Documents for companies
Data processing agreement (DPA)
under Art. 28 of the General Data Protection Regulation (GDPR) between the customer as controller and HSE Support Germany s.r.o. as processor.
Parties
Controller: the customer who uses MoveMyFile for business, school, club or other not purely private purposes (the “customer”).
Processor: HSE Support Germany s.r.o., Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic, company register C 152831, Regional Court in Brno, company ID (IČO) 29772745, represented by the managing director Renata Havlíková (“MoveMyFile”). Data protection contact: support@movemyfile.eu.
§ 1 Subject and term
MoveMyFile processes personal data on behalf of the customer to provide the MoveMyFile service under the terms of use: storing, sending and sharing files and photos, recipient lists, upload requests, transfers between one’s own devices, teams and the related notifications.
This agreement applies as long as the customer uses MoveMyFile and ends with the deletion of the account or team. Obligations on deletion, confidentiality and evidence continue beyond that.
§ 2 Nature, purpose, data and data subjects
Nature and purpose: hosting, storage, transfer to the recipients chosen by the customer, creating previews of photos, logging access, sending e-mails and notifications.
Types of data: content of uploaded files (which may contain any personal data the customer uploads), file names and metadata, account data (name, e-mail address), data of recipients and lists (name, e-mail address), comments and notes, access and device protocols (time, device name, country and city of the connection).
Data subjects: the customer’s users (employees, members, teachers), recipients of files and links, people who send files or sign up through upload requests or QR codes, and people shown or named in the files.
MoveMyFile does not specifically process special categories of personal data (Art. 9 GDPR). If the customer uploads such data, the customer is responsible for the lawfulness; the measures in Annex 2 protect all content alike.
§ 3 Instructions
MoveMyFile processes the data only on documented instructions from the customer. The instructions are set out in this agreement, the terms of use and the settings the customer makes in the application (e.g. shares, expiry dates, deletions). Further instructions are given in text form to support@movemyfile.eu.
If MoveMyFile considers that an instruction infringes data protection law, it informs the customer without delay and may suspend carrying it out until clarified.
There is no processing for MoveMyFile’s own purposes; MoveMyFile does not sell data, show advertising or use content to train AI models. Exceptions apply only where Union or Member State law requires processing; MoveMyFile then informs the customer in advance unless the law prohibits it.
§ 4 Confidentiality
MoveMyFile uses only persons who have committed themselves to confidentiality or are under a statutory obligation of confidentiality. Access is limited to what operation requires.
§ 5 Security of processing
MoveMyFile takes the technical and organisational measures under Art. 32 GDPR described in Annex 2. The measures may be developed further as long as the level of protection is not reduced; significant changes are documented and published on the Annex 2 page.
§ 6 Sub-processors
The customer gives general authorisation to use the sub-processors listed in Annex 3. MoveMyFile concludes a contract with each that ensures at least the level of protection of this agreement.
MoveMyFile informs about intended changes at least 30 days in advance by e-mail to registered customers and on the Annex 3 page. The customer may object for an important data protection reason; if no solution is found, the customer may terminate before the change takes effect.
Transfers to third countries take place only under Art. 44 et seq. GDPR (e.g. adequacy decision, EU–US Data Privacy Framework, standard contractual clauses). Files are stored in storage bound to the EU jurisdiction, the database in Frankfurt am Main.
§ 7 Assistance
MoveMyFile assists the customer in fulfilling data subjects’ rights (Art. 15–22 GDPR). Much of it the customer can do in the application: download and delete files, stop shares, remove people from lists, delete the account. Requests from data subjects that reach MoveMyFile are forwarded to the customer without delay.
MoveMyFile also assists with data protection impact assessments and consultations of the supervisory authority with the information available to it.
§ 8 Personal data breaches
MoveMyFile notifies the customer of a personal data breach without undue delay, as a rule within 48 hours of becoming aware of it, at the e-mail address on file. The notification contains, as far as known, the nature of the breach, the data and people concerned, likely consequences and measures taken; missing details follow.
MoveMyFile immediately takes the measures needed to secure the data and mitigate possible adverse effects and assists the customer with its obligations under Art. 33 and 34 GDPR.
§ 9 Deletion and return
The customer can download (individually or as ZIP) and delete its files at any time. When the account or team is deleted, files and personal data are deleted immediately; database backups are overwritten within about 7 days.
Excepted are data MoveMyFile must keep by law and evidence needed to document proper processing (e.g. records of reports of illegal content).
§ 10 Evidence and audits
MoveMyFile makes available the information needed to demonstrate compliance: this agreement, Annexes 2 and 3, independent test results (Security page) and, on request, completed security questionnaires and information.
The customer or an auditor bound to confidentiality may also carry out audits, as a rule once a year, announced at least 30 days in advance, during business hours and without disrupting operations; at short notice after a data breach. As MoveMyFile operates no data centres of its own, data centres are audited through the providers’ certificates and reports (Annex 3).
§ 11 Liability
Liability is governed by Art. 82 GDPR; otherwise the liability rules of the terms of use or the individual contract apply.
§ 12 Final provisions
This agreement is concluded by accepting the terms of use for business use; text form is sufficient (Art. 28(9) GDPR). On request the customer receives a countersigned copy.
In the event of conflict this agreement prevails over the terms of use in matters of data protection. Changes are announced at least 30 days in advance. If a provision is invalid, the rest of the agreement remains in force.
The law applicable to the terms of use (Czech law) applies unless the GDPR provides otherwise. The German version prevails for customers in Germany and Austria; translations are for information.
Annexes
- Annex 1 — Subject, nature and purpose, data and data subjects: § 2 of this agreement.
- Annex 2 — Technical and organisational measures (TOMs).
- Annex 3 — Sub-processors.
Version 1.0 · as of 8 October 2026 · HSE Support Germany s.r.o.
Documents for companies
Everything your data protection officer or IT will ask for — public, current and free of charge.
- Technical and organisational measuresWhat we actually do to protect your data (Art. 32 GDPR)
- Sub-processorsWho helps us process data, where and on what legal basis
Need a countersigned copy, a security questionnaire filled in or a detailed description of our measures? Write to support@movemyfile.eu — usually answered within two working days.