Terms & Conditions
GCN.ONE — Encrypted File Transfer & Storage Service
Version: 1.5 | Effective Date: 2026-07-28 | Last Updated: 2026-07-28
These Terms and Conditions (“Terms”) govern your access to and use of the GCN.ONE encrypted file transfer platform operated by ORBCORE LTD (“Company”, “we”, “us”, or “our”), a company registered in England & Wales under company number 07930383, with registered office at 3rd Floor Suite, 207 Regent Street, London W1B 3HH.
By accessing or using GCN.ONE, you agree to be bound by these Terms and our Privacy Policy. If you do not agree, do not use the Service.
Table of Contents
- Definitions
- Eligibility and Account Registration
- Description of the Service
- Service Plans and Pricing
- Payment Terms
- Zero-Knowledge Architecture and Encryption
- Data Retention and Time-to-Live (TTL) Policy
- Acceptable Use Policy
- Intellectual Property
- Third-Party Services and Links
- Disclaimer of Warranties
- Limitation of Liability
- Indemnification
- Termination and Suspension
- Governing Law and Dispute Resolution
- Privacy Policy and Data Protection
- Cookie Policy
- Rights of Data Subjects (EU / UK / US)
- International Data Transfers
- Children’s Privacy
- Changes to These Terms
- Entire Agreement and Severability
- Contact Information
1. Definitions
For the purposes of these Terms:
- “Service” means the GCN.ONE encrypted file transfer platform, including all web interfaces, APIs, and related software operated by the Company.
- “User” means any individual or legal entity accessing or using the Service, including Anonymous Users, Pay-Per-Transfer Users, Subscribers, Business Users, Enterprise Users, and API Clients.
- “Anonymous User” means a User who accesses the Service without creating an account.
- “Subscriber” means a User who has registered an account and is enrolled in a paid or free subscription tier.
- “File” means any digital content, document, archive, or data uploaded to the Service by a User.
- “Transfer” means the act of uploading a File to the Service and generating a time-limited link for retrieval by one or more recipients.
- “TTL” (Time-to-Live) means the period after which a File and all associated metadata are permanently and irrecoverably deleted from the Service’s infrastructure.
- “Zero-Knowledge” means an architectural design in which the Company has no technical capability to access, read, or decrypt the content of Files uploaded by Users.
- “Content Encryption Key (CEK)” means a symmetric encryption key generated on the client device, used to encrypt File content with XSalsa20-Poly1305 authenticated encryption, and never transmitted to or stored by the Company’s servers in plaintext.
- “Personal Data” has the meaning given to it under applicable data protection law, including the EU General Data Protection Regulation (GDPR) 2016/679, the UK GDPR, and applicable US state privacy laws.
- “Processing” has the meaning given under applicable data protection law.
- “Controller” means the Company acting as data controller for metadata and account data processed in connection with the Service.
- “API” means the application programming interface through which third parties or Business/Enterprise Users may programmatically interact with the Service.
- “Business Day” means a day other than Saturday, Sunday, or a public holiday in the United Kingdom.
2. Eligibility and Account Registration
2.1 Age Requirement
You must be at least 18 years of age to use the Service in any capacity, including as an Anonymous User. By using the Service, you represent and warrant that you meet this age requirement. See also Section 20.
2.2 Legal Capacity
You represent and warrant that: (a) you have the legal capacity to enter into a binding contract; (b) your use of the Service does not violate any applicable law or regulation in your jurisdiction; and (c) if you are using the Service on behalf of a legal entity, you have authority to bind that entity to these Terms.
2.3 Account Accuracy
When creating an account, you agree to provide accurate, current, and complete information. You are responsible for maintaining the confidentiality of your credentials and for all activity that occurs under your account. You must notify us immediately at security@gcn.one if you suspect unauthorised access to your account.
2.4 Single Account
Each individual may maintain only one personal account unless otherwise agreed in writing with the Company for Enterprise or API use cases.
