This is a translation of the Dutch privacy statement. If the two versions differ, the Dutch text prevails.
1. Who is responsible for your data
PassTransfer is a service of Kobalt Digital B.V.
| Item | Value |
|---|---|
| Controller | Kobalt Digital B.V. |
| Address | Koelmalaan 350, Unit 3.08, 1812 PS Alkmaar, the Netherlands |
| Chamber of Commerce number | 68839383 |
| VAT number | NL857613947B01 |
| Phone | +31 (0)72 210 0600 |
| E-mail, also for privacy questions | hello@passtransfer.com |
| Data protection officer | Not appointed. For an organisation of this size with this kind of processing, that is not required (art. 37 GDPR). |
2. When this statement applies
PassTransfer can be used in two ways, with a different division of roles.
The free service. You share a password through a one-time link, without an account. For the data that arises in doing so, we are the controller. This statement applies to that data.
PassTransfer Pro. You have an account and your own workspace on a subdomain. For your customer data (account details and billing) we are the controller, and this statement applies. For the content that you and your staff share through that workspace, you are the controller and we are the processor. We offer a data processing agreement for that: e-mail hello@passtransfer.com and we will send it to you.
If a Pro customer closes their workspace, we also process e-mail addresses of that customer's staff, in order to determine who may sign in. For that we are the controller: we decide how that access control works and we send the login mail in our own name. What you need to know about it is in 3.7, and that processing therefore also applies to people who never created an account with us themselves.
The terms and conditions are separate, at /en/terms-and-conditions.
3. What we process, why, and for how long
3.1 Sharing a password (the free service and Pro)
We store the content you share in encrypted form, plus the moment the link expires.
Your browser encrypts the content before it reaches us. The key sits behind the # in the link
and is never sent to a server by browsers. So we cannot read that content.
The content you share may contain personal data. You decide that, not us.
- Purpose: transferring a secret once, encrypted, to a recipient you choose.
- Legal basis: performance of the agreement with you (art. 6(1)(b) GDPR), namely delivering the service you request.
- Retention: until the moment of retrieval, or until the expiry time you choose yourself (1 day, 1 week or 1 month), whichever comes first. After that we erase the content, the sender's name and the encryption data from the database. This happens immediately on retrieval, and on expiry through a task that runs every five minutes. What remains is an empty row with the link key and a timestamp, so we can count how many links have been used. The content can no longer be derived from it.
- We do not ask for: an e-mail address, a phone number, or the identity of the recipient. The sender's name is a free field that you fill in yourself and that may stay empty.
3.2 Your PassTransfer Pro account
For a Pro subscription we process: name, e-mail address, company name, address, postal code, city, country, and optionally the VAT number. In addition, an encrypted password, your language preference, and references to your customer number at our payment provider and our bookkeeping.
If you turn on two-step verification, we also store the key for your authenticator app and your recovery codes, both encrypted. That is optional: without two-step verification you sign in with your password alone. Turn it off again and we delete that key and those codes at that moment.
- Purpose: providing the account and your own workspace, and invoicing the subscription.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR) for the account, and a legal obligation (art. 6(1)(c) GDPR, art. 52 of the Dutch General Tax Act) for the invoice data.
- Retention: we keep invoice and bookkeeping data for seven years, because the fiscal retention obligation requires it. When your subscription expires or you cancel it, the account loses its access within minutes and is taken out of the active records. Six months after the end of the subscription we erase the account data that does not have to be kept for tax purposes, unless you submit an erasure request earlier yourself.
- Required or not: this data is needed to enter into a subscription and draw up an invoice. Without it we cannot deliver Pro. The VAT number is optional.
3.3 The branding of your workspace
Pro customers can set a logo, a background image and colours.
- Purpose: showing your house style in your workspace.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR).
- Retention: we remove these files from our storage at the moment we erase your account data: at your request, or after the period in 3.2.
- Please note: these images are publicly retrievable as soon as they are set, because they are shown to every visitor of the workspace. So do not upload an image you do not want to be public.
3.4 E-mail about your subscription
We send e-mail when a subscription starts, when a payment fails, on cancellation and on resumption, and when you request a password reset.
- Purpose: informing you about your subscription and your account.
- Legal basis: performance of the agreement (art. 6(1)(b) GDPR).
