Last updated: November 10, 2025

Privacy Policy

How Nomadesk collects, uses, protects and shares personal data when you use Nomadesk file sharing and EUDataVault S3 storage services.

This Privacy Policy applies to both Nomadesk file sharing and cloud storage services and EUDataVault S3 Storage services, both provided by Nomadesk BV.

We are committed to protecting your privacy and ensuring compliance with the General Data Protection Regulation (GDPR) and all applicable European data protection laws.

1. Introduction

Nomadesk BV ("we," "us," or "our") operates two distinct services: Nomadesk file sharing and cloud storage, and EUDataVault S3-compatible object storage. This Privacy Policy explains how we collect, use, protect, and share your personal data when you use either or both of these services. We process your data in accordance with the GDPR and other applicable European data protection legislation.

European data protection

All data processing activities are conducted within the European Union. We do not transfer personal data outside the EU/EEA except as explicitly stated in this policy and with appropriate safeguards in place.

2. Data controller

The data controller responsible for your personal data is:

Nomadesk BV

Foreestelaan 1

B-9000 Gent, Belgium

Company Registration: BE0465.918.714

Email: privacy@nomadesk.com

DPO contact: dpo@nomadesk.com

3. Data we collect

3.1 Account information (both services)

When you create an account, we collect:

  • Name and email address
  • Company name (for business accounts)
  • Billing address and payment information
  • Account credentials (encrypted passwords)
  • Phone number (optional)

3.2 Service usage data

Nomadesk file sharing:

  • File metadata (names, sizes, types, modification dates)
  • Folder structure and organization
  • Sharing settings and permissions
  • Sync activity and device information
  • Collaboration activity logs

EUDataVault S3 Storage:

  • Bucket names and configurations
  • Object metadata (keys, sizes, checksums)
  • API access patterns and request logs
  • Access credentials (access keys — hashed)
  • Storage usage metrics

3.3 Technical data

  • IP addresses and geolocation data
  • Browser type and version
  • Device identifiers and operating system
  • Referring URLs and page views
  • Session duration and interaction data

3.4 Communications

  • Support ticket content and correspondence
  • Email communications with our team
  • Feedback and survey responses

3.5 Your content

Important: content ownership

Your files and data remain yours. We do not claim ownership of any content you store using our services. For Nomadesk: files you upload and synchronise. For EUDataVault S3: objects and data stored in your buckets. We only access your content when necessary to provide the service, ensure security, or comply with legal obligations.

5. How we use your data

We use your personal data for the following purposes:

5.1 Service provision

  • Creating and managing your account
  • Storing, synchronising, and retrieving your files and data
  • Providing API access for S3-compatible storage
  • Enabling collaboration and file sharing features
  • Processing payments and managing subscriptions

5.2 Security & fraud prevention

  • Detecting and preventing unauthorised access
  • Monitoring for suspicious activity and abuse
  • Enforcing our Terms of Service
  • Protecting against malware and security threats

5.3 Customer support

  • Responding to your inquiries and support requests
  • Troubleshooting technical issues
  • Providing service updates and notifications

5.4 Service improvement

  • Analysing usage patterns to improve features
  • Conducting quality assurance and testing
  • Developing new features and services
  • Optimising performance and reliability

5.5 Communications

  • Sending service-related notifications (mandatory)
  • Sending marketing communications (with consent/opt-out option)
  • Requesting feedback and conducting surveys

6. Data sharing & third parties

6.1 We do not sell your data

We do not sell, rent, or trade your personal data to third parties for their marketing purposes.

6.2 Service providers

We may share data with trusted third-party service providers who assist us in operating our services:

  • Payment processors — to process billing and payments (PCI-DSS compliant)
  • Infrastructure providers — European data centres for hosting and storage
  • Email service providers — for transactional and marketing emails
  • Customer support tools — for managing support tickets
  • Analytics providers — for service improvement (anonymised where possible)

All service providers are contractually bound to GDPR-compliant data processing agreements and are only permitted to process data as instructed by us.

6.3 White-label infrastructure partner

For EUDataVault S3 Storage, we distribute storage services provided by our technology partner. Your storage data is processed by our partner under strict data processing agreements that ensure GDPR compliance and European data residency.

