1. Who controls your data
The data controller is Marco Ferré, a natural person operating the EASHR.COM project, with contact address at Brescia, Italy.
EASHR.COM is currently presented as a private project rather than as a company. This does not remove the controller’s responsibilities under applicable data-protection law.
2. Data processed
- Email address used to request and verify one-time access codes.
- Technical account identifiers, session data and language preference.
- File names, sizes, types, expiration settings, transfer codes, links and folder information.
- Recipient email addresses entered by users for private delivery or shared-folder invitations.
- File contents, only to store, deliver, download, expire and remove them as requested through the service.
- Technical logs such as date and time, IP address, browser or device information, errors, upload and download events and security events.
- Messages and information sent when contacting support, privacy or abuse channels.
3. Purposes and legal bases
- Providing access, uploads, downloads, links, folders, email delivery and automatic expiration: performance of the service requested by the user.
- Sending OTP codes and operational notifications: performance of the service and security.
- Preventing abuse, fraud, malware, unauthorised access and service disruption: legitimate interests in protecting users and infrastructure.
- Handling legal notices, rights requests and communications from authorities: compliance with legal obligations.
- Defending legal claims and documenting material security events: legitimate interests and, where applicable, legal obligations.
4. Cookies and local storage
EASHR.COM uses technical cookies or equivalent storage needed for sessions, login persistence, language selection, security and Progressive Web App functions.
No profiling or advertising cookies are described by this policy. If analytics or non-essential tracking is introduced, a separate assessment and, where required, a consent banner will be needed.
5. Recipients and service providers
- Hosting and infrastructure provider: OVHcloud, with infrastructure indicated as located in Italy.
- Email and SMTP providers used to send access codes and service notifications.
- People selected by the user as recipients, or anyone who receives a valid public sharing link.
- Technical consultants who may assist under confidentiality and data-protection obligations.
- Public authorities or other parties when disclosure is required by law or necessary to protect rights and safety.
6. International transfers
The operator should configure and verify where hosting, email and support providers process data. If data are transferred outside the European Economic Area, EASHR.COM will rely on an applicable legal mechanism, such as an adequacy decision or appropriate safeguards.
7. Retention and deletion
- Files and transfer data are retained until the expiration selected by the user and are then queued for automatic removal. Technical cleanup may take up to 24 additional hours.
- Security and operational logs are normally retained for up to 30 days, unless a longer period is needed to investigate abuse, security events or legal claims.
- Account and access records may be retained for up to 365 days after the last activity, subject to technical and legal needs.
- Support and legal correspondence is retained for the time necessary to handle the request and document its outcome.
- Backups, if used, may retain deleted data for a limited technical rotation period and are not intended for ordinary user access.
8. Security
EASHR.COM applies reasonable technical and organisational measures designed to protect data, including access controls, expiring links, isolated private storage and encrypted network transport where HTTPS is used.
No internet service can guarantee absolute security. Users should avoid sharing secrets through public links and should protect access codes and devices.
9. Your choices and rights
A request may require reasonable identity verification. Rights are not absolute and may be limited by law or by the rights of other people.
- Request access to personal data concerning you.
- Request correction of inaccurate or incomplete data.
- Request deletion or restriction where the legal conditions are met.
- Object to processing based on legitimate interests.
- Request data portability where applicable.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the competent data-protection authority, including the Italian Data Protection Authority if applicable.
10. Data entered about other people
When a user enters another person’s email address or uploads files containing third-party personal data, that user is responsible for having an appropriate reason and authority to do so and for informing the other person where required.
11. Minors
EASHR.COM is intended for users aged at least 18. The service is not designed for children, and users must not knowingly upload unlawful content involving minors.
12. Changes to this notice
This policy may be updated when the service, providers or legal requirements change. The current version and update date will remain available on this page.
Privacy contacts
Use the privacy address for data-protection requests. Use the abuse address to report a specific file or illegal content.