Back to homepage

Security & GDPR

An honest and complete account of how we handle your files, your account data and the data of the people who receive your downloads.

GDPR-compliant Storage in the EU (Amsterdam) TLS 1.3 in transit AES-256 at rest

Where are my files stored?

The specific location, the supplier, and how long they stay there.

Object storage

Files are stored on Backblaze B2, an S3-compatible object storage service in a European data centre (Amsterdam, the Netherlands). Backblaze is a US company, but our storage bucket is physically located in the EU and falls under European data sovereignty rules.

Your files are not stored or replicated outside the EU — they stay in the bucket in Amsterdam. When a recipient opens a download link, the bytes come straight from that bucket to their browser: the short-lived signed link in the address is the only access. The website itself runs on Cloudflare's network; for the file bytes that detour is off and exists only as a reserve for large volumes.

Separate from your files: if you use one of our AI features, such as the weekly summary in the planning tool, we send the data you supply for it — and, for features that read a document for you, also the contents of that document — to Anthropic in the United States. We keep the response for at most thirty days, so the same question does not have to be asked twice. If you copy that response into something you keep yourself, it remains until you delete it.

Retention

For each upload you choose how long the link remains valid: 1, 3, 7, 14, 30, 60 or 90 days, or 'valid indefinitely'. On a free account 30 days is the maximum; 60 days, 90 days and 'indefinitely' belong to a paid plan or the one-off Pro trial, and on such a plan you can extend a package afterwards — via 'edit' or via the API — to up to 365 days. If the administrator of your business workspace has set their own maximum, that always takes precedence, even over 'indefinitely'. After this period, the files are physically deleted from the servers — not merely made inaccessible. A clean-up task sweeps through every few minutes, with an additional nightly check as a safety net. Along with the files, the package details, the recipients' email addresses and, as a rule, the download log of that package (time, IP address and browser of whoever downloaded) disappear too. Log entries containing an IP address that outlive the package — visits to the download page, blocked download attempts and download logs left behind during clean-up — are in any case kept for a maximum of 365 days. A link you have revoked yourself is not cleaned up automatically, so that you can undo it.

When a visitor opens an expired link, they see a tidy "expired" page. From that moment on, the site no longer issues any new download links, and nothing is left behind in a cache: our download proxy deliberately keeps no copies of files. One thing worth knowing: a direct download link fetched just before the expiry date remains valid until its own lifetime runs out — five minutes for a single file, up to six hours for "Download all" — and a download that has already started is allowed to finish. If you want a wrongly sent file shut down immediately, delete the package under "My uploads": we then remove the files from storage straight away, after which even a link already handed out yields nothing.

How are files protected?

Encryption, authentication and access control — specific, no marketing nonsense.

ComponentImplementation
Transport encryption TLS 1.3(forced HTTPS, HSTS enabled, no TLS 1.0/1.1 allowed)
Encryption at rest AES-256 server-side encryption on the object storage
Download links Random token of 16 hex characters (64 bits), generated with secrets.token_hex(8). Older links with a 10-character token remain valid. The token is the access; in addition, a password and email verification of the recipient can be enabled per package.
Password hashing scrypt (n=32768, r=8, p=1) with a random salt per password. We store only the hash, never the password itself.
Password-protected downloads Optional per package. The password is hashed separately and checked server-side
Rate limiting Download and upload links: 30 failed attempts (unknown link or wrong password) per minute per IP, then no access for 5 min. Downloading and viewing online: each max. 60 times per minute per link + IP, then a 10 min pause. Logging in: 5 failed attempts per 5 min per IP, then locked for 15 min, plus a more generous counter per account.
Audit log All login events, password changes and account actions are logged with IP address and timestamp
CSRF protection Token-based on all state-changing endpoints
Session cookies HttpOnly, Secure, SameSite=Lax

Who can access my files?

The access model explained — who has technical and organisational access.