2.5 Anonymous and Pay-Per-Transfer (PPT) Access
Anonymous Users and Pay-Per-Transfer Users may use certain features of the Service without creating a registered account. Such Users accept these Terms by initiating a Transfer. Anonymous use is subject to the bandwidth and file-size limitations set out in Section 4.
3. Description of the Service
3.1 Core Functionality
GCN.ONE is a zero-knowledge encrypted file transfer and storage platform that enables Users to securely send files to one or more recipients via time-limited, encrypted links. The Service is designed on the principle that the Company never has technical access to the content of any File uploaded by a User.
3.2 Service Features
Depending on the plan, the Service may include the following features:
- Encrypted shares — sending a File to one or more recipients via a time-limited, end-to-end-encrypted link.
- Proof of Delivery — an optional, cryptographically signed record of access events (such as when a link was opened or a File was downloaded) which Users may export as a certificate. Proof-of-Delivery records contain access metadata only, never File content. These certificates and any associated timestamp anchoring are provided as informational cryptographic records for the User’s own evidentiary use; they are not a qualified electronic registered delivery service, qualified electronic timestamp, or other qualified trust service within the meaning of Regulation (EU) No 910/2014 (eIDAS).
- Tamper-evident activity log — a hash-chained, independently verifiable log of upload and download events that records metadata only (no File content, file hashes, or recipient identities).
- Business and Enterprise features — team management, programmatic API access, and a GDPR Article 28 Data Processing Agreement (see Section 16).
3.3 Storage and Retention
The Service is not a general-purpose file storage service. All Files uploaded are subject to automatic and permanent deletion upon expiry of the applicable TTL period (see Section 7). The Company does not offer indefinite file hosting.
3.4 Service Availability
The Company will use reasonable commercial efforts to maintain Service availability. However, the Service is provided on an “as is” basis, and the Company does not guarantee uninterrupted availability. Scheduled maintenance will be communicated where practicable.
3.5 API Access
Business, Enterprise, and API-tier Users may access the Service programmatically subject to the rate limits, quotas, and technical specifications set out in the API documentation, which forms part of these Terms by reference.
4. Service Plans and Pricing
4.1 Plan Overview
The Service is offered under the following tiers. All prices are in EUR unless otherwise indicated.
| Plan | Type | Price | Allowance |
|---|---|---|---|
| Anonymous | Anonymous (no account) | Free | Up to 50 MB per transfer; 5 transfers per IP per rolling week |
| Free (registered) | Registered | Free | Up to 250 MB per transfer; 20 lifetime transfers; 2 GB lifetime storage |
| Pay-Per-Transfer Starter | One-time (no account) | €4/transfer | Up to 1 GB per transfer |
| Pay-Per-Transfer Small | One-time (no account) | €9/transfer | Up to 6 GB per transfer |
| Pay-Per-Transfer Large | One-time (no account) | €19/transfer | Up to 15 GB per transfer |
| Pro | Monthly subscription | €29/month | Up to 20 GB per transfer; 200 transfers per month |
| Business | Per-seat subscription (min. 5 seats) | €39/seat/month | Up to 30 GB per transfer; unlimited transfers; includes DPA |
| Enterprise | Per-seat subscription (min. 5 seats) | €59/seat/month | Unlimited file size and transfers; includes DPA |
| API | Usage-based | Custom / tiered | Per API documentation |
4.2 Free Tier Limitations
Anonymous Users are subject to: (a) per-transfer file-size limits; (b) bandwidth caps enforced at the network level; and (c) shorter TTL periods compared to paid tiers. The Company reserves the right to adjust free-tier limits at any time with reasonable notice.
4.3 Plan Changes
Subscribers may upgrade or downgrade their plan at any time. Upgrades take effect immediately. Downgrades take effect at the end of the current billing period. No refunds are issued for unused time on downgraded plans unless required by applicable consumer law.
4.4 Price Changes
The Company reserves the right to modify pricing at any time. Existing Subscribers will receive 30 days’ advance written notice of any price change affecting their current subscription. Continued use of the Service after the price change takes effect constitutes acceptance of the new pricing.
