Everabyte

Products

EverSparkSecure cloud storage for individualsEverStreamCloud storage for developers & startupsEverBlazeEnterprise-grade cloud storage for organizations

By Industry

Public SectorEnterprise & SMBHealthcareEducationFinancial ServicesMedia & Creative

By Use Case

Secure Cloud StorageBackup & ArchivingRansomware ProtectionEncrypted File Sharing
Pricing

Resources

Security ArchitectureWhitepapersBlog & InsightsFree Tools & Guides

Company

About UsContactPartner with Us

Language

Get Started
AES-256 · ZERO-KNOWLEDGE
EverSparkEverStreamEverBlaze

By Industry

Public SectorEnterprise & SMBHealthcareEducationFinancial ServicesMedia & Creative

By Use Case

Secure Cloud StorageBackup & ArchivingRansomware ProtectionEncrypted File Sharing
Pricing
Security ArchitectureWhitepapersBlog & InsightsFree Tools & Guides
About UsContactPartner with Us
Get Started

Privacy Policy

Last Updated: 28/08/2026·

Contents
  1. In short
  2. 1. Who we are
  3. 2. What we collect
  4. 3. Why we process it, and our lawful basis
  5. 4. Who we share it with
  6. 5. Where your data is stored, and transfers out of the UK
  7. 6. How long we keep it
  8. 7. Security
  9. 8. Your rights
  10. 9. Cookies
  11. 10. Automated decisions
  12. 11. Children
  13. 12. Complaints
  14. 13. If you don't provide data
  15. 14. Third parties and changes

In short

Everabyte is zero-knowledge encrypted cloud storage. Your files are encrypted on your device with a key we do not hold, so we cannot read them — and cannot recover them if you lose your key.

This policy covers the data we hold about you: your account, billing, support history and technical logs. We are the controller for that data.

If you are a business customer, the personal data inside the files your organisation stores is a separate matter: we process it as your processor under our Data Processing Agreement, not under this policy.

We do not sell your data, do not share it for advertising, and do not use it to train AI models.

1. Who we are

Everabyte Limited
Suite 3173, 275 New North Road, London N1 7AA, United Kingdom
Company no. 16338558
ICO registration: ZC209141

Data Protection Officer: [email protected] · General: [email protected] · Security: [email protected]

Everabyte is established in the United Kingdom, so no representative under Article 27 UK GDPR is required. Our supervisory authority is the Information Commissioner's Office (ICO).

This policy is governed by the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR), each as amended by the Data (Use and Access) Act 2025.

2. What we collect

From you: name, email, phone, username, hashed password, organisation and role, billing and mailing address. Invoices, transaction records, subscription status, tax identifiers where required. Whatever you send us through support, feedback or surveys.

We never store full payment details. Stripe handles card and bank payments, NowPayments handles cryptocurrency payments, and in both cases we receive only the transaction status and reference — never your card number, wallet credentials or private keys.

Automatically: IP address, browser, device, operating system, language, time zone, device identifiers. Pages and features used, session duration, and file events (upload, download, share, delete) at metadata level only. Authentication attempts, API calls, errors, security events.

From others: transaction and fraud signals from Stripe and NowPayments; identity verification data where anti-money-laundering or sanctions rules require it; publicly available business data such as a LinkedIn profile if you engage our sales team. Where we obtain data about you from a source other than you, we will tell you within one month.

What we never collect: the content of your encrypted files. We do not hold the keys and have no technical means of reading them.

This holds across our storage platform, including white-label deployments, which run the same software and handle keys the same way. It can differ on a dedicated server, or where you ask us to build a custom module that needs your data in readable form — in those cases your order form or DPA states what we can access, and we tell you before building anything that changes the position.

We do not process special category data (Article 9) or criminal offence data (Article 10) as a controller. Where a business customer stores such data in their files, we act only as their processor under the DPA — and cannot access it in any event.

3. Why we process it, and our lawful basis

PurposeLawful basis
Run your account, authenticate you, provide and maintain the ServicesArt. 6(1)(b) — contract
Take payment, manage your subscription, issue invoicesArt. 6(1)(b) — contract
Keep accounting and tax recordsArt. 6(1)(c) — legal obligation
Answer your support requestsArt. 6(1)(b) — contract
Send operational, security and policy noticesArt. 6(1)(b) — contract
Detect and prevent fraud, abuse and unauthorised accessArt. 6(1)(f) — legitimate interests
Analytics to improve performance and featuresArt. 6(1)(a) — consent, via the cookie banner. Decline and we do not do it.
Marketing to prospective customersArt. 6(1)(a) — consent
Marketing about similar products to existing customersArt. 6(1)(f) — legitimate interests (PECR soft opt-in). Object and we stop immediately.
Meet legal obligations and respond to lawful requestsArt. 6(1)(c) — legal obligation
Establish, exercise or defend legal claimsArt. 6(1)(f) — legitimate interests
Disclose to a public body on request, or for crime prevention, safeguarding or an emergencyArt. 6(1)(ea) — recognised legitimate interests

Where we rely on legitimate interests we have documented a Legitimate Interests Assessment. We have also completed a data protection impact assessment for the platform. Summaries of both: [email protected].

