Terms of service
Last updated: 7 October 2026
In short
- Files is a CodeLevel39 service that lets applications upload, store, download and delete files without knowing where they physically live. It is meant for businesses and professionals.
- Today it is a restricted service: we activate accounts and projects on request. It is provided as is, with no availability guarantees; any fees are agreed separately.
- Only upload files you have the right to store and share. No illegal content and no malicious code.
- Your files stay yours: we only process them on your behalf.
1. Who we are and what these terms are for
The Files service is provided by Code Level 39 di Anderlini Michele (“CodeLevel39”), a sole proprietorship, VAT no. IT03778360549, registered at Via Piave 20, 06028 Sigillo (PG), Italy ("we", "us"). These terms are the contract between us and the business, organisation or professional using the service ("you" or "the customer"). You accept them when we activate a project or an account for you, or when you use the service.
How we process personal data is explained in the Privacy policy, which forms part of these terms. This English text is a translation: in case of differences, the Italian version prevails.
2. The service
Files lets your applications upload, store, download and delete files through an API, with requests authenticated by a key and a digital signature. Each project has a single storage (a service compatible with Amazon S3, Microsoft Azure Blob Storage or the disk of our servers) and its own rules: maximum storage, maximum file size, allowed extensions, days during which deleted files can be recovered, maximum duration of download links. Applications only know each file's identifier; to let a person download it, they ask Files for a temporary signed link. The portal lets you manage users, projects, API keys and files, and follow storage usage and downloads.
The service is in its launch phase: features may change, be improved or, if necessary, be withdrawn. If we remove an important feature you are using, we will try to tell you in good time.
3. Who can use it
- Files is intended for professional use: businesses, public bodies, associations and professionals. It is not offered to consumers for personal purposes, nor as a public file-sharing service.
- Today the service is restricted to CodeLevel39's projects and to customers we have an agreement with: there is no open sign-up.
- Whoever requests activation must be of legal age and authorised to accept these terms on behalf of the organisation they represent. The details they give us must be true and kept up to date.
4. Account and security
- Portal users have a role on each project they are assigned to. A project's administrators can create other users, assign them to the project and manage API keys; you are responsible for what the people, applications and API keys you authorise do in your projects.
- Keep passwords, API keys and signing secrets confidential, don't share them and don't reuse them elsewhere. If you think someone has obtained them, change or revoke them immediately and let us know.
- We may temporarily block an account, an API key or an IP address to protect the service, for example after too many wrong sign-in attempts.
5. Access to the service, limits and costs
- Today Files has no public plans: we activate projects and accounts on request. Any fees are agreed in writing before activation; we will never charge you without your explicit consent.
- Each project has limits (for example maximum storage, maximum file size and allowed extensions), which you can see in the portal and which we may change. When a project's storage is full, new uploads are refused; downloads and deletions keep working.
- If the project uses storage under your own account, its costs (storage, traffic, operations) are not included: the provider bills you directly, under your contract with them.
6. Storage and credentials
- If you connect your own account with a storage provider to a project (for example a service compatible with Amazon S3, or Microsoft Azure), the contract with them is yours: you comply with their terms, usage rules and prices, and you choose the geographic region where they store the data.
- We use the credentials you entrust to us only to store, read and delete the project's files, we protect them with appropriate measures and we never show them in clear, not even in the portal. Keeping them valid, and revoking them when no longer needed, is up to you; before saving new ones we check that they work.
- Once a project contains files, the storage type, the container (bucket or container) and the service address can no longer be changed: the existing files would become unreachable.
- We are not responsible for the decisions and malfunctions of providers you choose: if a provider limits, suspends or closes your account, or loses files or makes them inaccessible, that is outside our control.
7. Acceptable use
By using Files you agree to:
- upload only files you have the right to store and to make available for download, with a valid legal basis for the personal data they contain;
- give download links only to those who should be able to download the file, knowing that anyone holding a valid link can use it until it expires;
- comply with applicable law, including the GDPR, the Italian Privacy Code and copyright law.
You may not:
- upload or distribute content that is illegal, fraudulent, phishing, contains viruses or malicious code, is offensive, discriminatory or infringes third-party rights (for example trademarks, copyright, confidentiality);
- use Files as a public file-sharing service open to anyone, or to publish files to an indefinite number of people, unless agreed with us;
- circumvent project limits or security measures, access files of other projects or other customers, probe the service for vulnerabilities or overload it (good-faith security reports are welcome: see our security.txt);
- resell the service to third parties without an agreement with us.
If we receive reports or notice use contrary to these rules, we may act as described in section 12.
8. Your files and your data
- The files and data you upload remain yours. You only grant us the right to use them as needed to provide the service to you.
- You are responsible for the files you upload and make available for download, and for having all the rights and consents needed to use them.
