This Privacy Policy explains how Permafiles Ltd ("Permafiles", "we", "us" or "our") collects, uses, stores and otherwise processes personal data when you visit our website, create or use a Permafiles account, purchase or use our services, contact us, or otherwise interact with us.
Permafiles is established in the United Kingdom and provides cloud-based file hosting, storage and sharing services to customers in the United Kingdom and the European Economic Area (EEA), including consumers and businesses.
We process personal data in accordance with applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Where the EU General Data Protection Regulation (EU GDPR) applies to our processing, we also comply with its applicable requirements.
The controller responsible for the processing described in this Privacy Policy can be found in section 24.
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us using the privacy contact details below.
Depending on how you interact with Permafiles, we may collect the following categories of personal data:
We collect personal data directly from you when you create an account, purchase a service, contact us, submit a form, communicate with support, or otherwise provide information to us.
We also collect certain technical and security information automatically when you use our website or services, including information generated by your browser, device, network connection and interactions with our systems.
We may receive personal data from service providers involved in payments, security, hosting, storage or other functions necessary to provide our services.
We use personal data only where we have a lawful basis to do so. Depending on the circumstances, we may use personal data to:
The lawful basis depends on the particular processing activity. We may rely on:
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
When you register for or purchase a Permafiles service, we process the information necessary to establish and administer your customer relationship. This may include your name, email address, contact details, account information, subscription information, billing records and relevant technical information.
We use this information to provide the service, administer your subscription, communicate with you about important service matters, process payments and comply with applicable legal obligations.
Service-related communications, such as security notices, account notices, billing information and important changes to the service, are not treated as optional marketing communications.
Permafiles provides online file storage and sharing services. Files and other content that you choose to upload or store through your Permafiles account are processed as necessary to provide the service you have requested.
Where you use Permafiles to store personal data relating to other individuals, you are responsible for ensuring that your use of the service complies with applicable data protection law. Depending on the circumstances, Permafiles may process such personal data on your behalf as a data processor, while you or your organisation remains the controller.
Permafiles does not use customer files for advertising or unrelated commercial purposes. Access to customer content is limited to what is necessary to provide, maintain, secure and support the service, or where access is required by law or necessary to protect our systems, users or rights.
Customer files are currently stored using third-party cloud storage infrastructure located in the United Kingdom.
Permafiles may change or add storage regions or infrastructure providers in the future. If such changes involve an international transfer of personal data, we will ensure that the transfer is carried out in accordance with applicable data protection law.
Permafiles uses third-party hosting and infrastructure providers to operate its services. Our application and server infrastructure may be hosted using providers located in the United Kingdom and European Economic Area.
Customer file storage is provided through third-party cloud storage infrastructure. Different categories of personal data may therefore be processed by different providers and in different locations.
We require relevant service providers to process personal data only as necessary for the services they provide and to maintain appropriate security and confidentiality measures.
We use selected third-party providers to operate and support Permafiles. Depending on the service you use, these may include:
We do not sell your personal data to third parties.
We may share personal data with trusted service providers where this is necessary to provide, maintain, secure or support our services, process payments, prevent fraud, comply with legal obligations, or otherwise perform functions on our behalf.
Where a service provider processes personal data on our behalf, we require it to process that data only as necessary for the services it provides and to maintain appropriate security and confidentiality measures.
Some third-party providers may process personal data under their own privacy terms and may act as independent controllers for particular processing activities, where applicable. For example, payment providers may process payment and transaction information under their own terms and privacy policies.
We do not permit third-party service providers to use customer files or personal data for their own unrelated advertising or commercial purposes where they are processing that information on our behalf.
We may appoint additional processors or service providers where reasonably necessary to operate, secure or improve the service. Where required by applicable law, appropriate contractual and other safeguards will be put in place.
Payments may be processed through third-party payment service providers. Relevant payment and transaction information may be processed as necessary to complete transactions, prevent fraud, comply with legal obligations and administer the payment relationship.
Payment providers may process personal data under their own privacy terms and may act as independent controllers for certain processing activities. Permafiles does not receive or store full payment-card credentials where those credentials are handled directly by the payment provider.
We use third-party network, security and infrastructure services to help deliver the website and services and to protect against malicious, abusive or unauthorised traffic. Depending on the services used, these providers may process technical information such as IP addresses, request information, security events, browser or device information and related network data.
These providers process data under applicable data-processing terms and appropriate transfer safeguards.
Permafiles may use cookies and similar technologies that are necessary for website operation, security, account functionality and, where applicable, analytics or marketing.
Strictly necessary technologies may be used where permitted without consent. Non-essential cookies and similar technologies will be used only where the required consent has been obtained, or where another lawful basis permitted by applicable law applies.
For full details of the cookies and similar technologies used on the website, including their purposes and how to manage your choices, please see our separate Cookie Policy.
We may send service-related communications where necessary to administer your account or provide the service.
Where marketing consent is required, we will ask for it and provide a straightforward way to withdraw it. You can unsubscribe from marketing communications at any time using the unsubscribe mechanism provided in the communication or by contacting us.
We retain personal data only for as long as necessary for the purposes for which it was collected, including to provide services, maintain appropriate business and security records, resolve disputes, enforce agreements and comply with legal obligations.
Retention periods vary depending on the type of information and the reason it is processed. When personal data is no longer required, we will securely delete it or anonymise it where appropriate.
When a Permafiles account or subscription ends, customer files may be deleted in accordance with the applicable service terms and account-deletion process. Customers are responsible for maintaining their own independent backups where appropriate.
Permafiles is established in the United Kingdom and provides services to customers in the UK and EEA.
Customer files are currently stored in the United Kingdom. Our application and service infrastructure may be hosted or processed within the United Kingdom and European Economic Area.
We may use other service providers that process personal data outside the UK or EEA. Where a restricted transfer occurs, we will ensure that an appropriate transfer mechanism is in place, such as an applicable adequacy decision, appropriate contractual safeguards or another lawful transfer mechanism.
Where the EU GDPR applies, we will comply with its requirements for transfers of personal data outside the EEA.
Subject to applicable law and any relevant exemptions, you may have the right to:
These rights are not absolute and may be subject to legal conditions or exemptions.
To exercise your rights or ask a question about how we process your personal data, contact us using the privacy contact details in section 2.
We may need to verify your identity before responding to a request. We will normally respond within the period required by applicable data protection law.
If you are in the United Kingdom, you have the right to complain to the Information Commissioner's Office (ICO), the UK's independent supervisory authority for data protection.
If you are in the EEA, you may also have the right to complain to the data protection supervisory authority in the EEA country where you live, work or believe an infringement occurred.
Because Permafiles Ltd is established in the UK and offers services to customers in the EEA, the EU GDPR may apply to some of our processing activities. Depending on the nature and scope of the processing, the EU GDPR may require a UK organisation without an EEA establishment to appoint an EEA representative.
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
These measures may include access controls, authentication, encryption in transit, security monitoring, infrastructure protection and other safeguards appropriate to the risks involved.
No internet-based service can be guaranteed to be completely secure. You are also responsible for maintaining appropriate security of your account credentials and for maintaining independent backups of important customer content.
Permafiles does not intend to make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you. If this changes, we will provide the information required by applicable law.
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements or data-processing practices.
When we make material changes, we will take reasonable steps to bring the updated policy to your attention. The latest version will be published on this page with its effective date.
For privacy questions, requests or concerns, please contact:
Permafiles Ltd
Unit 4, Maryfield Green
United Kingdom
[email protected]
Effective date: 2 September 2026
