chose, or as soon as a download limit the sender set is reached, whichever comes first; from that moment no new download can be started through the Service, though a download already in progress may still finish. A reached download limit blocks new downloads but does not shorten storage: the encrypted files stay until the chosen expiry. After expiry the files are removed by automatic deletion processing, our own and the storage provider's (Cloudflare or AWS); this normally completes soon after expiry, but we do not promise a fixed deletion time, and the link is unavailable from expiry regardless. Three cases keep the files longer: if the sender turned on recovery when creating the transfer, the files are kept for a further 30 days after expiry so the sender can restore the link once, and when those 30 days end, whether or not the link was restored, the recovery window closes and the files are removed by the same deletion processing; a transfer created with no expiry is kept until it is deleted or the account it belongs to is deleted; a transfer placed under a legal hold is kept until the hold is released, and while the hold is in place neither its files nor the transfer itself can be deleted and the account cannot be closed. You can also delete things yourself, with immediate effect on availability: deleting a single file removes access to that file at once and does not delete the transfer's other files; deleting the whole transfer, or deleting its last remaining file, disables the transfer's link at once and removes the transfer from the account's history. In either case the stored files are then removed by the same deletion processing. A transfer we suspend after an abuse report is blocked for recipients but is deleted on the same schedule as any other.
- Transfer records and download activity. Automatic removal of stored files after expiry does not remove the transfer record. Deleting a transfer, including by deleting its last remaining file, removes that record. The record (file names, sizes and types, timestamps, the message, the recipient addresses entered and the download count, never the file contents) remains in the transfer history of the account the transfer belongs to until the transfer or that account is deleted. The log of downloads and download-page visits keeps the time, what was opened or downloaded and the country for as long as the record exists, so the sender can see download activity and we can investigate abuse; the IP address and browser identifier in that log are erased once they are 180 days old, by a cleanup that runs daily. Automated database backups are kept for 7 days, so a deleted record can remain in a backup for up to 7 days.
- P2P transfers are not stored: file contents exist only during the live transfer.
- Account and identity data. Your account record and the sign-in identities linked to it, described in Section 2, are kept for as long as your account exists and are deleted with the account; after the account is deleted, only the limited categories listed in this section remain.
- Account deletion. Once we accept your request, access to the account and paid features is disabled immediately. Provider and product-data deletion is processed asynchronously. Deletion processing removes owned product data and hosted files and deletes the associated Stripe Customer, which cancels active subscriptions without waiting for period end and removes saved card details. A failed step may require retry or repair. Under Section 9 of our Terms, we automatically refund the fee for the days you no longer use, pro rata, to the original payment method. If you want to keep paid access until the end of the period, cancel the subscription instead and delete the account afterwards. Account deletion is separate from withdrawal; your statutory refund and withdrawal rights remain unaffected. The limited retention categories and purpose limits are described below.
- Mandatory accounting registers and supporting documents. Mandatory accounting registers and supporting documents are access-restricted and retained for 5 years, calculated from 1 July of the year following the financial year in which they were prepared. They are retained only to meet applicable Romanian accounting and tax obligations.
- Union OSS records. Only where the Union One Stop Shop scheme applies, the required transaction records are access-restricted and retained for 10 years from the end of the year in which the transaction occurred.
- Legal-claim records. The minimum records needed to establish, exercise or defend legal claims may be retained for the applicable limitation period. Access is restricted and the records are not used to provide the Service or for marketing.
- Statutory purchase records. The order confirmation we send after a purchase, your express consent to immediate performance given at checkout, the Stripe event that proves when the checkout completed, the record of the Terms version and price shown to you at checkout, and our acknowledgement of a withdrawal declaration are kept until the end of the third full calendar year after the contract they document ends, then deleted. Three years is the limitation period for contract claims under both § 195 of the German Civil Code and art. 2517 of the Romanian Civil Code; we count it from the end of the year, as § 199(1) of the German Civil Code does, so one window applies to every purchase. If you start a checkout and do not complete it, the record of the Terms version and price is deleted about a month later, once no payment can still be confirmed for it. If you delete your account before the window ends, only these purchase records are kept, detached from the account, for the rest of it, to establish, exercise or defend legal claims (GDPR Art. 17(3)(e)). Access is restricted and they are not used to provide the Service or for marketing.
- Security and anti-reprovisioning records. Minimal deletion-status and identity-link records may be retained only as necessary to block authentication or account reprovisioning and to protect the Service. Access is restricted, and the records are deleted or anonymized when no longer needed for those purposes.
