1. Controller and contact
Soroltech, a Finnish private trader, is the controller for personal data processed to provide Soroltech accounts and services. Business ID: 3363620-8. Address: Ruuhikoskenkatu 15 B 7, FI-24240 Salo, Finland. Telephone: +358 45 865 3436. Privacy requests may be sent to support@soroltech.fi. Abuse reports concerning links may also be sent to abuse@soroltech.fi.
Soroltech remains the controller for account administration, security, billing, service operations, and its own legal duties. Where a Business customer determines the purposes and means of processing personal data placed in messages, files, monitoring, links, or team accounts, the Business customer is the controller and Soroltech acts as its processor to the extent applicable. Team members should normally direct requests about customer-controlled content to their Business owner. This policy does not replace the customer's own privacy notice or any required processing agreement.
2. Data we process
- Account and entitlement data: username, email address, password hash, email-confirmed state, user/admin role, package and per-user limits, licence expiry, active/suspended state, creation time, and Business owner/member relationship.
- Authentication and verification data: hashed email-confirmation and password-reset tokens; two-factor method; encrypted TOTP secret; hashed recovery, enrolment, and email sign-in codes; two-factor security-event type and time; and session identifier, user-agent label, creation, last-use, expiry, and revocation times. The bearer token is stored in the user's browser.
- Business Teams data: owner and member account identifiers, member contact and status, seat allocation, shared entitlement, and aggregate monitor, link, and file-drop usage. The owner supplies initial member credentials and can administer member access.
- Service data: encrypted one-time-message payloads and usage counts; monitor names, public targets, results, error descriptions, status history, and optional logo URLs; encrypted link domains, paths, and destinations, keyed lookup hashes, provider/DNS verification state, and aggregate daily clicks.
- Encrypted file-drop data: the browser-encrypted archive chunks; archive name; source, plaintext, encrypted, and chunk sizes; uploader/account identifier; selected sharing host; creation, completion, and expiry times; upload state; download limit and count; moderation state; and a Business widget access key where generated.
- Encrypted form data: the public form title, description, questions, language, publishing host and status; the public encryption key; an encrypted owner private key; and ciphertext, encrypted per-response keys, timestamps and expiry times for submitted responses; the selected duplicate-response policy; and, when that policy is enabled, a keyed one-way hash of the submitter IP address scoped to that form. Soroltech does not receive the owner recovery key or readable answers.
- Billing and support data: invoice contact name, company, billing email, optional VAT identifier, requested plan, request/decision state, accepted agreement version and time, signed Order reference, acceptance date, package snapshot, activating administrator, and mail-delivery error; correspondence; and Paddle customer, transaction, subscription, product, price, status, period, checkout-consent evidence, and webhook-event identifiers and times.
- Moderation and anti-abuse data: file identifier, uploader and administrator identifiers, takedown reason and time, account suspension state, and the administrator-maintained list of disallowed email domains. A rejected registration address is not added to that domain list.
- Technical and operational data: infrastructure providers necessarily process network identifiers such as an IP address. Soroltech API telemetry records a request identifier, method, normalized route without query strings or embedded identifiers, response status, and duration for failed or slow requests. It does not put raw request queries, account details, IP addresses, or user-agent strings in those application events.
- Privacy preference: your accepted or rejected optional-analytics choice is stored in local browser storage and a first-party preference cookie for up to one year.
- Optional website analytics: Google Tag Manager is not requested unless you accept optional analytics through the site privacy controls. Tags configured through it may then process page, device, referral, and interaction information and may use cookies. Identifier-free performance measurement additionally reports only the product, a coarse page class, rounded Core Web Vitals, and a capped error count; it excludes paths, accounts, error details, and device identifiers. Rejecting analytics does not limit the service.
3. Special design of encrypted services
One-time messages, file-drop archives and form responses are encrypted in your browser. A message key remains in the URL fragment; a file-drop key is delivered separately. Neither key is sent to Soroltech. A one-time payload is deleted when first retrieved. Encrypted file chunks are deleted at expiry, after the configured download limit is reached, on owner deletion, or following takedown; incomplete uploads are cleaned after 24 hours. Link domains, paths, and destinations are encrypted at rest and keyed hashes support lookups. Link analytics store aggregate counts rather than visitor IP addresses or user-agent strings. Each form response uses a one-time AES-GCM key wrapped with the owner's RSA-OAEP public key. The owner private key is encrypted in the browser; its recovery key remains in the owner's URL fragment and local browser storage. Losing it makes responses permanently unreadable, including to Soroltech. Optional duplicate-response protection compares a form-specific keyed hash of the request IP; the raw IP is not stored in the form response database, and the hash is deleted with the encrypted response.
