1. Data controller
{COMPANY_NAME}, {ADDRESS}, is the data controller for the personal data processed through the TrivoCloud website, control panel and support systems.
You can reach us at bok@cloudservicedroid.site for any privacy question, including to exercise the rights listed below.
2. What we collect
Account data: name, billing address, email address, hashed password, phone number where you provide one, and where applicable your EU VAT identification number.
Order and billing data: plans purchased, invoices issued, taxes applied, payment method type, last four digits and expiry of the payment instrument (never full card numbers).
Service data: IP addresses assigned to your servers, resource usage metrics, snapshot metadata, hypervisor event logs and abuse reports we receive about your services.
Website data: IP address, user agent, pages requested and timestamps, held in access logs for security and diagnostics.
3. Purposes and legal bases
Providing the service and honoring our contract with you (Art. 6(1)(b) GDPR): account creation, provisioning, billing, delivery of the service and technical support.
Legal obligation (Art. 6(1)(c) GDPR): keeping invoices and tax records for the statutory retention period, responding to lawful requests from competent authorities and enforcing sanctions law.
Legitimate interests (Art. 6(1)(f) GDPR): preventing fraud and abuse, securing our infrastructure, improving reliability and defending legal claims. We balance these interests against your rights and only rely on this basis where the intrusion is proportionate.
Consent (Art. 6(1)(a) GDPR): optional analytics and marketing cookies and any newsletter you opt into. You can withdraw consent at any time.
4. Recipients and processors
We share personal data only with processors who help us run the service. Current subprocessors include our payment providers (Stripe, PayPal and, where enabled, a cryptocurrency processor), our transactional email provider, our anti-fraud provider and the datacenter operators who host our physical hardware in Frankfurt, Madrid and Amsterdam.
Every subprocessor is contractually bound by a Data Processing Agreement that mirrors Article 28 GDPR obligations. An up-to-date list is available on request from bok@cloudservicedroid.site.
5. International transfers
Personal data is primarily processed within the European Economic Area. Where a subprocessor is located outside the EEA, transfers rely on the European Commission's Standard Contractual Clauses (2021/914) together with supplementary technical measures such as encryption in transit and at rest.
6. Retention
Account data is retained for as long as your account is active and for 30 days after closure so you can reactivate it.
Invoices and related tax records are retained for the statutory period required by our country of registration, currently 10 years.
Server access logs and abuse-related evidence are retained for up to 90 days unless a longer retention is required to defend a specific legal claim.
7. Your rights
You have the right to access your personal data, to have inaccurate data corrected, to have data erased where the legal basis no longer applies, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent for any processing that relied on it.
You can exercise any of these rights by writing to bok@cloudservicedroid.site. We respond within one month.
You also have the right to lodge a complaint with the data protection authority in your country of habitual residence.
8. Security
We use encryption in transit (TLS 1.2+), encryption at rest for backups, role-based access control, multi-factor authentication for all staff accounts, network segregation between the management plane and customer workloads, and structured incident-response procedures. In the unlikely event of a personal data breach that poses a risk to your rights, we notify affected customers and the competent supervisory authority within 72 hours as required by Article 33 GDPR.
9. Changes to this policy
We may update this policy from time to time. Material changes are announced by email to the address on file at least 30 days before they take effect. The date at the top of this page reflects the last revision.