Legal

Data Processing Agreement

Processor terms that apply when your organization stores personal data in InfiniDrive.

Effective 9 August 2026

1. Scope and roles

This DPA supplements the Terms of Service whenever a customer acts as controller of personal data contained in uploaded content and InfiniDrive processes that data on the customer's behalf. For account, billing, and security data that InfiniDrive needs for its own operations, InfiniDrive remains an independent controller under the Privacy Policy.

2. Nature and purpose of processing

The subject matter is hosted file storage: receiving, storing, versioning, sharing, recovering, and deleting customer content for the duration of the contract. Data subjects may include the customer's employees, clients, and any persons represented in uploaded files. Categories cover whatever the customer chooses to upload — identifiers, contact details, documents, media, and metadata.

3. Documented instructions

InfiniDrive processes customer content only on documented instructions — expressed through this agreement, product configuration, and lawful written requests — unless applicable law requires otherwise, in which case InfiniDrive informs the customer where legally permitted. The customer is responsible for the lawfulness of its instructions and for informing its own data subjects.

4. Security measures

Personnel with production access are bound by confidentiality. Technical and organizational measures include role-based access control, TLS 1.3 transport encryption, RAID-backed storage redundancy, continuous monitoring, reviewed and versioned changes, and a documented account-deletion process. The Security page describes each control and its limits in detail.

5. Subprocessors

The customer grants general authorization for the subprocessors listed on the Subprocessors page. InfiniDrive imposes data-protection obligations on each of them and remains responsible for their performance. Material changes to the list are published in advance where reasonably practicable; customers who need direct notice can request it via [email protected].

6. Assistance and incident notice

Taking the nature of processing into account, InfiniDrive provides reasonable assistance with data-subject requests, security obligations, and impact assessments. A confirmed personal-data breach affecting customer content is notified to the customer without undue delay once sufficient facts are established.

7. Return and deletion

Throughout the contract the customer can export content through the product. Upon verified termination, InfiniDrive deletes customer content following the documented deletion process, unless law requires further retention. Records that InfiniDrive controls independently (billing, security) are handled under the Privacy Policy.

8. Transfers and audit information

Primary processing takes place in Europe. Where a listed provider may process limited data outside the EEA, a recognized transfer mechanism is applied where required. On reasonable written request, InfiniDrive provides the information necessary to demonstrate compliance with this DPA, subject to confidentiality and proportionality.

9. Contact

Questions about this DPA and requests for signed copies go to [email protected].