- We send no newsletter and no marketing mail. So there is nothing to unsubscribe from either.
- Retention: the delivery logs of our mail provider follow that provider's own period; we do not keep the content of these messages ourselves.
3.5 Error tracking
When something goes wrong in the application, we send an error report to Flare, a service of Facade BV (Spatie) in Belgium. That report contains technical data: which page, which error, and which queries were executed.
- Purpose: finding and fixing errors, and keeping the service secure.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR), namely a working and secure service. We have weighed that interest against your privacy and shaped the report accordingly: no data that could identify you goes along, and no content of what you share. That way it never becomes more than technical error information.
- What we deliberately leave out: the visitor's IP address does not go along. The values from
database queries do not go along. Passwords and the encrypted content of a shared link do not go
along. The link key is replaced by
[key]in the report, so an error report can never give access to a shared secret. - Retention: Flare keeps the data in an error report for at most 40 days and deletes it after that.
3.6 Server logs
Our web server records which requests come in, with IP address, time and the requested page.
- Purpose: security, detecting abuse and investigating outages.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR).
- Retention: our hosting provider keeps the access logs for 24 days. After that they are summarised into aggregate statistics from which no individual visitor can be traced. Back-ups are kept for 14 days.
3.7 Access to a closed workspace (Pro)
A Pro customer can close their workspace. Not everyone can send a password there any more, only the owner of the workspace and people with an e-mail address at a domain the owner has verified. Retrieving a shared password stays possible for everyone, always; this changes nothing about that.
To make that work we process two things. When a domain is verified, we send a verification link to an e-mail address at that domain, which the owner enters themselves. And when someone signs in, we process the e-mail address they enter, plus the language in which they use the site and the moment of their last sign-in.
- Purpose: access control on a closed workspace, and establishing that someone controls a mailbox at the verified domain.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR). The interest is our customer's, namely preventing strangers from sending passwords under their house style, and ours in being able to deliver that service. We have weighed that against your privacy: it concerns a business e-mail address, we record no name (that column does not exist), we attach no profile to it, and the data goes to no party other than the processors in chapter 5. We do not ask for consent here, because refusing it is the same as having no access, and a choice that is not a choice would not be valid consent.
- What this explicitly is not: we do not record which passwords have been sent through a workspace, or to whom. No such overview exists, and none ever has. A closed workspace prevents an outsider from sending under our customer's house style. It is not oversight of what staff share: the free service on passtransfer.com stays open to everyone.
- Retention: twelve months after the last time you signed in to that workspace. After that, a daily task deletes the row holding your e-mail address. If the workspace itself is deleted, we delete those rows along with it immediately. If the owner withdraws the verification of a domain, your address stops giving access at once, but the row stays until the twelve months have passed. You lose nothing by the deletion: as long as your domain is verified, you can request a new login link.
- Requesting a login link is a separate, short-lived record. When you request a link, we record the e-mail address you entered separately, together with your language and an unreadable imprint of the link. That is what makes the link valid exactly once. That record goes as soon as the link has been used or has expired: the same daily task clears it, so it is stored for at most the fifteen minutes the link is valid plus the time until the next run. If you never click a link, or never confirm the sign-in on the page the link opens, your address does not end up in the workspace's member list. If the workspace itself is deleted, these records go with it immediately as well.
- Opening a login link does not sign you in yet. The link takes you to a page with a single button, and only that button redeems the link and creates your row in the member list. That step is there because email security software opens links in mail automatically, before you ever click them: without it, your link would already be used up by the time you opened it. Opening records nothing; confirming does.
- The links themselves: a login link is valid for fifteen minutes and works once, a verification link for twenty-four hours and also once. Of both we keep only an unreadable imprint (a hash), so the link itself cannot be taken from our database. An expired or used link does not become usable again. When a domain verification succeeds we also erase the address the verification link was sent to: we no longer need it after that.
- Your rights here: because this processing rests on legitimate interest, you can object to it (art. 21 GDPR), and you can ask for your row to be deleted. E-mail hello@passtransfer.com from the address in question; see chapter 8. We then delete that row, which means you no longer have access to that workspace. There is no settings page for you to do that yourself, because this access has no account; mailing us is the way. Your access also lapses on its own: if you do not sign in for twelve months a daily task deletes your row, and if the owner deletes the workspace that row goes with it at once. If the owner only withdraws the verification of your domain, you lose access immediately, but the row stays until one of those two moments. Beyond that, who has access remains a choice of the workspace owner, since they decide which domains are verified.
