Privacy statement

Version 4.2 · in force from 1 March 2026 · replaces version 4.1 of 12 June 2025

1. Two roles, two sets of rules

DocShare B.V., Keizersgracht 241, 1016 EA Amsterdam (KvK 87654321), processes personal data in two distinct capacities, and it matters which one applies to you.

As a processor, when a customer organisation uses DocShare to send documents. The content of those documents, and the recipients they are addressed to, are determined by that organisation. They are the controller; we act only on their documented instructions under a data processing agreement.

As a controller, for our own website, our commercial contacts, our support desk and our security logging. Here we decide the purposes ourselves and answer for them directly.

2. Where we act as processor

When a customer seals a document with DocShare, we hold the following on their behalf:

CategoryWhat it isCan we read it?
Document contentThe file itselfNo — held only as ciphertext
ManifestDigest, page count, file name, algorithm suiteYes
Recipient addressEmail address or mobile number the link is dispatched toYes
Sender identityThe user and department that created the shareYes
Release recordVerification results, timestamps, source network, outcomeYes
PassphraseNever stored — only a derived value and a saltNo

We do not use any of this for our own purposes. We do not profile recipients, build audiences, train models on customer content, or sell anything to anyone.

3. Where we act as controller

For our own purposes we process:

  • Enquiry data — what you submit through the contact form or by email, to answer you and to administer the resulting commercial relationship. Legal basis: legitimate interest, and the performance of a contract once you become a customer.
  • Account data — names, business email addresses and roles of customer administrators and senders. Legal basis: performance of a contract.
  • Support correspondence — tickets and call notes, retained to resolve issues and to show what advice was given. Legal basis: legitimate interest.
  • Security telemetry — IP addresses, request metadata and abuse signals, used to detect attacks against the platform. Legal basis: legitimate interest in the security of a service that carries other people's confidential documents.
  • Statutory records — invoices and the accounting trail. Legal basis: legal obligation.

4. If you received a document through DocShare

You are not our customer and you have no relationship with us. The organisation that sent you the document decided to send it, chose your address, and is the controller for that processing. Questions about why you received something, what it contains, or how long it is kept belong to them.

What we do with your data is narrow and finite: we deliver one link, record the verification attempts and the release for the sender's audit trail, and stop. Your address is not added to any mailing list, and we do not contact you about anything else. We set no cookie before you act on the page, and the viewer carries no third-party analytics, advertising or tracking pixels of any kind.

5. Retention

DataKept for
Encrypted documentsUntil the share expires or is revoked; the wrapped key is then destroyed
Release and audit recordsSeven years by default, or as the customer configures
Security telemetry90 days, then aggregated
Enquiry data (no contract)12 months from last contact
Support correspondence3 years after the ticket closes
Invoices and accounts7 years (Dutch statutory retention)

6. Location and transfers

All processing takes place in the Netherlands, in two facilities in Amsterdam and Eindhoven. We do not transfer personal data outside the European Economic Area, and we do not engage sub-processors with access to customer content that are established or accessible from outside the EEA. Our current sub-processor register is published in the data processing agreement.

7. Your rights

Under the GDPR you may request access to your personal data, rectification, erasure, restriction, portability, and you may object to processing based on legitimate interest.

Where we act as processor, please direct these requests to the organisation that sent you the document — we are not permitted to act on them ourselves and will forward them. Where we act as controller, write to dpo@doc-share.online. We respond within one month, and will tell you promptly if we need the extension the regulation allows.

8. Cookies

This website sets no cookies at all. There is no analytics platform, no advertising network, no consent banner and nothing to opt out of. Web fonts are loaded from Google Fonts, which receives your IP address as part of that request; if that matters to you, we self-host the fonts on request for customer-facing deployments.

The recipient viewer sets one strictly necessary cookie, and only after you press “Unlock PDF”: a session identifier that ties the verification sequence to the release. It is deleted when you close the tab. No consent is required for it, and it is used for nothing else.

The sender console sets a session cookie and, if you choose it, a “remember this device” cookie valid for thirty days.

9. Contact and complaints

Data protection officer: dpo@doc-share.online
Postal: DocShare B.V., attn. DPO, Keizersgracht 241, 1016 EA Amsterdam

If you are not satisfied with our response, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), or with the supervisory authority in your country of residence.