TrustMFT
Privacy Policy Terms of Service

Privacy Policy

Effective date: May 23, 2026

TrustMFT ("we", "us", or "our") operates the TrustMFT managed file transfer platform. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it. By using TrustMFT, you agree to the practices described below.

1. Information We Collect

Account information. When you sign up, we collect your name, email address, company name, and a password (stored as a one-way hash — we never store your plaintext password).

File data. Files you upload through the web portal or SFTP are stored on your behalf. We do not access the contents of your files except as required to provide the service (e.g., malware scanning) or as required by law.

Audit and activity logs. We record all significant actions — logins, uploads, downloads, deletions, and administrative changes — along with the user, timestamp, IP address, and outcome. These logs are used for security, compliance, and troubleshooting purposes.

Technical data. We collect standard server logs including IP addresses, browser type, and pages accessed. We use Microsoft Azure Application Insights for performance monitoring and error tracking.

SFTP credentials. SFTP usernames and hashed passwords are stored separately from web portal credentials.

2. How We Use Your Information

  • To provide, operate, and maintain the TrustMFT service
  • To authenticate you and control access to files and features
  • To send transactional emails (file notifications, password resets, email verification)
  • To monitor service health, investigate security incidents, and prevent abuse
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising.

3. Data Storage and Security

All data is hosted on Microsoft Azure infrastructure. Files are stored in Azure Blob Storage with server-side AES-256 encryption. Encryption keys are managed per tenant in Azure Key Vault. All web traffic is encrypted using TLS 1.2 or higher. SFTP connections use SSH encryption.

Access to your data is restricted by role-based access controls. Audit logs record all access to your files. We enforce account lockout after repeated failed login attempts and require email verification for new administrator accounts.

4. Data Retention

Your files and account data are retained for as long as your account is active or as needed to provide the service. Audit logs are retained for a minimum of 12 months. If you close your account or your subscription is terminated, your data will be deleted within 30 days unless we are required to retain it longer by law.

5. Third-Party Service Providers

We use the following third-party providers to deliver the service:

  • Microsoft Azure — cloud infrastructure, storage, database, and email delivery
  • Azure Communication Services — transactional email delivery
  • Azure Application Insights — performance monitoring and error tracking
  • Stripe — payment processing for paid subscriptions. Stripe collects and processes payment card data directly and does not share it with us. See Stripe's Privacy Policy for details.

These providers process data on our behalf under their own privacy and security standards. We do not share your data with any other third parties without your consent, except as required by law.

6. International Data Transfers

Your data is stored and processed within Microsoft Azure data centres. If you are located in the European Economic Area (EEA), your data may be transferred outside the EEA. Where this occurs, we ensure appropriate safeguards are in place in accordance with applicable data protection law.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your personal data
  • Object to or restrict certain processing
  • Request a portable copy of your data

To exercise any of these rights, contact us at legal@trustmft.com. We will respond within 30 days.

8. Cookies and Session Data

TrustMFT uses a session authentication cookie to keep you logged in. This cookie is:

  • HttpOnly — not accessible by JavaScript
  • Secure — transmitted only over HTTPS
  • SameSite: Strict — not sent with cross-site requests

We do not use advertising cookies or third-party tracking cookies. Sessions expire after 25 minutes of inactivity.

9. Children's Privacy

TrustMFT is a business-to-business service and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the portal. Continued use of the service after changes take effect constitutes your acceptance of the updated policy.

11. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us at legal@trustmft.com.

© 2026 TrustMFT — Privacy Policy · Terms of Service