Legal

Privacy policy

What data we process, for what purpose, on what legal basis and for how long. Plus the list of sub-processors, named.

Last updated: 7 August 2026

This is a translation. In case of any discrepancy, the Romanian version at /ro/privacy/ prevails.

Who processes your data

The controller is the Cyber Security Education Association, 50 Linia de Centură Street, Ștefăneștii de Jos, Ilfov County, Romania, tax ID 48106635. Write to gdpr@amprentadigitala.ro with any question about your data.

The principle everything else follows from

Your files are encrypted on your device, with a key computed from your password, before being transmitted to us. We receive meaningless blocks of data. We do not hold the key and cannot reconstruct it.

This is why most of this policy talks about metadata rather than content: the content is not accessible to us.

What data we process

  • Email address. To create your account, send space notifications and invoices. Basis: performance of the contract. Retention: while you have an account, plus 30 days.
  • Password verifier. Not the password. A value derived from it, which we hash again on the server with Argon2id. The password cannot be obtained from it, and it cannot open the vault. Basis: performance of the contract.
  • Wrapped key. Your vault key, encrypted with your password and with your recovery code. Without one of them, it is a useless string. Basis: performance of the contract.
  • Billing data. Name, address, country, optionally a tax ID. Collected by Stripe directly from you. Basis: legal obligation, accounting. Retention: 10 years.
  • File metadata. Size, content date, general category (image, video, document), the shape of the folder tree and the number of files. File names, tags and notes are encrypted and not accessible to us. Basis: performance of the contract, so we can measure space and display your list.
  • Access logs. IP address, country, timestamp, device type and action. Basis: legitimate interest, service security. Retention: 12 months.
  • Correspondence. What you write to us. Basis: legitimate interest. Retention: 24 months.

What we cannot see

Your password. The vault key. File contents. File and folder names. Tags, notes and photo EXIF data. Thumbnails in the clear. Your recovery code.

This is not an internal policy promise, it is a consequence of the encryption. Technical detail is on the security page.

What the server does see

We prefer to write this explicitly rather than leave the impression that we see nothing. The server sees the email address, billing data, IP address and country, the timestamp of every action, the number of files and folders, the shape of the tree, the size of each file, the general type category, the last modification date, and connected devices.

This information is necessary in order to measure purchased space, display your file list without downloading everything, and detect abuse.

Who else touches the data

  • Chroot Network SRL, Romania. Hosting of the application and encrypted blocks.
  • Cloudflare, Inc., United States. Protection and content delivery. Cloudflare terminates the secure connection, so it sees HTTP traffic, but it does not see the vault key and cannot decrypt the blocks.
  • Stripe Payments Europe, Ltd., Ireland. Payment processing and invoicing. Card data never passes through our servers.
  • Google Ireland Ltd. Transactional email.

We do not sell, rent or exchange data with anyone. We have no advertising partners.

Transfers outside the European Economic Area

Cloudflare and Stripe may process data on servers in the United States. Transfers rely on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU-US Data Privacy Framework. Encrypted blocks remain unreadable wherever they end up.

How we protect the data

  • Encryption on your device with AES-256-GCM, before transmission.
  • Keys derived with Argon2id, 64 MiB of memory and 3 iterations.
  • TLS 1.3 connections, with HSTS enabled.
  • Integrity of every block verified with SHA-256 on each download.
  • Blocks stored outside the server's public area, accessible only through the application.
  • A cryptographically chained audit log, in which retroactive modification is detectable.
  • Administrative access limited to metadata, impossible for content, with an automatic email to you if an administrator accesses your account for support.

We hold no ISO or SOC certifications and do not claim to. If we obtain one, we will publish it together with the attesting document.

No tracking

We use no Google Analytics, no tracking pixels, no advertising cookies, and we build no profiles. We honour the Global Privacy Control signal. Details about strictly necessary cookies are in section 16, on cookies.

How long we keep data

Account data for as long as you have an account. On deletion we first destroy the wrapped key, which makes content unrecoverable instantly, and blocks are physically deleted within 7 days. Accounting records are kept for 10 years as required by law. Access logs, 12 months.

