Legal
Privacy Policy
What personal data we hold, why we hold it, and what you can ask us to do with it.
Effective
24 August 2026
Last Updated
1 September 2026
Version
1.1
1. Who we are and what this covers
Syncplify, Inc. ("Syncplify", "we", "us") operates SFTP.cloud (the "Service"). This Privacy Policy explains how we handle personal data when you visit our website, open an account, or use the Service.
For the personal data of our own customers, prospects, and website visitors, Syncplify is the controller. Where a customer uses the Service and we process personal data on that customer’s behalf, the customer is the controller and Syncplify is the processor. In that case this Policy describes our practices, and the Data Processing Addendum governs the relationship. Terms not defined here have the meaning given in the Terms of Service.
2. The short version
We hold the data needed to run your account and keep the Service secure. We do not hold your files, and we cannot read them.
The Service is a protocol relay. Files move between your storage and your users through the channel established by the Storage Connector, and are not persisted to storage we operate. We do not hold credentials to your storage. What we do hold is account information, billing information, and operational records about how the Service is being used.
We do not sell personal data, and we do not share it for cross-context behavioral advertising.
3. What we collect
3.1 Account data
The name, work email address, and, where applicable, company name, job title, and telephone number of the people who administer or use an account. Authentication data, including password hashes and multi-factor authentication settings. Support correspondence and its contents.
3.2 Service Metadata
The operational records our systems generate about use of the Service: account identifiers, connection and session records, source IP addresses, authentication events, configured storage endpoints, Storage Connector version and status, transfer volumes and timings, and administrative actions taken in the console. Some of this is personal data because it relates to an identifiable user.
3.3 Billing data
Billing contact details, billing address, tax identifiers, plan and subscription history, and invoice records. Card details are collected and stored by our payment processor, not by us. We receive only a token and the last four digits.
3.4 Website data
Pages visited, referring page, approximate location derived from IP address, browser and device type, and similar analytics data. See section 11.
3.5 Marketing data
Where you contact us, request a trial, or subscribe to updates: the details you give us and your communication preferences.
4. What we do not collect
We do not collect, store, scan, index, or review the contents of the files transferred through the Service, and we have no technical means of doing so. We do not hold credentials to your storage. Your audit trail is generated within your own environment and signed with a key we do not hold.
This means that if the files you transfer contain personal data, that personal data is not held by us. It is on your storage, under your control, and its processing is governed by your own privacy notice rather than this one.
We do not knowingly collect special category data, and the Service is not designed to be used as a repository for it in our systems.
5. Why we use it, and our legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases.
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the Service and administering accounts | Account data, Service Metadata | Performance of a contract |
| Billing, collections, and tax records | Billing data | Performance of a contract; legal obligation |
| Security, abuse prevention, and investigating violations | Service Metadata, account data | Legitimate interests in keeping the Service secure |
| Support and service communications | Account data, support correspondence | Performance of a contract |
| Improving and troubleshooting the Service | Service Metadata, website data | Legitimate interests in improving our product |
| Marketing to business contacts | Marketing data | Consent, or legitimate interests where permitted |
| Complying with law and responding to legal process | Any of the above | Legal obligation |
Where we rely on legitimate interests, we have considered the impact on you and concluded that our interest is not overridden by your rights. You may object at any time using the contact details in section 14.
6. Who we share it with
We share personal data with service providers who process it on our behalf under written contracts that restrict their use of it. Our current sub-processors are listed in Annex III of the Data Processing Addendum, and we maintain that list as required by the Data Processing Addendum. They fall into these categories:
- Cloud infrastructure and hosting for the control plane.
- Payment processing and invoicing.
- Customer support and ticketing.
- Email delivery for transactional and service messages.
We also disclose personal data where required by law or valid legal process, to protect our rights or the safety of others, and to a successor in connection with a merger, acquisition, or sale of assets, in which case we will give notice before personal data becomes subject to a different privacy policy.
If we receive legal process seeking customer information, we can produce only Service Metadata. We cannot produce file contents. Where we are legally permitted to do so, we will make reasonable efforts to notify the customer before responding.
We do not sell personal data, and we do not share it for cross-context behavioral advertising, as those terms are used in United States state privacy laws.
7. International transfers
Syncplify is based in the United States, and personal data we hold as controller is processed there. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, and on supplementary measures where our transfer assessment shows they are needed.
A copy of the transfer mechanism relevant to you is available on request from privacy@sftp.cloud.
8. How long we keep it
| Category | Retention |
|---|---|
| Account data | For the life of the account, then 12 months after closure |
| Service Metadata | 13 months from creation |
| Security and audit logs | 24 months from creation |
| Billing and tax records | 7 years, as required by law |
| Support correspondence | 24 months from the last message |
| Marketing data | Until you unsubscribe, then 24 months on a suppression list |
We may keep data for longer where we are required to by law, or where it is needed to establish, exercise, or defend legal claims. Where we are required to preserve records under 18 U.S.C. § 2258A, we do so for the period that statute requires.
9. How we protect it
We maintain technical and organizational measures appropriate to the risk, including encryption in transit, encryption at rest for the data we hold, role-based access control with least privilege, multi-factor authentication for administrative access, logging and monitoring, secure development practices, vendor review, and an incident response process. The measures applicable to processing on behalf of customers are described in the Data Processing Addendum.
No system is perfectly secure. We ask that suspected vulnerabilities be reported to security@sftp.cloud, on the terms in section 9 of the Acceptable Use Policy.
10. Your rights
10.1 If the GDPR or UK GDPR applies to you
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to data portability, and, where we rely on consent, to withdraw that consent at any time without affecting processing already carried out. You also have the right to lodge a complaint with your supervisory authority, though we would ask you to contact us first.
10.2 If a United States state privacy law applies to you
Depending on your state, you may have the right to know what personal data we have collected and the categories of recipients, to obtain a copy of it, to have it corrected or deleted, and to be free from discrimination for exercising those rights. Because we do not sell personal data or share it for cross-context behavioral advertising, there is no opt-out for those activities. You may use an authorized agent, and we may take reasonable steps to verify their authority.
10.3 How to exercise them
Write to privacy@sftp.cloud. We will verify your identity, usually through the email address on the account, and respond within the period the applicable law requires. Where a request concerns personal data we process on behalf of a customer, we will refer it to that customer and assist them in responding.
11. Cookies and analytics
We use cookies that are strictly necessary to operate the website and the Service, including for authentication and security. We also use analytics cookies to understand how the website is used, and we set those only after you accept them. You can change your choice at any time through the cookie settings on the website. Our Cookie Policy describes both kinds in more detail.
We do not use advertising cookies and we do not permit third parties to use our website to build advertising profiles.
12. Children
The Service is a business product and is not directed to children. We do not knowingly collect personal data from anyone under sixteen (16). If you believe a child has provided us with personal data, write to privacy@sftp.cloud and we will delete it.
13. Changes to this Policy
We may update this Policy. Material changes will be notified to customers at least thirty (30) days before they take effect, by email to the account’s administrative contact or by notice within the Service, and the date at the top of this document will be updated. Changes required by law may take effect immediately upon notice.
14. Contact
| Purpose | Address |
|---|---|
| Privacy questions and rights requests | privacy@sftp.cloud |
Syncplify, Inc. a Delaware corporation