4. Why and on what basis we process data
- To create accounts, provide requested services, process subscriptions, administer Business members, deliver encrypted files, verify domains and email, enforce package/team limits, and answer support requests: performance of a contract or steps requested before a contract.
- To secure authentication, maintain the disallowed-domain list, troubleshoot, prevent abuse, moderate links/files/accounts, monitor reliability, and improve the services: our legitimate interests in operating safe and effective services and protecting users and others.
- To respond to valid legal notices and maintain accounting, tax, dispute, fraud, and compliance records: legal obligations and, where applicable, legitimate interests in establishing, exercising, or defending legal claims.
- For non-essential analytics cookies: consent. You can reject them initially or withdraw consent at any time with the persistent “Privacy settings” button. Withdrawal does not affect processing that occurred before withdrawal.
5. Payments and Paddle
Paddle is Merchant of Record for individual subscription purchases and processes checkout identity, payment, tax, fraud-prevention, receipt, refund, and subscription data under Paddle’s own terms and privacy notice. Soroltech receives identifiers and status information needed to provide or remove access, but not full card details. Visit Paddle’s Privacy Notice for its processing.
6. Recipients and processors
We disclose data only as needed to operate the services: Paddle for individual payments; Brevo/Sendinblue SAS for confirmation, two-factor, invoice, and other transactional email; Hetzner Online GmbH for the current Helsinki server and storage infrastructure; Cloudflare for network delivery and, where enabled, DNS/domain verification; Google only after optional analytics consent and where configured tags are active; a Business owner for its member accounts and aggregate team use; professional advisers; and authorities or rights holders where legally required. Email recipients naturally receive the messages addressed to them. We do not sell personal data. The current Business subprocessor schedule is in the Business and Custom Agreement.
7. International transfers
Some providers may process data outside Finland or the European Economic Area. Where required, transfers rely on an adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism. Provider privacy notices contain further details.
8. Retention
- Account, entitlement, team membership, active/revoked session records, 2FA configuration/security events, link configuration, monitor configuration, and other account-owned service records remain until the account or relevant item is deleted, unless a legal or dispute record must be retained. Login access expires after 12 hours even though its session record remains until account deletion.
- When registration email confirmation is enabled, an unconfirmed account and its hashed token are deleted by the hourly cleanup after the administrator-selected period of 1–365 days (seven days by default). Confirmation and 2FA email/setup codes expire after 10 minutes and are removed or replaced when the flow is completed or settings change; all related records are deleted with the account. A hashed password-reset token expires after one hour and is deleted when used, replaced, expired, or when the account is deleted.
- A one-time encrypted message remains until first retrieval or account deletion. Monitor history is capped at the latest 2,000 results per monitor and is deleted with the monitor. Managed links and aggregate daily counts remain until the link/domain or account is deleted.
- An encrypted file drop remains for its user-selected period up to the applicable package/account maximum, or until its download limit is reached, it is manually deleted, moderated, or its account is deleted. Incomplete uploads are removed after 24 hours. A takedown deletes encrypted bytes promptly; takedown metadata and audit reasons currently have no automatic time-based deletion and are retained only as needed for abuse response, disputes, and legal claims.
- Encrypted form responses remain for the package retention period shown when the form is created (currently 90 days on Free, 730 days on Pro and 1,825 days on Max), unless the owner deletes the response or form earlier. Public form definitions remain until their owner deletes the form or account.
- Invoice, accepted Order, commercial-agreement, subscription, webhook, accounting, tax, fraud, support, and transaction records have no short automatic deletion period and are retained only as required for the transaction, statutory duties, disputes, and Paddle's Merchant-of-Record obligations. Business data return and deletion follow the accepted Order and the versioned Business and Custom Agreement. Disallowed-domain and service settings remain until an administrator changes them.
- Production service logs use compressed, size-based rotation—not a fixed 30-day timer. The deployment default is at most 30 files of 10 MiB per container, so the actual duration depends on traffic. In-memory operational request metrics cover a rolling five-minute window. The optional-analytics preference remains in your browser for up to one year unless you change it or clear site data.
9. Security
We use access controls, password hashing, transport encryption, encryption for sensitive service fields, signature verification for payment events, network restrictions, backups, and monitoring appropriate to the service. No system is completely secure. Keep your credentials, recovery codes, complete one-time-message links, file-drop keys, and Business widget keys confidential.
10. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to a supervisory authority. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman. We may need to verify your identity before completing a request. If a Business customer is the controller for the requested content, we will direct or assist the request according to that customer's lawful instructions.
11. Children
The services are not directed to children under 16. Paid packages may only be purchased by an adult or an authorized organizational representative. Contact us if you believe a child has provided personal data improperly.
12. Changes
We may update this policy when our services, providers, or legal obligations change. The current version and effective date are published on this page. Material changes will be communicated where required.