Your rights, in brief

You have the rights set out in the General Data Protection Regulation, detailed together with how to exercise them in section 15, below.

Minors

The service is intended for people over 18. We do not create accounts for minors and do not knowingly collect data about them.

Changes

If we change this policy in a way that affects you, we notify you by email 30 days in advance.

Contact

gdpr@amprentadigitala.ro.
We are not legally required to appoint a data protection officer and have not appointed one. Requests are handled directly by the association's management.

Your GDPR rights

Send your request to gdpr@amprentadigitala.ro from the email address on the account. We reply within 30 days at most, but aim for 5 working days. No fees. If the request comes from another address we will ask for confirmation from the account address, so that we do not hand your data to someone who is not you.

Right to be informed

What data we process, why, on what legal basis and for how long. Written out above, in this policy, without circular references.

Right of access

We send you a copy of everything we hold about you: account data, subscriptions, activity log, sessions, and the file list with sizes and dates.

Right to rectification

You can correct your email address and billing data. File names, tags and notes can only be corrected by you, from within the account, because they are encrypted and we cannot read them.

Right to erasure

We delete the account on request. We first destroy the wrapped key, which makes the content mathematically unrecoverable on the spot, including for you. You receive a deletion certificate. Encrypted blocks disappear from disk within 7 days.

Legal exceptions: accounting records for payments are kept for 10 years, and the audit log remains but contains only identifiers and timestamps, never content.

Right to restriction of processing

You can ask us to freeze processing while a dispute is clarified. In practice this means we suspend the account without deleting anything.

Right to data portability

We give you an archive with all your data, in an open format. You should know one particularity of the architecture from the outset: your files are delivered encrypted, exactly as we hold them, together with the documentation needed to decrypt them with your password. We cannot deliver content in the clear, because we do not have it in the clear.

Right to object

You may object to processing based on our legitimate interest, that is the access logs kept for security. If you object, we cannot operate the service safely, so objection amounts to closing the account.

Right not to be subject to automated decisions

We make no automated decisions with legal effect on you and do no profiling. The only automatic process affecting your data is the deletion of files when you exceed purchased space, described with figures in terms, section 8, preceded by five notices.

What we cannot do, however much you insist

We cannot recover your password. We cannot open the vault without your password or recovery code. We cannot read, verify or restore content. We cannot give a third party access to your vault, not an heir, not an authority. This is not a policy choice, it is a mathematical impossibility.

If you are not satisfied with our answer

You may contact the Romanian National Supervisory Authority for Personal Data Processing, B-dul General Gheorghe Magheru 28-30, sector 1, Bucharest, or via www.dataprotection.ro. You also have the right to go to court.

Cookies and local storage

Why you do not see a cookie banner

Because we do not need your consent. We use no tracking cookies, no third-party analytics, no advertising pixels, and we build no profiles. Cookies strictly necessary for the service to work do not require consent under the law.

A banner asking permission for something we do not do would just be one more useless window.

What we use, exactly

  • Session cookie. Keeps you signed in between pages. Deleted when you close the browser or sign out. Strictly necessary.
  • Form protection token. Prevents requests being submitted on your behalf from other sites. Lasts as long as the session. Strictly necessary.
  • Language preference. Remembers whether you chose Romanian or English, so we do not route you by country on every visit. Lasts 12 months. Strictly necessary.

All are first-party cookies, marked HttpOnly, Secure and SameSite=Strict where applicable. None contains personal data in the clear, and none contains your password or vault key.

What we keep in your browser's storage

  • The search index, encrypted. Because the server cannot search your data, search runs on your device. The index is encrypted with your vault key.
  • The state of unfinished uploads. So you can resume an interrupted file without starting over.

The vault key is never saved in cookies, in local storage, or anywhere else. It lives only in the page's memory, for as long as the page is open. That is why we ask for your password again when you reload the page. It is intentional.

How to control them

You can delete or block cookies in your browser settings. If you block the session cookie you cannot sign in, because we have no other way of remembering that it is you. If you clear local storage you lose only the search index and unfinished uploads, not the data in your vault.

We honour the Global Privacy Control signal sent by your browser, although, not using tracking, we have nothing to switch off.