- Deletion-completion and audit records. Minimal deletion state, retry or repair metadata, and audit evidence may be retained only as necessary to complete, repair or demonstrate the deletion process. Access is restricted, and the records are deleted or anonymized when no longer needed for those purposes, unless another stated legal obligation or legal claim requires retention.
- Stripe records. The addresses you enter at checkout are kept on your Stripe customer record, together with your billing details, for as long as that record exists; account deletion deletes the record, as described above. When acting as an independent controller, Stripe may retain payment, billing, address, fraud-prevention and compliance data under its own legal obligations and retention periods.
- Server logs. We do not keep server logs for a fixed period. A log entry is kept for as long as it is needed for security, abuse investigation, troubleshooting and keeping the Service running, and is deleted or anonymized once it is no longer needed for any of those purposes; an entry set aside as evidence of a specific incident is kept until that incident, and any legal claim arising from it, is resolved.
- Analytics. Analytics data is kept for as long as it is needed for the statistics purposes described in Section 3: measuring how the Service is used so we can improve it. A record that can still be linked to you is deleted or anonymized once it is no longer needed for those statistics; only aggregated statistics that no longer relate to an identifiable person are kept beyond that.
- Abuse-limit records. The parts of the Service anyone can call without signing in are rate-limited, which keeps one row per network per window holding a keyed hash, a request count and a time - never an address in the clear, and never what the request was for. A row is needed only for the length of its window, typically an hour, and a routine sweep removes it afterwards. The sweep works through spent rows at a bounded pace shared with every other protected part of the Service, so a spent row can persist beyond its window - under sustained traffic, considerably longer - until its turn comes; it is not read again in the meantime.
- Acquisition and advertising-measurement data - the coarse channel, referring website's domain and first landing page kept for product analytics, and the click identifier kept for advertising measurement, all described in section 3 - is kept for at most 365 days and is then deleted, whether or not you are still a customer. It is deleted immediately if you delete your account.
- Recipient opt-out records. If you unsubscribe from transfer emails, we record a one-way cryptographic fingerprint of your address - not the address itself - together with the date and whether the opt-out arrived through the one-click header or the confirmation page. We keep that record for as long as the opt-out stands, with no fixed end date, because deleting it would let transfer emails to your address start again. It is used only to block delivery - never to contact you, and never for marketing. Write to support@transferify.cloud if you want the record removed so that senders can reach you again.
- Account marketing preferences and consent history. We keep these records with your account to honour your latest choice and demonstrate recorded consent or withdrawal, including under GDPR Article 7(1). Withdrawing stops future promotional deliveries but does not erase that history. The records are deleted with your account. Before account binding, a pending grant and its receipt are held in this tab's session storage. They are usable for at most 30 minutes and removed when confirmed, cancelled or checked after expiry. No receipt is added to anonymous decision statistics.
- Email delivery records. Mailjet processes the messages it delivers for us and keeps its own delivery logs as our processor. Those logs are processed under its data-processing agreement solely for delivery, troubleshooting and abuse prevention - never for Mailjet's own purposes. A record is kept for as long as it is needed to deliver the mail the Service sends, to prove and troubleshoot that delivery and to prevent abuse, and is deleted once it is no longer needed for any of those purposes; where a law requires Mailjet to keep a particular record longer, it is deleted when that legal duty ends.
8. Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to:
- Access - obtain a copy of the personal data we hold about you.
- Rectification - correct inaccurate or incomplete data.
- Erasure - ask us to delete your personal data ("right to be forgotten").
- Restriction - ask us to limit how we process your data.
- Portability - receive your data in a structured, machine-readable format.
- Objection - object to processing based on our legitimate interests.
- Withdraw consent - where we rely on consent (such as analytics, advertising measurement and advertising audiences), withdraw it at any time, without affecting processing already carried out.
Right to object (GDPR Art. 21)
You can object at any time, on grounds relating to your particular situation, to processing of your personal data that we base on our legitimate interests (GDPR Art. 6(1)(f)). We then stop, unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed to establish, exercise or defend legal claims. You can object to processing for direct marketing at any time and without giving reasons, the plan suggestions shown inside the app included; we then no longer use your data for it. Object by email to support@transferify.cloud, through the unsubscribe link in any offer email, or in your account settings.
You can erase your account and its data yourself from inside the product - the steps are on our Data Deletion Instructions page.
If you received a transfer email or a file request and simply want them to stop, you do not need to write to us first: use the unsubscribe link in that email. That is the direct way to exercise your right to object under GDPR Art. 21 to the processing described in Section 5, and it applies to every sender at once.