4. Who we share it with

  • Stripe — card and bank payment processing, and fraud detection.
  • NowPayments — cryptocurrency payment processing, if you choose to pay that way.
  • IONOS UK — data centre hosting and storage.
  • Google Analytics — website and product analytics. Only if you consent.
  • Professional advisers — auditors, accountants, lawyers, insurers, banks, where necessary.
  • Public authorities — where legally required, or on the recognised legitimate interests grounds above.
  • An acquirer — in a merger, sale or restructuring, under equivalent safeguards. We will tell you if it materially affects your rights.

All providers act under written contracts with confidentiality and Article 28 obligations. We give business customers 30 days' notice by email before adding a new provider that processes their data.

Government and law enforcement requests. We require them in writing, verify their legal authority, challenge requests that are overbroad or unlawful, disclose only the minimum specified, and notify you unless legally prohibited.

5. Where your data is stored, and transfers out of the UK

Business customers choose the data centre region for their storage. Individual accounts default to London.

Available regions, and how we make each transfer lawful:

RegionBasis for the transfer
LondonUnited Kingdom — no transfer out
Amsterdam · Frankfurt · Paris · MilanUK adequacy regulations (EEA)
Toronto · TokyoUK adequacy regulations (Canada, Japan)
Oregon · San José · VirginiaUK-US Data Bridge where the recipient is on the Data Privacy Framework list, otherwise the UK International Data Transfer Agreement
Sydney · SingaporeUK International Data Transfer Agreement

Where we rely on the IDTA rather than adequacy, we assess and document whether protection in the destination is not materially lower than under the UK GDPR, as the Data (Use and Access) Act 2025 requires.

Two transfers happen outside your chosen storage region. If you consent to analytics, Google Analytics data goes to Google LLC in the United States under the UK-US Data Bridge. And payment processing by Stripe and NowPayments may involve transfers outside the UK, under adequacy regulations or the IDTA depending on the provider.

Your account, support and log data stays in the UK regardless of the storage region you pick. Limited cross-region processing happens for authentication, billing and DDoS mitigation, and encrypted backups may sit in a secondary region. Anything crossing a border does so as ciphertext we cannot read.

Copies of the relevant transfer agreement and assessment: [email protected].

6. How long we keep it

Most of these periods are enforced automatically by scheduled jobs, not by someone remembering to do it.

DataKept for
Your account and profileWhen you delete your account: 14-day grace period, then permanently closed — the account cannot be recovered, reactivated or accessed by anyone, including us
Business account14-day grace period after the organisation is closed, then permanently closed on the same basis
Files you delete30 days in trash, then purged
Files under a retention lockFor the lock period you set — anywhere from 30 days to 5 years — then released and purged
Login and authentication attempts90 days
In-app notifications90 days
Transfer and file-event history15 days in detail, then reduced to aggregate statistics not linked to you
Webhook events and job records30 days for webhook events, 90 days for job execution records
Billing, tax and payment records7 years from the end of the tax year (HMRC requirement). Held in our accounting records, separately from the platform.
Support tickets3 years from closure
Security incident records6 years from resolution
Marketing consent records6 years after consent ends. Suppression list (name and email only, so we don't contact you again): kept indefinitely
BackupsRolling 90 days
CookiesSession / analytics 13 months / marketing 30 days

On erasure. We delete files by destroying the encryption key. From that moment the ciphertext is permanently unreadable, including in any backup still in rotation — so there is no window in which erased data stays recoverable. Where a retention lock applies, the ciphertext stays in place until the lock lifts, but nobody can decrypt it.

On account closure. Once the 14-day grace period ends, the closure is final. Neither you nor we can recover or reactivate the account, nothing in it stays accessible or usable, and there is no reserve copy to restore from. Whatever remains in our systems can no longer be used to identify you or to reconstruct the account.

7. Security

Encryption in transit (TLS 1.3 over QUIC) and at rest (AES-256-GCM) with client-side keys we cannot access. Role-based, least-privilege access with mandatory multi-factor authentication for all staff access to production. DDoS mitigation, WAF, network segmentation, intrusion detection. 6+3 erasure coding across 7 Tier III+ data centres with tested failover. Continuous monitoring, audit logging, SIEM. Annual penetration testing, responsible disclosure, dependency scanning, code review. Background checks, security training and confidentiality agreements for staff.

If a breach happens. Where we are the controller, we notify the ICO within 72 hours of becoming aware, unless the breach is unlikely to be a risk to you — and we notify you without undue delay where the risk to you is high. Where we are a processor, we notify the customer without undue delay.

