Privacy Policy
How Nomadesk collects, uses, protects and shares personal data when you use Nomadesk file sharing and EUDataVault S3 storage services.
This Privacy Policy applies to both Nomadesk file sharing and cloud storage services and EUDataVault S3 Storage services, both provided by Nomadesk BV.
We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and all applicable European data protection laws.
1. Introduction
Nomadesk BV ("we," "us," or "our") operates two distinct services: Nomadesk file sharing and cloud storage, and EUDataVault S3-compatible object storage. This Privacy Policy explains how we collect, use, protect, and share your personal data when you use either or both of these services. We process your data in accordance with the GDPR and other applicable European data protection legislation.
European data protection
All data processing activities are conducted within the European Union. We do not transfer personal data outside the EU/EEA except as explicitly stated in this policy and with appropriate safeguards in place.
2. Data controller
The data controller responsible for your personal data is:
Nomadesk BV
Foreestelaan 1
B-9000 Gent, Belgium
Company Registration: BE0465.918.714
Email: privacy@nomadesk.com
DPO contact: dpo@nomadesk.com
3. Data we collect
3.1 Account information (both services)
When you create an account, we collect:
- Name and email address
- Company name (for business accounts)
- Billing address and payment information
- Account credentials (encrypted passwords)
- Phone number (optional)
3.2 Service usage data
Nomadesk file sharing:
- File metadata (names, sizes, types, modification dates)
- Folder structure and organization
- Sharing settings and permissions
- Sync activity and device information
- Collaboration activity logs
EUDataVault S3 Storage:
- Bucket names and configurations
- Object metadata (keys, sizes, checksums)
- API access patterns and request logs
- Access credentials (access keys — hashed)
- Storage usage metrics
3.3 Technical data
- IP addresses and geolocation data
- Browser type and version
- Device identifiers and operating system
- Referring URLs and page views
- Session duration and interaction data
3.4 Communications
- Support ticket content and correspondence
- Email communications with our team
- Feedback and survey responses
3.5 Your content
Important: content ownership
Your files and data remain yours. We do not claim ownership of any content you store using our services. For Nomadesk: files you upload and synchronise. For EUDataVault S3: objects and data stored in your buckets. We only access your content when necessary to provide the service, ensure security, or comply with legal obligations.
4. Legal basis for processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
4.1 Contract performance (Article 6(1)(b))
Processing is necessary to provide the services you have subscribed to, including account management, file storage and synchronisation, API access, billing, and customer support.
4.2 Legal obligation (Article 6(1)(c))
Processing required to comply with legal obligations such as tax laws, financial reporting requirements, and law enforcement requests.
4.3 Legitimate interests (Article 6(1)(f))
Processing based on our legitimate interests in:
- Preventing fraud and ensuring service security
- Improving and optimising our services
- Network and information security
- Direct marketing to existing customers (with opt-out option)
4.4 Consent (Article 6(1)(a))
For optional features such as marketing communications, analytics cookies, and optional data processing activities. You may withdraw consent at any time.
5. How we use your data
We use your personal data for the following purposes:
5.1 Service provision
- Creating and managing your account
- Storing, synchronising, and retrieving your files and data
- Providing API access for S3-compatible storage
- Enabling collaboration and file sharing features
- Processing payments and managing subscriptions
5.2 Security & fraud prevention
- Detecting and preventing unauthorised access
- Monitoring for suspicious activity and abuse
- Enforcing our Terms of Service
- Protecting against malware and security threats
5.3 Customer support
- Responding to your inquiries and support requests
- Troubleshooting technical issues
- Providing service updates and notifications
5.4 Service improvement
- Analysing usage patterns to improve features
- Conducting quality assurance and testing
- Developing new features and services
- Optimising performance and reliability
5.5 Communications
- Sending service-related notifications (mandatory)
- Sending marketing communications (with consent/opt-out option)
- Requesting feedback and conducting surveys
6. Data sharing & third parties
6.1 We do not sell your data
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
6.2 Service providers
We may share data with trusted third-party service providers who assist us in operating our services:
- Payment processors — to process billing and payments (PCI-DSS compliant)
- Infrastructure providers — European data centres for hosting and storage
- Email service providers — for transactional and marketing emails
- Customer support tools — for managing support tickets
- Analytics providers — for service improvement (anonymised where possible)
All service providers are contractually bound to GDPR-compliant data processing agreements and are only permitted to process data as instructed by us.
