Legal

Privacy notice

How Vaultline OÜ collects and uses personal data, in what capacity, and what rights you have. Written to be read rather than to be survived.

Version 4.2 · Effective 1 May 2026 · Supersedes version 4.1 of 2 October 2025

1. Who we are

Vaultline OÜ ("Vaultline", "we", "us") is a company registered in Estonia under registry code 14827301, with its registered office at Rotermanni 8, 10111 Tallinn, Estonia. We provide a secure document exchange and virtual data room service.

Our Data Protection Officer can be contacted at dpo@fileshare-portal.com, or by post at the address above marked for the attention of the Data Protection Officer.

2. Two different roles

It matters which capacity we are acting in, because it determines who decides what happens to your data.

As a processor. When our customers put documents and invite people into Vaultline, we process that content on their instructions. The customer is the controller; they decide what goes in, who sees it and how long it stays. If you have been invited into a room by a firm and want to know why your data is there, ask that firm — we will help them respond, but we cannot make those decisions for them. This processing is governed by our data processing agreement.

As a controller. When you visit this website, contact us, buy a subscription, apply for a job or receive our emails, we decide how that data is used. That processing is described below.

3. What we collect as a controller

  • Contact and account data — name, work email, telephone number, firm name, role, and the correspondence you send us.
  • Billing data — billing contact, address, VAT number, and payment records. We do not store full card numbers; card payments are handled by our payment provider.
  • Service usage data — administrative logs about how your account is configured and used: sign-in times, feature usage, seat counts, storage volumes. This is about account administration, not about the content of your documents.
  • Website data — pages visited, referring page, approximate location derived from IP address, browser and device type. See section 8 on cookies.
  • Recruitment data — CV, application correspondence and interview notes, where you apply for a role.

4. Why we process it, and on what basis

Purposes and lawful bases for processing
PurposeLawful basisRetention
Providing and administering the servicePerformance of a contract (Art. 6(1)(b))Life of the account, then 30 days
Billing, invoicing and tax recordsLegal obligation (Art. 6(1)(c))7 years, per Estonian accounting law
Support and correspondencePerformance of a contract; legitimate interests (Art. 6(1)(f))3 years from last contact
Security monitoring and fraud preventionLegitimate interests — protecting the service and its users12 months
Product improvement from aggregate usageLegitimate interests — improving a service you use24 months, pseudonymised
Marketing emails to prospectsConsent (Art. 6(1)(a)), or soft opt-in for existing customersUntil you withdraw, then suppression list only
RecruitmentSteps prior to entering a contract; consent for talent pool6 months after the process closes
Establishing or defending legal claimsLegitimate interestsLimitation period plus 1 year

Where we rely on legitimate interests, we have carried out a balancing assessment and will share a summary on request.

5. Who we share it with

We do not sell personal data, and we do not share it with advertising networks or data brokers. We disclose personal data only to:

  • Sub-processors acting on our instructions — all established in the EEA. The current list, with purposes and locations, is on our security page.
  • Professional advisers — auditors, lawyers and accountants, bound by confidentiality.
  • Authorities — where we are legally required to. We assess every request for validity, require it in writing, disclose the minimum necessary, and notify the affected customer unless legally prohibited from doing so.
  • An acquirer — if the business is sold or reorganised, subject to the same protections and with notice to you.

6. Where your data is

All personal data is stored and processed within the European Union. Our primary region is Tallinn, Estonia; our backup region is Helsinki, Finland. We do not transfer customer content outside the EEA, and we do not use sub-processors established outside it.

In the limited cases where a corporate administrative tool involves a non-EEA transfer, we rely on the European Commission's standard contractual clauses together with a transfer impact assessment and supplementary technical measures. Our data processing agreement incorporates those clauses.

7. How we protect it

Personal data is encrypted at rest with AES-256 and in transit with TLS 1.3. Access is restricted on a least-privilege basis, requires phishing-resistant multi-factor authentication, and is reviewed quarterly. We hold ISO/IEC 27001:2022 certification and produce an annual SOC 2 Type II report. Full detail is on our security page.

8. Cookies and analytics

This marketing website sets only what is strictly necessary to serve the pages you request. We do not use advertising cookies and we do not embed third-party tracking pixels or social media widgets.

The site does load web fonts and a stylesheet framework from third-party content delivery networks. Those providers necessarily receive your IP address in order to serve the files; we receive no analytics or reporting from them, and they are not used to identify or profile you. The map on our contact page is a static image rather than an embedded mapping service, so no map provider is contacted when you view it.

Inside the product we set a small number of first-party cookies that are necessary for the service: a session cookie, a CSRF token and a preference cookie. Product analytics are collected through a self-hosted service under our own control, retained for 24 months in pseudonymised form, and never combined with document content.

9. Your rights

Under the GDPR you have the right to:

  • Be informed about how your data is used — this notice.
  • Access a copy of the personal data we hold about you.
  • Rectify data that is inaccurate or incomplete.
  • Erase data, where there is no overriding basis for keeping it.
  • Restrict processing while a concern is resolved.
  • Portability — receive your data in a structured, machine-readable format.
  • Object to processing based on legitimate interests, and to direct marketing at any time and without qualification.
  • Not be subject to solely automated decisions with legal or similarly significant effects. We do not make any such decisions.
  • Withdraw consent at any time, where consent is the basis.

To exercise any of these, write to dpo@fileshare-portal.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We do not charge a fee unless a request is manifestly unfounded or excessive.

If your data is in Vaultline because a customer of ours put it there, direct your request to that firm. We will forward it and assist them, but they hold the decision.

10. Complaints

If you are unhappy with how we have handled your data, please tell us first — we would rather fix it. You also have the right to complain to a supervisory authority. Our lead authority is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)
Tatari 39, 10134 Tallinn, Estonia
www.aki.ee

You may also complain to the supervisory authority in your own country of residence or place of work.

11. Changes to this notice

We review this notice at least annually. For material changes we give at least 30 days' notice by email to account administrators and by a banner on this site before the change takes effect. Previous versions are available on request.