This is a translation of the Dutch privacy statement. If the two versions differ, the Dutch text prevails.
1. Who is responsible for your data
PassTransfer is a service of Kobalt Digital B.V.
| Item | Value |
|---|---|
| Controller | Kobalt Digital B.V. |
| Address | Koelmalaan 350, Unit 3.08, 1812 PS Alkmaar, the Netherlands |
| Chamber of Commerce number | 68839383 |
| VAT number | NL857613947B01 |
| Phone | +31 (0)72 210 0600 |
| E-mail, also for privacy questions | hello@passtransfer.com |
| Data protection officer | Not appointed. For an organisation of this size with this kind of processing, that is not required (art. 37 GDPR). |
2. When this statement applies
PassTransfer can be used in two ways, with a different division of roles.
The free service. You share a password through a one-time link, without an account. For the data that arises in doing so, we are the controller. This statement applies to that data.
PassTransfer Pro. You have an account and your own workspace on a subdomain. For your customer data (account details and billing) we are the controller, and this statement applies. For the content that you and your staff share through that workspace, you are the controller and we are the processor. We offer a data processing agreement for that: e-mail hello@passtransfer.com and we will send it to you.
The terms and conditions are separate, at /en/terms-and-conditions.
3. What we process, why, and for how long
3.1 Sharing a password (the free service and Pro)
We store the content you share in encrypted form, plus the moment the link expires.
Your browser encrypts the content before it reaches us. The key sits behind the # in the link
and is never sent to a server by browsers. So we cannot read that content.
The content you share may contain personal data. You decide that, not us.
- Purpose: transferring a secret once, encrypted, to a recipient you choose.
- Legal basis: performance of the agreement with you (art. 6(1)(b) GDPR), namely delivering the service you request.
- Retention: until the moment of retrieval, or until the expiry time you choose yourself (1 day, 1 week or 1 month), whichever comes first. After that we erase the content, the sender's name and the encryption data from the database. This happens immediately on retrieval, and on expiry through a task that runs every five minutes. What remains is an empty row with the link key and a timestamp, so we can count how many links have been used. The content can no longer be derived from it.
- We do not ask for: an e-mail address, a phone number, or the identity of the recipient. The sender's name is a free field that you fill in yourself and that may stay empty.
3.2 Your PassTransfer Pro account
For a Pro subscription we process: name, e-mail address, company name, address, postal code, city, country, and optionally the VAT number. In addition, an encrypted password, your language preference, and references to your customer number at our payment provider and our bookkeeping.
- Purpose: providing the account and your own workspace, and invoicing the subscription.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR) for the account, and a legal obligation (art. 6(1)(c) GDPR, art. 52 of the Dutch General Tax Act) for the invoice data.
- Retention: we keep invoice and bookkeeping data for seven years, because the fiscal retention obligation requires it. When your subscription expires or you cancel it, the account loses its access within minutes and is taken out of the active records. Six months after the end of the subscription we erase the account data that does not have to be kept for tax purposes, unless you submit an erasure request earlier yourself.
- Required or not: this data is needed to enter into a subscription and draw up an invoice. Without it we cannot deliver Pro. The VAT number is optional.
3.3 The branding of your workspace
Pro customers can set a logo, a background image and colours.
- Purpose: showing your house style in your workspace.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR).
- Retention: we remove these files from our storage at the moment we erase your account data: at your request, or after the period in 3.2.
- Please note: these images are publicly retrievable as soon as they are set, because they are shown to every visitor of the workspace. So do not upload an image you do not want to be public.
3.4 E-mail about your subscription
We send e-mail when a subscription starts, when a payment fails, on cancellation and on resumption, and when you request a password reset.
- Purpose: informing you about your subscription and your account.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR).
- We send no newsletter and no marketing mail. So there is nothing to unsubscribe from either.
- Retention: the delivery logs of our mail provider follow that provider's own period; we do not keep the content of these messages ourselves.
3.5 Error tracking
When something goes wrong in the application, we send an error report to Flare, a service of Facade BV (Spatie) in Belgium. That report contains technical data: which page, which error, and which queries were executed.
- Purpose: finding and fixing errors, and keeping the service secure.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR), namely a working and secure service. We have weighed that interest against your privacy and shaped the report accordingly: no data that could identify you goes along, and no content of what you share. That way it never becomes more than technical error information.
- What we deliberately leave out: the visitor's IP address does not go along. The values from
database queries do not go along. Passwords and the encrypted content of a shared link do not go
along. The link key is replaced by
[key]in the report, so an error report can never give access to a shared secret. - Retention: Flare keeps the data in an error report for at most 40 days and deletes it after that.
3.6 Server logs
Our web server records which requests come in, with IP address, time and the requested page.
- Purpose: security, detecting abuse and investigating outages.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR).
- Retention: our hosting provider keeps the access logs for 24 days. After that they are summarised into aggregate statistics from which no individual visitor can be traced. Back-ups are kept for 14 days.