3.8 Visitor statistics
We count how often our pages are opened, so that we know which ones are used and whether the site works. We do that ourselves, on our own server. No external party is involved, no cookie is placed and no script runs in your browser for it.
- What we process: a hash of your session (calculated with a key that only we have), the page you opened and, if the link you followed carried a campaign parameter, that parameter, the moment, your browser, operating system and kind of device, the language your browser asks for, the country you appear to be in, the site you came from, whether you were on our own site or in a customer's workspace (and if so, which one), and whether the page existed. We count that last one so we can repair dead links; a retrieval link that does not exist is never counted, because that address is itself a guess at a secret.
- If you were signed in, we record who: whether it was the owner of a workspace or a colleague who signed in with a login link, and which account or which colleague it was. We count that to know how much of the use comes from people who are signed in, and which pages they use. If you were not signed in, all it says is that nobody was, and nothing more: there is no way for us to tie a visit without an account to a person. If you ask for erasure (art. 17) we remove this link and all that remains is that somebody was signed in; if you ask for access (art. 15) this list is in the file you get.
- What we count in the tool itself: that a password was created, that a password was retrieved, and that a link turned out to be expired or already used. Of those we keep the moment, whether the password was encrypted in your own browser, how many days it was valid, roughly how long it took to be collected (within an hour, within a day, and so on), and whether it happened on our own site or in a workspace.
- What we count around a sign-up: that a sign-up was started and that a first payment succeeded, with nothing recorded but whether a coupon was used. No order number, no account number, no amount and no e-mail address. We count this to know which channels bring customers.
- What we deliberately leave out: the page where a password is retrieved is never counted at all, because the link itself is the secret, and neither is a reset link or a login link. The rest of the web address is thrown away before anything is stored, so a code or a token in the link you followed leaves nothing behind. The moments above never carry the link, the key, the password, a name, an e-mail address or the name of a workspace: of a password created or retrieved we record only whether it happened on our own site or in a workspace, never in which one. Which workspace was visited we record on a page view only, and that is about our customer rather than about you. Who was signed in we likewise record on a page view only, and only in the individual records: the daily totals that remain afterwards contain no person. And we store no hash of your IP address, not even an unreadable one. We do compare your IP address against a list of our own addresses, so that a page we open ourselves does not count as a visit, and we look up the country that goes with it. Both happen on our own server, against a list that sits there, so your IP address does not go to another party. After that we throw the address away: what is left is two letters, and those are the country. We record nothing finer than a country, so no city, no region and no location.
- Purpose: knowing which pages are used and whether the site works.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR).
- Retention: the individual records for ninety days. After that only daily totals remain, in which no visitor and no person appears.
4. Cookies and storage on your device
We use no tracking cookies, no third-party analytics, and no advertising pixels. There is not a single third-party script on this site. Our own visitor statistics (see 3.8) work without a cookie and without a script. Even our fonts are served from our own server, so your IP address does not end up with an external party when you open the site. That is pinned down in an automated test, so it cannot accidentally come back.
What we do place is strictly necessary to make the site work:
| Name | Kind | What for | How long |
|---|---|---|---|
passtransfer_workspace_session |
cookie | remembering your session within a visit | 8 hours |
XSRF-TOKEN |
cookie | protection against form abuse (CSRF) | 8 hours |
remember_web_… |
cookie | staying signed in as an owner, only if you tick "remember me" when signing in | 400 days |
remember_member_… |
cookie | staying signed in to a closed workspace after the link you were mailed | 1 year |
passtransfer_lang |
cookie | remembering your language choice | 1 year |
passtransfer_lang |
sessionStorage | the same language choice within the tab | until you close the tab |
info |
localStorage | remembering that you have already seen the explanation, so it does not open every visit | until you clear it |
The remember_web_ cookie is only there if you ask to stay signed in yourself. The
remember_member_ cookie is always placed when you use a login link for a closed workspace: you
have no password there, so without it the only way back in is another mailed link. Both disappear
the moment you sign out. No consent is needed for these seven, because they are necessary for a service
you asked for yourself (art. 11.7a(3) of the Dutch Telecommunications Act). That is also why you see no cookie
banner on this site: there is nothing to choose, because there is nothing you would want to
refuse.