- Files is not a backup service: we recommend keeping your own copy of important files. A deleted file can only be recovered for the number of days set in the project, then it is permanently deleted, as stated in the Privacy policy.
- The software, the brand and the service materials remain CodeLevel39's.
9. Data processed on the customer's behalf (Art. 28 GDPR)
For the personal data contained in the files you upload, their descriptive data and the download logs, you are the controller and CodeLevel39 is the processor. This section is the contract required by Article 28 GDPR.
- Subject matter and duration: provision of the Files service, for the whole term of the contract.
- Nature and purpose: receiving, storing, making available for download and deleting files in the project's storage; logging downloads; usage statistics for you.
- Types of data: the personal data contained in the files you decide to upload, the files' descriptive data (name, type, size, free-form metadata) and technical download data (date and time, IP address, browser type). Do not upload special categories of data (for example health data) unless they are essential and you have an adequate legal basis.
- Data subjects: the people whose data appears in the files, your users and customers, and those who download files through the links you have generated.
- Instructions: we process the data only on your documented instructions, i.e. these terms, the project settings and the requests made in the portal or through the API. If an instruction seems unlawful to us, we will tell you.
- Confidentiality: anyone accessing the data on our behalf is bound by confidentiality.
- Security: we apply the Art. 32 GDPR measures described in the privacy policy.
- Sub-processors: you authorise us to use the providers indicated in the Privacy policy (hosting and, when we provide it, the project's storage), bound by the same obligations. We will inform you of changes by publishing the updated information and, for significant ones, by email, so that you can object; if your objection prevents us from continuing to provide the service, you may close the project. Storage providers connected with your own account are not our sub-processors: you choose them and we store files there on your instruction.
- Assistance: we help you answer data subjects' requests (the API and the portal let you find, download and delete files) and, as far as we are concerned, with the obligations of Arts. 32–36 GDPR.
- Breaches: if we become aware of a breach affecting this data, we notify you without undue delay, with the information we have.
- End of the contract: when the project is closed we delete the files and related data, except what must be kept by law; before that you can download the files through the API.
- Audits: on reasonable request we provide the information needed to demonstrate compliance with these obligations.
10. Availability and support
- Unless otherwise agreed in writing, the service is provided "as is" and "as available", with no availability guarantees or service levels (SLA). We do our best to keep it working well and continuously, but there may be interruptions, including for maintenance or updates.
- The availability and speed of uploads and downloads also depend on storage providers and networks: we cannot guarantee them.
- Support is by email, with no guaranteed response times.
11. Liability
- To the fullest extent permitted by Italian law, CodeLevel39 is not liable for indirect damage, loss of profit, loss of opportunity or of data, or for damage caused by storage providers, third-party services, force majeure or use of the service contrary to these terms.
- These limitations do not apply in case of wilful misconduct or gross negligence (Art. 1229 of the Italian Civil Code), nor in other cases where the law does not allow liability to be limited.
- You agree to hold CodeLevel39 harmless from third-party claims (data subjects, rights holders, storage providers, authorities) arising from your use of the service in breach of these terms or the law.
12. Suspension and termination
- You can stop using the service and ask for your projects and accounts to be closed at any time by writing to info@codelevel39.it.
- We may immediately suspend, in whole or in part, an account, an API key or a project that breaches these terms or the law, endangers the security of the service or other customers, is the subject of well-founded abuse reports, or if an authority requires it. Where possible we will explain the reason and give you a chance to fix it.
- For other reasons, including the end of the service, we may close a project with at least 30 days' notice by email, so that you can download your files.
- After closure, data is deleted as stated in the Privacy policy.
13. Changes
We may change these terms, for example for new features or changes in the law. The current version is always on this page with the date of the last update. We will notify you of significant changes by email at least 15 days before they take effect, except those required by law or for security reasons. If you don't accept them you can close your projects before that date; if you keep using the service, the changes are deemed accepted.
14. Governing law and jurisdiction
These terms are governed by Italian law. The courts of Perugia have exclusive jurisdiction over any dispute about their interpretation or performance.
15. Contact
Code Level 39 di Anderlini Michele, VAT no. IT03778360549, Via Piave 20, 06028 Sigillo (PG), Italy. Email: info@codelevel39.it. For security reports: the address in our security.txt.
16. Specific approval of clauses
Under Articles 1341 and 1342 of the Italian Civil Code, the customer specifically approves the following clauses: 5 (changes to project limits and refusal of uploads when storage is full), 6 (exclusion of liability for storage providers chosen by the customer), 10 (service without availability guarantees), 11 (limitations of liability and indemnity), 12 (suspension and termination), 13 (changes to the terms), 14 (governing law and exclusive jurisdiction).