Effective Date: 2026-04-02. We may update this notice from time to time. Where changes are material, we will update this page and may also provide additional notice by email or in-product messaging.
This policy is intended to reflect the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and related applicable laws.
1. Data Controller Details
Data controller: FileKit
Contact: info@filekit.eu
2. Our Role in Processing
FileKit generally acts as a controller for account data, billing data, support communications, service analytics, fraud-prevention logs, and other data needed to operate the platform.
For user-provided content, including uploaded files, converted files, generated outputs, QR payload data, and destination URLs, FileKit may process such content primarily to provide the service requested by the user. Depending on the context, this may be operationally similar to processor-style handling of user content, while FileKit remains controller for the surrounding account, security, payment, and platform administration functions.
3. Data We Process and Purposes
Account data
Email address, encrypted password, account identifiers, and related account settings used for registration, login, authentication, and account administration.
QR content and generated QR outputs
Text, URLs, structured payloads, QR configuration data, and generated QR image files used to create, store, and deliver QR codes.
Uploaded files and converted outputs
Files uploaded for conversion, temporary processing copies, converted output files, and associated file metadata needed to perform requested file conversion or related delivery.
Transactional communications
Email data used for verification, password resets, order-related notices, file or QR delivery, support, and other transactional service messages.
Usage, security, and abuse-prevention data
Service logs, IP-related security records, access events, technical diagnostics, and anti-abuse signals used to secure the service, troubleshoot issues, and prevent misuse.
Payment-related data
Payment status, billing references, transaction identifiers, and subscription or purchase metadata. Card details are processed by payment providers and are not fully stored by FileKit.
4. QR Scan and Usage Analytics
Where analytics features are enabled, we may process usage and scan-related event data to measure performance, improve reliability, prevent abuse, and provide analytics functionality.
Depending on the feature used, this may include event timestamp, destination request data, approximate technical metadata, browser or device category, and other service usage information. If IP-related data is processed for analytics, security, or fraud prevention, we treat it as personal data where required by applicable law.
We do not describe exact analytics fields here as fixed in all cases because they may vary by feature, deployment, abuse-prevention need, or processor configuration.
5. Legal Bases
- Contract performance: registration, login, QR creation, file conversion, storage necessary for delivery, and other core service functions.
- Consent: non-essential cookies, consent-based analytics, and any optional marketing features where offered.
- Legal obligation: invoicing, accounting, tax, compliance, and lawful response obligations.
- Legitimate interests: service security, fraud prevention, abuse detection, troubleshooting, system monitoring, and service improvement.
6. Processors and Infrastructure Providers
We may use service providers that process data on our behalf, such as:
- Payment providers, such as Stripe, for billing and payment processing.
- Analytics providers, such as Google Analytics, for usage measurement.
- Hosting, storage, CDN, email delivery, and infrastructure providers needed to operate the service, deliver files and QR outputs, secure the platform, and maintain availability.
Processors may change over time as our infrastructure evolves.
7. Transfers Outside the EU/EEA
Some processors or infrastructure providers may process data outside the European Economic Area. Where applicable, we rely on recognized transfer safeguards, such as the EU Standard Contractual Clauses, or other lawful transfer mechanisms.
8. Retention Periods
Personal data linked to a FileKit user account is generally retained for as long as the user maintains that account.
If a user deletes their FileKit account, the personal data associated with that account will be deleted or irreversibly anonymized, except where continued retention is required by applicable law, necessary for billing or accounting compliance, needed for security or fraud prevention, or temporarily retained in secure backups until deletion cycles are completed.
- Account data: retained while the account remains active.
- Uploaded files, converted files, and generated outputs: retained while associated with the active account or as needed to provide the service.
- QR outputs and related records: retained while associated with the active account or as needed for service delivery and account access.
- Analytics and log data: retained for a limited period appropriate to analytics, reliability, and security purposes.
- Billing and invoice data: retained for the period required by applicable accounting and tax laws.
- Backups: deleted data may remain in secure backups for a limited rolling period until those backups expire or are overwritten.
9. Data Subject Rights
Subject to applicable law, you may have the right to request access, rectification, deletion, restriction, portability, or objection to certain processing.
To exercise your rights, contact us at info@filekit.eu. We may ask for information necessary to verify your identity before acting on a request.
You may also have the right to lodge a complaint with your local supervisory authority.
10. Security Measures
We use reasonable technical and organizational measures designed to protect data from unauthorized access, misuse, alteration, disclosure, or loss.
- Transport encryption such as HTTPS/TLS.
- Restricted access controls and authentication measures.
- Password storage protections for account credentials.
- Operational logging and monitoring for reliability and abuse detection.
- Security-oriented deletion and lifecycle handling for service data where applicable.
- Incident response and remediation efforts appropriate to the size and nature of the service.
11. Children and Sensitive Data
FileKit is not directed to children. Do not use the service if you are not legally permitted to do so under applicable law.
Users should not upload or submit special-category personal data, confidential information, or other highly sensitive material unless they are legally authorized to do so and such processing is necessary for their intended lawful use.
13. Changes to This Policy
We may update this notice from time to time. We will publish updates on this page and may provide additional notice for material changes. The most recent effective date will always appear at the top of this page.
14. Contact
For privacy questions or to exercise your rights, contact us at: info@filekit.eu