PRE-LAUNCH REVIEW DRAFT
Law enforcement guidelines
For authorities and for anyone serving legal process on FileMentra. It explains what data exists, what does not, how to ask for it, and what we tell the person concerned.
- Status
- Internal review
- Last revised
- August 18, 2026
Where to send a request
Email [email protected] from an official address, with the legal instrument attached as a PDF. We accept requests in English. We do not accept service of process by telephone or through support channels, and a message to support does not start the clock.
Operator: To be confirmed before launch. Registered address: To be confirmed before launch. Data is processed in Frankfurt, Germany (EU).
Contact points
Under Articles 11 and 12 of the Digital Services Act, these are our single points of contact. Both accept English.
| Who | Contact |
|---|---|
| Authorities of Member States, the Commission and the Board | [email protected] |
| Users and anyone reporting content | [email protected], or the report form |
| Privacy and data protection requests | [email protected] |
| Security vulnerabilities | [email protected] |
What exists, and what does not
FileMentra is a file transfer and storage service. The most important thing for a request to know: we do not read customer file contents, and our staff cannot open them. There is no internal tool that downloads or previews a customer's file. A request for file contents can only be answered by data held by the customer themselves, or through the account holder.
What can exist, depending on the service used:
| Record | Typically includes | Kept |
|---|---|---|
| Account | Email address, display name, workspace, plan, creation date | While the account exists |
| Sign-ins | Outcome, IP address, browser string, time | 180 days |
| Sessions | IP address, browser string, start and last activity | Session lifetime |
| Workspace activity log | Actions with actor, IP address and identifiers, not file names | As long as the workspace |
| Send made without an account | Sender email and IP, browser, recipients, file names, sizes and SHA-256 fingerprints, and each download with its address | 90 days |
| Abuse reports and blocklist | The report, our decision, and blocked fingerprints or addresses | Until removed |
| File contents | Not readable by FileMentra | Not available |
What process we require
- Valid legal process. A court order, warrant or equivalent binding instrument, issued by an authority with jurisdiction over the operator, or transmitted through the applicable treaty or mutual legal assistance route. A foreign authority cannot compel disclosure directly.
- Specific identifiers. An email address, workspace identifier, transfer link or IP address with a time window. We do not run open-ended searches, and we do not hand over data about people who are not named in the request.
- Proportionality. We disclose the narrowest set of records that answers the request, and we refuse or ask to narrow requests that go beyond it.
- Data protection law still applies. Where the data concerns people in the European Economic Area, we assess the request against the GDPR before answering.
Preservation
A written preservation request to [email protected] naming specific accounts, transfers or addresses freezes what exists at that moment for 90 days, renewable once on request. Preservation is not disclosure: the data is held, and released only against valid legal process. Preservation stops our normal deletion for those records, including the 90 day record of a send made without an account.
Emergencies
Where a request explains a risk of death or serious physical harm and why it is urgent, we review it immediately and may disclose the limited data needed to address that risk. Mark the email subject EMERGENCY DISCLOSURE REQUEST and include a callback number.
Telling the person concerned
Our default is to tell the customer or sender about a request for their data before we answer it, so they can seek their own advice. We do not tell them when a court order, a statute or a credible emergency forbids it, and when a non-disclosure period ends we may tell them then.
Content we act on ourselves
We act on reports through the report form under the Acceptable Use Policy, and on orders issued under Articles 9 and 10 of the Digital Services Act. We do not monitor customer content generally, and no law requires us to. Files are scanned for malware before delivery, and a file whose fingerprint we have blocked is refused everywhere.
Costs and abuse of this channel
We do not charge for responding to valid process. We log every request and every disclosure, and we refuse requests that are not what they claim to be.