AspisFile

Privacy Policy

Last updated: August 2026

This Privacy Policy explains how AspisFile (“AspisFile”, “we”, “us”) collects, uses, and protects personal data when you use our confidential file‑sharing and access‑control service — the website, dashboard, and the AspisFile viewer apps (together, the “Service”). It applies to both people who send files (“senders”) and people who receive them (“recipients”).

Who is responsible for your data

AspisFile is the data controller for account and service data. When a sender uses AspisFile to share a file, the sender is the controller of the file content and recipient list, and AspisFile acts as a processor for that content on the sender’s behalf.

Data we collect

Account data (senders). Your name, email address, and optional business name; authentication credentials (password hash held by our authentication provider, and/or passkey credential identifiers); and, for paid plans, billing details processed by our payment provider.

Recipient data. The email address a sender provides to share a file with you, and — if you enrol a passkey to open files — passkey credential identifiers. We do not receive your passkey’s private key.

Device & technical data. To bind access to your device and detect abuse, we collect:

Usage & audit data. To provide access control and an audit trail, we log file‑access events (opens, pages viewed, downloads where permitted), timestamps, the approximate location and security verdict of each open (e.g. verified, VPN‑detected, blocked), and a record of shares, approvals, and revocations.

File content. Files you send are encrypted. They are rendered for viewing through the Service and are not retained as readable copies on our servers beyond what is needed to deliver them for the recipient’s first open (see “How long we keep data”). We do not read, index, or analyse the contents of your files.

How we use your data

Legal bases (where GDPR applies)

We rely on: performance of a contract (to provide the Service you or a sender requested); our legitimate interests (securing the Service, preventing fraud and unauthorised access, and maintaining audit records) balanced against your rights; consent where specifically requested; and compliance with legal obligations.

Where your data is stored

Encrypted file data is stored on Amazon Web Services in the EU (S3, eu‑north‑1, Stockholm) with server‑side encryption. Account, recipient, and audit data are held in our EU‑based database and authentication infrastructure. We use a small number of processors to run the Service: our cloud storage and database/authentication providers, our email‑delivery provider, and — for paid plans — our payment provider. Processors act on our instructions under data‑processing terms.

How long we keep data

Sharing and disclosure

We do not sell your personal data and do not share it for advertising. We share data only with the processors described above, and where required to comply with law, enforce our terms, or protect the rights and safety of users and the public.

Your rights

Depending on your location, you may have the right to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. To exercise any of these, or to ask what data we hold about you, contact privacy@aspisfile.com. If a sender shared a file with you, requests about that file’s content may need to be directed to the sender as its controller.

Security

We protect data with encryption in transit and at rest, per‑page watermarking, identity‑bound access, screen‑capture protection in the viewer apps, and one‑click revocation. No system is perfectly secure, but we design AspisFile so that access can be cut and audited at any time.

International transfers

Our infrastructure is EU‑based. Where data is transferred outside your region (for example to a processor), we rely on appropriate safeguards such as Standard Contractual Clauses.

Children

The Service is for business use and is not directed to children under 16. We do not knowingly collect data from children.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above and, where appropriate, communicated to account holders.

Contact

For any privacy question or request, contact privacy@aspisfile.com.