5. Who else receives your data
We do not sell your data and do not share it for commercial purposes. The following parties process data for us, on our instructions.
| Party | What for | Where |
|---|---|---|
| Shock Media B.V. | hosting of the application, the database and the uploaded branding images | the Netherlands |
| Mollie B.V. | handling payments | the Netherlands |
| Moneybird B.V. | invoicing and bookkeeping | the Netherlands |
| Facade BV (Flare, Spatie) | error tracking | Belgium |
| Google Ireland Limited (Google Workspace) | sending and receiving e-mail | Ireland, with the United States as fallback |
With Shock Media, Mollie and Moneybird we have concluded a data processing agreement. With Flare and Google Workspace the data processing agreement is part of the standard terms under which we use those services.
6. Transfers outside the European Economic Area
Our hosting, database, back-ups, payments, bookkeeping, file storage and error tracking stay within the European Economic Area.
For e-mail we use Google Workspace. Google Ireland Limited processes those messages within the EEA, but may involve Google LLC in the United States for that. That transfer rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework of 10 July 2023, under which Google LLC is certified. You can verify that at dataprivacyframework.gov/list.
7. How we secure your data
- A shared password is encrypted in your browser with AES-128-GCM. The key sits in the part of the
link behind the
#and never reaches our server. So we cannot read the content, even if we wanted to. - A shared secret can only be retrieved once. We claim the row in a single database operation, so two simultaneous attempts cannot both succeed.
- After retrieval or expiry we erase the content from the database.
- On the retrieval page we send the browser no
Referer, so the link (and with it the secret) cannot end up in another site's logs. - The whole site runs over HTTPS, with HSTS.
- Account passwords are stored as bcrypt hashes, never readable.
- We limit the number of login attempts and the number of retrieval attempts per IP address.
- An uploaded logo in SVG format is sanitised before we store it, so it cannot contain scripts.
- We apply a Content-Security-Policy that only allows our own domains.
No measure is a guarantee. If you think something is wrong with the security, e-mail
hello@passtransfer.com. We respond within five working days. Give us the chance to fix it before
you publish it, and do not access other people's data; then we will not take legal action against
you. The same agreement is in /.well-known/security.txt.
8. Your rights
You have the right to:
- Request access to the data we hold about you (art. 15 GDPR).
- Have incorrect data corrected (art. 16 GDPR).
- Have your data erased (art. 17 GDPR).
- Have the processing restricted (art. 18 GDPR).
- Receive your data in a common file format, or have it transferred (art. 20 GDPR).
- Object to processing based on our legitimate interest (art. 21 GDPR), namely the error tracking, the server logs, the visitor statistics and the access control on a closed workspace.
If you have a Pro account, you can carry out two of these yourself, without e-mailing us: in your account settings you download all your data as a file, and you submit an erasure request. We carry out an erasure request as soon as the subscription has ended, because until that moment we need the data to perform the agreement. What happens then: your name, e-mail address, company details, password and the references to our payment provider and bookkeeping are erased, your workspace and the uploaded images are removed, and only the invoice lines remain for the fiscal retention obligation.
For the other rights, or if you have no account, e-mail hello@passtransfer.com. We respond within one month. If a request is complicated, we may extend that period by two months, and we will let you know within that first month. We ask you to send your request from the e-mail address of your account, so we know it is you. We do not ask for a copy of your passport. A first request is free.
For a shared password we cannot carry out an access request, and that is deliberate: we do not have the key, so we cannot show the content. If you want to undo a shared link, open it once yourself. That uses it up and the content is erased.
If you are not satisfied with how we handle your data, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl.
9. Consent
We base no processing on your consent. So there is nothing to withdraw either. If that changes (for example because we ever add third-party analytics or a newsletter), we will ask for it separately, and you will be able to withdraw that consent at any moment as easily as you gave it.
10. Automated decision-making
We take no decisions about you based on automated processing, and we build no profiles.
11. Minors
PassTransfer is meant for business use and is not aimed at children. We do not knowingly process data of persons under 16. If you think we do anyway, e-mail us and we will delete it.
12. Changes
We may amend this statement. The current version is always on this page, with the date of the last change at the bottom.