Data Processing Agreement (DPA)
This document constitutes the Data Processing Agreement (DPA) within the meaning of Article 28 of the General Data Protection Regulation (GDPR - EU 2016/679) between PrivCloud and any professional client using the service.
Last updated: May 19, 2026
Article 1 - Parties to this agreement
This DPA is entered into between:
Article 2 - Purpose and nature of processing
PrivCloud processes, on behalf of the Data Controller, the data strictly necessary to provide the end-to-end encrypted file transfer service. Processing is limited to encrypted hosting of transferred files and management of associated metadata (link access, notifications, account management).
Article 3 - Categories of data processed
Email address - for user accounts and download notifications.
Transfer metadata - filename (encrypted), size, creation date, expiration date, uploader IP address (pseudonymised).
Content of transferred files - end-to-end encrypted (AES-256-GCM) in the browser. The processor has no technical access to the plaintext content (zero-knowledge architecture).
Account data - username, preferences, transfer history (metadata only).
Article 4 - Retention periods
Article 5 - Data location and transfers
All data is hosted on an infrastructure (server and object storage) located in France (European Union). No transfers to third countries (outside EU/EEA) are carried out. As file content is end-to-end encrypted, it is stored only in encrypted form, inaccessible in plaintext by the hosting providers.
Article 6 - Technical and organisational security measures
End-to-end encryption - AES-256-GCM, key derived in the uploader's browser (PBKDF2/HKDF). The key is never transmitted to the server.
Zero-knowledge architecture - the processor is technically unable to decrypt transferred files.
HTTPS / TLS 1.3 - all client-server communications are encrypted in transit.
Strong authentication - two-factor authentication (2FA/TOTP) available for all accounts.
Firewall and monitoring - iptables/ip6tables with strict rules, Wazuh security monitoring (alerts + auto-remediation), Zabbix monitoring, intrusion detection (MalwareDetect / Clamav).
Restricted access - administrator access limited, logged and protected by SSH key only with 82-character password + 2FA (SSH bastion). No unsecured remote access.
Encrypted backups - automated backups, encrypted with Restic.
Open source code - the source code is publicly auditable on GitHub.
Article 7 - Sub-processors
PrivCloud relies on infrastructure providers (hosting and storage) located exclusively in France (European Union). Due to the zero-knowledge architecture and end-to-end encryption, none of these providers has technical access to the plaintext content of transferred files: they only host encrypted data that they cannot decrypt. The technical providers involved are:
Article 8 - Assistance with data subject rights
PrivCloud undertakes to assist the Data Controller in responding to requests from data subjects exercising their rights under Articles 15 to 22 of the GDPR (right of access, rectification, erasure, portability, objection, restriction).
Requests can be sent to: contact@stockageprive.net
Article 9 - Data breach notification
In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, likely to engage the liability of the Data Controller, PrivCloud undertakes to notify the Data Controller within 48 hours of becoming aware of the incident, by email to the address registered on the account.
Article 10 - Transparency and audit
The complete PrivCloud source code is publicly available on GitHub, enabling any independent technical audit. The Data Controller may send any additional information request regarding security measures to contact@stockageprive.net.
Article 11 - Data return and deletion
At the end of the contractual relationship or upon request from the Data Controller, PrivCloud undertakes to delete all data from the relevant account within 30 days. Since encrypted files are inaccessible in plaintext without the decryption key held by the user, their physical deletion from the servers constitutes a final and irreversible destruction.
Article 12 - Acceptance and entry into force
Use of the PrivCloud service by any professional entity (company, association, freelancer acting in the context of their professional activity) constitutes acceptance of this DPA. This DPA comes into force from the first professional use of the service and remains in force for the entire duration of the contractual relationship.
Contact & questions
For any questions regarding this DPA, to request a signed copy, or to exercise your rights, contact us:
E-mail : contact@stockageprive.net
Website: share.privcloud.fr
Security page: PrivCloud Security model
Related documents
This document has been drafted in accordance with Article 28 of the GDPR (EU Regulation 2016/679). It may be updated to reflect technical or regulatory changes. Last updated: May 19, 2026.