Your team

Users on your account (your subdomain) have access to:

By default that overview shows the last 30 days and can be set from 1 to 365 days; the CSV export of one specific package contains the full download history of that package. Download and visit data containing an IP address is retained for a maximum of 365 days, after which it is erased automatically. The CSV export of the audit log also contains IP addresses: these are the login and account events of your own users, not of recipients. Bear this in mind when handing out administrator rights — an administrator can view the recipients of all colleagues on the account, not only those of their own packages.

Users of a different account (another Downloadlink customer) cannot see your files or packages. This does not work with a separate database per customer, but with a single database in which every package, file and piece of data is tied to the account that created it. Every query filters on that — including when editing and deleting, where we additionally check that the package really is yours. Guessing an id therefore gets you nowhere. What you share yourself is a different matter: anyone who has a download link from you can open that package — that is precisely what such a link is for.

One thing works differently, and we would rather tell you about it: if you use the AI features in the planning (the AI week overview and the AI planning proposal), we temporarily store the generated text in a cache that is not partitioned per account; anything older than 30 days is cleared out. A stored answer only comes back for exactly the same input — the same week, the same names, the same hours — so in practice only for your own planning. Your files and packages do not appear in it.

We (Downloadlink)

Technically, Downloadlink's administrators — currently one person — have access to:

We are not in your files for any purpose other than that: no analytics on the content, no reselling. One exception, and it always starts with an action — by you, or by someone to whom you send a document for review. When an AI feature is used (the covering note with a package, the AI text check, recognising a scan (OCR), and in a business environment also the quotation assistant, the checking of calculations and the Word suggestions in a review), the content needed for it goes to Anthropic (Claude), with processing in the United States. Under Anthropic's terms, what we send via the API is not used to train AI models. We ourselves keep nothing extra from those features: the text check and scan recognition store nothing, and what the AI writes belongs to the piece it was made for — a covering note disappears with the package, a quotation with the quotation. Only the AI assistance in the planning (weekly summary and scheduling suggestions) has a cache: that response is kept by us for a maximum of 30 days. If no one touches an AI feature, nothing from your files goes to an AI party. This is set out in black and white in the privacy statement.

Sub-processors

To run the service we engage these sub-processors:

That last one differs from the other four and deserves explanation. If you switch on Cover note (AI) when sending, the names of your files are sent along plus up to three PDFs from the package — small files in full, only the first pages of large ones. If you have a scan read out in the PDF tools (OCR), the image of that page is sent along. If you use the AI assistance in the planning tool (weekly summary or planning proposal), the weekly figures are sent along: names of employees, their discipline and their hours. And in the business environment with document review, the pages to be reviewed or the text taken from them are sent along. If you use no AI feature at all, nothing goes to Anthropic and your content does not leave the EU.

This is a transfer outside the EU. The same safeguards apply as for the other sub-processors — a data processing agreement with EU model clauses — and under Anthropic's commercial API terms your data is not used to train AI models. We ourselves keep only the result, not what we sent: a covering letter belongs to the package and disappears with it on the expiry date; we keep nothing from a scan that has been read; AI answers for the planning go into a cache that we keep to 30 days — with each new AI answer we delete whatever is older.

There are also parties that are independent controllers — they process data under their own privacy terms, not on our behalf:

We conclude a data processing agreement with all of these parties. For your own records we can send you a data processing agreement between Downloadlink and your company —request one via contact.

What do we do — and what do we not do?

Managing expectations. No false promises, no concealed shortcomings.

What we do:

What we do not (yet) do:

GDPR: rights of data subjects

How you handle data requests from your customers to you (and your requests to us).

As the controller for your customer communications, you have rights and obligations under the GDPR. What we do to help you:

For requests that are not self-service: email Patricklankhorst@hotmail.com. We respond within 5 working days, well inside the GDPR limit of 30 days.

Data breach procedure

What if something goes wrong — our duty and yours.

If a security researcher finds a vulnerability, or if we detect a data breach, we:

Security researchers can report vulnerabilities safely via the address in security.txt(RFC 9116).

Questions about security?

For IT coordinators, procurement or compliance people: ask your questions directly.

Mail security@

For responsible disclosure: see security.txt