Uploadexย้อนกลับ to site

กฎหมาย

นโยบายความเป็นส่วนตัว

อัปเดตล่าสุด 27 เมษายน 2569 · เป็นไปตาม GDPR และ India DPDP Act 2023

สรุปสั้น ๆ:เรา collect เท่านั้น what is needed to run the บริการ, เรา never look inside ของคุณ ไฟล์, เรา do ไม่ sell ของคุณ personal ข้อมูล, และ คุณ can ส่งออก หรือ ลบ everything at any เวลา.

1. Who เรา are

อัปโหลดex is opeอัตราd by Brixial Technoบันทึกies Pvt Ltd ("Brixial", "เรา", "us"), a private ขีดจำกัดed company incหรือpoอัตราd in India on 26 December 2023. Brixial is the "ข้อมูล Controller" under the EU ทั่วไป ข้อมูล Protection Regulation (GDPR) และ the "ข้อมูล Fiduciary" under India's Digital Personal ข้อมูล Protection Act, 2023 ("DPDP Act") fหรือ personal ข้อมูล processed through อัปโหลดex.

นี้ นโยบายความเป็นส่วนตัว explains what personal ข้อมูล เรา process, why เรา process it, how long เรา keep it, who เรา แชร์ it with, และ how คุณ can exercise ของคุณ rights. It applies to the อัปโหลดex เราbsite at อัปโหลดex.net และ every บริการ, API และ subโดเมน opeอัตราd จาก it (the "บริการ").

2. Personal ข้อมูล เรา process

เรา เท่านั้น collect ข้อมูล that is necessary to provide, secure, และ improve the บริการ.

  • บัญชี ข้อมูล — อีเมล เพิ่มress, display name, hashed รหัสผ่าน, preferred language, และ บัญชี การตั้งค่า. จำเป็น to สร้าง และ sign in to an บัญชี.
  • ไฟล์ เมทาดาทา — ไฟล์ name, ขนาด, MIME type, SHA-256 hash, อัปโหลด และ expiry เวลาstamps. จำเป็น to list, pรีวิว และ deliver ของคุณ ไฟล์.
  • ไฟล์ contents — stหรือed in เข้ารหัส fหรือm at rest (AES-256-GCM). เรา do ไม่ เปิด, read, สแกน fหรือ advertising, หรือ train any machine-learning model on ของคุณ ไฟล์ contents. Automated ปลอดภัยty สแกนs (see §9) examine cryptographic hashes, ไม่ content.
  • Usage และ device ข้อมูล — IP เพิ่มress, ผู้ใช้-agent string, referring URL, คำขอ path, HTTP status codes, และ เวลาstamps. Geneอัตราd whenever คุณ interact with the บริการ.
  • การสนับสนุน communications — the content of อีเมลs, ตั๋วs หรือ chat ข้อความs คุณ ส่ง to our การสนับสนุน ทีม, และ our replies.
  • Cookies และ local พื้นที่เก็บข้อมูล — strictly-necessary cookies fหรือ authentication และ ความปลอดภัย (e.g. CSRF โทเค็นs, session IDs) และ a preference cookie that stหรือes ของคุณ theme choice. เรา do ไม่ use advertising, profiling หรือ cross-site tracking cookies.

เรา do ไม่ kตอนนี้ingly collect sensitive personal ข้อมูล such as health, bioเมตริก, financial บัญชี หมายเลขs, caste, religion, political opinion, หรือ sexual-หรือientation ข้อมูล.

3. Why เรา process it (purposes และ กฎหมาย bases)

ภายใต้ GDPR เราต้องอาศัยฐานทางกฎหมายอย่างน้อยหนึ่งข้อสำหรับทุกวัตถุประสงค์ในการประมวลผลข้อมูล ส่วน DPDP Act กำหนดให้ต้องระบุวัตถุประสงค์อย่างชัดเจน และในกรณีที่เกี่ยวข้อง ต้องได้รับความยินยอมจากคุณด้วย ตารางด้านล่างนี้อธิบายว่าเราทำอะไรและเพราะเหตุใด

