01
Data controller
The data controller is Steeve Aukingso / Kreative Monster, publisher of the xFer service (kxfer.app). For any question about your data, write to steeve@aukingso.com.
№ 009 · Legal
Last updated: June 2026
01
The data controller is Steeve Aukingso / Kreative Monster, publisher of the xFer service (kxfer.app). For any question about your data, write to steeve@aukingso.com.
02
We only collect the data necessary to operate the Service:
Authentication (magic link), transactional notifications
Legal basis: Contract performance
Name (optional)
Delivery and account personalization
Legal basis: Consent
Uploaded files
Hosting and delivery to recipients
Legal basis: Contract performance
Delivery metadata
Tracking deliveries, approvals and revisions
Legal basis: Contract performance / legitimate interest
IP fingerprint (hashed)
Anonymized usage statistics, security
Legal basis: Legitimate interest
Stripe identifiers (customer / subscription)
Payment and subscription management
Legal basis: Contract performance / legal obligation
We never sell your data and do not use your files to train any AI model without your explicit consent.
03
To provide the Service, we use the following sub-processors, all hosted / operated in the European Union or offering appropriate safeguards:
04
Account data is retained as long as your account is active. Delivery files and links expire automatically according to your plan's durations. After your account is deleted, data is erased within 30 days, except for legal obligations (billing records: up to 10 years for accounting documents).
05
Under the General Data Protection Regulation, you have the following rights: access, rectification, erasure, portability and objection. To exercise them, write to steeve@aukingso.com. We respond within one month.
06
xFer only uses strictly essential cookies: a session cookie to keep you signed in. No advertising cookies, third-party trackers, or external analytics tools (such as Google Analytics) are used. No consent banner is therefore required for these essential cookies.
07
We implement appropriate technical measures: row-level access policies (RLS) on the database, signed and expiring URLs for downloads, encryption of data in transit (HTTPS/TLS), and unguessable link tokens.
08
Our processing is primarily located within the European Union. Where a sub-processor may involve a transfer outside the EU, it is governed by appropriate safeguards (European Commission standard contractual clauses or an adequacy decision).
09
If you believe your rights are not being respected, you can file a complaint with the CNIL (French data protection authority), www.cnil.fr.