5. Payment Terms
5.1 Payment Processing
All payments are processed through third-party payment processors. The Company does not store full payment card information on its servers. By providing payment information, you authorise the Company or its designated processor to charge the applicable fees.
5.2 Billing Cycles
Subscription fees are billed in advance on a monthly or annual basis, as selected at checkout. Pay-Per-Transfer fees are charged at the time of transfer initiation.
5.3 Failed Payments
If a payment fails, the Company will attempt to re-process the charge. If payment remains outstanding after 15 days, the Company may suspend or downgrade your account to the free tier. You will be notified before suspension.
5.4 Refund Policy
Payments for completed Pay-Per-Transfer transactions are non-refundable unless the File was not successfully delivered due to a confirmed Service error. Monthly subscription fees are non-refundable except where required by applicable law. Annual subscribers who cancel within 14 days of their initial purchase or renewal may request a pro-rata refund. Users located in the European Union or United Kingdom may have additional statutory cancellation and refund rights under applicable consumer protection law (see Section 5.5).
5.5 EU and UK Consumer Right of Withdrawal
If you are a consumer located in the EU or UK, you have the right to withdraw from a subscription contract within 14 days of purchase, without giving any reason. By proceeding to use the Service immediately after purchase, you expressly request performance to begin before the end of the withdrawal period. If you exercise your right of withdrawal after partial performance has begun, you may be charged for the portion of the service already provided. To exercise this right, contact us at legal@gcn.one.
5.6 Taxes
Prices are exclusive of applicable taxes (including VAT, GST, or sales tax) unless expressly stated otherwise. Users are responsible for any taxes arising from their use of the Service in their jurisdiction.
6. Zero-Knowledge Architecture and Encryption
6.1 Client-Side Encryption
All Files are encrypted on the User’s device before being transmitted to the Service. The Content Encryption Key (CEK) is generated locally and applied using XSalsa20-Poly1305 authenticated symmetric encryption; it is never transmitted to or stored by the Company in plaintext form. Wrapping of the CEK for recipients is performed using X25519 elliptic-curve key exchange, with an optional hybrid X25519 + ML-KEM-768 key format (in which the CEK is additionally protected with AES-256-GCM under a key derived from both key exchanges) available for post-quantum protection. Equivalent client-side encryption mechanisms apply to anonymous and mass-broadcast flows.
6.2 No Content Access
Due to the zero-knowledge design, the Company is technically unable to access, read, decrypt, or otherwise process the content of any File uploaded to the Service. This limitation applies equally to Company employees, contractors, and any third parties, including law enforcement agencies making requests for file content.
6.3 Metadata
The Company processes certain metadata in connection with the Service, including transfer timestamps, file size (not content), TTL settings, IP address logs, and account identifiers, as further described in Section 16. Metadata does not include file content.
6.4 User Responsibility for Encryption Keys
If you lose access to the link or encryption key for a transfer, the Company cannot recover the File or the key. You are solely responsible for retaining access to any links or credentials required to retrieve Files within the applicable TTL window.
6.5 Law Enforcement Requests
Because the Company has no technical capability to decrypt File content, we cannot comply with requests for File content from law enforcement or other government authorities. Any lawful request for metadata will be processed in accordance with applicable law and our Law Enforcement Guidelines. This includes responding to valid European Production Orders and European Preservation Orders under Regulation (EU) 2023/1543 (“e-Evidence”) and comparable lawful orders, in each case limited to the metadata and encrypted data actually in our possession; the Company cannot produce plaintext File content because it does not hold the decryption keys.
6.6 No Content Scanning
Consistent with the zero-knowledge design, the Company does not and cannot scan, filter, hash-match, or otherwise inspect the content of Files, and performs no client-side scanning on your device. The Company does not rely on the voluntary detection framework permitted by the EU interim “Chat Control” derogation (Regulation (EU) 2021/1232). Detection and enforcement of prohibited content is limited to metadata signals and user reports as described in Section 8.
