Last updated: 2 June 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Nullsend and the customer using the Nullsend service ("Customer"). It governs how Nullsend processes personal data on the Customer's behalf, and reflects the requirements of UK GDPR and EU GDPR (Article 28).
Nullsend Ltd is a company registered in England & Wales with company number 17266592. References to "Nullsend", "we", "us" and "our" mean Nullsend Ltd.
For the personal data contained in the files a Customer sends, and the recipient details a Customer enters, the Customer is the data controller and Nullsend is the data processor. We process that data only to provide the service, and only on the Customer's documented instructions (which include the Customer's use of the service and this DPA).
For the Customer's own account information (such as the account holder's email and company name), Nullsend is a controller; that processing is covered by our Privacy Notice.
This is the most important clause, because of how the service is built.
Files are encrypted in the Customer's (or their sender's) browser before they reach us. The key needed to decrypt them lives in the share link, in the part after the "#", which by web standards is not transmitted to our servers in normal use. As a result, we hold the contents of files only as ciphertext, and we cannot read, scan, index, or otherwise access them. This is a property of the architecture, not a policy commitment.
One honest exception, stated upfront. If a Customer or their user chooses to have Nullsend email a transfer link on their behalf (an optional convenience, not the default), that link must contain the decryption key, because a link without the key cannot be opened by its recipient. In that single case the key passes through our email system and is held only transiently, long enough to send the message, and is then purged from the mail record. This is the only circumstance in which a key reaches Nullsend. It does not let us read any file: we would still need to combine that key with the matching ciphertext, which we do not do. Customers who want the key never to touch our systems can simply copy and share links themselves rather than asking us to email them.
The personal data we process on the Customer's behalf therefore consists of:
We process this for the purpose of operating the file transfer service, for the duration of the Customer's use of it.
We will:
The Customer warrants that it has a lawful basis for the personal data it sends through the service, and that its instructions to us comply with applicable data protection law. The Customer is responsible for the content of the files it sends and the accuracy of the recipient details it provides.
The Customer authorises Nullsend to engage the following sub-processors to provide the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner | Hosting and infrastructure | European Union (Finland) |
| Backblaze B2 | Encrypted file storage | European Union |
| Stripe | Payment processing | United States |
| Postmark | Sending transactional email | United States |
| Cloudflare | DNS and bot protection (Turnstile) | Global network |
| Anthropic | AI onboarding assistant (signup conversation only; never file contents or recipient data) | United States |
Each sub-processor is bound by data protection terms no less protective than those in this DPA. Because file contents are ciphertext, our storage and infrastructure sub-processors cannot read them.
If we intend to add or replace a sub-processor, we will give the Customer reasonable prior notice and an opportunity to object on reasonable data protection grounds. If the Customer objects and we cannot offer a reasonable alternative, the Customer may terminate the affected service.
We maintain technical and organisational measures appropriate to the risk, including:
Because the contents of files are never available to us in readable form, the personal data within them is protected even in the event of a breach of our systems.
Files are deleted automatically on the expiry schedule set when they are sent, or on first download where that option is chosen. On termination of the service, or on the Customer's request, we will delete the personal data we process on the Customer's behalf from our active systems. Data already deleted falls out of encrypted backups as they rotate, within the backup retention period. We will not retain personal data longer than needed to provide the service or as required by law.
We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including a description of our security measures and answers to reasonable security questions. Given the scale of the service, audits take the form of providing this documentation and responding to reasonable written requests, rather than on-site inspection. We will update this approach as the service matures.
If we become aware of a personal data breach affecting the Customer's data, we will notify the Customer without undue delay, and in any event within 72 hours of becoming aware. The notification will include, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. We will cooperate with the Customer and take reasonable steps to mitigate the breach.
File ciphertext and Customer account data are stored within the European Union. Some sub-processors (Stripe, Postmark, and Anthropic) are based in the United States; where personal data reaches them, the transfer is protected by appropriate safeguards under UK and EU data protection law, such as Standard Contractual Clauses and applicable data transfer frameworks. File contents remain ciphertext throughout, so the providers involved cannot read them.
This DPA applies for as long as Nullsend processes personal data on the Customer's behalf, and survives termination of the service until that data has been deleted in accordance with Section 7.
If we change this DPA, we will update it and change the date above. For changes that materially affect the Customer's rights, we will take reasonable steps to notify the Customer.
Questions about this DPA or our data processing: privacy@nullsend.io
Nullsend Ltd