Privacy policy
Translation provided for information purposes only. In the event of any discrepancy, the French version shall prevail.
Data controller
PP2P TECHNOLOGIES (SIREN 995 286 689), contact@narvalio.com.
Principle: zero-knowledge
Your files are encrypted in your browser (AES-256) before upload. We store only encrypted binary data; we can read neither your files nor their names. We do not ask for your name, e-mail address or telephone number.
Data processed
- By us: a random vault identifier, the fingerprint (hash) of your authentication key, the encrypted size of the files, and dates. No personally identifying data.
- By Stripe (payment processor): the billing data required for payment, on its own servers. See Stripe's policy.
- Technical logs: kept for a maximum of 30 days, without any vault identifier.
- Waiver of the right of withdrawal: a timestamp linked to the Stripe payment session only, never to a vault.
- Contact form: the e-mail address and the message you send us, forwarded to contact@narvalio.com for the sole purpose of handling your request, then deleted once the exchange is complete. This data is never linked to a backup vault, and is not used for any marketing purposes.
Legal basis and retention periods
Performance of the contract (provision of the service), compliance with legal obligations (proof of the waiver, accounting) and your consent (contact form, obtained via the tick box before sending). Content is deleted after 90 days (+7 days of grace).
Processors
Stripe (payment) and Infomaniak (hosting, Switzerland — a country recognised as adequate by the European Commission). Their data processing agreements (DPA) apply.
Your rights
You have the rights of access, rectification, erasure, restriction and objection (GDPR). As we hold no personally identifying data on our side, these rights are exercised mainly with Stripe for billing. For any request: contact@narvalio.com. A complaint may be lodged with the CNIL.