Privacy Policy
How we handle your data and the files shared via downloadlink.nl.
Version: 1.1 • Last updated: 29-07-2026
1. Who are we?
downloadlink.nl is responsible for the processing of personal data as described in this statement. For questions you can reach us via Patricklankhorst@hotmail.com.
2. What data do we process?
About you as a customer:
- Contact details: name, email address, company name (via the request form).
- Account and payment data: customer number, chosen plan, payment transaction data via Mollie/PayPal (no credit card numbers).
- Usage data: log files, IP addresses, browser information, file uploads.
- Planning data: if you use the planning module, we process data about your staff — name, discipline, contracted hours, scheduled and available hours, and for hours booked outside the planning also the project and who worked on it. For the AI assistance in the planning, part of this goes including names to Anthropic in the United States: the AI weekly overview sends that data automatically shortly after you open the planning, even if you do not use the AI button; the AI planning proposal only when you ask for it. We keep the AI's response for a maximum of 30 days, so the same question does not have to be sent again. See point 6 for the recipients and the safeguards outside the EU.
- Communication: emails or support requests.
- Data you enter about others yourself: the email addresses of the recipients you send a link to, your address book (email address and name) and the names of team members you link to your account. We use the recipient addresses to send your link, to show you the status per recipient and to send any reminders; the sending runs via our email provider (see point 6). We do not use your address book or your team members for anything else. If colleagues share a single login, we keep the personal address book separate per person; a team account additionally has a shared address book that is deliberately visible to everyone on that account. You decide who you write to; we process this data on your instructions. Recipient addresses remain for as long as the package exists: if it expires or you delete it, they go with it. Your address book and your team members remain until you erase them or delete your account.
- Verification of recipients: if you switch on the verified-recipient option for a package, we send that recipient a code by email. In doing so we keep their email address, the IP address from which the code was requested and confirmed, and the time of confirmation. We do not keep the code itself, only an irreversible encrypted imprint with which we can check a code that is typed in. This is precisely the proof you switch the option on for: in your overview you can see per recipient whether and when they verified themselves, and the proof of delivery (pdf) also states the IP address. Codes that are not used are erased 7 days after they expire; the rest disappears together with the package.
- Advertising attribution: if you arrived via a Google advert, we store the click ID (gclid) and the time to measure which advert works. While your sign-up is in progress, that click ID sits in the same record as your email address and IP address; we delete that record no later than seven days after the sign-up has been completed or has expired. After that, only the click ID and the time remain, without an email address, and we export that manually to Google Ads; after 90 days we delete that too. We set no cookies for this and load no third-party advertising or tracking scripts: during your visit, our own page code remembers the click ID in your browser's session storage, and that disappears as soon as you close the tab.
About the people you share with — recipients, signers, submitters and visitors to a portal. We record this data as a result of your use of the service, and you largely see it yourself: together it forms the proof that something arrived or was signed. To that extent we act on your instructions — so inform your recipients about this yourself. In addition, we use the same records to keep the service secure and available (abuse and overload detection); for that we are responsible ourselves.
- Download records: for everyone who opens a download page or retrieves a file, we record the date/time, IP address and browser information. As the sender, you see the downloads in full — including the IP address — on your package's activity page, in the CSV export, on the proof of delivery (PDF) and via the API. We keep these records for a maximum of 12 months.
- Recipients' email addresses: if you send a package by email, we store to whom, when this first happened and when it last happened (in the case of a reminder). The address and the first send also appear on the proof of delivery. Disappears as soon as the package itself is gone.
- Verification by email code: if your package has a code on it, we keep the email address, the time and the IP address of the recipient who requested and entered the code. A successful verification (address, time, IP) appears on the proof of delivery — that is its compliance value. Disappears as soon as the package is gone; a code that was never used, no later than 7 days after it expires.
- Signing: for a signature request we record the signer's name, email address, time, IP address and device/browser. These are printed on the signing certificate in the PDF document itself — that is what gives the signature its evidential value. You can withdraw an outstanding request; the request then remains in your overview and disappears with your account.
- Submissions via an inbox link: name, email address, message and IP address of the person uploading files to you. A submission that was never completed is erased after 48 hours. A completed submission remains in your overview — even if you revoke the link — and disappears with your account.
- Visits to a client portal or data room: for each view and download, the time, IP address and browser information, visible to the owner of the portal. A maximum of 12 months.
