Legal document - GDPR Article 28

Data Processing Agreement (DPA)

This document constitutes the Data Processing Agreement (DPA) within the meaning of Article 28 of the General Data Protection Regulation (GDPR - EU 2016/679) between PrivCloud and any professional client using the service.

Last updated: May 19, 2026

Article 1 - Parties to this agreement

This DPA is entered into between:

RoleEntity
Data ControllerThe company, association or freelancer using the PrivCloud service in the context of their professional activity.
Data ProcessorTHEMIOT Informatique, operating the PrivCloud service (share.privcloud.fr), hosted in France.

Article 2 - Purpose and nature of processing

PrivCloud processes, on behalf of the Data Controller, the data strictly necessary to provide the end-to-end encrypted file transfer service. Processing is limited to encrypted hosting of transferred files and management of associated metadata (link access, notifications, account management).

Article 3 - Categories of data processed

  • Email address - for user accounts and download notifications.

  • Transfer metadata - filename (encrypted), size, creation date, expiration date, uploader IP address (pseudonymised).

  • Content of transferred files - end-to-end encrypted (AES-256-GCM) in the browser. The processor has no technical access to the plaintext content (zero-knowledge architecture).

  • Account data - username, preferences, transfer history (metadata only).

Article 4 - Retention periods

Data typeRetention period
Transferred filesAutomatic deletion at user-configured expiration (1 day default, 30 days maximum)
Security logs (IP, access)90 days maximum
Account dataUntil account deletion by the user

Article 5 - Data location and transfers

All data is hosted on an infrastructure (server and object storage) located in France (European Union). No transfers to third countries (outside EU/EEA) are carried out. As file content is end-to-end encrypted, it is stored only in encrypted form, inaccessible in plaintext by the hosting providers.

Article 6 - Technical and organisational security measures

  • End-to-end encryption - AES-256-GCM, key derived in the uploader's browser (PBKDF2/HKDF). The key is never transmitted to the server.

  • Zero-knowledge architecture - the processor is technically unable to decrypt transferred files.

  • HTTPS / TLS 1.3 - all client-server communications are encrypted in transit.

  • Strong authentication - two-factor authentication (2FA/TOTP) available for all accounts.

  • Firewall and monitoring - iptables/ip6tables with strict rules, Wazuh security monitoring (alerts + auto-remediation), Zabbix monitoring, intrusion detection (MalwareDetect / Clamav).

  • Restricted access - administrator access limited, logged and protected by SSH key only with 82-character password + 2FA (SSH bastion). No unsecured remote access.

  • Encrypted backups - automated backups, encrypted with Restic.

  • Open source code - the source code is publicly auditable on GitHub.

Article 7 - Sub-processors

PrivCloud relies on infrastructure providers (hosting and storage) located exclusively in France (European Union). Due to the zero-knowledge architecture and end-to-end encryption, none of these providers has technical access to the plaintext content of transferred files: they only host encrypted data that they cannot decrypt. The technical providers involved are:

ProviderRoleLocation
HolyCloudServer hosting (compute and network infrastructure)France, UE
iDrive e2Object storage of encrypted files (end-to-end encrypted data only)France, UE

Article 8 - Assistance with data subject rights

PrivCloud undertakes to assist the Data Controller in responding to requests from data subjects exercising their rights under Articles 15 to 22 of the GDPR (right of access, rectification, erasure, portability, objection, restriction).

Requests can be sent to: contact@stockageprive.net

Article 9 - Data breach notification

In the event of a personal data breach within the meaning of Article 4(12) of the GDPR, likely to engage the liability of the Data Controller, PrivCloud undertakes to notify the Data Controller within 48 hours of becoming aware of the incident, by email to the address registered on the account.

Article 10 - Transparency and audit

The complete PrivCloud source code is publicly available on GitHub, enabling any independent technical audit. The Data Controller may send any additional information request regarding security measures to contact@stockageprive.net.

Article 11 - Data return and deletion

At the end of the contractual relationship or upon request from the Data Controller, PrivCloud undertakes to delete all data from the relevant account within 30 days. Since encrypted files are inaccessible in plaintext without the decryption key held by the user, their physical deletion from the servers constitutes a final and irreversible destruction.

Article 12 - Acceptance and entry into force

Use of the PrivCloud service by any professional entity (company, association, freelancer acting in the context of their professional activity) constitutes acceptance of this DPA. This DPA comes into force from the first professional use of the service and remains in force for the entire duration of the contractual relationship.

Contact & questions

For any questions regarding this DPA, to request a signed copy, or to exercise your rights, contact us:

This document has been drafted in accordance with Article 28 of the GDPR (EU Regulation 2016/679). It may be updated to reflect technical or regulatory changes. Last updated: May 19, 2026.