Privacy Policy
What personal data Dropable processes, on what basis, and what rights you have.
- Version:
- 2026-08-15
- In force since:
- 2026-08-15
- Last updated:
- 2026-08-15
This policy explains how NinetoSix GmbH processes personal data when you visit dropable.io and when you use Dropable.
One distinction runs through the whole document: for the account data of the businesses who buy Dropable we are the controller, while for the media those businesses upload we act only on their instructions. The section on our two roles sets this out.
1. Controller
- Controller
- NinetoSix GmbH
- Address
- Willy-Brandt-Platz 4, 90402 Nürnberg, Germany
- legal@dropable.io
- Phone
- +49 (0) 151 23476125
We have not appointed a data protection officer, as we are not required to do so. Enquiries about data protection reach us at legal@dropable.io.
2. Two roles: controller and processor
Dropable is sold to businesses, typically agencies, who use it to share media with their own clients. That produces two different relationships, and this policy covers both.
Where we are the controller
For the data of our own customers and their users, we decide the purposes and means of processing. This covers account and login data, workspace and membership data, billing data, support correspondence, and our own measurement of how the product is used.
Where we are a processor
For the files a customer uploads, and for the data of the clients that customer invites, the customer is the controller and we process only on their documented instructions. We do not use that content for our own purposes.
The processing on behalf of our customers is governed by the data processing agreement at https://dropable.io/dpa.
3. Visiting the website
When you open a page, technical data required to deliver it is processed: IP address, the requested address, the time of the request, the referring page, and information about your browser and operating system.
This processing is necessary to deliver the page and to maintain the security and stability of the service. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in operating the service securely.
Server-side log data is generated by our hosting provider and is kept for a short period for security and diagnostic purposes.
5. Account and workspace
To create an account we process your email address, your name where you provide it, and your profile picture where you upload one. For a workspace we process its name, brand settings, membership and roles.
The legal basis is Article 6(1)(b) GDPR: the processing is necessary to perform the contract you entered into, or to take steps at your request before entering into it.
6. Signing in
We authenticate by email link and by passkey. We do not use passwords, so no password is stored.
For a passkey we store the public key, a credential identifier, and metadata about the device that registered it. The private key never leaves your device and is not accessible to us.
For an email link we process your email address and a single-use token. Changing your email address requires confirmation from both the old and the new address, so that neither can be changed without access to the other.
The legal basis is Article 6(1)(b) GDPR, and Article 6(1)(f) GDPR for the security measures involved.
7. Files, previews and video
Files uploaded to a workspace are stored, and previews and other derivatives are generated from them so they can be displayed in a browser. Video files are additionally processed for adaptive delivery.
The content of those files is processed on behalf of the customer who uploaded them. We do not inspect, analyse or use it for our own purposes, and we do not use it to train any model.
We record technical delivery events, such as which stored object was delivered and how much data that involved, because that measurement is the basis for usage-based billing.
9. Billing
For paid plans we process the data required to conclude and perform the contract: company name, billing address, VAT identification number where given, plan and subscription state, usage measured for billing, and invoices.
Payment is processed by Stripe. Card details are entered on Stripe's payment page and are not received or stored by us. Stripe processes payment data as its own controller for its own compliance obligations.
The legal basis is Article 6(1)(b) GDPR for performance of the contract, and Article 6(1)(c) GDPR for retention of accounting records under commercial and tax law.
10. Email we send
We send transactional email: sign-in links, invitations, confirmations of address changes, notifications you have enabled, and billing notices. Delivery is handled by Resend.
The legal basis is Article 6(1)(b) GDPR. We do not send advertising email without separate consent.
11. Early access list
If you request early access on our website, we store your email address, the language of the page, where on the site you signed up, your browser user agent, the referring page and the version of this policy you saw. We do not store your IP address with the entry. We use a hashed form of it only briefly to limit repeated requests.
We first send a confirmation email. Your address is only on the list once you confirm it. We use it to contact you about access to Dropable and for nothing else.
The legal basis is your consent under Article 6(1)(a) GDPR. You can withdraw it at any time with the link in our email or by writing to us; the entry is then marked as withdrawn and no further email is sent.