4. Cookies and storage on your device
We use no tracking cookies, no analytics, and no advertising pixels. There is not a single third-party script on this site. Even our fonts are served from our own server, so your IP address does not end up with an external party when you open the site. That is pinned down in an automated test, so it cannot accidentally come back.
What we do place is strictly necessary to make the site work:
| Name | Kind | What for | How long |
|---|---|---|---|
passtransfer_session |
cookie | remembering your session within a visit | 2 hours |
XSRF-TOKEN |
cookie | protection against form abuse (CSRF) | 2 hours |
passtransfer_lang |
cookie | remembering your language choice | 1 year |
passtransfer_lang |
sessionStorage | the same language choice within the tab | until you close the tab |
info |
localStorage | remembering that you have already seen the explanation, so it does not open every visit | until you clear it |
No consent is needed for these five, because they are necessary for a service you asked for yourself (art. 11.7a(3) of the Dutch Telecommunications Act). That is also why you see no cookie banner on this site: there is nothing to choose, because there is nothing you would want to refuse.
5. Who else receives your data
We do not sell your data and do not share it for commercial purposes. The following parties process data for us, on our instructions.
| Party | What for | Where |
|---|---|---|
| Shock Media B.V. | hosting of the application, the database and the uploaded branding images | the Netherlands |
| Mollie B.V. | handling payments | the Netherlands |
| Moneybird B.V. | invoicing and bookkeeping | the Netherlands |
| Facade BV (Flare, Spatie) | error tracking | Belgium |
| Google Ireland Limited (Google Workspace) | sending and receiving e-mail | Ireland, with the United States as fallback |
With Shock Media, Mollie and Moneybird we have concluded a data processing agreement. With Flare and Google Workspace the data processing agreement is part of the standard terms under which we use those services.
6. Transfers outside the European Economic Area
Our hosting, database, back-ups, payments, bookkeeping, file storage and error tracking stay within the European Economic Area.
For e-mail we use Google Workspace. Google Ireland Limited processes those messages within the EEA, but may involve Google LLC in the United States for that. That transfer rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework of 10 July 2023, under which Google LLC is certified. You can verify that at dataprivacyframework.gov/list.
7. How we secure your data
- A shared password is encrypted in your browser with AES-128-GCM. The key sits in the part of the
link behind the
#and never reaches our server. So we cannot read the content, even if we wanted to. - A shared secret can only be retrieved once. We claim the row in a single database operation, so two simultaneous attempts cannot both succeed.
- After retrieval or expiry we erase the content from the database.
- On the retrieval page we send the browser no
Referer, so the link (and with it the secret) cannot end up in another site's logs. - The whole site runs over HTTPS, with HSTS.
- Account passwords are stored as bcrypt hashes, never readable.
- We limit the number of login attempts and the number of retrieval attempts per IP address.
- An uploaded logo in SVG format is sanitised before we store it, so it cannot contain scripts.
- We apply a Content-Security-Policy that only allows our own domains.
No measure is a guarantee. If you think something is wrong with the security, e-mail
hello@passtransfer.com. We respond within five working days. Give us the chance to fix it before
you publish it, and do not access other people's data; then we will not take legal action against
you. The same agreement is in /.well-known/security.txt.
8. Your rights
You have the right to:
- Request access to the data we hold about you (art. 15 GDPR).
- Have incorrect data corrected (art. 16 GDPR).
- Have your data erased (art. 17 GDPR).
- Have the processing restricted (art. 18 GDPR).
- Receive your data in a common file format, or have it transferred (art. 20 GDPR).
- Object to processing based on our legitimate interest (art. 21 GDPR), namely the error tracking and the server logs.
If you have a Pro account, you can carry out two of these yourself, without e-mailing us: in your account settings you download all your data as a file, and you submit an erasure request. We carry out an erasure request as soon as the subscription has ended, because until that moment we need the data to perform the agreement. What happens then: your name, e-mail address, company details, password and the references to our payment provider and bookkeeping are erased, your workspace and the uploaded images are removed, and only the invoice lines remain for the fiscal retention obligation.
For the other rights, or if you have no account, e-mail hello@passtransfer.com. We respond within one month. If a request is complicated, we may extend that period by two months, and we will let you know within that first month. We ask you to send your request from the e-mail address of your account, so we know it is you. We do not ask for a copy of your passport. A first request is free.
For a shared password we cannot carry out an access request, and that is deliberate: we do not have the key, so we cannot show the content. If you want to undo a shared link, open it once yourself. That uses it up and the content is erased.
If you are not satisfied with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl.
9. Consent
We base no processing on your consent. So there is nothing to withdraw either. If that changes (for example because we ever add analytics or a newsletter), we will ask for it separately, and you will be able to withdraw that consent at any moment as easily as you gave it.
10. Automated decision-making
We take no decisions about you based on automated processing, and we build no profiles.
11. Minors
PassTransfer is meant for business use and is not aimed at children. We do not knowingly process data of persons under 16. If you think we do anyway, e-mail us and we will delete it.
12. Changes
We may amend this statement. The current version is always on this page, with the date of the last change at the bottom.