- Blocked download attempts: if a download is stopped because a download limit has been reached, we record the reason, the IP address and the browser information. We do this to detect abuse and overload; the administrator of your workspace can see it in the insights dashboard. A maximum of 12 months.
3. What do we use this data for?
- Performance of the agreement (hosting & file exchange, invoicing, support).
- AI functions in the service: the cover letter the recipient sees with your package, text recognition of a scan (OCR), the automatic reading of receipts and invoices you import into the bookkeeping module, and, in the weekly planner, the weekly summary and the scheduling proposal. The relevant content is sent to our AI processor Anthropic in the United States: the file names and part of the contents of your package, the scanned page, the receipt or invoice, or planning data with names, disciplines and hours (see point 6). This happens as soon as you use the function; in addition, the weekly summary is prepared in advance shortly after you open the planner, even without you asking for it. We keep nothing from a scan, the cover letter belongs to the package and disappears with it, what the AI reads from a receipt ends up in your own records, and the weekly summary and the scheduling proposal are kept in a temporary cache that is cleaned up whenever a new AI result is added — anything older than 30 days is then removed.
- Security and availability of the service (monitoring, abuse detection).
- Legal obligations (administration, tax rules).
- Contact and customer service.
- Download statistics for the sender (knowing whether and when a package was collected).
- Measuring which ad or entry point led to a sign-up (aggregated, cookieless).
4. On what legal bases?
- Performance of an agreement (service provision and payments).
- Legal obligation (record-keeping requirement).
- Legitimate interest (security, abuse prevention, business communication).
5. How long do we keep data?
We do not keep personal data longer than necessary. Administrative and invoicing data: 7 years (statutory retention obligation). Account and usage data: no longer than 12 months after the service ends, unless a longer period is required by law.
In concrete terms: files and packages disappear automatically on the expiry date chosen by the sender. If you delete your account, it is deactivated immediately and your download links stop working straight away. Within 30 days we permanently erase your files and account data; only invoicing data (7 years, statutory retention obligation) and security logs remain. Your data then disappears from our daily database backups within 14 days: these are kept on our server at Render and as a copy at Backblaze B2, expire automatically and are used solely to recover after an outage. Usage and visit data containing date/time, IP address and browser information — downloads and view-in-browser, blocked download attempts, visit statistics, visits to a shared folder, sent notifications and linked devices — we retain for a maximum of 12 months, advertising-attribution data for 90 days, and security logs (who logged in and when) for a maximum of 12 months.
Some of the data is inextricably tied to a delivery, a signature or a submission. These have no fixed retention period: they remain for as long as the package, the document or your account exists. This applies to:
- Review records for a file shared for review — who opened it and when, with IP address and browser information. This is the evidence that a review actually took place, so we do not clear it after 12 months. It disappears as soon as you delete the package, and when you delete your account.
- Verifications with an access code — the email address and IP address of a recipient who entered a code. This is needed for the proof of delivery and remains as long as the package exists; for a package without an expiry date, therefore, until you delete it yourself. Codes that no one has used are erased 7 days after they expire.
- Signing records — for a digitally signed document we record the signer's IP address and browser information. These belong to the signature and are retained for as long as your account exists. Withdrawing a request or letting it expire only changes the status; it does not delete this data.
- Submissions via an upload link — for a completed submission we store the submitter's IP address, so that the submission remains visible to you. That data remains for as long as your account exists. Submissions that stall partway through disappear automatically after 48 hours.
If you use the planning tool, our AI assistant automatically creates an AI weekly overview shortly after you open it, and a planning proposal at your request. We keep that output — including the names it contains — for a maximum of 30 days in our own database, so that if the data is unchanged, a new text does not have to be fetched from our AI supplier each time; after that we clear it. This output does not belong to a package and therefore does not disappear along with it when a package expires; an AI covering letter does belong to that package and disappears together with it.
6. Who do we share data with?
We engage these sub-processors — they process solely on our instructions, under a data processing agreement:
- Render — application hosting. The public downloadlink.nl service (application and database) runs in Frankfurt (EU). We back up the database every night; we keep those backups for 14 days, on the server itself and as a second copy in the object storage below. A bespoke environment on its own subdomain may, by agreement with that customer, run in another region, including outside the EU; this is then recorded with that customer and never applies to the public service.
- Backblaze B2 — object storage of your files (EU Central, Amsterdam).
- Brevo — transactional email (welcome, notifications, password reset).
