FileBackerz.com, LLC
Privacy Policy
How we handle personal information, and your rights over it.
Effective 1 September 2026 · Version 1.0 · Last updated 9 August 2026
Contents
THIS POLICY DESCRIBES TWO DIFFERENT ROLES WE PLAY. FOR INFORMATION ABOUT OUR CUSTOMERS AND VISITORS WE ACT AS A CONTROLLER. FOR THE FILES OUR CUSTOMERS STORE WITH US WE ACT AS A PROCESSOR ON THEIR BEHALF. SECTION 2 EXPLAINS THE DIFFERENCE AND WHY IT MATTERS TO YOU.
1. Who We Are and What This Policy Covers
FileBackerz.com, LLC ("FileBackerz," "we," "us," or "our") is a Texas limited liability company with its principal place of business at 3723 Greenville Avenue, Suite 19910, Dallas, Texas 75206. We operate the FileBackerz cloud file storage, backup, and sharing platform (the "Service").
This Privacy Policy explains how we handle personal information when you visit filebackerz.com, create an account, use the Service, or communicate with us. It forms part of our Terms of Service.
For the purposes of the EU General Data Protection Regulation ("GDPR") and the UK GDPR, the controller of personal information described in Section 3.1 is FileBackerz.com, LLC at the address above. You can reach us at [email protected].
2. Our Two Roles: Controller and Processor
The distinction below determines who you should contact about your data and whose privacy notice applies.
| Situation | Our role | What it means |
|---|---|---|
| Information about our customers, account administrators, billing contacts, prospects, and website visitors | Controller | We decide why and how this information is processed. This Policy governs it, and you may exercise your rights directly with us under Sections 10-12. |
| Files, folders, and other content our customers upload to the Service, including any personal information contained inside those files | Processor (service provider) | Our customer decides why and how that content is processed. We act only on their documented instructions. Our customer's own privacy notice applies, and our Data Processing Addendum governs the processing. |
| Members and guests invited to a customer's Workspace | Processor, on behalf of the customer | The customer who invited you is the controller. Direct your requests to them; we will assist them in responding. |
If you are an employee, client, contractor, or other individual whose files were uploaded to FileBackerz by a business, we process that content only for that business. Please direct requests to them. If you contact us instead, we will refer you to them or forward your request.
3. Information We Collect
3.1. Information you provide directly
- Account information: full name, email address, password (stored only as a salted hash), and optionally company name, phone number, organization type, and workspace name.
- Billing information: billing name and address, subscription plan, transaction history, and the last four digits and expiry of your payment card. Full payment card numbers are collected and stored by our payment processor, not by us.
- Support and communications: the contents of emails, support tickets, and any information you choose to include.
- Marketing preferences and any information you submit through forms on our website.
3.2. Customer Content
Files, folders, file names, and other material you or your Members upload to the Service, together with associated metadata such as file size, type, version history, and upload timestamps. We handle Customer Content as a processor (Section 2). We do not inspect the contents of your files except as described in Section 5.
3.3. Information collected automatically
- Usage data: features accessed, pages viewed, actions taken within the Service, and timestamps.
- Audit log data: uploads, downloads, deletions, share-link creation, permission changes, and sign-in events, each recorded with the acting user, timestamp, and IP address. Audit logs are a core Service feature and cannot be disabled.
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language, and referring URL.
- Cookies and similar technologies, as described in Section 6 and in our Cookie Policy.
3.4. Information from third parties
- Single sign-on providers: if you sign in with Google or Microsoft, we receive your name, email address, and profile identifier from that provider. We do not receive your password.
- Payment processor: transaction status, authorization results, and fraud signals.
- Connected Storage: where you connect a third-party storage account, we receive the credentials or tokens you supply and metadata about the objects stored there.
3.5. Information we do not collect
We do not knowingly collect special categories of personal data as defined in Article 9 GDPR, government identification numbers, precise geolocation, or biometric data. Our Acceptable Use Policy prohibits uploading protected health information without a Business Associate Agreement, and cardholder data in any circumstance. If you upload such data into your files in breach of that policy, we do not treat it as intentionally collected.
4. Why We Use Information, and Our Legal Basis
Where the GDPR or UK GDPR applies, we rely on the following legal bases. Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
| Purpose | Personal information used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and administer your account; authenticate you | Account information, device data | Performance of a contract |
| Provide, host, sync, and restore the Service | Account information, Customer Content, usage data | Performance of a contract |
| Process payments, invoicing, and collections | Billing information | Performance of a contract; compliance with legal obligation (tax and accounting records) |
| Provide customer support | Account information, support communications, usage data | Performance of a contract; legitimate interests in resolving issues |
| Maintain audit logs and access records | Usage data, IP address, account information | Performance of a contract (audit logging is a contracted feature); legitimate interests in security |
| Secure the Service; detect and prevent fraud, abuse, and unauthorized access | Device data, usage data, account information | Legitimate interests in protecting the Service, our customers, and third parties |
| Monitor, analyze, and improve the Service | Usage data, aggregated and de-identified data | Legitimate interests in improving our product |
| Send service, security, and transactional notices | Account information | Performance of a contract; legitimate interests; compliance with legal obligation (breach notification) |
| Send marketing communications | Account information, marketing preferences | Consent, where required; otherwise legitimate interests in marketing to business contacts, subject to opt-out |
| Analytics cookies and similar technologies | Device data, usage data | Consent, where required by the ePrivacy Directive or UK PECR |
| Comply with law; respond to lawful requests; establish, exercise, or defend legal claims | Any of the above as relevant | Compliance with legal obligation; legitimate interests in defending claims |
We do not use Customer Content to train machine learning or artificial intelligence models. We do not use Customer Content for advertising. We do not sell personal information.
