Our Data Privacy Commitment
Our mission is to make privacy and security available to people and businesses. That’s why we use end-to-end encryption to protect files and folders you share and store in the cloud.
We encrypt all and every transmission containing personal data using Secure Socket Layer technology (SSL) and apply additional, client-side encryption on the files and directories uploaded and stored in protected storage folders (the Encrypted Content).
We never collect or store your files, encryption keys and passwords in an unencrypted or invertible form. The Encrypted Content and corresponding encryption keys can only be decrypted by you and persons with whom you explicitly share them. However, if you have an account that is part of a Business Domain with recovery master key, Your Encrypted Content may also be accessed by your Subscription Owner.
According to the best of Exceed Digital’s knowledge, the current state of the art and the public knowledge of the human race,Exceed Digital is unable to decrypt the Encrypted Content and accordingly, Exceed Digital cannot access it. As a result, we cannot use Your Encrypted Content to identify any individual.
However, when using the service, creating and using your user account, you also submit some non-encrypted data, which may include personal data as well.
In a nutshell
Even though we can’t read or access the files and folders you store with Exceed Digital, we need to process some of your personal data to provide you with services.
What kind of personal data do we process?
What is the legal basis for processing?
How do we use your data?
How do you use your personal data?
Do we share your personal data with third parties?
Where do we transfer your data?
How do we protect your data?
How long will we retain your information?
Any further question?
Who will process your personal data?
If you have a subsciption with Exceed Digital as an individual user, Exceed Digital will be the controller of your personal data under EU law.
Your data is processed by Exceed Digital. However, if you are a part of a business subscription, certain data is processed upon the instructions of your organization.
If your account is part of a Business Domain in accordance with section III of our Terms, in certain cases, the ultimate decisions regarding your personal data will be made by your organisation. In such case, your company will be considered as a controller and Exceed Digital will act as a processor, acting upon the instructions of your organisation.
In any case, certain activities of Exceed Digital are outsourced to third parties (processors), they may also use your personal data when acting on behalf of Exceed Digital. You can find more details about our sub-processors here.
What kind of personal data do we process?
A) Data that you provide to us
Registration information: When you register for our services, you submit some non-encrypted identification and contact data (such as your e-mail address, name, job title or position, address, phone number). The data that we request at the time of registration is necessary for the provision of our services.
Certain basic information, like your name and email address, is necessary for setting up a Exceed Digital account.
Billing Information: At the time of registration, you also need to provide us certain billing information. You might also provide payment information, such as payment card details, which we collect via secure payment processing services. This data is necessary in order to provide you Exceed Digital services.
When you purchase a subscription, you also need to provide payment information, which will be handled by secure processing services.
Account information: When you use our services, you provide us access to certain information (such as the images, content, information to put on the site) that is necessary for the provision and maintenance of your user account. For the avoidance of any doubt, Exceed Digital cannot connect such metadata information to Your Encrypted Content or file names as Exceed Digital has no access to the Encrypted Content or file names.
In order to send and deliver invitations upon your instructions, Exceed Digital stores and accesses certain personal data (such as the email address, name, website name and its unique URL, storage account and username of the inviter and the invited person).
Other Information: You may decide to share further information, including personal data, with us when you contact our Support or Sales Teams, submit forms on our website or otherwise communicate with us. It is solely your decision to share any detailed, non-aggregated logs (which may contain e.g. non-encrypted filenames), your screen or any other data with us during such communications, so our processing of such data will be based on your consent.
Sometimes, when you require assistance from our Sales and Support teams, you may choose to share additional information with us.
We collect data through cookies and similar technologies on our website.
Website statistics: You can visit the Exceed Digital website, which is separate from the Exceed Digital app and service, without providing any direct information about yourself.
We collect data from our website visitors – we can’t identify you directly without your consent.
We store access data without direct personal references, namely the visitor’s browser types, the name of your internet service provider, the website from which you have visited us, the name of the requested file, the Tresorit client version you download, and internet protocol addresses.
Unless you choose to identify yourself, either by responding to a promotional offer, opening an account or filling out a web form, this data does not allow us to draw any conclusions regarding your identity. By storing and analyzing such information, we are able to create in-depth analysis about our service, which is essential for improvement, security and debugging purposes.
Logs: As most websites and services provided through the Internet, we gather certain information and store it in log files when you interact with our website or service.
We log website visits and application usage statistics to improve our services.
This information includes internet protocol (IP) addresses as well as browser type, operating system, identification numbers associated with your devices, time of access, and error logs.
Analytics: When you use our services, we automatically collect information such as the type of device you use, operating system version and the IP addresses associated with you.
B) Information that we collect from third parties
Our resellers and distributors: From time to time, we engage trusted business partners who help us generate leads, and market, promote and resell our product. We receive information from these partners, such as billing information, contact information, company name and registered address.
We reach out to audiences who might be interested in our product with targeted marketing campaigns.