7. Data Retention and Time-to-Live (TTL) Policy
7.1 Automatic Deletion
All Files and associated per-transfer metadata are automatically and permanently deleted from the Service infrastructure upon expiry of the applicable TTL period. Deletion is irreversible. The Company does not maintain backups of user File content. The only exception is a legal preservation hold under Section 7.6.
7.2 TTL by Plan
| Plan | Default TTL |
|---|---|
| Anonymous | 3 days |
| Free (registered) | 3 days |
| Pay-Per-Transfer | 3 days |
| Pro | 1–3 days (user-selectable) |
| Business / Enterprise | Configurable within plan limits |
7.3 No Recovery After Deletion
The Company is unable to recover Files after TTL expiry. Users should download all required content before the TTL period expires. The Company is not liable for any loss arising from failure to retrieve Files before deletion.
7.4 Early Deletion
Users may manually delete a transfer at any time before TTL expiry. Upon manual deletion, the File and associated metadata are permanently removed from active storage. Residual data may remain in encrypted infrastructure for up to 30 days before being overwritten. All of the foregoing is subject to Section 7.6.
7.5 Account Data Retention
Account-level data (e.g., email address, billing history, usage logs) is retained for the duration of your account and for up to 3 years after account closure to comply with legal, tax, and audit obligations (billing and tax records are retained for up to 7 years where required by law). You may request deletion of account data subject to the exceptions in Section 18.
7.6 Legal Preservation Holds
In some jurisdictions we may be served with a legally binding order, warrant, or statutory preservation request from a court, regulator, or law enforcement authority requiring us to preserve data associated with an identified account, transfer, or object. Examples include European Preservation Orders under Regulation (EU) 2023/1543, orders of the courts of England and Wales, and preservation requests under 18 U.S.C. § 2703(f) where applicable. This list is not exhaustive.
Where we receive such an order, we may, to the extent it requires and notwithstanding Sections 7.1 to 7.5:
- (a) suspend automatic TTL deletion for the identified data;
- (b) retain encrypted File content, wrapped key material, and associated metadata beyond the periods stated in these Terms, including after you delete a transfer or close your account;
- (c) preserve the account record itself.
The following limits apply in every case:
- We act only on orders that are valid, legally binding, and sufficiently particularised (see Section 6.5). We do not act on informal requests.
- A hold is limited to the data identified in the order. It does not extend to other users, other transfers, or your data generally.
- Preserved File content remains encrypted ciphertext. A hold does not give us, the requesting authority, or anyone else the ability to decrypt it. We do not hold your keys, and preservation does not change that.
- Preserved data is held separately from active storage, is not used for any purpose other than compliance with the order, and is deleted once the order lapses, is withdrawn, or is set aside, unless a further legal obligation applies.
- Where we are permitted to tell you and time allows, we will notify you (see Section 15.4 of the Privacy Policy). Where an order prohibits disclosure, we cannot tell you that a hold is in place, and the Service may continue to show the affected data as deleted.
Our lawful basis for this processing is compliance with a legal obligation (GDPR Art. 6(1)(c)) and/or the establishment, exercise, or defence of legal claims (Art. 6(1)(f)). Your right to erasure does not apply to data under a hold for as long as the hold subsists (GDPR Art. 17(3)(b) and (e)) — see Section 18.
8. Acceptable Use Policy
8.1 Prohibited Content
You must not upload, transmit, share, or facilitate access to any content that:
- (a) is illegal under applicable law in your jurisdiction or the recipient’s jurisdiction;
- (b) constitutes, depicts, or facilitates child sexual abuse material (CSAM) or any sexual content involving minors — zero tolerance; any suspected CSAM will be reported to NCMEC, IWF, and relevant national authorities;
- (c) infringes any intellectual property right, including copyright, trademark, or trade secret;
- (d) constitutes malware, ransomware, trojans, spyware, or any other malicious code;
- (e) facilitates, promotes, or instructs on terrorism, mass violence, or other criminal activity;
- (f) constitutes harassment, hate speech, or content targeting individuals based on protected characteristics;
- (g) violates applicable data protection law, including transferring Personal Data of third parties without lawful basis;
- (h) violates applicable sanctions laws, export control regulations, or embargoes.
