Translation provided for convenience. The French version is the only legally binding one.
Your data
Please Send It is published by PAPEL SAS (Paris Trade and Companies Register 843 729 864, 58 rue de Monceau, 75008 Paris). Depending on the data, PAPEL acts as controller, or as processor on behalf of the person asking you for documents. Here is who decides what, plainly.
1. Accounts and billing: PAPEL is the controller
- Account (email, first name, last name, optional phone number, password stored as a salted scrypt hash, never in plain text). To provide the service and sign your messages. Legal basis: the contract. Retention: as long as the account exists; everything is erased when you delete it.
- Sign-in with Google, Microsoft or Apple, if you choose it: the name of the service, your account identifier with it (a number that says nothing about you), the email address it sends us, whether it is verified, and the dates of linking and of the last sign-in. To recognize you without a password. Legal basis: the contract. Retention: as long as the method stays linked; you remove it in "My account". No access token to your Google, Microsoft or Apple account is kept.
- Acceptance of terms (text accepted, version, date and time, IP address). To prove what was accepted: Terms of Use (data processing agreement included) and data policy at sign-up, Terms of Sale before each payment. Legal basis: legal obligation and legitimate interest. Retention: as long as the account exists, then 5 years at most.
- Subscription, payments and invoices (plan, amounts, Stripe identifiers; your card is never seen by Please Send It). To invoice and keep the accounts. Legal basis: the contract and legal obligation. Retention: 10 years for accounting records.
- Affiliate program, if you join it: acceptance of the agreement, your code, clicks on your link (counted through a daily fingerprint, never through the IP address in the clear), linked accounts and organizations, commissions and payments, how you choose to be paid and, depending on that choice, your name, postal address, IBAN (stored encrypted, only its last 4 characters are shown), legal name and SIRET number, your invoices, and your declaration of employer consent. To calculate and pay your commissions and meet our accounting and tax obligations (DAS2 return above €2,400 per year). Legal basis: the contract and legal obligation. Retention: as long as you take part; the IBAN and the address are erased when you delete your account; records linked to payments (commission statements, invoices, payments) are kept for 10 years, like any accounting record.
- History of messages sent (date, channel, type, result) and an organization's activity log. To prove what was sent and ensure security. Legal basis: legitimate interest. Retention: as long as the project or organization exists.
- Email confirmation and new password links (hash only). To secure the account. Validity: 7 days for confirmation, one hour for the password.
2. Documents and recipients: PAPEL acts on behalf of the requester
If you received a link to upload documents, it is the person or organization asking you for them who decides why and for how long they need them: they are the controller. PAPEL hosts and delivers on their behalf, on their instructions, and uses your documents for no other purpose.
- Data concerned: your name, your email and possibly your phone number (entered by the requester), the files, links and answers you upload (renamed and filed in the project folder, with their original name, size, a checksum and the upload date), the date of your last visit, any electronic signatures, and the delivery status of the messages sent to you, reported by Brevo (email or SMS delivered, email opened, invalid address or number), so the requester knows whether their request reached you.
- Retention: files received are deleted automatically 90 days after the deadline of the request, unless the requester chose another period, from 30 days to one year, or deletes them earlier. Your upload link stops working on the same date. The requester is notified by email 7 days before. For a request created before September 29, 2026, the period runs from that date. Sensitive documents (ID card, passport, residence permit, bank details, payslips, tax notices, health insurance card, criminal record) are deleted sooner: 30 days after they are received, with the requester warned 3 days before.
- For an organization (company, association), the data processing agreement (Article 28 of the GDPR) forms part of the Terms of Use, accepted at sign-up.
- If the requester is an individual acting for personal purposes, PAPEL applies the same retention, security and deletion rules, and answers your requests itself.
- To stop receiving reminders for a request, use the "Stop reminders for this request" link included in each email, or "Stop reminders" at the bottom of your upload page: the requester is notified.
3. Who sees what
Only the requester (and, within an organization, the colleagues they share the project with) sees your files. Other recipients of the same project see neither your files nor your contact details. The PAPEL team only accesses them for a requested technical operation or a legal obligation.
4. Our providers (processors)
- Hostinger International Ltd (Cyprus, server in France): hosting of the whole service, database and files.
- Brevo (Sendinblue SAS, France): delivery of emails and text messages.
- Anthropic (United States, standard contractual clauses): answers from the site assistant. Only the questions you ask it are sent, with no cookie or account; Please Send It does not store them. Do not type personal data into it.
