Data Processing Terms
This translation is provided for convenience. The English version is the authoritative text.
Last updated: September 8, 2026
These Data Processing Terms (the “Data Processing Terms”) form part of, and are incorporated by reference into, the Terms of Service (the “Terms”) between you and uploadthefile.com (“we,” “us”), which operates the websites, subdomains, and services offered under that name (the “Service”). They describe how we process personal data contained in the content you upload and configure, when we do so as your processor. Capitalized terms not defined here have the meaning given in the Terms.
1. Parties & roles
“Covered Content” means the files and content you upload to the Service, the personal data contained within them, and personal data collected from visitors through features you configure (for example, email addresses captured by an email-gate on a link or page you publish).
To the extent Covered Content contains personal data and data-protection law (such as the GDPR) applies to your use of the Service, you act as the controller of that personal data (or on behalf of, and with the authority of, a controller), and we act as your processor, processing it only at your request and on your instructions as described below.
Separately, and not as your processor, we act as an independent controller for the account, billing, support, security, safety, and analytics data described in our Privacy Policy, and for the safety and abuse-prevention processing described in Section 3. That processing is governed by the Privacy Policy and these Data Processing Terms, not by your instructions.
2. When these terms apply
These Data Processing Terms apply only to the extent the GDPR or a similar data-protection law applies to your use of the Service and you act as a controller (or for one). If you use the Service purely for personal or household activity, the GDPR’s household exemption generally means you are not acting as a controller, and these terms impose no controller/processor obligations on that use. Nothing here treats every user as a controller.
3. Processing we carry out as a controller
Some processing is carried out for our own purposes rather than on your instructions, namely to operate and secure the Service, prevent abuse, and comply with law. For that processing we act as an independent controller. It includes:
- account, billing, support, security, and analytics data, as described in the Privacy Policy;
- screening the URLs of uploads and links against Google Safe Browsing;
- automated moderation of images and sampled video frames for explicit content (advisory only: it flags a page for review and never blocks a publish);
- detecting child sexual abuse material (CSAM) using Cloudflare’s scanning tool, and making any legally required reports;
- re-screening the destinations of short links (Google Safe Browsing and urlscan.io);
- checking files for malware by submitting file hashes to VirusTotal;
- applying geographic access restrictions where required by law;
- activating a content feature (such as PDF chat) over a specific document when our support team does so at a user’s request or on review, rather than the content owner enabling it. Such activation is recorded in our admin audit log;
- handling abuse reports and carrying out moderation.
Our lawful bases for this processing are our legitimate interests in securing the Service and its users and preventing abuse, and compliance with our legal obligations.
4. Processing on your documented instructions
We process Covered Content only on your documented instructions, including those set out in these Data Processing Terms and the Terms. Your uploads, your configuration of features and sharing settings, and your API calls each constitute your documented instruction to host, store, process, and serve that content. We may also process where required by a law to which we are subject; in that case we will inform you of the requirement before processing, unless that law prohibits it on important grounds of public interest. If we consider that an instruction infringes data-protection law, we will tell you.
5. Confidentiality
We ensure that the people we authorize to process Covered Content are bound by appropriate obligations of confidentiality and process it only as needed to provide the Service.
6. Security measures
Taking into account the state of the art and the risks of processing, we implement appropriate technical and organizational measures under Article 32 of the GDPR, including:
- encryption of data in transit (HTTPS/TLS);
- storing IP addresses only in hashed form;
- access controls that limit who can reach Covered Content;
- HttpOnly and Secure session cookies;
- a validation pipeline that quarantines uploaded files and validates them before they are published; and
- audit logging of administrative actions.
Covered Content is not end-to-end encrypted. We hold it in a form we can read, which is what allows us to serve it, to apply the screening and moderation described in section 3, and to respond to abuse reports and lawful requests. Personnel access is limited under section 5 and administrative actions are logged. You should assess whether these measures are appropriate for the personal data you choose to upload, and encrypt content yourself before uploading if it requires protection we cannot provide.
7. Subprocessors
You give us general authorization to engage subprocessors to help provide the Service. We impose data-protection obligations on each subprocessor that are consistent with these Data Processing Terms. Our current subprocessors are:
| Subprocessor | Purpose | Processing location |
|---|---|---|
| Supabase | Database, file storage, and authentication | US / EU (region per deployment) |
| Cloudflare | Hosting, CDN, Workers compute, Workers AI inference (for the PDF-chat feature), image downscaling and video frame extraction for automated content moderation, CSAM scanning, and DNS/registrar | Global edge network |
| Google Safe Browsing | URL threat screening | US |
| urlscan.io | URL analysis | EU |
| VirusTotal | File-hash reputation (admin-triggered) | US |
The current list is also published, with a log of changes, at /subprocessors. We will update that page when we add or replace a subprocessor and give notice of the change. You may object to a new subprocessor by deleting the affected content or closing your account. Document conversion (Gotenberg) runs on infrastructure we operate ourselves and is not a third-party subprocessor. Our internal operations alerting tools, which notify our team of safety, billing, and deletion events, receive only minimal controller data (such as an account identifier and event type) and never Covered Content, so they are not Covered-Content subprocessors.
8. Assisting with data-subject requests
Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as this is possible, to respond to requests from data subjects exercising their rights. Where you are the controller and we receive a request that concerns your Covered Content, we forward it to you rather than respond directly, and we provide self-service export tools to help you meet these requests.
9. Personal-data breaches
We notify you without undue delay after becoming aware of a personal-data breach affecting Covered Content, and we provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR (security of processing, breach notification, and data-protection impact assessments), taking into account the nature of the processing and the information available to us.
10. Deletion & return of Covered Content
At the end of the provision of the Service, we delete or return Covered Content at your choice, and delete existing copies unless the law requires us to keep them. In practice you can delete Covered Content yourself at any time and export it using our tools; when you close your account we delete your content; and residual copies in backups are purged in the ordinary course.
11. Demonstrating compliance
We make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and these Data Processing Terms, on reasonable request.
12. International data transfers
We are established in the United Arab Emirates. Our subprocessors process personal data in the United States, the European Union, and on global edge networks (see Section 7). Where personal data is transferred across borders, we rely on appropriate contractual safeguards with the recipients and on the necessity of providing the Service you have requested.
13. Precedence
If there is a conflict between these Data Processing Terms and the Terms regarding the processing of personal data, these Data Processing Terms prevail to the extent of that conflict.
14. Contact
Questions about these Data Processing Terms? Email contact@uploadthefile.com.