8.2 Prohibited Conduct
You must not:
- (a) circumvent, disable, or interfere with the security or integrity of the Service;
- (b) use automated tools, bots, or scripts to access the Service in a manner that places unreasonable load on infrastructure;
- (c) probe, scan, or test the vulnerability of any part of the Service without prior written authorisation;
- (d) attempt to reverse-engineer, decompile, or derive source code from any part of the Service;
- (e) resell, sublicense, or commercialise access to the Service without a separate written agreement;
- (f) impersonate any person or entity or misrepresent your affiliation with any person or entity;
- (g) use the Service to send unsolicited commercial communications in violation of applicable anti-spam law.
8.3 Enforcement
The Company reserves the right to investigate suspected violations and to take appropriate action, including account suspension, termination, referral to law enforcement, or civil legal action. Because of the zero-knowledge architecture, enforcement is limited to metadata signals and user-reported violations; the Company cannot proactively scan File content.
8.4 Reporting Violations
To report suspected misuse or illegal content, contact abuse@gcn.one. We will acknowledge reports within 5 Business Days.
8.5 Illegal Content, Notice-and-Action, and Removal Orders
As a hosting service provider, the Company operates a notice-and-action mechanism in accordance with the Digital Services Act (Regulation (EU) 2022/2065, “DSA”). Any person may notify the Company of content they consider illegal by contacting abuse@gcn.one (our designated point of contact for such notices), providing sufficient information to identify the specific transfer, share link, or object concerned. The Company will assess valid and sufficiently substantiated notices and act expeditiously to disable or remove the identified content where warranted, and will inform the notifying party and, where appropriate, the affected User of the action taken.
The Company will comply with legally valid orders to remove or disable access to specific content issued by competent authorities, including orders under the DSA and orders to remove terrorist content within one hour under Regulation (EU) 2021/784, and will report and remove child sexual abuse material as described in Section 8.1(b) above. Because of the zero-knowledge architecture, the Company acts on specific, identified items (by transfer, object, or share reference) rather than by scanning content, and cannot proactively detect illegal content.
The Company is a provider of hosting services within the meaning of Article 6 of the DSA and, where applicable, the corresponding provisions of the UK Electronic Commerce (EC Directive) Regulations 2002. The Company does not initiate transmissions, does not select the recipient of a transmission, and does not select or modify the content transmitted. Accordingly, the Company is not liable for information stored at a User’s request provided that it does not have actual knowledge of illegal activity or content and, upon obtaining such knowledge or awareness, acts expeditiously to remove or disable access to it, as described in this Section 8.5.
8.6 User Responsibility for Content
You are solely responsible for the Files and any other content you upload, transmit, store, share, or otherwise make available through the Service, and for your choice of recipients. The Company does not create, select, review, endorse, or control that content, and — as set out in Section 6 — is technically incapable of inspecting it.
By using the Service you represent and warrant that, for every File you transmit:
- (a) you own the content or otherwise hold all rights, licences, and permissions necessary to upload, store, and share it;
- (b) the content and its transmission comply with all applicable law, including in your jurisdiction and in the recipient’s jurisdiction, and do not breach Section 8.1;
- (c) where the content contains personal data of any third party, you have a lawful basis to disclose it to the recipient and have met any notice or consent obligations owed to that person; and
- (d) you have verified the identity of your intended recipient and the accuracy of the address or link through which you share the content.
No monitoring obligation. The Company does not monitor Files or User activity for illegal or infringing content and is under no general obligation to do so. Nothing in these Terms, and no action taken by the Company under Sections 8.3 to 8.5, creates any duty to monitor, screen, or pre-approve content, or shall be construed as knowledge or awareness of any particular content. The Company’s right to act on reports and orders is a right, not an undertaking to detect.