What is the legal basis for processing? (for EEA users)
If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have legal bases for doing so under applicable EU laws. This means we collect and use your information only where:
- It is necessary in order to provide you Exceed Digital services, including to set up and maintain an Exceed Digital account for you, to provide customer support and to protect the safety and security of our services;
- It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote our services and to protect our legal rights and interests;
- You give us consent to do so for a specific purpose; or
- It is needed to comply with a legal obligation.
We only collect and use your personal data with a lawful basis: with your consent, when it is necessary in order to provide our services, when we need to fulfill a legal obligation or when there’s a legitimate business reason behind.
How do we use your data?
We may process your personal data for several purposes. How we use your personal data depends on your subscription plan, on how you use the Exceed Digital services, and your preferences you have communicated to us.
We will use your personal data, such as Registration and Account Information, for the provision and maintenance of your user account, for authentication purposes, and for providing the Exceed Digital service to you and to other registered Exceed Digital users as designated by you.
We will process your Registration and Billing Information for billing purposes, i.e. to complete transactions, and send you related information, including purchase confirmations and invoices.
- We will send you technical notices, updates, security alerts, support and administrative messages. Please be aware that you cannot opt out of receiving certain service messages from us, including necessary security alerts and legal notices.
- We also send messages about how to use the services. You may change your communication preferences any time.
You cannot opt-out of emails which contain necessary information such as security alerts and legal notices.
We will send you emails with tips and tricks on how you can use Exceed Digital the best. You can change your email preferences anytime.
- We are always looking for ways to make Exceed Digital services better, faster, smarter, and more secure. We use aggregated web statistics and logs about how people use our services and feedback provided directly to us to troubleshoot and to identify trends, usage, activity patterns and improvement of our services.
- We also test and analyze certain new features with some users before rolling the feature out to all users.
We collect and analyze usage data from our users – this data is used for the research and development of our services.
- If you are an existing customer of Exceed Digital, we may use your email address and phone number provided to us to send you marketing communications, such as providing you with information about similar Tresorit products and services, unless you have opted-out.
- We may also use information about you, including web statistics and logs, to personalize the content and experience you receive on our websites or in our marketing communications, as well as by displaying Exceed Digital ads on other companies’ websites and applications, such as on platforms like Facebook and Google. Where legally required, we also seek your consent for sending marketing communications.
Some of your data is used for authentication. This is required to secure your account and to prevent fraud or theft.
- Occasionally, we connect personal information to information gathered in our log files as necessary to provide better customer experience and to improve our services. In such a case, we would treat the combined information in accordance with this policy.
- You may opt-out to send those statistics or logs any time by editing settings at device level, but please note that in this case, it might be more difficult to our support team to find the problem when something goes wrong.
Exceed Digital collects your activity and usage statistics to log files, which is also helpful when you require the assistance of our support team.
Protecting our legitimate business interests and legal rights
Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business.
We use mobile analytics software to allow us to better understand the functionality of our mobile application on your device. This software may record information such as how often you use the mobile application, the events that occur within the mobile application, aggregated usage, and performance data. While we use your information to produce aggregate insights, such insights do not identify you.
We use your data to generate aggregate user insights that we use to research and develop our product. These insights cannot be used to track your individual actions.
We may also process your data for any other purposes for which we obtain your consent where necessary or otherwise in accordance with applicable law and this policy.
Do we share your personal data with third parties?
We will share your personal data with third parties only in accordance with this policy. We will never sell your personal data to third parties. However, we may need to share some information, including personal data, we obtain from your use of our service in the following circumstances.
1) Complying with legal requirements
Exceed Digital may transmit personal data if the applicable legal provisions so require, or when such action is necessary to comply with any laws, including to meet national security or law enforcement requirements. We may also need to share personal data for the protection of our rights and interests, to protect your safety or the safety of others or to investigate fraud, in accordance with the applicable laws.
In certain cases, we may need to oblige to national security or law enforcement requirements and provide personal data to authorities.
2) Using third-party service providers
In certain cases we need to share information, including personal data with our third-party service providers. We use third-party service providers for a number of services, including application development, backup, storage, payment processing, analytics and other services. We require our third-party service providers to use the personal data that we share with them solely in connection with the services they provide to us. The current list of our service providers is available here.
As any other business, we may need to share personal data with other service providers that we use in our operation for billing, backup, analytics etc.
3) Sharing content by you
We may also share personal data with third parties when we have your consent to do so. For example, information, including personal data, will be shared with a third-party when you share content using our service with a third party. When you share content or content is shared with you – either by accepting, downloading, assessing a website link or invitation –, your activity, relevant metadata of file edits or downloads, might also be disclosed to the shared party. You acknowledge that once you shared all or a part of Your Encrypted Content by using our service with any person who accepted your invitation, such content goes out of your control and remains accessible to the extent you granted access. Accordingly, we ask you to pay special attention with whom you share Your Encrypted Content.
When you are a member of a shared folder, besides its content, your activity will also be visible to other members.
4) Your Subscription Owner
If your account is subject to Advanced Control, your Subscription Owner may also be able to access Your Encrypted Content as set out in section III of our Terms. You can always check whether Advanced Control is set up in respect of your account, under the Settings menu.
By accepting Advanced Control, you give your Subscription Owner permission to have cryptographic access to your files.
