PRE-LAUNCH REVIEW DRAFT
Privacy Notice
A layered explanation of the personal data FileMentra uses, why it is used, how long it is kept and the choices available to people.
- Status
- Internal review
- Last revised
- August 18, 2026
At a glance
FileMentra acts as controller for account, security, product and billing data needed to operate the service. For files and collaboration content submitted by a customer, FileMentra acts as that customer’s processor. The customer decides why that content is processed and who may access it.
Data we process and why
| Data | Purpose | Typical basis |
|---|---|---|
| Name, email, workspace and role | Create and administer accounts and provide collaboration | Contract |
| Login, MFA, IP, device and session events | Authentication, abuse prevention, audit and incident response | Contract and legitimate interests in security |
| Files, folders, messages, requests, Rooms and recipient details | Process customer content on workspace instructions | Customer-determined basis; FileMentra acts as processor |
| Plan, usage and billing metadata | Administer subscriptions, limits and invoices | Contract and legal obligations |
| Support communications | Respond to requests and maintain service quality | Contract and legitimate interests |
Sources and recipients
Data comes from account holders, workspace administrators, invited collaborators, recipients and normal use of the service. It may be disclosed to authorized workspace members, recipients selected by customers, vetted service providers, professional advisers and authorities where legally required. FileMentra does not sell personal data or use customer files to train general-purpose AI models.
Hosting and international transfers
The planned primary production region is Frankfurt, Germany. The final production notice and subprocessor register must identify every active provider, processing location and transfer safeguard before launch. Where data leaves the EEA, an applicable adequacy decision or contractual and supplementary safeguards will be used.
Retention and deletion
Account information is retained while the account is active and during the documented recovery period after deletion. Customer content follows workspace retention controls. Rejected malware bytes are removed immediately; related verdict metadata is scheduled for removal after 90 days. Security audit evidence has a 365-day minimum. A valid legal hold overrides normal deletion until it is released. Production backup erasure timing must be added after the hosting provider is finalized.
Your rights
Depending on location, people may request information, access, correction, deletion, restriction, portability or object to certain processing, and may complain to a data protection authority. Profile editing, personal data export and account deletion are available in My account → Privacy. Other requests will use the final privacy contact. Identity may be verified before disclosure. A customer controls requests concerning content it submitted, and FileMentra assists that customer as processor.
Cookies and local storage
The application uses essential session cookies and limited browser storage for security, registration continuity, transfer continuity and interface preferences. There are no advertising cookies in the current implementation. See the Cookie Notice.
Security, children and automated decisions
FileMentra uses tenant isolation, encryption, scoped access, threat scanning, audit logs, step-up authentication and controlled deletion. No system can guarantee absolute security. The service is not directed to children, and the current product does not make solely automated decisions with legal or similarly significant effects about people.
Contact and changes
The final notice must provide the controller’s legal identity, postal address, privacy email and, if required, EU/UK representative and data protection officer details. Material changes will be presented before taking effect and previous versions will be retained.