Dealings between Users. The Service is a transmission and storage tool. The Company is not a party to, and assumes no responsibility for, the relationship, communications, transactions, or disputes between a sender and a recipient, or between any User and any third party, arising out of content exchanged through the Service. Any such dispute is to be resolved between those parties directly.
9. Intellectual Property
9.1 Company IP
The Service, including its software, design, trademarks, logos, and documentation, is owned by or licensed to the Company and is protected by intellectual property laws. These Terms do not grant you any ownership rights in the Service or the Company’s intellectual property.
9.2 User Content
You retain full ownership of all Files and content you upload to the Service. By uploading content, you do not grant the Company any licence to your content beyond what is strictly necessary to provide the Service (i.e., the technical storage and transmission of your encrypted data).
9.3 Feedback
If you provide suggestions, feedback, or ideas regarding the Service (“Feedback”), you grant the Company a perpetual, irrevocable, royalty-free licence to use and incorporate such Feedback into the Service or other products, without any obligation to you.
10. Third-Party Services and Links
The Service may integrate with or link to third-party services, including payment processors. The Company is not responsible for the content, privacy practices, or terms of third-party services. Your use of third-party services is at your own risk and subject to those third parties’ terms.
11. Disclaimer of Warranties
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, OR UNINTERRUPTED, ERROR-FREE OPERATION.
Nothing in these Terms excludes or limits any warranty that cannot be disclaimed under applicable consumer protection law.
12. Limitation of Liability
12.1 General Cap
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY’S TOTAL AGGREGATE LIABILITY TO YOU FOR ANY CLAIM ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF: (A) THE TOTAL FEES PAID BY YOU IN THE 12 MONTHS PRECEDING THE CLAIM; OR (B) €100.
12.2 Exclusion of Consequential Damages
THE COMPANY SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF PROFITS, LOSS OF DATA, LOSS OF BUSINESS OPPORTUNITY, OR REPUTATIONAL HARM, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
12.3 Consumer Carve-Out
Nothing in Sections 12.1 or 12.2 limits liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) any other liability that cannot be excluded or limited under applicable law.
12.4 File Loss
The Company accepts no liability for loss of Files resulting from: (a) TTL expiry; (b) User failure to download Files before expiry; (c) loss of access credentials or transfer links; or (d) technical failures beyond the Company’s reasonable control.
12.5 User Content
To the maximum extent permitted by applicable law, and without prejudice to Section 12.3, the Company accepts no liability for: (a) the content of any File uploaded, transmitted, stored, or shared by a User; (b) any loss, damage, or claim arising from that content, including where it is unlawful, infringing, inaccurate, harmful, or misdirected; (c) any act or omission of a sender or a recipient, or any dispute between them; or (d) a User sharing a transfer link or credentials with, or transmitting a File to, an unintended party. Responsibility for content and for the choice of recipient rests with the User under Section 8.6.
13. Indemnification
You agree to indemnify, defend, and hold harmless the Company and its officers, directors, employees, and agents from and against any claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or relating to: (a) your use of the Service in breach of these Terms; (b) your violation of any applicable law or regulation; (c) your infringement of any third-party intellectual property right; or (d) any content you upload to the Service that causes harm to a third party.
14. Termination and Suspension
14.1 Termination by You
You may close your account at any time by following the account deletion process within the Service settings. Closure takes effect immediately. Prepaid subscription fees are non-refundable except as provided in Section 5.4.
14.2 Termination by the Company
The Company may suspend or terminate your account immediately, with or without notice, if: (a) you breach these Terms in a material way; (b) continued provision of the Service poses a legal, security, or reputational risk; (c) required by law or court order; or (d) you fail to pay applicable fees after reasonable notice.
14.3 Effect of Termination
Upon termination: (a) your right to access the Service ceases immediately; (b) Files associated with your account will be deleted in accordance with the TTL and account data retention policy, except where a legal preservation hold under Section 7.6 applies; (c) provisions of these Terms that by their nature should survive termination shall survive.
15. Governing Law and Dispute Resolution
15.1 Governing Law
These Terms are governed by and construed in accordance with the laws of England and Wales, without regard to its conflict-of-law rules.
