Home / Legal
Privacy Policy
Last updated
This policy explains what personal information DatasetSync collects when you use DatasetSync, how we use it, and the choices you have. It also explains how data you upload is stored, including in our archival tier.
1. Our role
For account information (your name, email, sign-in activity and billing details) DatasetSync is the controller. For the files and metadata you upload ("Customer Data") we act as a processor on behalf of your organization, and process it only to provide the Service according to your instructions. A data processing agreement is available on request.
2. Information we collect
- Account data: name, email address, password hash, two-factor settings, organization memberships and roles.
- Billing data: plan, subscription status and invoices. Card details are handled by our payment processor and never stored by us.
- Usage and security data: IP addresses, user agents, API request logs, storage and egress metrics, and an audit log of sensitive actions in your organization.
- Customer Data: the content and metadata of the files you upload.
3. How we use it
We use account and usage data to operate, secure and bill for the Service, prevent abuse, provide support and send service emails (verification, password reset, invitations, billing). We do not sell personal information, use it for third-party advertising, or train models on Customer Data.
4. Archival storage and deletion
Archived data is stored with independent third-party providers
After upload, Customer Data is kept on our hot storage tier and archived to a durable archival tier. Archival splits files into segments, encrypts each segment, and stores the encrypted segments with independent third-party storage providers, which may be located around the world, under fixed-term storage contracts. These providers are outside our direct control.
When you delete a file, dataset or organization, we immediately remove it from our hot tier, revoke all access through the Service (including share links and presigned URLs) and stop renewing its archival storage. Data already stored by providers may persist on their systems until their existing storage contracts expire, and cannot be recalled earlier. For this reason we strongly recommend encrypting sensitive data client-side before uploading, and not uploading special-category personal data unencrypted.
5. Who we share data with
- Infrastructure providers that host our servers and hot storage tier.
- Independent third-party archival storage providers, for encrypted archived segments of Customer Data (see section 4).
- Our payment processor, for billing.
- Our email delivery provider, for transactional email.
- Authorities, when required by law or to protect the rights and safety of users and the public.
Anyone you give a share link, presigned URL or public dataset address to can access the data it covers until it expires or is revoked.
6. Retention
We keep account data while your account is active and for a limited period afterwards to meet legal, tax and security obligations. Audit logs are retained for the life of the organization. Customer Data is retained until you delete it, subject to section 4.
7. Security
Traffic is encrypted with TLS. Passwords and API keys are stored as hashes, two-factor authentication is available, and access to production systems is restricted and logged. No system is perfectly secure; we will notify affected customers of a personal data breach without undue delay.
8. Cookies
We set a single, strictly necessary cookie that keeps you signed in, plus a local preference for light or dark mode stored in your browser. We do not use advertising or analytics cookies and do not track you across other sites, so no cookie consent banner is shown.
9. Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal information, and to object to or restrict its processing. Most account data can be edited in the dashboard. For Customer Data that contains personal information, contact the organization that controls it. To exercise your rights, email [email protected].
10. International transfers
We and our providers may process data in countries other than yours, and archival storage providers operate globally. Where required, we rely on appropriate safeguards such as standard contractual clauses.
11. Changes and contact
We will post updates here and notify you of material changes. Questions or requests: [email protected].