Last updated: June 1, 2026
GDPR Compliance
stored.ge is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page describes how our service maps to GDPR requirements. For the full legal framework, see our Privacy Policy and Data Processing Agreement.
Contents
- Article 5 — Data Processing Principles
- Article 17 — Right to Erasure
- Article 20 — Data Portability
- Article 25 — Data Protection by Design
- Article 28 — Data Processing
- Article 32 — Security of Processing
- Articles 33/34 — Breach Notification
- Data Residency
- Sub-processors
- Contact
Article 5 — Data Processing Principles
stored.ge adheres to the core GDPR principles in the design and operation of our service:
- Data minimization: We store only the objects you upload and the minimal account metadata required to operate the service (email, hashed password, billing information). We do not collect analytics, behavioral data, or advertising profiles.
- Purpose limitation: Your data is processed solely for the purpose of providing object storage and delivery. We do not access, analyze, or profile the content of stored objects.
- Storage limitation: Account data is retained only for the duration of your account. Upon account deletion, a 30-day grace period allows data recovery, after which all data is permanently destroyed.
Article 17 — Right to Erasure
Data subjects have the right to request deletion of their personal data. stored.ge supports this through:
- Account deletion: Available via the dashboard settings page or the management API (
DELETE /account). Initiates a 30-day grace period, after which all account data, stored objects, and metadata are permanently deleted. - Object deletion: Individual objects can be deleted at any time via the S3-compatible API (
DELETEoperation) or dashboard. - Cancellation: Account deletion can be cancelled during the 30-day grace period via the dashboard settings page.
Object Lock exemption: Objects protected by Object Lock (WORM retention) cannot be deleted until the retention period expires. This is a legal compliance mechanism — if you use Object Lock for regulatory retention, erasure requests are deferred until the retention period concludes.
Article 20 — Data Portability
stored.ge provides full data portability through multiple channels:
- S3-compatible API: All stored objects are accessible via the standard S3 protocol. You can export your entire data set using any S3-compatible tool —
aws-cli,boto3,rclone,s3cmd, Cyberduck, and others — with zero modification. - GDPR data export: The dashboard settings page includes a one-click data export that downloads a JSON file containing all account data: profile, tenant information, quotas, buckets, objects, API keys, and 90 days of bandwidth history.
- No proprietary formats: Objects are stored as-is. We do not wrap, transform, or encode your data in any proprietary format.
Article 25 — Data Protection by Design
Privacy and security are built into stored.ge from the ground up:
- Encryption at rest: All stored objects are encrypted using server-side encryption (SSE-S3) with AES-256-GCM. Key encapsulation uses ML-KEM-768, a post-quantum key encapsulation mechanism standardized by NIST.
- Encryption in transit: All connections are encrypted via TLS 1.2 or higher. HSTS headers are enforced on all responses.
- Scoped API keys: API keys can be scoped to specific buckets and operations, following the principle of least privilege.
- Two-factor authentication: TOTP-based 2FA is available for all accounts and enforced for administrative access.
- No tracking: stored.ge does not use analytics cookies, advertising trackers, or third-party behavioral tracking scripts.
Article 28 — Data Processing
When you use stored.ge, FairForge LLC acts as a Data Processor on your behalf. Our processing obligations are formalized in our Data Processing Agreement, which covers:
- Processing only on documented instructions from the Controller.
- Confidentiality obligations for all authorized personnel.
- Technical and organizational security measures.
- Assistance with data subject requests and data protection impact assessments.
- Audit rights for the Controller.
To execute a DPA for your organization, visit our DPA page or contact privacy@stored.ge.
Article 32 — Security of Processing
stored.ge implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
- Encryption: AES-256-GCM at rest with ML-KEM-768 key encapsulation; TLS 1.2+ in transit.
- Access controls: Per-tenant credentials, scoped API keys, role-based dashboard access.
- Integrity: ETag (MD5) verification on every upload, Object Lock (WORM) for immutable retention, MFA Delete for versioned objects.
- Audit logging: API operations, account access, and administrative actions are logged.
- Breach notification: Automated breach tracking with 72-hour notification deadline, severity assessment, and affected user notification (see below).
- Backups: Daily PostgreSQL backups with 7-day retention in a separate location.
Articles 33/34 — Breach Notification
stored.ge maintains a breach response workflow compliant with GDPR Articles 33 and 34:
- 72-hour notification: In the event of a personal data breach, we will notify affected Controllers without undue delay, and in no case later than 72 hours after becoming aware of the breach.
- Severity assessment: Each incident is assessed for severity and scope to determine notification obligations to supervisory authorities and affected individuals.
- Notification content: Breach notifications include the nature of the breach, categories and approximate number of affected data subjects, likely consequences, and measures taken or proposed to address the breach.
- Data subject notification: When a breach is likely to result in a high risk to the rights and freedoms of individuals, affected data subjects are notified directly.
For HIPAA-covered entities, our Business Associate Agreement provides additional breach notification commitments.
Data Residency
Default storage is in the United States (Dallas, Texas: region us-central-1) through our infrastructure partner iDrive e2. Additional regions are enabled per deployment and offered in the bucket-creation region picker; regions that are not enabled cannot be selected. The regions our partner operates are:
| Region | Location |
|---|---|
| us-central-1 | Dallas, United States (default) |
| us-west-2 | Los Angeles, United States |
| us-west-4 | Oregon, United States |
| us-southwest-1 | Phoenix, United States |
| us-southeast-1 | Miami, United States |
| us-midwest-1 | Chicago, United States |
| us-east-1 | Virginia, United States |
| eu-west-1 | Ireland |
| eu-west-3 | London, United Kingdom |
| eu-west-4 | Paris, France |
| eu-central-1 | Frankfurt, Germany |
| eu-south-1 | Milan, Italy |
| ap-northeast-1 | Tokyo, Japan |
A bucket's region is fixed at creation and its objects are stored only in that region: EU regions keep data within the European Union and United Kingdom as labelled above. International data transfers are governed by Standard Contractual Clauses as described in our DPA.
Sub-processors
stored.ge engages the following sub-processors in delivering the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| iDrive Inc. | Object storage infrastructure | United States / EU |
| Stripe Inc. | Payment processing and billing | United States |
| Resend Inc. | Transactional email delivery | United States |
Changes to sub-processors are communicated with at least 30 days' notice. The full sub-processor list and notification process are documented in our DPA.
Contact
For GDPR-related inquiries, data subject requests, or to exercise your rights:
- Data Protection Officer: dpo@stored.ge
- Compliance: compliance@stored.ge
- Entity: FairForge LLC, Salt Lake City, Utah, United States