15.2 Jurisdiction
Subject to Section 15.3, any dispute arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
15.3 EU and UK Consumer Forum
If you are a consumer resident in the European Union or United Kingdom, you may also bring proceedings in the courts of your country of residence. Nothing in these Terms affects any right you may have to use alternative dispute resolution procedures available to consumers under applicable law.
15.4 US Dispute Resolution
CLASS ACTION WAIVER: TO THE EXTENT PERMITTED BY LAW, YOU WAIVE ANY RIGHT TO BRING CLAIMS AS A CLASS ACTION, COLLECTIVE ACTION, OR REPRESENTATIVE PROCEEDING.
For Users located in the United States, the parties agree to attempt informal resolution of any dispute before commencing formal proceedings. Disputes not resolved informally within 30 days of written notice may be brought in the courts of England and Wales (or, for US-resident Users invoking a US state privacy law, the courts of the User's state of residence for claims under that state's law).
16. Privacy Policy and Data Protection
This section constitutes the Privacy Policy of GCN.ONE and applies to all Personal Data processed by the Company in connection with the Service.
16.1 Data Controller
ORBCORE LTD
3rd Floor Suite, 207 Regent Street, London W1B 3HH
Registered in England & Wales, company no. 07930383
Data Protection contact: privacy@gcn.one
16.2 What Personal Data We Collect
| Category | Specific Data | Source |
|---|---|---|
| Account Data | Email address, password hash, account preferences | Provided by User |
| Payment Data | Billing name, address, last 4 digits of card | Provided by User |
| Usage Metadata | Transfer timestamps, file size, TTL settings, number of transfers | Automatically collected |
| Technical Data | IP address, browser type, OS, referring URL | Automatically collected |
| Communications | Support ticket content, abuse reports | Provided by User |
| Anonymous Transfer Metadata | File size, TTL, upload/download timestamps | Automatically collected |
We do not collect, access, or process the content of Files you upload. File content is encrypted client-side and is technically inaccessible to us.
16.3 Purposes and Legal Bases for Processing
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Service | Performance of contract (Art. 6(1)(b)) |
| Payment processing and billing | Performance of contract (Art. 6(1)(b)) |
| Security monitoring and abuse prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
| Service improvement (anonymised) | Legitimate interests (Art. 6(1)(f)) |
| Marketing (opt-in only) | Consent (Art. 6(1)(a)) |
16.4 Data Retention Schedule
| Data Category | Retention Period |
|---|---|
| Transfer metadata | Deleted on TTL expiry |
| Proof-of-Delivery access events | 90 days after transfer expiry (IP anonymised) |
| Tamper-evident activity log | 36 months (authenticated); 90 days (anonymous) |
| Account data (active) | Duration of account |
| Account data (closed) | 3 years post-closure |
| Payment records | 7 years (tax/audit) |
| IP address logs | 90 days rolling |
| Support communications | 3 years from ticket closure |
| Data under legal preservation hold (Section 7.6) | Duration of the order; deleted when it lapses |
16.5 Data Sharing and Sub-Processors
We share Personal Data only with the following categories of recipient, under GDPR Article 28 data processing agreements where applicable: our payment processor (Stripe Payments Europe, Ltd.), legal authorities (metadata only, where required by law), and professional advisers under confidentiality obligations. Our infrastructure and hosting runs on servers located within the European Union. Our IP-geolocation database (MaxMind GeoLite2) and our transactional email (SMTP) relay are not sub-processors — the geolocation database is queried locally so your IP is never sent to MaxMind, and the mail relay is self-operated on our own domain and infrastructure. We do not sell Personal Data to third parties. We do not share Personal Data with advertising networks.
Our current sub-processor list is published at gcn.one/Pages/SubProcessors and is also available on request. Business and Enterprise customers may enter into a GDPR Article 28 Data Processing Agreement (DPA) with us through their account settings once their business details have been verified; Annex 2 of that agreement reproduces the same list.
