1. Controller and contact
Workfiles is provided by Securesoft OÜ, registry code 17530831. For privacy and data protection questions, contact info@failijagaja.ee.
For data protection questions and data subject requests, the contact address is info@failijagaja.ee.
Where an organization uses the service to exchange documents with employees, clients or partners, that organization may be the controller for the document and recipient data, and Securesoft OÜ processes that data to provide the service according to the organization’s instructions. Securesoft OÜ remains separately responsible for data processed for service security, billing, support, fraud prevention and legal obligations.
2. What the service does
Workfiles allows signed-in users to share files, define access by personal code, email address or domain, use one-time verification codes, manage organizations and licenses, and run digital signing workflows.
Users sign in with strong electronic identity methods such as Smart-ID, Mobile-ID or ID card through the Authentigate service. Access to shared files depends on the sender’s access rules and authentication.
3. Personal data we process
- Account and authentication data: personal code, personal code country, first name, last name, email address, authentication provider, authentication method, provider subject ID and last login time.
- Session data: technical application session identifier, session hash, creation, expiry, revocation and last-seen timestamps. Session cookies are HTTP-only, secure in production and configured with sameSite lax.
- File data: original filename, storage key, MIME type, size, creation time, expiry time, share type, encryption metadata, checksums and related access rules.
- Recipient and access data: allowed recipient personal codes and countries, allowed email addresses or domains, email OTP code hash, OTP expiry, attempt count, lock information and email sending, delivery, open, bounce or failure status.
- Access logs: which file was accessed, which method verified access, personal code or email address where applicable, and access time.
- Signing workflow data: workflow title and description, signer names, email addresses, expected personal codes and countries, signing statuses, token statuses, OTP data, uploaded version metadata, ASiC-E or other container information, validation summaries, event logs, IP addresses and user-agent values.
- Organization data: organization name, members, roles, permissions, license seats, ownership transfers, audit logs and organization activity IP addresses and user-agent values.
- Billing data: selected plan, Stripe customer ID, Stripe subscription or payment reference, subscription status, period end, cancellation information and payment failure information. Card details are processed by Stripe; the application does not store full card details.
- Support and contact data: information you send to us by email.
4. File content and rights
Rights to files and documents remain with you or your organization. Workfiles does not claim ownership of uploaded files.
We use files only to provide the service: uploading, encrypted storage, delivery to authorized recipients, signing workflow management, technical support at your request, security and compliance with legal obligations.
We do not use uploaded files for advertising, selling to third parties or training artificial intelligence models. If a future feature uses document content for any other purpose, it must be described separately and require a separate legal basis or consent.
5. Why we use data
- To identify users and enable login.
- To upload, encrypt, store, download and delete files.
- To control file recipient access by personal code, email address, domain or verification code.
- To create signing workflows, invite signers, log actions and manage signed versions.
- To manage organizations, roles, licenses and ownership transfers.
- To manage plans, subscriptions and payment status.
- To protect security, detect misuse, fix errors and maintain an audit trail.
- To comply with legal obligations and protect legal rights.
6. Legal bases
- Contract performance: to provide the core account, file sharing, signing, organization and billing functionality.
- Legitimate interests: service security, audit logs, fraud prevention, technical logs, error handling and legal protection.
- Legal obligation: accounting, tax records, statutory requirements and lawful requests from competent authorities.
- Consent: where we use data for an activity that requires separate consent.
7. Encryption and security measures
Files are protected using AES-256-GCM encryption. For standard uploads, an encryption envelope is created and the file is encrypted before being sent to storage.
Signing workflow file versions also contain encryption metadata and are decrypted only after access control has passed. Checksums and encrypted object metadata are used to verify file integrity.
The application uses hashing or HMAC-based verification for sessions and signing tokens. Audit logs record important actions, including organization administration, signing events and access confirmations.
8. Access to files
A file can be accessed only if the user is the file owner or matches the access rule set by the sender. For personal-code sharing, the recipient’s personal code and country are checked. For email sharing, the email or domain and verification code are checked.
File expiry is also checked before download. Expired files are not served. Successful access is logged so the sender or organization has an audit trail.
9. Service providers
The service uses selected third-party providers, including Authentigate for authentication, Stripe for payments, Resend for email delivery and S3-compatible object storage for file storage.
Providers receive data only to the extent necessary for their specific function. For example, Stripe processes payment and subscription data, Resend processes email sending and delivery data, and the authentication provider processes electronic identity data.
10. Retention
- The free plan has limited file retention and, according to the service configuration, the maximum free retention is up to 7 days. After the retention period ends, expired files are deleted automatically by the nightly cleanup process.
- With a paid plan, files and workflows can be retained until manually deleted if the account or organization plan is active, the plan storage limit has not been exceeded, and the file or workflow is not deleted earlier by the user, organization or a lawful requirement.
- Plan storage means the total amount of actively stored files and workflows in the account or organization, not a single-file limit or monthly transfer volume.
- Upload intents are short-lived and, according to the service configuration, expire by default after 15 minutes.
- Email access OTP codes have an expiry time and the code itself is stored as a hash, not in plain text.
- Sessions have an expiry time and can be revoked. The application session default duration is 7 days in the code.
- Billing, audit and security logs are retained as long as needed for service operation, dispute resolution, security or legal obligations.
11. File Deletion and Recovery
For security and privacy reasons, we do not restore files that have been permanently deleted by the user. Users are responsible for keeping any necessary copies before deletion.
12. International users and transfers
The service can be used by users with Estonian, Latvian, Lithuanian and Belgian personal codes, and recipients can also be reached by email. If data is processed or transferred outside the European Economic Area because of a service provider, appropriate safeguards such as data processing agreements and standard contractual clauses must be used where required.
Securesoft OÜ takes reasonable measures to ensure that service providers and data processing locations comply with applicable data protection requirements.
Where required, transfers are protected using the European Commission’s Standard Contractual Clauses (SCCs).
13. Your rights
You have the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, object to processing and request data portability where applicable.
To exercise your rights, contact info@failijagaja.ee. If you use the service as a member of an organization, or you are a recipient of an organization’s client or partner, some requests may need to be coordinated with the organization that determined the purpose of processing.
We generally respond to requests within one month of receiving them.
Where necessary, we may request additional information to verify your identity.
14. Complaints
If you believe your data has been processed unlawfully, please first contact info@failijagaja.ee. You also have the right to contact the Estonian Data Protection Inspectorate or the competent data protection authority in your country of residence.
15. Changes
We may update this privacy policy when the service, law or providers change. We will notify users of material changes in a reasonable way.