Documents for companies
Technical and organisational measures
Annex 2 to the data processing agreement (Art. 32 GDPR). What we actually do — only measures that are in place.
1. Confidentiality — physical access
- MoveMyFile runs no servers of its own. All systems run in data centres of Cloudflare and Supabase (AWS, Frankfurt am Main) certified to ISO/IEC 27001, with access secured by badges, video surveillance and staff.
- Files are kept in storage bound to the EU jurisdiction, the database in Frankfurt am Main (Germany).
2. Confidentiality — system access
- Passwords are never stored in readable form, only as a secure hash (bcrypt).
- Two-factor sign-in (TOTP, authenticator app) available to every user; turning it on or off always sends a security e-mail.
- Sign-up and sign-in are protected against bots (captcha) and limited against password guessing.
- Every new device on an account immediately triggers a security e-mail; devices can be removed at any time.
- Administrative access (hosting, database, code, e-mail delivery) is limited to the management.
3. Confidentiality — data access
- Who may see what is checked by the database itself on every request (row level security and checked database functions) — not only by the app. Tables are not directly readable for users.
- Files are delivered only through signed download tickets valid for five minutes.
- Shared links can have an expiry date, a PIN or password and a download limit; a link is blocked after too many wrong PINs.
- Roles in teams (owner, admin, member, guest) with graded rights.
- Teams on Crew or Fleet set sharing rules (PIN required, maximum validity, no public links, allowed recipient domains); the database enforces them — for the API too.
- Payment data is processed only by Paddle; MoveMyFile never sees card details.
4. Confidentiality — separation
- Data of every account and every team is logically separated (own workspace, enforced in the database).
- Test and production systems are fully separate: own database, own file storage, own keys. Test data is not customer data.
5. Confidentiality — pseudonymisation and data minimisation
- For statistics we keep only the country and language, never the IP address.
- No advertising, no tracking scripts, no third-party cookies.
- The content of push notifications is encrypted up to the device.
6. Integrity — transfer control
- Every connection is encrypted (HTTPS, TLS 1.2 or 1.3); HSTS forces browsers to use HTTPS.
- Strict content security policy and security headers; independently tested (SSL Labs A+, Mozilla HTTP Observatory A+, Security Headers A+).
- Internal calls between the application and the database are secured with cryptographic proofs (HMAC).
7. Integrity — input control
- Protocol of every transfer between a user’s devices (sent, arrived, downloaded with location) and of every device added or removed; kept for 12 months and not deletable by users.
- Shares record when they were opened and downloaded; changes to plans and limits are logged with time and editor.
- Deleted files are marked as deleted in the database (evidence); the content itself is removed.
- Teams on Crew or Fleet: audit log (uploads, sharing, opens, downloads, deletions, members, API) with CSV export for owners and admins.
8. Availability and resilience
- Daily database backup at the provider; backups are overwritten within about 7 days.
- Protection against overload attacks (DDoS) and Cloudflare’s worldwide network.
- Highly durable file storage at the provider (redundant storage).
9. Regular testing and evaluation
- Before every release more than 600 automated tests run, more than 250 of them checking access rights directly against the database. If a test fails, nothing is released.
- Database changes are made only through versioned migrations with a prepared rollback; the application starts only with the matching database version.
- Only the owner of the code repository can release to production; every change is checked on the test system first.
- Security review of the code before releases; the measures in this document are reviewed at least once a year and on significant changes.
10. Processor control and organisation
- Sub-processors only with a contract under Art. 28 GDPR; current list in Annex 3, changes are announced in advance.
- Everyone with access to personal data is bound to confidentiality.
- Security and privacy reports to support@movemyfile.eu are handled with priority; the processor reports personal data breaches to the controller without undue delay (see DPA § 8).
- MoveMyFile is explicitly not end-to-end encrypted: technically we could reach stored files. We do not look into them; access only when the law requires it or content is reported as illegal.
Version 1.0 · as of 8 October 2026 · HSE Support Germany s.r.o.
Documents for companies
Everything your data protection officer or IT will ask for — public, current and free of charge.
- Data processing agreementUnder Art. 28 GDPR — applies automatically with our terms, free of charge
- Sub-processorsWho helps us process data, where and on what legal basis
Need a countersigned copy, a security questionnaire filled in or a detailed description of our measures? Write to support@movemyfile.eu — usually answered within two working days.