  • Provide the บริการ — stหรือe, pรีวิว และ deliver the ไฟล์ คุณ อัปโหลด. Basis: ประสิทธิภาพ of a contract (GDPR Art. 6(1)(b)); ประสิทธิภาพ of a contract under DPDP §7(a).
  • Keep the บริการ secure — detect การละเมิด, prเหตุการณ์ มัลแวร์ distribution, investigate เหตุขัดข้องs, อัตรา-ขีดจำกัด automated clients. Basis: legitimate interests (GDPR Art. 6(1)(f)); legitimate use under DPDP §7(i).
  • Comply with law — respond to lawful คำขอs, ไม่ify authหรือities of child-ปลอดภัยty concerns, maintain statutหรือy บันทึกs under the Infหรือmation Technoบันทึกy Act, 2000 และ the Infหรือmation Technoบันทึกy (Intermediary Guideบรรทัดs และ Digital Media Ethics Code) Rules, 2021. Basis: กฎหมาย obligation (GDPR Art. 6(1)(c)); การปฏิบัติตามข้อกำหนด with law under DPDP §7(c).
  • Communicate with คุณ — reply to การสนับสนุน คำขอs, ส่ง essential บริการ ไม่ices (e.g. ความปลอดภัย alerts, policy changes). Basis: legitimate interests / ประสิทธิภาพ of a contract.
  • Improve the บริการ — aggregate, anonymised การวิเคราะห์ such as total อัปโหลดs per ภูมิภาค หรือ median transfer ความเร็ว. Basis: legitimate interests.

เรา do ไม่ process personal ข้อมูล fหรือ advertising, profiling, automated decision-making that produces กฎหมาย effects, หรือ sale to third parties.

4. วิธี long เรา keep it (retention)

  • ไฟล์ คุณ อัปโหลด — kept until คุณ ลบ them หรือ ของคุณ บัญชี is ปิดd. ลบd ไฟล์ are purged จาก all primary พื้นที่เก็บข้อมูล within 24 hours และ จาก edge caches within 72 hours.
  • บัญชี ข้อมูล — kept fหรือ the life of ของคุณ บัญชี. ลบd within 30 วัน after คุณ ปิด ของคุณ บัญชี, unless เรา are จำเป็น to retain it longer by law.
  • Usage และ ความปลอดภัย บันทึกs — 14 วัน, then automatically truncated. Aggregated, non-identifying เมตริกs may be kept longer.
  • การสนับสนุน communications — 24 เดือนs จาก the last ข้อความ, fหรือ training และ quality-assurance.
  • Recหรือds จำเป็น by law — statutหรือy recหรือds (e.g. those mและated by Rule 3(1)(h) of the IT Rules, 2021) are kept fหรือ the ขั้นต่ำ period จำเป็น by the relevant law.

5. Who เรา แชร์ it with

เรา แชร์ personal ข้อมูล เท่านั้น with the following categหรือies of recipients, และ เท่านั้น to the ขั้นต่ำ extent necessary.

  • Infrastructure processหรือs — cloud hosting, content-delivery และ อีเมล-delivery providers acting under written ข้อมูล-processing agreements (with stและard-contractual-clauses where applicable).
  • Professional advisers — บัญชีants, auditหรือs และ lawyers bound by confidentiality.
  • Law-enfหรือcement หรือ regulatหรือs — เท่านั้น where เรา have a good-faith belief that disclosure is กฎหมายly จำเป็น under a ถูกต้อง, binding หรือder. เรา publish an annual transparency รายงาน summarising such คำขอs.
  • Successหรือs — if Brixial is acquired หรือ undergoes a reหรือganisation, personal ข้อมูล may be transferred under the same protections as set out here.

เรา do ไม่ sell หรือ rent personal ข้อมูล to anyone.

6. International transfers

อัปโหลดex opeอัตราs a global edge netwหรือk. ของคุณ ข้อมูล may be processed in jurisdictions outside India และ the European Economic Area, including the United States, the United Kingdom, Singapหรือe, และ Germany. Where เรา transfer personal ข้อมูล out of the EEA เรา rely on the European Commission's Stและard Contractual Clauses (2021 version) together with supplementary technical measures (การเข้ารหัส in transit และ at rest). Transfers จาก India are made in การปฏิบัติตามข้อกำหนด with §16 of the DPDP Act.

7. ของคุณ rights

หัวข้อ to local law, คุณ have the following rights over ของคุณ personal ข้อมูล:

  • การเข้าถึง — ask fหรือ a คัดลอก of the ข้อมูล เรา hold about คุณ.
  • Cหรือrection — ask us to cหรือrect inaccuอัตรา หรือ incomplete ข้อมูล.
  • Erasure / deletion — ask us to ลบ ของคุณ ข้อมูล where เรา have no overriding กฎหมาย basis to retain it.
  • Pหรือtability — receive ของคุณ ข้อมูล in a structured, commเท่านั้น-ใช้แล้ว, machine-readable fหรือmat.
  • Objection / withdrawal of consent — object to, หรือ withdraw previously-given consent fหรือ, specific processing.
  • Grievance / complaint — raise a grievance with our Grievance Officer (India) หรือ complain to a supervisหรือy authหรือity.

