Data processing
Revision of 1 March 2026.
What we process
| Category | Retention | Basis |
|---|---|---|
| Account data: email, name, billing details | Contract term + 5 years | Contract performance, accounting requirements |
| Sign-in log: source address, time, result | 90 days | Account security |
| Job metadata: schedules, volumes, durations | Contract term + 12 months | Service delivery, billing |
| Copy contents (encrypted) | Per the plan's retention policy | Service delivery |
| Web-server logs | 14 days | Diagnostics, abuse protection |
What we cannot read
Copy contents are encrypted by the agent before transfer, with a key that stays with you. We hold encrypted blocks and have no means to decrypt them — including in the case of a lawful request from a third party. In that situation we can hand over only the metadata listed in the table above, and are obliged to notify you unless the request itself forbids it.
Where the data lives
The account and metadata are in the Moscow region. Encrypted copies are in the regions you chose in your plan: Moscow only, or Moscow and Amsterdam. Changing the set of regions applies to new copies; ones already stored are migrated on your request.
Whom we share with
- Infrastructure providers in the chosen regions — encrypted blocks only.
- The payment operator — billing details and amounts, without job metadata.
- The email delivery service — the address and the content of notifications.
We do not pass data to advertising or analytics platforms. Public pages carry no third-party scripts, counters or external fonts — only files from this same domain.
Cookies
Public pages set no cookies. The panel uses a single session cookie with the HttpOnly,
Secure and SameSite=Strict flags; it is removed on sign-out. There is no
consent banner because there is nothing to consent to.
Your rights
- Obtain a copy of your account data in a machine-readable form.
- Correct inaccurate account data.
- Require deletion after termination, immediately instead of after 30 days.
- Withdraw consent to optional notifications, without affecting incident notifications.
Data-processing requests go to privacy@clouderra.ru, answered within 30 days. Vulnerability reports go to the address in security.txt.