- Cloudflare — the network and security layer in front of the website (CDN/DDoS protection) and the pass-through for downloads: the files themselves also travel via their network to the recipient, through the server closest to them — and that server may be outside the EU. The files are not stored and not cached in the process. Uploading a package goes directly from your browser to the storage; smaller files that you upload within the app itself pass through Cloudflare on the way in as well.
- Anthropic (United States) — the AI behind our AI features. Transfers outside the EU take place under EU standard contractual clauses. Below you will find, per feature, exactly what is sent.
What goes to the AI? Only what the function in question needs, and only for these three functions:
- Covering letter — the tick box when uploading. What is sent: the names of all the files in the package, plus a few of the smallest PDFs from it, truncated to their first pages. The text that comes back is stored with your package and disappears together with that package.
- Recognise a scan (OCR) — the page itself is sent as an image. You get the text back immediately; we keep none of it.
- AI assistance in the planning tool — the weekly overview and the proposed work distribution. What is sent: the names of employees, their discipline, their free and booked hours, and the project numbers, service names and hour-type names they work on. Please note: the weekly overview is prepared in advance shortly after the planning tool is opened, so even without you clicking on it. We keep the answer in a cache for a maximum of 30 days, so that the same question does not have to go to the AI a second time.
Outside these features, nothing of yours goes to the AI: files you simply send are not read by an AI.
In addition, the following parties are independent controllers; they process under their own privacy terms:
- Mollie and — for existing subscriptions —PayPal, for processing payments.
- Google, Microsoft of Facebook, if you choose to "sign in with" one of these accounts. They will then see that you are signing in with us; we receive from them your email address and whether they have verified that address (Facebook also sends along your name and user ID, which we do not store). We never see your password with that party. If you do not yet have an account with that email address, a trial account can be created with it straight away. You can see which of these buttons are enabled on the login page.
- Google, if you arrived via a Google advert: cookieless conversion measurement in which we pass on only the click ID, the time and the name of the step (for example "trial account created"), so no name or email address. We retain that data for 90 days.
We never sell your data and use no advertising or tracking cookies.
With the AI functions, data is processed outside the EU. On downloadlink.nl this concerns the cover letter you can tick when sending, and the recognition of text in a scan (OCR) in the PDF tools. On business environments where we offer them, this is joined by the weekly overview and the scheduling proposal in the planner, plus the checking of submitted documents, the quotation assistant and the text suggestions in a Word document.
What is sent along is what the feature needs: for the covering note, the names of the files in your package and the first pages of at most three PDFs from it; for OCR, the image of the page you have recognised; and for the planning, the names of employees, their discipline and their hours. That data goes to Anthropic in the United States, which processes it solely on our instructions, under a data processing agreement and with EU standard contractual clauses for the transfer. This only happens when you use such a feature; if you do not use it, your files and planning data are not submitted to an AI.
We keep the output of the planning AI for a maximum of 30 days in a temporary cache, so that the same overview does not have to be recalculated each time. For the other parties mentioned above, too, where they process outside the EU we ensure appropriate safeguards such as EU standard contractual clauses.
7. Cookies
We use functional cookies only — no advertising, analytics or tracking cookies, and therefore no cookie banner either. Here are all three of them:
- A session cookie to keep you logged in. In it we also store the security token that protects forms against abuse (CSRF); so that is not a separate cookie. The cookie disappears as soon as you log out, and expires after 12 hours in which you do not use the site. If you are not logged in, it disappears as soon as you close your browser.
- A language cookie (
dl_lang, 180 days) that we only set if you choose a language yourself, so that the site opens in that language straight away next time.
- A device cookie (
mt_device_id, around 2 years, renewed on each visit) that we set as soon as you open the planning. It remembers who works on that device, so that changes are linked to the right person — necessary because colleagues often share a single login.
In addition, we store a few preferences in your browser's local storage, for example which person you are in the planning tool and the email address on which you want to receive notifications. This is not a cookie: that data stays on your own device, is not automatically sent to the server and is not used for tracking. You can erase it by deleting the site data in your browser.
8. Your rights
You have the right to:
- Request access to your personal data.
- Request correction or erasure.
- Object to processing or request restriction of it.
- Request data portability.
- Lodge a complaint with the Dutch Data Protection Authority.
You can send requests to Patricklankhorst@hotmail.com. We respond within 30 days.
9. Security
We take appropriate technical and organisational measures to protect personal data against misuse, loss, unauthorised access, unwanted disclosure and unauthorised modification.