Data Processing Agreement (DPA)

This agreement applies when a business customer (the Customer) uses upload.am — in particular a Team account — to store or share files that contain personal data. It forms part of the Terms of Service. Last updated: 9 October 2026.

1

1. Roles

The Customer is the controller of the personal data in the files, folders, links and messages it places in upload.am. upload.am (Leads.am) is the processor and processes this data only to provide the service and on the Customer's documented instructions, which are the use of the service features and this agreement.

2

2. Subject matter, duration and nature

Subject matter: hosting, transfer, sharing and deletion of the Customer's files and related account data. Duration: for as long as the Customer uses the service, plus the deletion period in section 9. Nature: storage, transmission, access control, backup copies made by the Customer's own settings, and deletion.

3

3. Types of data and data subjects

Data subjects: the Customer's employees and team members, its clients and other recipients of its links, and anyone whose data the Customer decides to upload. Types of data: whatever the Customer uploads (we do not inspect it), account identifiers (name, email), sharing and access records (IP address, time, device type) and audit-log entries.

4

4. Processor obligations

We process data only on the Customer's instructions and tell the Customer if we believe an instruction breaches data protection law. Everyone at upload.am with access to the data is bound by confidentiality. We do not use the content of the Customer's files for any purpose of our own.

5

5. Security measures

Encrypted connections; access to files only through unguessable links, passwords, email locks, address restrictions and sessions the Customer controls; hashed passwords; optional two-step sign-in and new-device confirmation; role-based access and folder permissions in Team; an audit log of who did what in the Team; client-side encrypted storage in the Windows app; storage on separate object storage nodes; rate limiting and abuse controls; regular updates. The Customer is responsible for configuring link and Team settings appropriately for its data.

6

6. Sub-processors

The Customer gives general authorisation for the sub-processors below. Object storage: Internetport (Sweden). Application hosting: Contabo (United States). Card payments: way2bill. Cryptocurrency payments: Shieldz. Bot protection on sign-in forms: Cloudflare Turnstile. We will update this list before adding or replacing a sub-processor that handles Customer files and give Team customers the opportunity to object by contacting us.

7

7. Assistance to the Customer

We help the Customer answer requests from data subjects and meet its own duties (security, impact assessments, consultation with authorities), taking into account the nature of processing. Much of this is available directly in the service: the Team audit log with CSV export, usage statistics, the ability to delete files and members, and account data export.

8

8. Personal data breaches

We notify the Customer without undue delay after becoming aware of a breach affecting the Customer's data, and in any case within 72 hours, with the information we have about what happened, the data concerned and the measures taken.

9

9. Return and deletion

The Customer can download or delete its data at any time. When the account is closed or the plan ends, files are removed according to the plan's retention rules and the trash period, after which copies are permanently deleted from storage. On written request we confirm deletion.

10

10. Audits and information

On reasonable request we provide the information needed to show compliance with this agreement. Audits by the Customer or an auditor it appoints are possible once a year with reasonable notice, during business hours and under confidentiality, at the Customer's expense.

11

11. International transfers

Where processing involves a transfer of personal data outside the European Economic Area, it takes place under appropriate safeguards required by data protection law. The locations of our sub-processors are listed in section 6.

12

12. Liability and law

Liability under this agreement is subject to the limitations in the Terms of Service. The governing law and jurisdiction are those of the Terms of Service.

13

13. A signed copy

This agreement applies automatically to business customers using the service. If you need a countersigned copy or have questions, write to us through the contact page.

May tanong ka pa ba?

Masaya kaming ipaliwanag sa iyo ang anumang bahagi nito.

Makipag-ugnayan