Files.

Privacy policy

Last updated: 7 October 2026

In short

1. Who we are

The data controller is Code Level 39 di Anderlini Michele (“CodeLevel39”), a sole proprietorship, VAT no. IT03778360549, registered at Via Piave 20, 06028 Sigillo (PG), Italy. Files (the website files.codelevel39.it, the portal and the service's API) is a service of CodeLevel39: there is no separate company called Files.

For questions about this policy or to exercise your rights, write to info@codelevel39.it. We have not appointed a data protection officer (DPO): we answer directly at that address.

This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003). The Italian version is the reference text.

2. CodeLevel39's two roles

Files lets our customers' applications upload, store, download and delete files. Each application works within one or more projects, each with its own storage. There are two kinds of data in the service, and we have a different role for each:

3. The data we process as controller

When you visit files.codelevel39.it

The website uses no cookies, stores nothing in your browser and contains no analytics tools, social buttons or third-party resources (even the typeface is hosted by us). Like any web server, it technically records the requests it receives (IP address, page requested, date and time, browser type) to work and to defend itself against abuse.

When you use the portal

There is no open sign-up in the portal: accounts are created by CodeLevel39 or by a project administrator, who gives us your details.

We collect no payment data through the service.

4. Why we process it and on what legal basis

PurposeLegal basis
Creating and running portal accounts, providing the service, sending service alerts (for example when a project's storage thresholds are exceeded, or about security)Performance of the contract (Art. 6(1)(b) GDPR)
Protecting the service, users and customers' files: operation and sign-in logs, account and IP blocks, abuse preventionLegitimate interest in security (Art. 6(1)(f) GDPR)
Answering your support requestsPerformance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR)
Complying with legal obligations and defending our rightsLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f) GDPR)

We don't use your data for advertising, we don't sell it, and we make no decisions based solely on automated processing that have legal effects on you (Art. 22 GDPR). If we ever want to send you promotional messages, we will ask you first.

The data needed to create the account (username and password) is required: without it you cannot sign in to the portal.

5. How long we keep it

DataRetention
AccountAs long as the account is active. When it is deleted we delete the data, except what we must keep by law or to defend our rights.
Operation and sign-in logs (with IP address)For a limited period, as long as needed to keep the service secure and to reconstruct any incidents; then they are deleted automatically
Session tokensExpire after a limited period; expired or revoked ones are deleted periodically
IP address blocksA block lasts a limited period; a record of the block is kept as security history
Support requestsAs long as needed to handle them and document the answer

6. Files uploaded by projects

Customers' applications upload files to Files through the API. For each file we keep its content and some descriptive data: original name, content type (recognised from the first bytes of the file), size, checksum (SHA-256), any free-form metadata chosen by the application, upload and deletion dates, and the project it belongs to. For each download we record the date and time, the file and link used, and technical data about the request, such as the IP address and browser type. Files may contain personal data of any kind: Files does not examine their content, except to recognise their type and check the project's rules (maximum size and allowed extensions).

For this data the customer who owns the project is the controller and CodeLevel39 is a processor (Art. 28 GDPR): we process it only to provide the service and according to the customer's instructions, which are those in the Terms of service (section "Data processed on the customer's behalf"), the project settings and the requests made through the API. We don't use it for our own purposes.

The customer's responsibilities

The tools available

Retention

DataRetention
Files and their descriptive dataUntil the application or an authorised user deletes them. After deletion they can be recovered for the number of days set in the project, then they are permanently deleted from the storage.
Interrupted uploadsDeleted automatically
Download log (with IP address)For a limited period, as long as needed to provide the log to the customer and to keep the service secure

When a project is closed, its files are deleted. Before that, the customer can download them through the API.

Is your data in a file managed with Files, or did you receive a download link? The controller of your data is the organisation that uses Files for its application: contact them to exercise your rights. If you write to us, we will forward your request to the customer concerned.

7. Where the data is and who helps us

We disclose data to authorities only when the law requires it. We don't sell or hand over data to third parties for their own purposes.

Transfers outside the EU. If one of our providers processes data outside the European Economic Area, it does so under the safeguards of Articles 44–49 GDPR, such as an adequacy decision of the European Commission (for the United States, the Data Privacy Framework) or standard contractual clauses. You can ask us for more information at info@codelevel39.it.

8. Security

We protect data with technical and organisational measures appropriate to the risk: connections always encrypted (HTTPS), passwords stored in a non-reversible form, short-lived sessions, role-based access and strict separation between projects, application requests signed with a key and a digital signature (with a timestamp and a one-time code, so a request cannot be replayed or altered), checks on the real type of files, file types that could run code in the browser always served as attachments, storage credentials never shown in clear, signed download links with an expiry, account locking after repeated wrong sign-in attempts, limits against abusive use, and automatic deletion of data when the periods above expire.

Found a security issue? Report it to the address in our security.txt (help@codelevel39.it). If a personal data breach occurs, we will notify the Italian Data Protection Authority and, where required, the people affected; for customers' files we will notify the customer (the controller) without undue delay.

9. Cookies and browser storage

Website files.codelevel39.it

No cookies and no data stored in the browser.

Portal

The portal only uses strictly necessary tools that it needs to work:

Download links

Opening a download link sets no cookies and stores nothing in the browser.

We use no profiling, advertising or statistics cookies, neither ours nor third parties'. Strictly necessary tools do not require consent (Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021): that is why we show no banner. You can clear cookies and local storage in your browser settings; without the session cookie you will have to sign in again.

10. Your rights

For the data we control, you can ask us at any time:

Write to info@codelevel39.it. It is free and we reply within one month (for complex requests this can be extended by two more months, and we will tell you). We may ask you to confirm your identity, for example through your project's administrator.

If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.

11. Changes to this policy

We may update this policy, for example when the service or our providers change. The current version is always on this page, with the date of the last update; if the changes are significant we will also tell customers and project administrators.