How SikkerFTP.dk processes personal data
Version 2026-08-13 · technical log description updated 10 September 2026
1. Controller and contact
Rasmus Jensen, Denmark, is the controller for account, support and security information in SikkerFTP.dk. Privacy and data subject rights enquiries should be sent to privacy@sikkerftp.dk.
2. What information is processed?
- Account: name, email address, optional company name, password hash, accepted terms version and timestamps.
- Invitations: email address, optional name and company, expiry, issuer and acceptance status. The invitation token itself is stored only as a hash.
- Endpoint metadata: name, technical username, UUID, quota, usage, file count, status and last sign-in.
- Operations, connections and security: IP address, protocol, authentication method, session ID, sign-in attempts, connection duration, file operation, virtual file path, data volume, result, errors and security events. Physical server paths and authentication secrets are not stored in customer logs.
- Technical visit log: timestamp, IP address, generalised page type, HTTP method/status, server processing time and a broad client category. Country is estimated from a local IP database; hostnames may be obtained through reverse DNS. Admin pages, invitations, authentication tokens, URL parameters, form contents, referrer addresses and raw browser identification are not stored in this log. The visit log is not linked to account IDs or marketing profiles.
- Files: filenames, folder structures and contents are processed technically to receive, temporarily store and deliver material according to the user's instructions.
- Support: information the user chooses to provide in an enquiry.
- Usage statistics: after active consent, page views, timestamps and standard technical client information are recorded in the self-hosted Matomo installation. Account IDs, email addresses, endpoint names, invitation tokens and URL parameters are not sent to Matomo.
3. Purposes and legal basis
- Creating and providing the service, managing endpoints and carrying out the user's file transfers, under GDPR Article 6(1)(b).
- Protecting the service, preventing abuse, troubleshooting and documenting incidents based on a legitimate interest in secure, stable operations, under Article 6(1)(f).
- With voluntary consent, understanding overall service usage and improving the user experience, under GDPR Article 6(1)(a). Consent may be withdrawn at any time.
- Meeting legal obligations and handling valid requests from authorities, under Article 6(1)(c).
Information is not used for advertising and is not sold.
4. Customer content and roles
Users decide which files to transfer, who receives access and how long an active endpoint is used. A company or authority is itself the controller for personal data in its files. When an authorised account holder accepts the data processing agreement, SikkerFTP.dk processes the permitted personal data according to the organisation's instructions and within the agreement's limits.
Special categories of personal data, criminal offence data, Danish CPR numbers, patient data, payment card data, access keys or other high-impact material must not be uploaded during the beta.
5. Recipients and location
Account information and files are processed in the self-hosted portal and file transfer systems. Files are stored in Denmark. The operator may access data when necessary for security, troubleshooting, support or a binding request from an authority.
Matomo is self-hosted and loaded only after consent for internal usage statistics. Cloudflare provides DNS and may process IP addresses and connection information for proxied web domains. Cloudflare may process data outside the EEA under a lawful transfer framework. Customer SFTP file storage is not hosted by Cloudflare.
The technical visit log is accessible only to administrators and is used for security, troubleshooting and stable operations, not advertising. IP-to-country lookups run locally using the free DB-IP Country Lite database. Hostname lookups send a reverse-DNS query through the server's DNS resolver; the IP address is not sent to an external GeoIP API.
When antivirus is enabled, uploaded files are scanned locally for malicious content before release. File contents are not sent to external scanning services. Technical scan results and virtual file paths appear in the activity log. Transferred data is recorded per endpoint and totalled per account to enforce the traffic quota.
6. Retention and deletion
- Account information is retained while the account is active and afterwards for as long as necessary for closure, security or legal requirements.
- Files are temporary and expire according to the selected retention period, within 30 days at most. Cleanup runs hourly. Deleting an endpoint does not extend file expiry. Users should delete files as soon as possible.
- When an endpoint is deleted, access is closed immediately. The isolated folder may be retained for up to 30 days as a temporary safeguard before deletion. Recovery is not guaranteed.
- Customer files are not included in backups. Local control-plane backups contain database and configuration data and rotate after 30 days.
- The technical visit log is displayed for up to 30 days. Older entries and unused IP lookups are automatically deleted at the next hourly run. IP lookups are normally reused for 24 hours. Older copies in control-plane backups expire through backup rotation; the deletion policy must be reapplied after a restore.
- Application security events and permanent endpoint deletion metadata are deleted after 90 days at the next daily run.
- Monthly traffic aggregates are retained for the current and previous month. Active endpoint counters are retained for continued quota calculation; following permanent endpoint deletion, they are removed after the same period retention. A local file-event redelivery queue retains events for up to 30 days.
- Raw Matomo visitor data is retained for up to 90 days and aggregated reports for up to 13 months.
- The customer-specific SFTP activity log with IP addresses, virtual file paths and operations is retained for 90 days and then automatically deleted.
- Technical log files are rotated by count, time or capacity. Logs may contain IP addresses, requested URLs and referrer URLs. Application security events and permanent endpoint deletion metadata are automatically pruned after 90 days.
7. Cookies
The portal uses technically necessary session and security cookies for sign-in, CSRF protection and functionality. Cookieless Matomo statistics are loaded only after consent and respect the browser's Do Not Track setting. Administration is not tracked, referrer addresses are not recorded, and sensitive identifiers in portal URLs are replaced with generic values before recording. No marketing cookies are used. See purposes, durations and withdrawal options in the cookie policy.
8. Security
Measures include encrypted transport, isolated endpoint folders, access restrictions, rate limiting, brute-force protection and restricted administrative networks. No internet service can be guaranteed fault-free or unbreakable. Users must therefore minimise the sensitivity of content and always retain the original elsewhere.
9. Your rights
Depending on the circumstances, you may request access, rectification, erasure, restriction or data portability, or object to processing based on legitimate interests. Contact privacy@sikkerftp.dk. We may request information necessary to verify your identity.
You may complain to the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby.
10. Changes
This policy is updated when the service's processing changes. The current version and date appear at the top. Material changes are displayed in the service and implemented with the notice or new acceptance required by law.
Detailed traffic measurements are retained for up to 90 days and removed at the next daily run.