GDPR Compliance Statement

PhotonFile is committed to protecting the privacy and personal data of all users in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”).

Data Hosting and Processing

PhotonFile maintains a dedicated data center for EU customers located in Frankfurt, Germany. When an EU-based account is created, account data and associated uploads are processed and stored within this EU region to support GDPR data residency.

Data Transit and Relays

PhotonFile's relay system is designed for ephemeral data transfer only, no files or personal data are stored or retained on relays. EU customers typically use EU-based relays; however, depending on network conditions, traffic may be temporarily routed via relays outside the EU. This does not affect GDPR compliance, as relays act purely as transient network hops or switches without persistence, inspection, or storage of user content.

Privacy by Design

  • Files are processed in memory and never indexed or logged.
  • No long-term data retention occurs beyond the duration of a transfer.
  • End-to-end privacy and minimal data processing are core principles.

Data Protection Commitment

PhotonFile aligns with GDPR principles, including lawfulness, fairness, transparency, data minimization, purpose limitation, integrity, and confidentiality, supported by security measures appropriate to risk.

Contact

To ask questions or exercise your GDPR rights (access, erasure, rectification, or portability), contact our Data Protection Officer at [email protected].