8. Your rights

RightIn practice
Be informedThis policy.
AccessAsk what we hold and get a copy.
RectificationHave inaccurate data corrected — most of it you can edit in settings.
ErasureHave data deleted where Article 17 applies.
RestrictionHave processing paused in defined circumstances.
PortabilityGet your data in JSON, CSV or XML, or have it sent to another controller where feasible. Applies where our basis is consent or contract.
ObjectObject to legitimate-interests processing on grounds relating to your situation.
Object to direct marketingAbsolute. No reason needed, no balancing. We stop immediately and permanently.
Withdraw consentAt any time, as easily as you gave it. Past processing stays lawful.
Automated decisionsSee Section 10.
ComplainSee Section 12.

How. Email [email protected]. No particular wording needed.

We reply within one month. If we reasonably need clarification to find what you're asking for, we'll ask promptly and the clock pauses until you reply. Complex or repeated requests may take up to two extra months — we'll tell you why within the first month. Requests are free unless manifestly unfounded or excessive. We may verify your identity, proportionately. Access searches are reasonable and proportionate; we'll tell you if part of your request falls outside that. If we rely on an exemption in the Data Protection Act 2018, we'll say which and why.

One limit worth knowing. Because we don't hold your keys, we cannot produce the plaintext of your files, recover them, or extract records from inside them. We can confirm what exists, its metadata, and delete it. Export your files yourself, any time, through the platform.

9. Cookies

We use cookies under PECR and the UK GDPR. Every cookie we set, with its purpose and how long it lasts, is listed in the “Cookie preferences” panel in our website footer.

TypeConsent?
Strictly necessary — session authentication, security tokens, load balancing, storing your cookie choiceNo
Appearance and preferences — language, themeNo, but you can object freely and we stop
AnalyticsYes
Marketing and advertisingYes

Nothing non-essential is set before you consent. Accept and Reject are equally prominent; optional categories default to off; there is no cookie wall. Change your mind any time via “Cookie preferences” in the footer. We re-ask at least every 12 months. Persistent “remember me” cookies require consent.

10. Automated decisions

We do not make significant decisions about you by automated means alone. Every decision affecting your access or contract involves human review.

We do use automation for security: rate-limiting and temporary blocking of suspicious logins, and fraud scoring on payments. If a measure restricts your access, we tell you, and you can ask a person to review it, make representations and contest the outcome — email [email protected]. We don't use special category data in these measures, don't do marketing profiling, and don't train models on your data.

11. Children

Everabyte is for adults. You must be at least 18 to open an account. We do not offer accounts to under-18s, with or without parental consent, and we do not knowingly hold their data. If we learn we do, we close the account and delete it. Tell us at [email protected].

12. Complaints

Complain to us. You have a statutory right to complain directly to Everabyte about how we handle your data (section 164A, Data Protection Act 2018).

Email [email protected], or write to the DPO at Everabyte, Suite 3173, 275 New North Road, London N1 7AA.

We acknowledge within 30 days, investigate, and respond without undue delay. It costs nothing.

You do not have to come to us first: you can complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint, or take the matter to court.

13. If you don't provide data

Account and billing data are needed to perform our contract — without them we can't provide the Service or part of it, and we'll say so at the point of collection. Tax identifiers may be legally required. Everything else — optional profile fields, surveys, marketing and analytics consent — is genuinely optional, and declining changes nothing about your access.

14. Third parties and changes

We link to and integrate with services we don't run. We're not responsible for their privacy practices — read their notices. Before you authorise an integration we'll tell you what access it grants; you can disconnect in Settings.

We may update this policy. Minor changes appear here with a new date. Material changes — a new purpose, recipient or transfer mechanism, or anything affecting your rights — are emailed to you and shown in-product at least 30 days beforehand. Where a change needs your consent we ask for fresh, separate consent. Continuing to use the Service is never treated as consent to anything. Ask us at [email protected] if you want a previous version of this policy.

Read alongside: Terms and Conditions · Data Processing Agreement (prevails over this policy where we act as processor) · Zero-Knowledge Whitepaper

Questions?Email: [email protected]
Back to top
Everabyte

Your Data. Your Rules. Our Protection.

Secure cloud storage for individuals, startups, and enterprises.

Products

  • EverSpark
  • EverStream
  • EverBlaze

Solutions

  • Secure Cloud Storage
  • Backup & Archiving
  • Ransomware Protection
  • Encrypted File Sharing
  • Healthcare
  • Financial Services

Resources

  • Blog & Insights
  • Whitepapers
  • Free Tools & Guides

Company

  • About Us
  • Partner with Us
  • Contact
  • Datacenter

Legal

  • Privacy Policy
  • Terms of Service
GDPRsupport
PRIVATEencryption
AES-256at rest
TRUSTEDinfrastructure
SECURITY& compliance

© 2026 Everabyte. All rights reserved.

Privacy PolicyTerms of Service
EN