Data Controller and scope of this notice
The Controller determines the purposes and means of processing carried out through MegaFile.it.
The Data Controller is Marco Vinci, operator of MegaFile.it. Requests concerning personal data protection may be sent to info@megafile.it.
This notice applies to browsing the website, uploading files, generating and opening links, preparing downloads, security activities and internal technical analysis systems.
MegaFile.it does not provide user registration, personal accounts, permanent private folders, credential recovery or functions for sending email to recipients through the platform.
Data processed while browsing
A simple visit generates technical data necessary for the website to operate and additional information used for security and internal analysis.
Systems may record the IP address, user agent, browser, operating system, device type, language, requested page, previous page, referrer, date and time, approximate visit duration, events performed and information about detected anomalies or bots.
Random visit and session identifiers, technical browser or device hashes, IP subnet and signals such as time zone, screen and viewport dimensions, platform, hardware capabilities declared by the browser and touch support may also be processed. These elements may make it possible to link multiple accesses to the same browser or device, even though they do not directly contain a name or email address.
The IP address may be used to derive an approximate location, such as country, region and city. This location is not a GPS position and may be inaccurate.
Files, metadata and associated information
To provide the service, MegaFile processes uploaded content and the data required to identify, protect and make it available.
When the user selects one or more files or folders, the system processes the content, original name, extension, size, any relative path, upload date, selected duration and technical identifiers required to create the sharing link.
If additional protections are enabled, the system processes the technical data needed to verify them and authorise the download. Keys, tokens and other secrets must not be entered in forms other than those provided or shared separately unless necessary.
The file name may be displayed on the download page and may constitute personal data. The user is responsible for avoiding names that unnecessarily reveal confidential information or special categories of data.
File contents and data relating to third parties
Files may contain the user’s personal data or data relating to other people; MegaFile.it does not determine the content selected by the user.
The upload is initiated by the user, who decides which data to include and with whom to share the link. The user must have an appropriate legal basis for processing and disclosing data relating to third parties and must provide data subjects with any information required by law.
MegaFile.it does not ordinarily inspect content manually. Content is nevertheless processed automatically for receipt, encryption, temporary storage, decryption, reconstruction and delivery to the recipient.
Access by authorised personnel may occur only where necessary for user-requested support, security, abuse prevention, incident management, compliance with the law or protection of rights. Users are advised not to upload health, judicial, biometric, financial or other highly sensitive information unless strictly necessary and adequately protected.
Purposes and legal bases of processing
Each category of data is processed for specified purposes and on the basis of one of the conditions provided by the GDPR.
Performance of the service or steps requested by the user: receiving files, protecting them, generating their link, storing them for the selected period, preparing the downloadable copy, creating any archives and completing the download.
Legitimate interests of the Controller, within permitted limits: protecting infrastructure and users, preventing fraud, abuse, malware and anomalous automated access, diagnosing errors, ensuring technical continuity, documenting security events and establishing, exercising or defending legal claims.
Compliance with legal obligations: responding to requests from authorities, removing unlawful content, retaining data where required by law and handling requests from data subjects.
Consent: installing or using cookies and tracking tools that are not strictly necessary, including any third-party analytics or advertising services, where the law requires the user’s prior choice.
Encryption and temporary processing of files
MegaFile adopts technical measures intended to protect files throughout the different stages of the service, without being able to guarantee the complete elimination of every risk.
Files are processed using encryption systems and other technical measures consistent with the selected mode of use and the functions requested by the user.
To enable downloading, the Service may temporarily process, reconstruct or aggregate content. These activities may involve the temporary creation of technical copies or working archives.
Temporary data are subject to automated removal procedures at the end of operations or during subsequent system-cleaning cycles. In the event of errors, interruptions or processes that are still active, deletion may not be immediate.
MegaFile is a service still under development and testing. Malfunctions, vulnerabilities, cyberattacks or failures may cause loss, unavailability or unauthorised access to content. Users must therefore keep an independent copy of important files.
Retention and deletion
File retention periods depend on the option selected at the time of upload
Uploaded files are made available for the period selected by the user from 3, 7, 14, 30, 90 or 180 days. At expiry they are scheduled for automatic deletion. The Controller may delete them earlier for technical needs, security reasons, violations, legitimate requests or discontinuation of the service.
Technical materials connected with downloads, such as control information and data required for decryption, are retained for the time needed to make the file available and in any event no longer than its operational lifetime, without prejudice to technical remnants subject to periodic cleaning or legal obligations.
Temporary decrypted copies and working archives are designed to be removed quickly; current procedures carry out cleaning within a timeframe generally measured in minutes.
