PRIVACY · 24 SEPTEMBER 2026
How SendVeil handles data
This notice explains our data practices and the controls available for GDPR / DSGVO requests.
SendVeil is operated by Michael König-Weichhardt. For privacy requests, contact privacy@sendveil.link.
What we process
We store a workspace member’s email address, role, session records, billing identifiers if a paid plan is used, transfer titles and filenames, brand settings, and the original files the sender chooses to upload. We also keep a small audit record of workspace actions. Recipient links do not require an account or a recipient email address.
Why we process it
Account and transfer data are needed to provide the service, enforce storage limits, deliver files, and respond to support requests. Security records help prevent misuse. Where applicable, the legal bases are performance of a contract and our legitimate interest in operating a secure service. The workspace owner controls the content uploaded for recipients and is responsible for any notices or legal basis needed for that content.
Where it goes
Original transfer files and workspace state use Cloudflare storage and Durable Objects configured with EU jurisdiction. Cloudflare also handles delivery, security, and operational data; this EU storage configuration does not mean every network log or Cloudflare metadata item stays in the EU. Magic-link emails are sent through Cloudflare Email Service. Messages sent to our support or privacy addresses are routed by Cloudflare to the operator’s Google mailbox. When paid checkout becomes available, Stripe will handle payment and billing data.
How long it stays
Transfers expire according to the workspace’s selected retention period, currently 3 to 365 days depending on the plan. A free or otherwise unpaid workspace is deleted after 180 days without account activity; a successful sign-in resets that period. An active paid subscription keeps its workspace. Account deletion removes workspace data and file objects. Audit records remain with the workspace until its deletion. Providers may retain their own operational and legally required records under their policies.
Cookies and security
We use essential session and CSRF cookies to keep sign-in secure. We do not use advertising trackers. Files are held in private storage and delivered only through authorized links. A person with a valid recipient link can access its files until the link expires; senders can add a password.
Your choices and rights
Workspace owners can export account metadata or delete their account in the workspace settings. You can ask us about access, correction, deletion, restriction, or portability at privacy@sendveil.link. You can also complain to your local data protection authority; in Austria this is the Datenschutzbehörde.