Back to home
Legal

Privacy Policy

Effective Date: 04 July 2026Last Updated: 04 July 2026
This policy covers data collected from account holders (registered users), file recipients (people who view shared files), and document submitters (people who upload files via secure collection requests).

1. Introduction

FileLink is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Service — including both Secure File Sharing (sending files to recipients) and Secure Document Collection (receiving files from clients, employees, or vendors).

2. Information We Collect

Account & Profile Data

  • Name, email address, and account details provided during registration.
  • Company or organisation name (optional).

File Sharing — Sender Data

  • Files you upload for sharing (encrypted at rest and in transit using AES-256).
  • Link settings: expiry dates, OTP requirements, download/print restrictions, watermark preferences.
  • Metadata: file name, size, upload timestamp, number of links created.

File Sharing — Recipient / Viewer Data

  • Name and email address entered at OTP verification (if OTP is required on the link).
  • IP address, country, city, device type, operating system, and browser.
  • View duration, pages viewed, time of access.
  • Download or print attempt events.
  • This data is captured to generate your audit log and is accessible to the account holder who shared the file.

Document Collection — Submitter Data

  • Name and email address entered at the OTP verification step before submission.
  • Files submitted (encrypted at rest and in transit).
  • IP address, country, device type, and browser at time of upload.
  • Upload timestamp and file metadata.
  • This data is captured to provide a verified, auditable record of inbound submissions to the account holder who created the upload request.

Automatically Collected Data

  • Access logs for our platform (not the viewer audit logs described above).
  • Browser and operating system information for product improvement.
  • Error logs and performance metrics.

3. How We Use Information

  • To provide, operate, and improve the File Sharing and Document Collection services.
  • To authenticate recipients and submitters via OTP email.
  • To generate audit logs for account holders.
  • To send email alerts to account holders when their files are accessed or documents are submitted.
  • To process payments and manage your account.
  • To detect and prevent fraud, abuse, and security incidents.
  • To comply with applicable legal obligations and global data protection standards.

4. Sharing of Information

  • We do not sell personal data to third parties.
  • File recipients and document submitters: their data is visible only to the account holder who created the link or upload request, and to FileLink for service operation.
  • Service Providers: cloud storage (encrypted), transactional email provider — all under strict data processing agreements.
  • Legal Requirements: we may disclose data if required by law, court order, or government authority.
  • Business Transfers: if FileLink is acquired or merged, your data may transfer to the successor entity under equivalent protections.

5. Data Security

  • AES-256 encryption for all files at rest and in transit.
  • Secure viewer — files stream in-browser and are not cached or downloaded to recipient devices.
  • OTP verification reduces the risk of unauthorised access to shared files and inbound document submissions.
  • Regular security audits, access controls, and monitoring.
  • Multi-tenant data isolation — each account's files and audit logs are scoped to their tenant.

6. Data Retention

  • Files and upload request submissions are retained for the duration of your active account.
  • Audit logs (both file access logs and submission logs) are retained for 12–24 months or as required for compliance.
  • When an account is closed or deleted, data is purged within 30 days unless a legal hold applies.
  • OTP verification records are retained as part of the audit trail for compliance purposes.

7. Your Rights (Under Applicable Law)

  • Right to access the personal data we hold about you.
  • Right to correction of inaccurate data.
  • Right to erasure ("right to be forgotten") — subject to retention obligations.
  • Right to withdraw consent for optional processing.
  • Right to grievance redressal.

To exercise these rights, contact: privacy@filelink.in

8. Recipient and Submitter Rights

If you received a FileLink sharing link or were asked to submit a document via a FileLink upload request, the account holder who sent you the link is the data controller for your access data. FileLink acts as the data processor. To request deletion of your data, contact the account holder directly or email privacy@filelink.in and we will facilitate the request.

9. Cookies and Tracking

We use essential cookies for authentication and session management. We may use analytics cookies to understand how the platform is used. You can manage cookie preferences through your browser settings. We do not use third-party advertising trackers.

10. International Transfers

Your data is processed on infrastructure hosted in secure data centres. Data may be processed across global regions with appropriate safeguards in place to protect it under applicable data protection laws.

11. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect data from minors.

12. Changes to This Policy

We will notify you of material changes via email or in-app notice. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

Privacy Contact

For privacy concerns or data requests, email us at privacy@filelink.in