To exercise any of these rights, อีเมล [email protected] จาก the เพิ่มress associated with ของคุณ บัญชี. เรา respond within 30 วัน fหรือ GDPR คำขอs และ 30 วัน fหรือ DPDP คำขอs (extendable once by a further 30 วัน where the คำขอ is complex).

If คุณ are in the EEA หรือ UK คุณ may also complain to ของคุณ national ข้อมูล-protection authหรือity. If คุณ are in India คุณ may complain to the ข้อมูล Protection Board of India once it is operational.

8. ความปลอดภัย

เรา take the ความปลอดภัย of ของคุณ ข้อมูล seriously และ use industry-stและard controls, including:

  • TLS 1.3 fหรือ all ข้อมูล in transit.
  • AES-256-GCM fหรือ ไฟล์ contents at rest.
  • Argon2id fหรือ บัญชี-รหัสผ่าน hashing.
  • บทบาท-based การเข้าถึง control และ audit บันทึกging fหรือ all ผู้ดูแลistrative actions.
  • Least-privilege production การเข้าถึง, multi-factหรือ authentication fหรือ all staff, และ hardware-คีย์ enfหรือcement fหรือ privileged บทบาทs.
  • Annual third-party penetration testing และ a public, rewarded vulnerability-disclosure programme.

ไม่มี ออนไลน์ บริการ is 100% secure. If เรา become aware of a personal-ข้อมูล breach that is likely to result in a ความเสี่ยง to ของคุณ rights, เรา will ไม่ify คุณ และ the relevant supervisหรือy authหรือity within the เวลาframes จำเป็น by law (72 hours under GDPR; the prescribed period under the DPDP Act).

เนื้อหาไฟล์ถูกเข้ารหัสระหว่างการส่ง (TLS 1.3) และขณะจัดเก็บ (AES-256-GCM) โดยโครงสร้างพื้นฐานการจัดเก็บของเรา Uploadex ไม่ได้ใช้การเข้ารหัสแบบ end-to-end — ซึ่งหมายความว่า Uploadex สามารถเข้าถึงเนื้อหาไฟล์ได้เมื่อกฎหมายกำหนด หรือเพื่อการสแกนความปลอดภัยอัตโนมัติตามที่อธิบายในหัวข้อ §9

9. Automated content-ปลอดภัยty สแกนning

When คุณ อัปโหลด a ไฟล์, เรา compute a one-way cryptographic hash of the content และ compare it to industry hash-lists of kตอนนี้n ilกฎหมาย material (fหรือ example child-sexual-การละเมิด material และ มัลแวร์). เรา do ไม่ เปิด หรือ read the ไฟล์ itself. If a match is พบ, เรา act as จำเป็น by law, which may include preserving the ไฟล์, infหรือming a competent authหรือity, และ prเหตุการณ์ing further การเข้าถึง.

10. Children's ข้อมูล

อัปโหลดex is ไม่ directed to children under 16. Consistent with §9 of the DPDP Act, เรา do ไม่ kตอนนี้ingly process the personal ข้อมูล of a child without the verifiable consent of a parent หรือ lawful guardian. If คุณ believe a child has provided us personal ข้อมูล, please อีเมล [email protected] และ เรา will promptly ลบ it.

11. Changes to นี้ policy

เรา may อัปเดต นี้ นโยบายความเป็นส่วนตัว จาก เวลา to เวลา. When เรา make a material change, เรา will revise the "ล่าสุด อัปเดตd" date above และ ไม่ify active บัญชีs by อีเมล หรือ in-product banner at least 14 วัน befหรือe it takes effect, unless a shหรือter ไม่ice is จำเป็น by law.

12. Contact us

ข้อมูล Fiduciary / Controller
Brixial Technoบันทึกies Pvt Ltd
India
ทั่วไป ความเป็นส่วนตัว queries[email protected]
Grievance Officer (India)[email protected]
บริษัท enquiries[email protected]

See also our ข้อกำหนดการให้บริการ, นโยบายการใช้งานที่ยอมรับได้, และ DMCA / ลิขสิทธิ์ pages.