Effective date: 25 March 2020
For Tresorit, security and data privacy are of paramount importance. This Privacy Policy describes our commitment to protect the privacy of individuals in accordance with the GDPR (The General Data Protection Regulation (GDPR) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union.).
The main content on the left contains the legally binding full-length version. To help you understand our Privacy Policy better, we collected some helpful notes on the right to sum up the key points of the main content.
Our mission is to make privacy and security available to people and businesses. That’s why we use end-to-end encryption to protect files and folders you share and store in the cloud.
We encrypt all and every transmission containing personal data using Secure Socket Layer technology (SSL) and apply additional, client-side encryption on the files and directories uploaded and stored in protected storage folders (the Encrypted Content).
We never collect or store your files, encryption keys and passwords in an unencrypted or invertible form. The Encrypted Content and corresponding encryption keys can only be decrypted by you and persons with whom you explicitly share them. However, if you have an account that is part of a Business Subscription with recovery master key, Your Encrypted Content may also be accessed by your Recovery Administrator (Tresorit Business Subscriptions are administered by one person who has an extended set of rights – the Recovery Administrator. They manage the billing and users, and can also put security measures in place to protect confidential company data.).
According to the best of Tresorit’s knowledge, the current state of the art and the public knowledge of the human race, Tresorit is unable to decrypt the Encrypted Content and accordingly, Tresorit cannot access it. As a result, we cannot use Your Encrypted Content to identify any individual.
However, when using the service, creating and using your user account, you also submit some non-encrypted data, which may include personal data as well.
ℹ️ In a nutshell: Even though we can’t read or access the files and folders you store in Tresorit, we need to process some of your personal data to provide you with services.
ℹ️ Your data is processed by Tresorit. However, if you are a part of a business subscription, certain data is processed upon the instructions of your organization.
ℹ️ Certain basic information, like your name and email address, is necessary for setting up a Tresorit account.
ℹ️ When you purchase a subscription, you also need to provide payment information, which will be handled by secure processing services.
ℹ️ Some information about your Tresorit Folders is unencrypted, like its name, size and members. This is needed for features like your activity wall.
ℹ️ When sharing content, Tresorit users can enable access logs or request an email verification from those who wish to download their content. In these cases certain information about you will be logged and shared with the content’s owners.
ℹ️ For verification purposes, certain information, such as your email address, may be shared with the requester of the file.
ℹ️ Sometimes, when you require assistance from our Sales and Support teams, you may choose to share additional information with us.
ℹ️ We collect data through cookies and similar technologies on our website.
ℹ️ We collect data from our website visitors – we can’t identify you directly without your consent.
ℹ️ We log website visits and application usage statistics to improve our services.
ℹ️ We also receive personal data when new users are invited to a business subscription or to a Tresorit Folder.
ℹ️ We reach out to audiences who might be interested in our product with targeted marketing campaigns.
ℹ️ We only collect and use your personal data with a lawful basis: with your consent, when it is necessary in order to provide our services, when we need to fulfill a legal obligation or when there’s a legitimate business reason behind.
ℹ️ You cannot opt-out of emails which contain necessary information such as security alerts and legal notices.
We will send you emails with tips and tricks on how you can use Tresorit the best. You can change your email preferences anytime.
ℹ️ We collect and analyze usage data from our users – this data is used for the research and development of our services.
ℹ️ Some of your data is used for authentication. This is required to secure your account and to prevent fraud or theft.
ℹ️ Tresorit collects your activity and usage statistics to log files, which is also helpful when you require the assistance of our support team.
ℹ️ We use your data to generate aggregate user insights that we use to research and develop our product. These insights cannot be used to track your individual actions.
ℹ️ In certain cases, we may need to oblige to national security or law enforcement requirements and provide personal data to authorities.
ℹ️ As any other business, we may need to share personal data with other service providers that we use in our operation for billing, backup, analytics etc.
ℹ️ When you are a member of a shared folder, besides its content, your activity will also be visible to other members.
ℹ️ By accepting Advanced Control, you give your Recovery Administrator permission to have cryptographic access to your files.
ℹ️ Regardless of any changes that might happen in our company, your personal data will be protected the same way as it is right now.
ℹ️ Your data may be transferred outside of the EEA in accordance with legal and regulatory requirements.
ℹ️ We protect your data with the highest level of security technology available.
ℹ️ If you want to exercise your data privacy rights, please email us. We may ask for proof of identity.
ℹ️ You can change your email settings any time under the Profile tab, in My Account.
ℹ️ This policy may change from time to time. Check back here every now and then to take a look.
We want to be as transparent as possible about the changes we make to our Privacy Policy. In this archive you can see the previous versions of the policy.