FluxDrive

Privacy Policy

Last updated: December 27, 2025

1. Data Controller

The data controller for your personal data is Insolitum Sp. z o.o., with its registered office at ul. Chwarznieńska 198F, 81-602 Gdynia, Poland (NIP: 9581753176, KRS: 0001166174, REGON: 541402165).

For all privacy-related inquiries, please contact us at hello@insolitum.ai.

2. Data We Collect

2.1 Account Data

When you create an account, we collect:

  • Email address (required for account creation and authentication)
  • Account creation date
  • Subscription plan and payment status

2.3 Usage Data

We automatically collect:

  • Storage usage and transfer statistics
  • Number of share codes created
  • Download counts and device fingerprints (hashed, for abuse prevention)
  • IP addresses (hashed, for rate limiting and security)

2.4 Payment Data

Payments are processed by Paddle (Paddle.com Market Limited), our Merchant of Record. We do not store your full credit card details. Paddle handles all payment processing in compliance with PCI-DSS standards. We receive only:

  • Transaction ID
  • Subscription status
  • Payment method type (not full card details)

3. Legal Basis for Processing (GDPR)

We process your personal data based on the following legal grounds under Article 6 of GDPR:

  • Contract performance (Art. 6(1)(b)): To provide the FluxDrive service you requested
  • Legitimate interests (Art. 6(1)(f)): For security, fraud prevention, and service improvement
  • Legal obligation (Art. 6(1)(c)): To comply with applicable laws and regulations
  • Consent (Art. 6(1)(a)): For marketing communications (where applicable)

4. How We Use Your Data

We use your data to:

  • Provide, maintain, and improve the FluxDrive service
  • Process payments and manage subscriptions
  • Send transactional emails (account confirmation, password reset, usage alerts)
  • Prevent abuse and enforce usage limits
  • Comply with legal obligations
  • Respond to your support requests

5. Data Sharing

We share your data only with:

We do not sell your personal data to third parties.

  • Supabase: Our database and authentication provider (servers in EU)
  • Paddle: Our payment processor and Merchant of Record
  • Vercel: Our hosting provider (edge network with EU presence)
  • Law enforcement: When required by law or valid legal process

6. Data Retention

  • Uploaded files: Retained while your account is active; deleted upon account termination
  • Share codes: Automatically expire and are deleted after 24 hours
  • Account data: Retained for the duration of your account plus 30 days after deletion request
  • Usage logs: Retained for 90 days for security purposes
  • Payment records: Retained for 7 years as required by tax law

7. Your Rights (GDPR)

Under GDPR, you have the right to:

To exercise these rights, contact us at hello@insolitum.ai. We will respond within 30 days.

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure ("Right to be forgotten"): Request deletion of your data
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (TLS/HTTPS)
  • Encryption at rest for stored files
  • Hashed IP addresses and device fingerprints
  • Rate limiting and brute-force protection
  • Regular security audits

9. International Transfers

Your data may be processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

10. Cookies

FluxDrive uses only essential cookies required for the Service to function:

We do not use tracking or advertising cookies.

  • Authentication cookies: To keep you logged in
  • Session cookies: To maintain your session state

11. Children's Privacy

FluxDrive is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The "Last updated" date at the top of this page indicates when the policy was last revised.

13. Supervisory Authority

If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority. In Poland, the supervisory authority is:

Urząd Ochrony Danych Osobowych (UODO)

14. Contact

Insolitum Sp. z o.o.
ul. Chwarznieńska 198F
81-602 Gdynia, Poland

NIP: 9581753176
KRS: 0001166174
REGON: 541402165

Email: hello@insolitum.ai