6.3 White-label infrastructure partner
For EUDataVault S3 Storage, we distribute storage services provided by our technology partner. Your storage data is processed by our partner under strict data processing agreements that ensure GDPR compliance and European data residency.
6.4 Legal requirements
We may disclose your data when required by law, including:
- Compliance with legal obligations and valid legal processes
- Responding to lawful requests from public authorities
- Protecting our rights, property, and safety
- Enforcing our Terms of Service
6.5 Business transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections outlined in this policy.
7. Data location & international transfers
7.1 European data residency
Your data stays in Europe
All your data is stored exclusively in European Union data centres. We do not store your data in the United States or other non-EU countries.
7.2 Data centre locations
Our services use data centres located in:
- Germany
- Netherlands
- Belgium
All data centres are ISO 27001 certified and comply with European data protection standards.
7.3 Limited international transfers
In rare cases where international data transfer is necessary, we ensure:
- Standard Contractual Clauses (SCCs) are in place
- Adequacy decisions by the European Commission are respected
- Additional safeguards are implemented as required
8. Data security
We implement comprehensive security measures to protect your data.
8.1 Technical measures
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Regular security audits and penetration testing
- Multi-factor authentication options
- Intrusion detection and prevention systems
8.2 Organisational measures
- Employee training on data protection
- Access controls and least privilege principles
- Regular security assessments
- Incident response procedures
- Data protection impact assessments
8.3 Incident response
In the event of a data breach affecting your personal data, we will:
- Notify the relevant supervisory authority within 72 hours
- Notify affected individuals without undue delay when required
- Document the breach and remediation measures
- Take steps to mitigate harm and prevent future incidents
9. Data retention
We retain your data only as long as necessary for the purposes outlined in this policy.
9.1 Account data
Retained for the duration of your account and up to 30 days after account deletion to allow for account recovery.
9.2 Files and content
Retained for the duration of your subscription. Upon account termination, files are deleted within 30 days unless legally required to retain.
9.3 Billing records
Retained for 7 years as required by Belgian tax law.
9.4 Security logs
Retained for 12 months for security and fraud prevention purposes.
9.5 Support communications
Retained for 3 years after ticket resolution for quality assurance and legal purposes.
10. Your GDPR rights
Under GDPR, you have the following rights regarding your personal data:
Right of access (Article 15)
You have the right to obtain confirmation of whether we process your personal data and to access that data.
Right to rectification (Article 16)
You have the right to correct inaccurate personal data and to complete incomplete data.
Right to erasure (Article 17)
You have the right to request deletion of your personal data under certain circumstances.
Right to restriction (Article 18)
You have the right to restrict processing of your personal data under certain circumstances.
Right to data portability (Article 20)
You have the right to receive your personal data in a structured, commonly used format.
Right to object (Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Right to withdraw consent
Where processing is based on consent, you have the right to withdraw consent at any time.
How to exercise your rights
To exercise any of these rights, please contact us at: privacy@nomadesk.com. We will respond to your request within 30 days as required by GDPR.
Right to lodge a complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for Nomadesk BV is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, Belgium. Website: www.dataprotectionauthority.be
12. Children's privacy
Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16.
If you believe we have inadvertently collected data from a child under 16, please contact us immediately at privacy@nomadesk.com, and we will take steps to delete such information.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
How we notify you
- Email notification for significant changes
- Notice on our website and within the application
- Updated "Last modified" date at the top of this policy
Your continued use of our services after changes become effective constitutes acceptance of the updated policy.
14. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Postal address
Nomadesk BV
Foreestelaan 1
B-9000 Gent, Belgium
Company Registration: BE0465.918.714
General inquiries
Privacy-specific inquiries
Data Protection Officer
Questions about privacy?
We are here to help. Contact our Data Protection Officer with any privacy concerns.