Privacy policy
Last updated: 7 October 2026
In short
- Files is a service of CodeLevel39 (VAT no. IT03778360549), which is the controller of portal users' data.
- We process the files that customers' applications upload, their descriptive data and the download logs only on the customer's behalf, as a processor: the customer is the controller of that data.
- We don't sell data, we don't do advertising or profiling, and we use no analytics or tracking tools on the site or in the portal.
- We only use strictly necessary cookies and browser storage, which is why there is no cookie banner.
- For any request about your data, write to info@codelevel39.it.
1. Who we are
The data controller is Code Level 39 di Anderlini Michele (“CodeLevel39”), a sole proprietorship, VAT no. IT03778360549, registered at Via Piave 20, 06028 Sigillo (PG), Italy. Files (the website files.codelevel39.it, the portal and the service's API) is a service of CodeLevel39: there is no separate company called Files.
For questions about this policy or to exercise your rights, write to info@codelevel39.it. We have not appointed a data protection officer (DPO): we answer directly at that address.
This policy is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003). The Italian version is the reference text.
2. CodeLevel39's two roles
Files lets our customers' applications upload, store, download and delete files. Each application works within one or more projects, each with its own storage. There are two kinds of data in the service, and we have a different role for each:
- Data about portal users (the people who sign in to the Files portal to manage projects, API keys and files) and website visitors: here CodeLevel39 is the controller, and this policy explains everything we do. See sections 3 to 5.
- Files uploaded by customers' applications, with their descriptive data (metadata) and the download logs: here the customer is the controller and CodeLevel39 is a processor under Article 28 GDPR. See section 6.
3. The data we process as controller
When you visit files.codelevel39.it
The website uses no cookies, stores nothing in your browser and contains no analytics tools, social buttons or third-party resources (even the typeface is hosted by us). Like any web server, it technically records the requests it receives (IP address, page requested, date and time, browser type) to work and to defend itself against abuse.
When you use the portal
There is no open sign-up in the portal: accounts are created by CodeLevel39 or by a project administrator, who gives us your details.
- Account data: username, password (which we only store in a non-reversible form, as a hash), your role and the projects you are assigned to, and any contact details given to receive service alerts.
- Technical and security data: a log of the operations performed (user, operation, IP address, date and time), sign-ins and failed sign-in attempts (username, IP address, browser type, date and time), temporary account locks after too many wrong attempts, session tokens.
- Abuse protection: IP addresses sending abnormal requests (for example automated scans looking for vulnerabilities) may be blocked for a limited time. The list of blocked IPs may be shared among CodeLevel39's services, so an attacker stopped on one is stopped on all.
- Communications with us: what you write to us when you ask for support.
We collect no payment data through the service.
4. Why we process it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running portal accounts, providing the service, sending service alerts (for example when a project's storage thresholds are exceeded, or about security) | Performance of the contract (Art. 6(1)(b) GDPR) |
| Protecting the service, users and customers' files: operation and sign-in logs, account and IP blocks, abuse prevention | Legitimate interest in security (Art. 6(1)(f) GDPR) |
| Answering your support requests | Performance of the contract or pre-contractual steps (Art. 6(1)(b) GDPR) |
| Complying with legal obligations and defending our rights | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f) GDPR) |
We don't use your data for advertising, we don't sell it, and we make no decisions based solely on automated processing that have legal effects on you (Art. 22 GDPR). If we ever want to send you promotional messages, we will ask you first.
The data needed to create the account (username and password) is required: without it you cannot sign in to the portal.
5. How long we keep it
| Data | Retention |
|---|---|
| Account | As long as the account is active. When it is deleted we delete the data, except what we must keep by law or to defend our rights. |
| Operation and sign-in logs (with IP address) | For a limited period, as long as needed to keep the service secure and to reconstruct any incidents; then they are deleted automatically |
| Session tokens | Expire after a limited period; expired or revoked ones are deleted periodically |
| IP address blocks | A block lasts a limited period; a record of the block is kept as security history |
| Support requests | As long as needed to handle them and document the answer |
6. Files uploaded by projects
Customers' applications upload files to Files through the API. For each file we keep its content and some descriptive data: original name, content type (recognised from the first bytes of the file), size, checksum (SHA-256), any free-form metadata chosen by the application, upload and deletion dates, and the project it belongs to. For each download we record the date and time, the file and link used, and technical data about the request, such as the IP address and browser type. Files may contain personal data of any kind: Files does not examine their content, except to recognise their type and check the project's rules (maximum size and allowed extensions).
For this data the customer who owns the project is the controller and CodeLevel39 is a processor (Art. 28 GDPR): we process it only to provide the service and according to the customer's instructions, which are those in the Terms of service (section "Data processed on the customer's behalf"), the project settings and the requests made through the API. We don't use it for our own purposes.
The customer's responsibilities
- Having a valid legal basis for the personal data contained in the files it uploads and for sharing them.
- Telling data subjects, in its own privacy notice, that it uses Files (CodeLevel39) as a file storage provider.