To exercise any of these rights, including after account closure, contact EchoStream SRL at support@transferify.cloud. We will handle requests concerning our processing and, where appropriate, coordinate with or forward them to Stripe. Stripe may retain data for its independent legal obligations as described above. You also have the right to lodge a complaint with a supervisory authority. In Romania this is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
The GDPR applies to your data-protection rights directly, wherever you live. Which law governs the contract, and where a claim can be brought, is set out in Section 16 of our Terms & Conditions, which preserves the mandatory consumer-protection law of your country of residence. In addition, if you are a consumer domiciled in the European Union, Articles 18 and 19 of Regulation (EU) No 1215/2012 mean you can always sue us in the courts of the place where you are domiciled, and we can sue you only in the courts of the Member State where you are domiciled.
If you are in the United Kingdom
We are established in Romania, so the EU GDPR governs our processing wherever you live. Because we also offer the Service to people in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply to it as well, in addition to the EU GDPR and not instead of it. Every right listed above is available to you in the same form and subject to the same conditions under the UK GDPR, and you exercise them by the same routes: the unsubscribe link in any email we send you, the deletion steps on our Data Deletion Instructions page, or support@transferify.cloud.
You may lodge a complaint with the Information Commissioner's Office (ICO), the United Kingdom's supervisory authority, at https://ico.org.uk. That is in addition to the Romanian authority named above rather than instead of it.
9. How we protect your data (security)
We use technical and organizational measures designed to protect your data, including:
- Encryption in transit for connections to and within the Service.
- Client-side encryption of file contents (AES-256-GCM) for hosted transfers, including transfers sent to email recipients or groups and files uploaded in response to a file request, with default key escrow or the selected Zero-Knowledge mode as explained in Section 1.
- End-to-end encryption for peer-to-peer transfers, so file contents are not exposed to our servers.
- Encryption at rest for hosted files stored with Cloudflare and AWS.
- Zero-Knowledge mode (paid), where the file key never reaches our servers and we cannot decrypt your files.
No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee absolute security.
10. Cookies, analytics and advertising
We use a small number of essential cookies and similar technologies to run the Service, and - only with your consent, and separately for each purpose - Google’s analytics service for product analytics and Google’s advertising tags for campaign measurement and advertising audiences. The two reach Google by different routes. No analytics service runs in your browser: your browser sends what it measures to our own servers, and we pass it on to Google, so no analytics script from Google is loaded and no analytics cookie is set. Advertising does use a Google tag in your browser, and it loads only once you grant the advertising purpose. Until you grant a purpose, nothing is measured, no Google tag is loaded, and your browser sends Google no request of either kind. One disclosure does not run in your browser at all, although your answer here can start it: our servers send Google a one-way hash of your address if you accept the advertising purpose here, or switch on “Use my email for Transferify ads on Google” in your account settings, which Section 3 sets out as its own purpose. Signing in is separate: it is strictly necessary, it uses Google's authentication service, and it runs whatever you choose here. For details of what we use and how to control it, please see our separate Cookie Policy, which you can open from the same legal menu as this Privacy Policy.
11. Anonymous statistics we count without consent
Two things are counted whichever way you answer the cookie banner - and one of them is counted even if you never answer it at all. The totals themselves are aggregate statistics rather than personal data, so neither is something we ask you to agree to. Your IP address is personal data and does reach us on the way, so GDPR Art. 13 applies to that part - and rather than describe only that part, both counts are set out below.
- Your answer to the cookie banner. When you accept, reject, or save your own selection in "Cookie Settings", we count one decision for each purpose you answered - the optional email-offers choice included only once you have answered it: whether it was granted or denied, and which of those three controls recorded it. Nothing travels with it - no cookie, no session, no account, no email address and no identifier of any kind - and nothing we store says what any one visitor answered. A later change of mind counts as a new decision, so the totals measure decisions rather than people. We count them because a visitor who declines is invisible to every analytics and advertising tag by design, so a first-party count is the only way to know what share of visitors decline.