5) Business Transactions
We may assign or transfer this policy, as well as your account and related information and data, including any personal information, to any person or entity that acquires all or substantially all of our business, stock or assets, or with whom we merge.
Regardless of any changes that might happen in our company, your personal data will be protected in the same way as it is right now.
From time to time, we may post testimonials on our website that may contain personal data. We obtain your consent to post your name along with your testimonial. If you wish to update or delete your testimonial, you can contact us
If you choose to use our referral service to tell a friend about our products and services, we will ask you for your friend’s name and email address. We will automatically send your friend an email inviting him or her to visit our website and will store this information for the purpose of sending this initial email, tracking the success of our referral program and other marketing activities. We will not contact him or her more than once. Your referral may contact us to request that we remove their information from our database.
Where do we transfer your data?
We primarily store personal data within the EEA. Your personal data stored with us may also be transferred to countries outside of the EU. All such transfers of personal data are and will be made in accordance with applicable laws. You can reach the list of our current sub-processors here.
Your data may be transferred outside of the EEA in accordance with legal and regulatory requirements.
How do we protect your data?
We take appropriate technical and organizational measures to protect your personal data against loss or other forms of unlawful processing.
We protect your data with the highest level of security technology available.
We NEVER collect or store your files, encryption keys and passwords in an unencrypted or invertible form. The Encrypted Content and corresponding encryption keys can only be decrypted by you and persons with whom you explicitly share them with.
According to the best of Exceed Digital’s knowledge, the current state of the art and the public knowledge of the human race, Exceed Digital is unable to decrypt the Encrypted Content and accordingly, Exceed Digital cannot access it. As a result, we cannot use Your Encrypted Content to identify any individual.
How long will we retain your information?
A) Your Personal Data
We will retain your personal data as long as it is needed to fulfil the purposes specified above unless a longer retention period is required or permitted by law (such as tax, accounting or other legal requirements). When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymize it as soon as it is technically possible.
If your personal data is held by us on behalf of your company, we will retain such personal data in accordance with the terms and conditions of our data processing agreement with them, subject to applicable law.
Your privacy rights
You may ask us to:
- provide information to you about the personal data that we or our processors maintain about you,
- correct inaccuracies or amend your personal data,
- delete your personal data.
You can request this by send an email from contact us. We will respond to your request within thirty days. Please note that, we may ask you to verify your identity before complying with the request.
If you are from a country where the GDPR applies, you may have additional rights such as:
- In certain circumstances, you may have a broader right to erasure of your personal data. For example, if it is no longer necessary in relation to the purposes for which it was originally collected. Please note, however, that we may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations.
- You may have the right to request us to stop processing your personal data and/or to stop sending you marketing communications.
- You may have the right to request that we restrict processing of your personal data in certain circumstances (for example, where you believe that the personal data we hold about you is inaccurate or unlawfully held).
- In certain circumstances, you may have the right to be provided with your personal data in a structured, machine readable and commonly used format and to request that we transfer the personal data to another data controller without hindrance.
If you would like to exercise such rights, please contact us. We will consider your request in accordance with applicable laws. To protect your privacy and security, we may ask you to verify your identity before complying with the request.
If you want to exercise your data privacy rights, please email us. We may ask for proof of identity.
You also have the right to complain to a data protection authority or claim damages before the court. For more information, please contact your local data protection authority. A list of contact details for the EU data protection authorities is available here.
Withdrawal of consent
In cases where the processing of your personal data is based on your consent, you can withdraw your consent any time by editing settings at device level. In addition, you can also contact us. If you withdraw your consent, we will no longer process your personal data for the relevant purpose. However, please note that such withdrawal of your consent does not affect the lawfulness of our processing activities based on consent before its withdrawal.
You can change your email settings any time under the Profile tab, in My Account.
Changes to this policy
As every high-quality service, our service is constantly improved in effort to keep users satisfied, but these improvements necessarily mean changes. Due to the ongoing changes in the law and the changing nature of technology, data practices are changing from time to time. Thus, we reserve the right to alter or modify this policy when it is necessary.
If there are any material changes to this policy, you will be notified 30 days prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices. Your continued use of our website or our services constitutes your agreement to be bound by such changes to this policy. Your only remedy, if you do not accept the terms of this policy, is to discontinue use of our website and services.
This policy may change from time to time. Check back here every now and then to take a look.
Third party controllers
Our webpage or services may, from time to time, contain links to and from the websites or services of third parties. This policy does not extend to these external sites or companies, so please refer directly to their privacy policies.
Results may vary from individual to individual in calculating profits, and depend on the industry, capacity, advertising budget and other factors. The sales figures stated above are our own personal sales figures. Please understand our results are not typical, we’re not implying you’ll duplicate them (or do anything for that matter). The average person who follows any ‘how to’ information gets little to no results. We’re using these references for example purposes only. Your results may vary and depend on many factors including but not limited to your background, experience, and work ethic – we make no guarantees whatsoever. All business entails risk as well as massive and consistent effort and action. If you’re not willing to accept that, then we’re not a great fit for you.