Anti-abuse states, technical reports and certain operational records may be retained for an indicative period of up to 60 days. Browsing, security and audit logs are retained for as long as proportionate to the purposes of analysis, service protection, incident management and defence of rights; they are reviewed and must be deleted or anonymised when those purposes cease.
Cookies and identifiers have the duration stated in the Cookie Policy or in the relevant section of this notice. Deleting them from the browser does not automatically remove logs already recorded on the server.
Statistical data, approximate location and security
MegaFile may process technical data to assess how the Service operates, produce aggregated statistics and identify anomalous or potentially harmful use.
Technical and browsing information may include pages visited, date and time, visit duration, source, browser and device type, usage events and operations requested through the Service.
The IP address may be used to derive an indicative geographical location, generally limited to country, region or city. For this purpose MegaFile may use external technical providers, which receive the data strictly necessary to provide the relevant function.
The Service may automatically analyse certain technical characteristics of requests to prevent anomalous, automated or potentially harmful use.
Where anomalies are detected, proportionate technical measures may be applied, such as additional checks, temporary restrictions or security blocks. These assessments are not used to make decisions producing legal or similarly significant effects on the data subject.
Data collected for statistical and security purposes are retained for limited periods, as described in the Privacy Policy, and are accessible only to authorised persons.
Recipients, providers and disclosures
Data are accessible only to the extent necessary to provide and secure the service and comply with legal obligations.
Data may be processed by the hosting, connectivity and infrastructure provider, technical providers required for maintenance and security, the IP geolocation service and, where enabled, analytics or advertising providers.
Parties acting on behalf of the Controller must be bound by confidentiality obligations and, where required, appointed as processors pursuant to Article 28 of the GDPR.
Data and content may be disclosed to public authorities, law-enforcement bodies, judicial authorities, rights holders or advisers where required by law, necessary to handle a valid report or indispensable for establishing, exercising or defending a right.
MegaFile.it does not sell personal data or disclose them to third parties for their independent use in direct marketing.
Transfers to third countries
Some internet service providers may process data outside the European Economic Area.
The use of global services, including Google tools and the IP geolocation service, may result in data being accessed or processed in countries outside the European Economic Area.
Where the Controller carries out a transfer subject to the GDPR, the safeguards provided by Articles 44 et seq. apply, such as adequacy decisions, standard contractual clauses or other permitted grounds. Updated information about individual providers should also be consulted in their respective privacy notices.
Merely inserting a download link into messaging, email or social media services chosen by the user entails independent processing by those services, over which MegaFile.it has no control.
Security, incidents and technical limitations
Proportionate technical and organisational measures are adopted, without promising absolute security.
Measures may include encryption, segregation of technical data, access controls, security headers, request limiting, bot detection, lock files, integrity checks and automated deletion procedures.
No measure completely eliminates the risk of vulnerabilities, human error, data loss, unavailability, unlawful access or cyberattack. The platform is still being tested and may be modified or interrupted.
In the event of a personal data breach, the Controller assesses the risk and complies with the documentation, supervisory-authority notification and data-subject communication obligations provided by Articles 33 and 34 of the GDPR.
Nature of provision and consequences of refusal
Some data necessarily arise from the use of a web service; other data depend on the user’s choices.
Providing network data, the file and essential metadata is necessary to use the service. Without those data, the upload cannot be received, the link cannot be created and the download cannot be completed.
The user may choose not to upload files, to use less identifying names, to apply additional protections, to select the shortest appropriate period and not to share the link publicly.
Consent to non-essential cookies or tools is optional. Refusal might prevent access to essential functions, although certain measurements or non-essential components may be unavailable.
Rights of the data subject
In the cases provided by the GDPR, the data subject may request information and exercise control over data concerning them.
The data subject may exercise the rights provided by Articles 15–22 of the GDPR, including access, rectification, erasure, restriction, objection and portability, where applicable to the specific processing.
Because the service does not use accounts and some data are associated only with technical identifiers, an IP address, date, link or file, the requester may need to provide sufficient information to locate the data and demonstrate their entitlement. Complete keys or passwords must not be sent by email unless expressly requested through a secure channel.
Children, changes and contact details
This notice may be updated when the service, providers or applicable law change.
MegaFile.it is not specifically directed at children under 16. Persons exercising parental responsibility must supervise use of the service and the sharing of data relating to children.
This notice may be amended to reflect technical, organisational or legal changes. The new version becomes available through publication on the website, with the update date indicated.
Questions, requests to exercise rights or privacy reports may be sent to info@megafile.it. Reports concerning unlawful files or infringements of rights may be sent to the same address, stating the relevant link and the information necessary for assessment.