12. Product measurement
We measure how the product is used so that we can improve it: which steps of a flow are completed, which are abandoned, and how quickly pages render.
This measurement is first-party. It runs on our own infrastructure, no third-party analytics provider is involved, and no data leaves the service for that purpose. We do not use Google Analytics, Google Tag Manager, Meta Pixel or any comparable service.
On public pages the measurement is aggregate only: no visitor identifier and no session identifier is recorded, so public measurement cannot be related to an individual. Recorded page addresses are reduced to the bare path, so identifiers carried in a link are not stored.
In the signed-in area, events may be linked to the workspace and the acting user, because there the processing serves the operation and improvement of a service you are logged into. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is understanding and improving our own product.
13. Security and audit records
We record security-relevant actions inside a workspace, such as membership and permission changes, so that a customer can trace what happened in their own workspace and so that we can investigate misuse.
The legal basis is Article 6(1)(f) GDPR, and Article 6(1)(b) GDPR where the record forms part of the service owed to the customer.
14. Records of declarations and agreement
Because we contract only with businesses, we record the declaration of entrepreneur status and the acceptance of our terms and data processing agreement: which document, which version, when, and in which context.
We do not record an IP address for this purpose. The legal basis is Article 6(1)(c) and Article 6(1)(f) GDPR; our legitimate interest is being able to demonstrate the agreement that was concluded.
15. Processors and recipients
We use the following providers to operate the service. Each is bound by a data processing agreement, or processes as an independent controller where indicated.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and file storage |
| Vercel | Hosting and content delivery of the application |
| Cloudflare | Video processing and delivery |
| Stripe | Payment processing and invoicing |
| Resend | Delivery of transactional email |
The current list with processing locations and transfer bases is published at https://dropable.io/subprocessors.
Beyond this we pass personal data on only where we are legally obliged to, or where it is necessary to establish, exercise or defend legal claims.
16. Transfers outside the EU
We select providers so that stored content remains within the European Union wherever possible. Some providers nevertheless process data in third countries, in particular the United States, for example when delivering content through a global network.
Such transfers take place either on the basis of an adequacy decision by the European Commission, including the EU-US Data Privacy Framework where the provider is certified, or on the basis of standard contractual clauses under Article 46(2)(c) GDPR together with additional safeguards.
The basis applying to each provider is stated at https://dropable.io/subprocessors.
17. How long we keep data
| Data | Retention |
|---|---|
| Account and workspace data | For the duration of the agreement |
| Early access list entries | Until you withdraw consent or ask us to delete the entry |
| Files after deletion or after the agreement ends | 30 days, then irreversibly deleted |
| Raw usage events for billing | 90 days, aggregated figures are kept longer |
| Invoices and accounting records | Statutory retention periods under commercial and tax law |
| Records of declarations and agreement | For the duration of the agreement and the subsequent limitation period |
| Security and audit records | As long as necessary for the purpose |
Where a legal retention obligation prevents deletion, we restrict processing of the data concerned instead.
18. Security
Data is transmitted over encrypted connections and stored encrypted at rest by our infrastructure providers. Access to data is separated by workspace at the database level, so one customer cannot reach another customer's data.
Access to production systems is limited to the persons who need it, authentication uses passkeys and single-use links rather than passwords, and administrative access paths are separated from the paths the application itself uses.
19. Your rights
You have the right to obtain information about the personal data we process about you (Article 15 GDPR), to have inaccurate data corrected (Article 16), to have data erased (Article 17), to restriction of processing (Article 18), to receive your data in a portable format (Article 20), and to object to processing based on legitimate interests (Article 21).
Where processing is based on consent, you may withdraw it at any time with effect for the future.
To exercise your rights, contact legal@dropable.io. If your data was placed on the service by an agency, please contact that agency; we will forward your request to them and support them in answering it.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your residence, place of work, or the place of the alleged infringement.
20. No automated decision-making
We do not use automated decision-making producing legal effects concerning you, and we do not carry out profiling within the meaning of Article 22 GDPR.
21. Changes to this policy
We update this policy when the processing it describes changes. The version currently in force and the date it took effect are stated at the top of this page.
This document describes the processing that actually takes place. Where a change to the service changes the processing, this policy is changed with it.