- How your visit reached us. From the moment you open the site we work out a single coarse acquisition category, in your browser, from the kind of site the visit came from, the page it landed on, whether the link carried an advertising click parameter or someone's referral code, and the labels we ourselves put on our own advertisements and posts. That category is one word from a closed list:
paid-search,paid-social,organic,ai,social,referral,direct,recipient-page,recipient-page-game,recipient-page-control,request-pageorreferral-invite. The wordaisays only that the visit came from an AI assistant's site, never what was asked there. The wordsrecipient-page-gameandrecipient-page-controlsay only which of two test groups the download page load was put in, never anything you did on it. The group is drawn at random for each page load; if you allowed analytics, it is derived from your analytics identifier instead, so it stays the same between visits. That word, the two labels the link you arrived on carried - which campaign it was, and which version of the advertisement - and a fixed marker on the first request of each page load that carries the word, which says only that a visit has started, are the only things this count sends us; a label that is not one we wrote down ourselves is discarded rather than counted. The address of the site you came from is never sent for this count, and the page you landed on, anything else in the address, any advertising click identifier and any referral code are never collected for it. The labels name our own advertisement or post rather than you, and the word names no transfer, no request and no person. - What happens to them. The category and those labels ride on the requests that already carry your sign-in token, which for a visitor who has not signed in is the temporary anonymous session described in Section 2 - we say so plainly rather than let it sound like a separate, unconnected message. We read them at two moments. When an account is first established, we add one tick to an aggregate total for that category and those labels. And on every request that carries the category, we add one to that day's request total for the category, plus one to its visit total when the request carries the visit marker; the labels play no part in this second count. What we keep from it is one line per day and category holding those two numbers, and nothing else: nothing is written against your account, nothing about the request is stored beside the numbers, and no total can be traced back to an individual visit or signup. A category we do not receive or cannot recognise is counted as
untrackedin the signup total rather than guessed at, and adds nothing to the daily totals. The daily totals count every visit that carries a category, including the many from people who read a page and leave without ever signing in or creating an account; they tell us how many visits each source sends us. Where you have granted the advertising purpose, those two labels are ALSO kept against your account, alongside a third that names the network, which is a separate thing described in Section 3. We count this because the consent-based advertising measurement described in Section 3 can only ever see the people who consented, which makes the picture it gives systematically wrong; this total is what tells us by how much.
What is never collected for these totals. Neither count carries a name, an email address or any identifier of its own, and neither creates anything in your browser: no cookie is set and no storage entry is made for them. No click-identifier value and no page address is collected on either path, nothing about either is recorded against you or your account, and nothing is sent to Google or to any other analytics or advertising provider. The totals are counts and nothing else: they are not used to single you out, and they are never used to build a profile, to target advertising, or to make a decision about you. We will not claim more than that: the acquisition category travels beside your session token as described above, and at very low traffic a banner count and the abuse-limit row described next could in principle fall in the same minute - and, likewise, at very low traffic the minute a channel total moves could in principle be put beside the minute an account was created - which is why that row is deliberately keyed to a network rather than a device: it cannot name a machine, and on its own it cannot name a person.
Your IP address. Like every request to any website, these requests arrive carrying your IP address - the internet does not work otherwise. It is not stored in the clear anywhere on this path and never beside what was counted; ordinary server logs, where kept, are described in Section 7. Where a count arrives as a request of its own, the address is used only to enforce an abuse limit on that endpoint: it is first reduced to the network it belongs to rather than to your individual device, then turned into a keyed one-way hash, and only that hash is kept, next to a request count and a time recorded no more precisely than to the minute. That row records nothing about what you answered or where you came from. It is needed only while the limit's window runs - currently one hour - and a routine sweep removes it afterwards. The sweep works through spent rows at a bounded pace shared with every other protected part of the Service, so a spent row can persist beyond its window - under sustained traffic, considerably longer - until its turn comes; it is not read again in the meantime.
Legal basis. The totals themselves are aggregate statistics and are not personal data, so keeping them needs neither a legal basis nor your consent (GDPR Art. 4(1) and Recital 26). Getting to them does involve personal data: your IP address arrives with every request and, where a count arrives as a request of its own, is used to enforce the abuse limit described above; and the acquisition category travels beside your session token. For both of those we rely on our legitimate interests (GDPR Art. 6(1)(f)) in knowing how many visits each source sends us and whether our own measurements are representative, and in keeping an endpoint anyone can call usable, weighed against the fact that the address is reduced to a network and hashed before anything is written, and is never stored beside what was counted. You can object to processing based on our legitimate interests at any time - see Section 8; because the totals carry no identifier, we can act on an objection going forward but cannot pick a count already made back out of them.
12. Children
The Service is not directed at children under the age of 16, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, please contact us at support@transferify.cloud and we will take appropriate steps to delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you through the Service. We encourage you to review this page periodically.
14. How to contact us
For any questions about this policy or your personal data, contact EchoStream SRL at support@transferify.cloud, or by writing to our registered office at Str. Soporului nr. 8, bl. C, sc. 1, ap. 8, 400482 Cluj-Napoca, Romania.