This privacy policy explains how SASU Dynamic Foundries ("we", "us", "our") collects, uses, and protects your personal data when you use FileSendX ("the Service"), available at https://filesendx.com, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and French Law No. 78-17 of 6 January 1978 (Loi Informatique et Libertés).
Data Controller
- Company: SASU Dynamic Foundries (RCS Paris 102 801 206)
- Address: 15 Boulevard Saint-Marcel, 75013 Paris, France
- Email: contact@dynamic-foundries.com
We have not designated a Data Protection Officer (DPO): we do not meet the criteria of Article 37 of the GDPR (no large-scale systematic monitoring, no large-scale processing of special-category data, no public authority status). For any data-protection question, please write to contact@dynamic-foundries.com — we respond within 30 days.
Data We Collect
Data you provide
- Account data: username, email address, and password (stored as an irreversible hash)
- File transfer data: uploaded files, original file names, file sizes, recipient email addresses, and optional messages attached to transfers
- Billing data: payment method details are processed directly by Stripe and are not stored on our servers. We store your Stripe customer ID, subscription plan, and billing history.
Data collected automatically
- Technical data: IP address, browser type and version, operating system
- Usage data: pages visited, date and time of access (collected via Google Analytics only with your consent)
- Transfer metadata: upload dates, download counts, and file expiry dates
- Cookies: see the Cookies section below
Purpose and Legal Basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Account creation and management | Performance of contract (Art. 6(1)(b)) |
| File transfer and delivery | Performance of contract (Art. 6(1)(b)) |
| Payment processing and billing | Performance of contract (Art. 6(1)(b)) |
| Email notifications (transfer confirmations, account validation) | Performance of contract (Art. 6(1)(b)) |
| Website analytics (Google Analytics, consent-gated) | Consent (Art. 6(1)(a)) |
| Security, CAPTCHA verification, and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
Data Retention
| Data type | Retention period |
|---|---|
| Account data | Duration of the account; deleted within 30 days of account closure |
| Billing and invoice data | 10 years (French accounting obligations, Art. L123-22 Code de commerce) |
| Uploaded files | Automatically deleted upon expiry (3 to 90 days depending on your plan). Immediately deleted if your account is deleted. |
| Transfer metadata (file names, recipient emails, messages) | Duration of the account; deleted when account is deleted |
| Analytics data (Google Analytics) | 26 months |
| Server logs | 12 months |
| Support communications | 3 years after resolution |
Sub-processors
We use the following third-party services that may process your data:
| Service | Purpose | Location |
|---|---|---|
| OVH SAS | Web hosting and data storage | France (EU) |
| Stripe Payments Europe Ltd. (with transfers to Stripe, Inc. — US) | Payment processing | Ireland (EU); transfers to the US under EU-US Data Privacy Framework |
| Google LLC (Google Analytics) | Website analytics (consent-gated) | United States (EU-US Data Privacy Framework) |
| Google LLC (Google Fonts) | Delivery of the Inter web font (IP address is shared with Google as a technical necessity of font delivery) | United States (EU-US Data Privacy Framework) |
| Tailwind Labs, Inc. (Tailwind CDN) | Delivery of the Tailwind CSS framework used to style the site (IP address is shared with the CDN as a technical necessity of file delivery) | United States (EU-US Data Privacy Framework) |
| Cloudflare, Inc. and its EU affiliates (Turnstile) | CAPTCHA / bot protection on registration | EU and United States (EU-US Data Privacy Framework) |
Cookies
This Service uses cookies — small text files stored on your device. The following table lists every cookie that may be set when you use FileSendX, in line with CNIL recommendations on cookie transparency.
| Name | Vendor | Purpose | Duration | Category |
|---|---|---|---|---|
session | FileSendX (first-party) | Authentication and CSRF protection. Stores a signed session identifier so logged-in users remain authenticated. | Session (cleared at browser close or logout) | Strictly necessary |
cookie_consent | FileSendX (first-party) | Records your choice on the cookie banner (accepted or refused) so the banner does not reappear on every page. | 1 year | Strictly necessary |
_ga | Google LLC | Google Analytics — distinguishes unique visitors. Set only after you accept the analytics category in the consent banner. | 2 years | Audience measurement (consent required) |
_ga_<property-id> | Google LLC | Google Analytics 4 — persists per-property session state. Set only after you accept the analytics category. | 2 years | Audience measurement (consent required) |
cf_clearance, __cf_bm | Cloudflare, Inc. | Cloudflare Turnstile — challenge state for bot protection. Set only on pages that render the challenge widget (registration, password reset). | 30 minutes (__cf_bm) to 30 days (cf_clearance) | Strictly necessary (security) |
__stripe_mid, __stripe_sid | Stripe Payments Europe Ltd. | Stripe — fraud prevention and session continuity for payment processing. Set only on pages that load the Stripe Elements widget (checkout, payment-method updates). | 30 minutes (__stripe_sid) to 1 year (__stripe_mid) | Strictly necessary (contractual) |
You can revisit your consent at any time via the "Cookie preferences" link in the page footer, or manage cookies through your browser settings. Disabling strictly necessary cookies may prevent you from using the Service.
Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS)
- Passwords stored using a strong, salted, industry-standard one-way hashing function
- Regular security updates and patching
- Access controls and authentication for internal systems
- Web Application Firewall (WAF)
No method of transmission or storage is 100 percent secure. If you discover a security vulnerability, please contact us immediately at contact@dynamic-foundries.com.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — obtain a copy of your personal data
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure (Art. 17) — request deletion of your data
- Right to restrict processing (Art. 18) — limit how we use your data
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time for consent-based processing
To exercise any of these rights, contact us at contact@dynamic-foundries.com. We will respond within 30 days. You may also delete your account and associated data directly from your account settings.
If you believe your rights have not been respected, you may file a complaint with the French data protection authority:
- CNIL — Commission Nationale de l'Informatique et des Libertés
- 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- www.cnil.fr
International Transfers
Some of our sub-processors may transfer data outside the European Economic Area (EEA). When this occurs, we ensure appropriate safeguards are in place, including the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs) as approved by the European Commission.
Children's Privacy
This Service is not intended for children under 15 years of age, the digital age of consent under Article 7-1 of the French Loi Informatique et Libertés. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
Automated Decision-Making
FileSendX does not make any decision producing legal effects concerning you, or significantly affecting you, that is based solely on automated processing within the meaning of Article 22 of the GDPR. We do not perform profiling, scoring, or automated content evaluation on the files you upload or on your usage patterns.
Data Breach Notification
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 of the GDPR. Where applicable, we will also notify the CNIL within 72 hours of becoming aware of the breach (Article 33 GDPR).
Directives Concerning Your Data After Death
In accordance with Article 85 of the French Loi Informatique et Libertés, you may give us general or specific directives regarding the storage, deletion, and disclosure of your personal data after your death. General directives may be entrusted to a digital trusted-third-party certified by the CNIL. Specific directives concerning the data we hold may be sent directly to contact@dynamic-foundries.com. In the absence of any directives, your heirs may exercise certain rights on your behalf, subject to the conditions set out in Article 85 of the same law.
Changes to This Policy
We may update this privacy policy from time to time. If we make material changes, we will notify you via email or through the Service. The date of the last update is indicated below.
Last updated: May 2026