17. Cookie Policy
| Cookie Type | Purpose | Legal Basis |
|---|---|---|
| Strictly necessary | Session management, CSRF protection, authentication | No consent required |
| Functional | User preferences, language settings | Legitimate interests / consent |
| Analytics | Aggregate usage statistics (anonymised) | Consent |
| Marketing | Email campaign tracking (opt-in only) | Consent |
For Users in the EU and UK, we obtain your consent for non-essential cookies through our cookie consent banner before setting any such cookies. You may withdraw or change your cookie consent at any time as described in our Cookie Policy — for example, by clearing the consent cookie to re-display the banner, or via your browser’s cookie controls.
18. Rights of Data Subjects (EU / UK / US)
18.1 EU and UK Rights (GDPR / UK GDPR)
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of the Personal Data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate or incomplete data |
| Erasure (Art. 17) | Request deletion of your Personal Data, subject to exceptions |
| Restriction (Art. 18) | Request that we limit processing in certain circumstances |
| Data Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Object (Art. 21) | Object to processing based on legitimate interests |
| Withdraw Consent (Art. 7(3)) | Withdraw consent at any time without affecting prior processing |
| Lodge a Complaint | Lodge a complaint with a supervisory authority |
18.2 California Rights (CCPA / CPRA)
| Right | Description |
|---|---|
| Right to Know | Request disclosure of Personal Information collected, used, disclosed, or sold |
| Right to Delete | Request deletion of Personal Information, subject to exceptions |
| Right to Correct | Request correction of inaccurate Personal Information |
| Right to Opt Out | We do not sell or share your Personal Information |
| Right to Non-Discrimination | We will not discriminate against you for exercising your rights |
18.3 Other US State Rights
Residents of Virginia, Colorado, Connecticut, Texas, and other states with enacted privacy laws may have analogous rights. Contact privacy@gcn.one to exercise your rights.
18.4 How to Exercise Rights
Submit requests to privacy@gcn.one. Response times: 30 days for EU/UK requests; 45 days for US requests. We will not charge a fee for reasonable requests.
19. International Data Transfers
Where Personal Data of EU/EEA residents is transferred outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions. UK transfers are governed by the UK International Data Transfer Agreement (IDTA).
Personal Data and transfer metadata are stored on infrastructure located in the European Union (Germany). We do not transfer File content outside the Service infrastructure because File content is encrypted client-side and we do not hold the keys.
20. Children’s Privacy
The Service is not directed at, and may not be used by, individuals under the age of 18. The Company does not knowingly collect Personal Data from minors. If we become aware that we have inadvertently collected information from a child under 13 (US) or the applicable age of digital consent (EU/UK), we will delete it promptly.
21. Changes to These Terms
The Company may update these Terms at any time. For material changes, we will provide at least 30 days’ notice via email or a prominent banner on the Service. Continued use after the effective date constitutes acceptance. If you do not agree, you must discontinue use and may close your account.
Where applicable consumer protection laws require a longer notice period or the right to terminate without penalty, those rights are preserved.
22. Entire Agreement and Severability
These Terms, together with the Privacy Policy, Cookie Policy, API documentation, and any executed Enterprise agreements, constitute the entire agreement between you and the Company. If any provision is found invalid or unenforceable, it shall be modified to the minimum extent necessary, and the remaining provisions shall continue in full force. Failure to enforce any provision shall not constitute a waiver. You may not assign your rights without consent; the Company may assign in connection with a merger or acquisition.
23. Contact Information
ORBCORE LTD
207 Regent Street, London, W1B 3HH
| Contact Type | |
|---|---|
| General / Legal | legal@gcn.one |
| Privacy / Data Requests | privacy@gcn.one |
| Data Protection Officer | privacy@gcn.one |
| Billing | billing@gcn.one |
| Security / Abuse | security@gcn.one / abuse@gcn.one |
| Support | support@gcn.one |
Response time: We aim to acknowledge all enquiries within 2 Business Days and resolve them within 30 days.
© 2026 ORBCORE LTD. All rights reserved.