- Deciding who receives download links: anyone holding a valid link can download the file until the link expires.
- Answering data subjects' requests, for example by deleting the files that concern them.
The tools available
- Separation by project: each project has its own storage and its own API keys; a key only sees its own project's files.
- Temporary download links: signed, with a duration chosen by the application within the maximum set in the project, and revocable before they expire.
- Download log: to know which files were downloaded and when.
- Deletion: a deleted file can be recovered for the number of days set in the project, then it is permanently deleted.
- Per-project limits: maximum storage, maximum file size and allowed extensions.
Retention
| Data | Retention |
|---|---|
| Files and their descriptive data | Until the application or an authorised user deletes them. After deletion they can be recovered for the number of days set in the project, then they are permanently deleted from the storage. |
| Interrupted uploads | Deleted automatically |
| Download log (with IP address) | For a limited period, as long as needed to provide the log to the customer and to keep the service secure |
When a project is closed, its files are deleted. Before that, the customer can download them through the API.
Is your data in a file managed with Files, or did you receive a download link? The controller of your data is the organisation that uses Files for its application: contact them to exercise your rights. If you write to us, we will forward your request to the customer concerned.
7. Where the data is and who helps us
- Service servers: the website, portal, API and database run on servers in data centres in the European Union, with a hosting provider that processes data on our behalf under a contract binding it to confidentiality and security.
- File storage: each project uses a single storage, chosen when it is configured. It can be a service compatible with Amazon S3 (for example Amazon S3, DigitalOcean Spaces, Hetzner Object Storage, Cloudflare R2 or Backblaze), Microsoft Azure Blob Storage, or the disk of our servers in the European Union. If the storage is provided by CodeLevel39, the provider processes data on our behalf and we tell the customer which provider and which geographic region we use. If the project uses the customer's own account, the customer chooses the provider, under its own contract: Files stores and reads the files there on the customer's instruction, and that provider's terms and privacy notices apply, including the choice of the region where the data is stored.
- Service alerts: service emails (for example alerts about projects' storage) are sent through MessageWeave, another CodeLevel39 service, with the providers listed in its privacy policy.
We disclose data to authorities only when the law requires it. We don't sell or hand over data to third parties for their own purposes.
Transfers outside the EU. If one of our providers processes data outside the European Economic Area, it does so under the safeguards of Articles 44–49 GDPR, such as an adequacy decision of the European Commission (for the United States, the Data Privacy Framework) or standard contractual clauses. You can ask us for more information at info@codelevel39.it.
8. Security
We protect data with technical and organisational measures appropriate to the risk: connections always encrypted (HTTPS), passwords stored in a non-reversible form, short-lived sessions, role-based access and strict separation between projects, application requests signed with a key and a digital signature (with a timestamp and a one-time code, so a request cannot be replayed or altered), checks on the real type of files, file types that could run code in the browser always served as attachments, storage credentials never shown in clear, signed download links with an expiry, account locking after repeated wrong sign-in attempts, limits against abusive use, and automatic deletion of data when the periods above expire.
Found a security issue? Report it to the address in our security.txt (help@codelevel39.it). If a personal data breach occurs, we will notify the Italian Data Protection Authority and, where required, the people affected; for customers' files we will notify the customer (the controller) without undue delay.
9. Cookies and browser storage
Website files.codelevel39.it
No cookies and no data stored in the browser.
Portal
The portal only uses strictly necessary tools that it needs to work:
- One session cookie, which keeps you signed in. It cannot be read by the page's scripts, travels only over encrypted connections, is never sent to third-party sites, has a limited duration and is deleted when you sign out.
- The browser's local storage (localStorage), which keeps the details of the open session (username, role and permissions, not the password) and interface preferences such as language, theme and list filters.
Download links
Opening a download link sets no cookies and stores nothing in the browser.
We use no profiling, advertising or statistics cookies, neither ours nor third parties'. Strictly necessary tools do not require consent (Art. 122 of the Italian Privacy Code and the Italian Data Protection Authority's cookie guidelines of 10 June 2021): that is why we show no banner. You can clear cookies and local storage in your browser settings; without the session cookie you will have to sign in again.
10. Your rights
For the data we control, you can ask us at any time:
- to access your data and get a copy (Art. 15 GDPR);
- to correct or complete it (Art. 16);
- to erase it (Art. 17);
- to restrict its processing (Art. 18);
- to receive it in a structured, commonly used format to move it elsewhere (portability, Art. 20);
- to object to processing based on our legitimate interest (Art. 21).
Write to info@codelevel39.it. It is free and we reply within one month (for complex requests this can be extended by two more months, and we will tell you). We may ask you to confirm your identity, for example through your project's administrator.
If you believe the processing breaches the GDPR, you can lodge a complaint with the Italian Data Protection Authority, the Garante per la protezione dei dati personali (garanteprivacy.it), or with the supervisory authority of the EU country where you live or work.
11. Changes to this policy
We may update this policy, for example when the service or our providers change. The current version is always on this page, with the date of the last update; if the changes are significant we will also tell customers and project administrators.