5. When We Access the Contents of Your Files
We limit access to the contents of Customer Content to the following circumstances, and access is logged:
- Automated processing necessary to provide the Service, such as generating thumbnails and previews, indexing for search, computing checksums, encrypting, and creating and restoring backups.
- When you ask us to, for example in the course of a support request you initiate.
- When we have a good-faith basis to investigate a suspected violation of our Terms of Service or Acceptable Use Policy, or a security incident.
- Automated scanning for material whose possession or distribution is unlawful, including child sexual abuse material, which we are required to report under 18 U.S.C. § 2258A.
- When required by valid legal process, as described in Section 7.
Personnel access to Customer Content is restricted to a limited number of authorized staff, requires a documented business justification, and is recorded.
8. International Data Transfers
FileBackerz is established in the United States, and our infrastructure and personnel are located there. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States, which may not provide the same level of protection as your home jurisdiction.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, namely:
- The European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated into our Data Processing Addendum;
- The UK International Data Transfer Addendum to those Clauses, issued under section 119A of the UK Data Protection Act 2018; and
- For transfers from Switzerland, the Standard Contractual Clauses as adapted by the Swiss Federal Data Protection and Information Commissioner.
We supplement these with technical and organizational measures described in our Data Processing Addendum, including encryption in transit and at rest, and a commitment to challenge overbroad government requests where lawful. A copy of the relevant clauses is available on request from [email protected].
9. How Long We Keep Information
| Category | Retention period |
|---|---|
| Customer Content — active account | For as long as you keep it in the Service. Deleted files are moved to trash and permanently removed after 30 days. |
| Customer Content — after termination | 30 days from termination, so you can export it. Deleted thereafter. No retention period applies where we terminate for cause under Section 20.5 of the Terms of Service, in which case content may be deleted immediately or, where legally required, preserved. |
| Customer Content — backups | Backup copies expire on a rolling cycle and are fully overwritten within 35 days of deletion from the live system. |
| Account information | For the life of the account, then 90 days after closure. |
| Billing and transaction records | Seven (7) years from the transaction, to meet tax, accounting, and audit obligations. |
| Audit logs and security logs | Twelve (12) months, then deleted or aggregated. |
| Support communications | Three (3) years from the last message. |
| Marketing contact records | Until you unsubscribe, plus a suppression record kept indefinitely so we do not contact you again. |
| Records related to a legal claim, investigation, or preservation obligation | Until the matter is resolved and any applicable limitation period expires. |
Where we retain information for the periods above, we do so because it is necessary for the purpose for which it was collected, or because we are legally required to.
10. Your Privacy Rights (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights in relation to personal information for which we are the controller:
- Access — to obtain confirmation of whether we process your personal information and a copy of it.
- Rectification — to have inaccurate information corrected and incomplete information completed.
- Erasure — to have your personal information deleted in certain circumstances.
- Restriction — to have processing restricted in certain circumstances, for example while you contest accuracy.
- Portability — to receive personal information you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Object — to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation, and to object at any time and without reason to processing for direct marketing.
- Withdraw consent — where we rely on consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Lodge a complaint — to complain to your local supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). We would appreciate the chance to address your concern first.
To exercise these rights, email [email protected]. We will verify your identity before acting, and will respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.
Where we act as a processor — that is, for Customer Content — please direct your request to the customer who controls that Workspace. If you contact us, we will refer you to them or forward your request, and will assist them in responding as required by our Data Processing Addendum.
11. EU and UK Representative
FileBackerz is offered to businesses whose principal place of business is in the United States. We do not offer the Service to individuals in the European Economic Area or the United Kingdom, and we do not monitor the behaviour of individuals located there.
Because we do not target those markets, we have not appointed a representative under Article 27 of the EU or UK GDPR. If that changes, we will appoint one and name them here before offering the Service in those regions.
This does not mean personal data protected by the EU or UK GDPR may be uploaded. Our Acceptable Use Policy prohibits it unless you have executed our Data Processing Addendum, because a United States customer may still invite members located elsewhere. If that describes you, write to [email protected] before you upload.
12. Your Privacy Rights (United States)
12.1. California
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them.
