nullsend
How it works Features Pricing Enterprise Security
Sign in Get started
nullsend
How it works Features Pricing Enterprise Security
Sign in Get started
Legal

Data Processing Agreement

Last updated: 2 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Nullsend and the customer using the Nullsend service ("Customer"). It governs how Nullsend processes personal data on the Customer's behalf, and reflects the requirements of UK GDPR and EU GDPR (Article 28).

Nullsend Ltd is a company registered in England & Wales with company number 17266592. References to "Nullsend", "we", "us" and "our" mean Nullsend Ltd.

1. Roles

For the personal data contained in the files a Customer sends, and the recipient details a Customer enters, the Customer is the data controller and Nullsend is the data processor. We process that data only to provide the service, and only on the Customer's documented instructions (which include the Customer's use of the service and this DPA).

For the Customer's own account information (such as the account holder's email and company name), Nullsend is a controller; that processing is covered by our Privacy Notice.

2. The nature of what we process

This is the most important clause, because of how the service is built.

Files are encrypted in the Customer's (or their sender's) browser before they reach us. The key needed to decrypt them lives in the share link, in the part after the "#", which by web standards is not transmitted to our servers in normal use. As a result, we hold the contents of files only as ciphertext, and we cannot read, scan, index, or otherwise access them. This is a property of the architecture, not a policy commitment.

One honest exception, stated upfront. If a Customer or their user chooses to have Nullsend email a transfer link on their behalf (an optional convenience, not the default), that link must contain the decryption key, because a link without the key cannot be opened by its recipient. In that single case the key passes through our email system and is held only transiently, long enough to send the message, and is then purged from the mail record. This is the only circumstance in which a key reaches Nullsend. It does not let us read any file: we would still need to combine that key with the matching ciphertext, which we do not do. Customers who want the key never to touch our systems can simply copy and share links themselves rather than asking us to email them.

The personal data we process on the Customer's behalf therefore consists of:

  • File contents, held only as ciphertext that we cannot read.
  • Transfer metadata: file sizes, dates, download counts.
  • Recipient email addresses entered by a sender so we can deliver notifications.

We process this for the purpose of operating the file transfer service, for the duration of the Customer's use of it.

3. Our obligations as processor

We will:

  • Process personal data only on the Customer's documented instructions, including for transfers outside the UK or EU, unless required to do otherwise by law (in which case we will inform the Customer first, where legally permitted).
  • Ensure that anyone authorised to process the data is bound by confidentiality.
  • Implement appropriate technical and organisational security measures (set out in Section 6).
  • Respect the conditions in this DPA for engaging sub-processors (Section 5).
  • Assist the Customer, taking into account the nature of the processing, in responding to data subject rights requests.
  • Assist the Customer in meeting its obligations around security, breach notification, and data protection impact assessments, taking into account the information available to us.
  • Delete the personal data at the end of the service, as set out in Section 7.
  • Make available the information needed to demonstrate compliance with these obligations, as set out in Section 8.

4. The Customer's responsibilities

The Customer warrants that it has a lawful basis for the personal data it sends through the service, and that its instructions to us comply with applicable data protection law. The Customer is responsible for the content of the files it sends and the accuracy of the recipient details it provides.

5. Sub-processors

The Customer authorises Nullsend to engage the following sub-processors to provide the service:

Sub-processorPurposeLocation
HetznerHosting and infrastructureEuropean Union (Finland)
Backblaze B2Encrypted file storageEuropean Union
StripePayment processingUnited States
PostmarkSending transactional emailUnited States
CloudflareDNS and bot protection (Turnstile)Global network
AnthropicAI onboarding assistant (signup conversation only; never file contents or recipient data)United States

Each sub-processor is bound by data protection terms no less protective than those in this DPA. Because file contents are ciphertext, our storage and infrastructure sub-processors cannot read them.

If we intend to add or replace a sub-processor, we will give the Customer reasonable prior notice and an opportunity to object on reasonable data protection grounds. If the Customer objects and we cannot offer a reasonable alternative, the Customer may terminate the affected service.

6. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • End-to-end encryption: file contents are encrypted in the browser before upload, and the server is never given the decryption key to store or deliver files (see the opt-in email exception in clause 2). We cannot access file contents.
  • Encryption in transit (TLS) for all connections to the service.
  • Storage of file ciphertext within the European Union.
  • Access controls and authentication, including hashed passwords (Argon2id) and bot protection at sign-in and signup.
  • Minimisation of personal data, including not logging IP addresses beyond a 30 day security retention window, and not using analytics or tracking.
  • Separation of production and development systems, and encrypted, access-controlled backups held for a limited period.

Because the contents of files are never available to us in readable form, the personal data within them is protected even in the event of a breach of our systems.

7. Data deletion

Files are deleted automatically on the expiry schedule set when they are sent, or on first download where that option is chosen. On termination of the service, or on the Customer's request, we will delete the personal data we process on the Customer's behalf from our active systems. Data already deleted falls out of encrypted backups as they rotate, within the backup retention period. We will not retain personal data longer than needed to provide the service or as required by law.

8. Audit and demonstrating compliance

We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including a description of our security measures and answers to reasonable security questions. Given the scale of the service, audits take the form of providing this documentation and responding to reasonable written requests, rather than on-site inspection. We will update this approach as the service matures.

9. Personal data breaches

If we become aware of a personal data breach affecting the Customer's data, we will notify the Customer without undue delay, and in any event within 72 hours of becoming aware. The notification will include, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed. We will cooperate with the Customer and take reasonable steps to mitigate the breach.

10. International transfers

File ciphertext and Customer account data are stored within the European Union. Some sub-processors (Stripe, Postmark, and Anthropic) are based in the United States; where personal data reaches them, the transfer is protected by appropriate safeguards under UK and EU data protection law, such as Standard Contractual Clauses and applicable data transfer frameworks. File contents remain ciphertext throughout, so the providers involved cannot read them.

11. Duration

This DPA applies for as long as Nullsend processes personal data on the Customer's behalf, and survives termination of the service until that data has been deleted in accordance with Section 7.

12. Changes

If we change this DPA, we will update it and change the date above. For changes that materially affect the Customer's rights, we will take reasonable steps to notify the Customer.

13. Contact

Questions about this DPA or our data processing: privacy@nullsend.io

Nullsend Ltd

nullsend

Privacy-first file transfer for business. Built in the UK. Servers in the EU. Files encrypted in your browser.

Product

  • How it works
  • Features
  • Pricing
  • Enterprise
  • Security

Legal

  • Privacy notice
  • Terms
  • DPA
  • Sub-processors
  • Child safety
  • Report abuse
  • security.txt
© 2026 Nullsend Ltd. Registered in England & Wales, company number 17266592.
hello@nullsend.io