6.4 Legal requirements

We may disclose your data when required by law, including:

  • Compliance with legal obligations and valid legal processes
  • Responding to lawful requests from public authorities
  • Protecting our rights, property, and safety
  • Enforcing our Terms of Service

6.5 Business transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to the same privacy protections outlined in this policy.

7. Data location & international transfers

7.1 European data residency

Your data stays in Europe

All your data is stored exclusively in European Union data centres. We do not store your data in the United States or other non-EU countries.

7.2 Data centre locations

Our services use data centres located in:

  • Germany
  • Netherlands
  • Belgium

All data centres are ISO 27001 certified and comply with European data protection standards.

7.3 Limited international transfers

In rare cases where international data transfer is necessary, we ensure:

  • Standard Contractual Clauses (SCCs) are in place
  • Adequacy decisions by the European Commission are respected
  • Additional safeguards are implemented as required

8. Data security

We implement comprehensive security measures to protect your data.

8.1 Technical measures

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Regular security audits and penetration testing
  • Multi-factor authentication options
  • Intrusion detection and prevention systems

8.2 Organisational measures

  • Employee training on data protection
  • Access controls and least privilege principles
  • Regular security assessments
  • Incident response procedures
  • Data protection impact assessments

8.3 Incident response

In the event of a data breach affecting your personal data, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Notify affected individuals without undue delay when required
  • Document the breach and remediation measures
  • Take steps to mitigate harm and prevent future incidents

9. Data retention

We retain your data only as long as necessary for the purposes outlined in this policy.

9.1 Account data

Retained for the duration of your account and up to 30 days after account deletion to allow for account recovery.

9.2 Files and content

Retained for the duration of your subscription. Upon account termination, files are deleted within 30 days unless legally required to retain.

9.3 Billing records

Retained for 7 years as required by Belgian tax law.

9.4 Security logs

Retained for 12 months for security and fraud prevention purposes.

9.5 Support communications

Retained for 3 years after ticket resolution for quality assurance and legal purposes.

10. Your GDPR rights

Under GDPR, you have the following rights regarding your personal data:

Right of access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and to access that data.

Right to rectification (Article 16)

You have the right to correct inaccurate personal data and to complete incomplete data.

Right to erasure (Article 17)

You have the right to request deletion of your personal data under certain circumstances.

Right to restriction (Article 18)

You have the right to restrict processing of your personal data under certain circumstances.

Right to data portability (Article 20)

You have the right to receive your personal data in a structured, commonly used format.

Right to object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

Right to withdraw consent

Where processing is based on consent, you have the right to withdraw consent at any time.

How to exercise your rights

To exercise any of these rights, please contact us at: privacy@nomadesk.com. We will respond to your request within 30 days as required by GDPR.

Right to lodge a complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The lead supervisory authority for Nomadesk BV is the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, Belgium. Website: www.dataprotectionauthority.be

11. Cookies & tracking

11.1 Types of cookies we use

Essential cookies

Required for basic website functionality and security. Cannot be disabled.

Functional cookies

Remember your preferences and settings for improved user experience.

Analytics cookies

Help us understand how visitors use our website. Anonymised where possible.

Marketing cookies

Used to deliver relevant advertisements. Only with your consent.

11.2 Cookie consent

When you first visit our website, you will be presented with a cookie consent banner allowing you to accept or reject non-essential cookies. You can change your preferences at any time through our cookie settings.

11.3 Third-party tracking

We may use third-party analytics services such as Google Analytics. These services may set their own cookies. We configure these services to anonymise IP addresses where possible.

12. Children's privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16.

If you believe we have inadvertently collected data from a child under 16, please contact us immediately at privacy@nomadesk.com, and we will take steps to delete such information.

13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.

How we notify you

  • Email notification for significant changes
  • Notice on our website and within the application
  • Updated "Last modified" date at the top of this policy

Your continued use of our services after changes become effective constitutes acceptance of the updated policy.

14. Contact us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Postal address

Nomadesk BV

Foreestelaan 1

B-9000 Gent, Belgium

Company Registration: BE0465.918.714

General inquiries

info@nomadesk.com

Privacy-specific inquiries

privacy@nomadesk.com

Data Protection Officer

dpo@nomadesk.com

Questions about privacy?

We are here to help. Contact our Data Protection Officer with any privacy concerns.

Questions about privacy?

Speak to our Data Protection Officer.

We are happy to explain our data practices, assist with a data subject request, or provide a copy of our DPA.