File sharing for creative agencies
The thing that breaks file sharing at an agency is not size — it is that several people send on behalf of one company, and personal accounts do not survive staff turnover. When a designer leaves, every delivery link they created leaves with them, and nobody notices until a client asks for last year's assets.
That, a data processing agreement, and retention you control are what an agency actually needs. Transfer ceilings, which every comparison leads with, come fourth.
I run Yungle, so treat this as interested writing. Claims about other companies come from their own documentation on the date given; no competitor prices appear on this site.
The four failures that cost agencies money
Links owned by people, not by the company. A freelancer sends a delivery from their own account. Eight months later the client needs it again and the freelancer has moved on. This is the most common and the most avoidable.
No processing agreement. The moment you handle files containing personal data on a client's behalf — customer lists, photography of identifiable people, employee material — you are a processor and you need it in writing, both from your client and with your own vendors. What the GDPR actually requires covers the shape of it.
Retention that is somebody else's decision. Free tiers delete in 7 to 15 days. Client contracts often require deletion at the end of an engagement, or retention for a fixed period. Neither is served by a default you cannot change. Retention is a decision.
Delivery that carries someone else's brand. A client receiving your work on a page with another company's logo, and on some free tiers another company's advertising, is a small thing that reads badly at exactly the wrong moment.
What to require from a vendor
Ask these five in writing. Any serious vendor answers quickly, and the ones that cannot are telling you something.
- Can we sign a data processing agreement, and who are your sub-processors?
- Which country do the files sit in, and which country's courts can compel access?
- When someone leaves, what happens to the links they created?
- Can we control how long files are kept, in both directions?
- What does the recipient see — our brand, yours, or an advertisement?
Question two catches more people than the rest combined, because "EU data centre" and "EU company" are different answers. The CLOUD Act piece explains why that distinction decides procurement.
Where the options stand
Dropbox (Transfer checked 31 July 2026: 2 GB free, 30 days default, no ads). If the agency already runs on Dropbox, this is the path of least resistance, the account structure already exists, and it is a defensible institutional choice. The limits are the small transfer ceiling and that Transfer cannot be bought separately. It is a US company.
WeTransfer (checked 31 July 2026): 3 GB free counted across a rolling 30 days, ad-supported, never-expiring transfers on the top tier only. Widely used and widely understood by clients, which has real value. Put the five questions above to them directly.
Filemail (checked 1 August 2026): the Business plan lists transfer size as "Any Size", 1 TB per user and permanent file availability. If the agency's problem is genuinely enormous files, this is the category specialist.
SwissTransfer (checked 1 August 2026): free, 50 GB, files deleted after 15 days, archives over 10 GB downloaded file by file. Excellent for individuals, not designed for shared organisational use, and Swiss rather than EU.
Yungle, mine: collections that do not expire on a paid plan, folder structure preserved, client proofing, file request links, workspace members with their own named access to the same account, and delivery on your own domain on the top plan. Seats are billed per person. One server in Germany, backups in the EU, every file encrypted at rest with its own key, and a DPA you can read before committing to anything.
One thing to settle before committing: there is no service level agreement. If your client contracts pass delivery obligations down to you, that belongs in the decision.
Structuring it so it survives people leaving
Whatever you buy, three habits matter more than the vendor:
One company account, named members. Not a shared login with the password in a document. Named access means offboarding is a revocation, and it means an audit question has an answer.
Deliverables belong to the project, not the person. If your delivery structure is per-client rather than per-employee, staff changes stop being data-loss events.
Write down the retention rule, once. How long client files are kept after a project closes, and who deletes them. Then pick a service that can implement it rather than one that imposes its own.
Keep your own backup. No transfer service is your archive, including mine. If losing a deliverable would be a commercial problem, it needs to exist in two places.
Where to start
If the agency already has Dropbox or Google Workspace and nobody is complaining, the honest answer is that changing vendors is not the highest-value thing you could do this quarter — tightening the four habits above is.
Change vendors when a specific failure has cost you: a link that died with an employee, a client asking for a DPA you cannot produce, or a delivery that looked unprofessional. The full comparison is the place to start from, and the business-use page covers the smaller-company version of the same decision.