Notice at collection. In the twelve months before the effective date of this Policy, we collect and disclose the following categories.
| CCPA category | Do we collect it? | Purpose | Disclosed to |
|---|---|---|---|
| Identifiers (name, email, IP address, account ID) | Yes | Provide and secure the Service; billing; support | Subprocessors |
| Customer records (billing name, address, phone) | Yes | Billing and account administration | Payment processor; subprocessors |
| Commercial information (subscription, transactions) | Yes | Billing; account administration | Payment processor |
| Internet or network activity (usage, audit logs, device data) | Yes | Provide the Service; security; analytics | Subprocessors |
| Geolocation (approximate, from IP) | Yes | Security and fraud prevention | Subprocessors |
| Professional or employment information (company, job context) | Yes, if you provide it | Account administration | Subprocessors |
| Sensitive personal information | Only account credentials, used solely to authenticate you | Authentication | Not disclosed |
| Biometric information; precise geolocation; government IDs | No | — | — |
| Inferences used to create a profile | No | — | — |
We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve months, and we do not knowingly sell or share the personal information of consumers under 16.
We use sensitive personal information only for purposes permitted under Section 7027(m) of the CCPA regulations, so the right to limit its use does not give rise to additional choices here.
To exercise your rights, email [email protected]. We will verify your identity using information already associated with your account. You may use an authorized agent, who must provide written permission signed by you, and we may require you to verify your own identity directly. We will not discriminate against you for exercising any right.
12.2. Other U.S. states
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, sale, and certain profiling. We do not engage in targeted advertising, sale, or profiling that produces legal or similarly significant effects.
Use the same contact address to exercise these rights. If we deny a request, you may appeal by replying to our decision with the word "Appeal" in the subject line. We will respond to an appeal within 45 days and, if we deny it, will tell you how to contact your state attorney general.
12.3. Texas
As a Texas business, we note for Texas residents that we do not sell personal data, do not process it for targeted advertising, and do not use it for profiling in furtherance of decisions producing legal or similarly significant effects. Texas residents have the rights described in Section 12.2.
13. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing, and we do not engage in profiling for that purpose.
We do use automated systems for security, abuse detection, and content scanning as described in Section 5. Where such a system results in the suspension or restriction of an account, a human reviews the decision before it becomes final, except where immediate action is required to address apparent unlawful content or an active security threat. You may contest such a decision by writing to [email protected].
14. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These include encryption of data in transit using TLS and at rest using AES-256, role-based access controls, least-privilege administrative access, audit logging, network segmentation, vulnerability management, and personnel confidentiality obligations. A fuller description is in Annex II of our Data Processing Addendum.
No system is perfectly secure and we cannot guarantee absolute security. You play an essential part: choose a strong, unique password, enable two-factor authentication, configure sharing permissions carefully, and remove Members promptly when they leave your organization.
To report a suspected vulnerability or security issue, contact [email protected]. We will acknowledge reports promptly and will not pursue legal action against researchers who investigate and report in good faith, without accessing other users' data or degrading the Service.
15. Data Breach Notification
If we become aware of a personal data breach affecting personal information for which we are the controller, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Where we act as a processor, we will notify the affected customer without undue delay after becoming aware of a breach affecting their Customer Content, and will provide the information they need to meet their own notification obligations. Our Data Processing Addendum sets out the detail.
We will also comply with applicable U.S. state breach notification laws.
16. Children's Privacy
The Service is a business product and is not directed to children. We do not knowingly collect personal information from children.
In the United States, we do not knowingly collect personal information from children under 13, consistent with the Children's Online Privacy Protection Act.
In the European Economic Area and the United Kingdom, we do not knowingly offer the Service to, or collect personal information from, children under 16. Some EEA member states set a lower age between 13 and 16; where a lower age applies in your country, that age governs.
If you believe a child has provided us with personal information, contact [email protected] and we will delete it promptly.
17. Third-Party Websites and Services
The Service may link to or interoperate with websites and services we do not control, including single sign-on providers, Connected Storage providers, and payment processors. This Policy does not apply to them. Review their privacy notices before using them.
18. Changes to This Policy
We may update this Policy from time to time. When we do, we will change the effective date above and, for material changes, give at least 30 days' notice by email to the address on your account or through the Service before the change takes effect.
Where a change materially expands how we use personal information in a way that requires your consent, we will obtain it. We maintain prior versions and will provide them on request.
19. How to Contact Us
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | [email protected] |
| Data protection contact / DPO enquiries | [email protected] — we have determined that we are not required to appoint a Data Protection Officer under Article 37 GDPR, as our core activities do not consist of large-scale regular and systematic monitoring or large-scale processing of special category data. We will reassess this as the business grows. |
| Security reports | [email protected] |
| Legal and general | [email protected] |
| Postal | FileBackerz.com, LLC / 3723 Greenville Avenue, Suite 19910, Dallas, Texas 75206 |