- Anthropic or Microsoft (Azure OpenAI service), depending on the provider chosen by PAPEL: AI document review, only if the organization requesting your documents has turned it on (off by default). Details below.
- Stripe (Stripe Payments Europe, Ireland): payments, only for holders of a paid plan; no recipient data. Stripe may process some data outside the European Union, with the safeguards provided by the GDPR.
- Cloudflare: domain name management (DNS) only; no document or account data goes through it.
- Documenso: electronic signature software installed on our own servers, at Hostinger; it is not a third-party company receiving your documents.
No resale, no other transfer. Any new processor is announced to organizations 30 days in advance.
Google, Microsoft and Apple to sign in, chosen by the user. Anyone can open their account with their Google, Microsoft or Apple account instead of a password. These are not PAPEL's providers: the user chooses to use them, under their own terms with them. They only send us an account identifier, your name and your email address (Apple may send a "privaterelay.appleid.com" relay address, which forwards our emails to your real address); Please Send It sends them nothing but the sign-in request, and they have access to no document. Sign-in is independent of the storage connected below.
AI document review, chosen by the organization. A holder of an Unlimited or Business plan can turn on, in "My account", an aid for reviewing the documents received. It is off by default. Once turned on, each photo or PDF received is sent, right after upload, to an AI model that indicates whether it looks like the right document, readable, complete and still valid (dates read on the document). The AI decides nothing: it shows a signal next to the file, and the requester accepts or rejects. The provider is Anthropic (Anthropic PBC, United States, standard contractual clauses) or Microsoft (Azure OpenAI service), as chosen by PAPEL; the one in use is shown in "My account". What is sent: the image reduced to 1,600 pixels per side, or the first three pages of a PDF converted to images (failing that, a PDF under 4 MB as is), with the name and instructions of the requested item and today's date; never your name or contact details. No file is stored at the provider: the document goes with the question, the answer comes straight back, and the provider does not use it to train its models. We keep the result (looks right, unsure or does not match, with a short reason) next to the file, and the number of tokens used to track the cost. Sensitive documents (ID card, bank details, payslips, tax notices...) are only analyzed if the organization has explicitly allowed it with a second checkbox.
Google Drive, Dropbox and OneDrive, chosen by the customer. A holder of an Unlimited or Business plan can connect their own Google Drive, their own Dropbox or their own OneDrive (Microsoft, including the OneDrive of a work account, hosted on SharePoint) to receive a copy of every document received. These are not PAPEL's providers: the customer chooses to use them, with their own account and under their own terms. PAPEL only writes there the documents received for them (in a "Please Send It" folder on Google Drive, in the app folder on Dropbox and on OneDrive, "Apps/Please Send It") and has access to nothing else: the authorization requested from Google only covers files created by Please Send It, and those requested from Dropbox and Microsoft only the app folder (plus, at Microsoft, reading your name and address, to display the connected account). We keep the address of the connected account and the authorization, encrypted, for as long as the storage stays connected; the customer can remove it at any time with "Disconnect" in "My account", or from their Google, Dropbox or Microsoft account. Copies made in the customer's storage belong to them: Please Send It does not delete them, not even those of sensitive documents.
5. Security
- Encrypted connection (HTTPS), files isolated by project and by recipient, content check of every file received.
- Files received are encrypted at rest (AES-256-GCM), each with its own key, protected by a master key kept outside the data and the backups.
- Encrypted backup every hour in a second location in France; a file deleted from the service disappears from it within 30 days.
- Passwords, API keys and security links stored as hashes.
- No advertising trackers, no measurement cookies, no ads. An anonymous, cookieless audience measurement counts visits to public pages and to the signed-in area (Umami, installed on our own server): no IP address is kept, no data is resold, and recipients' upload pages are never measured.
- Technical cookies only: one to stay logged in (accounts only), one to remember the language you chose. If you sign in with Google, Microsoft or Apple, a cookie lasting 30 minutes at most ties the service's return to your browser. Recipients receive none. If you arrive through an affiliate's link, a cookie remembers their code for 90 days, and nothing else, so that they are rewarded if you become a customer.
6. Your rights
You can request access, rectification, erasure, restriction or portability of your data, and object to its processing. Recipients: contact the requester first; you can also write to support@pleasesendit.com, we will pass it on and help you. Account holders: "My account" lets you correct your information and delete everything.
If you believe your rights are not respected, you can file a complaint with the CNIL, the French data protection authority (www.cnil.fr).
Last updated: September 30, 2026.
Back · Terms of Use · Terms of Sale · GDPR data processing agreement