Skip to content
intoclouds.io
Back to siteLog in

Legal

Privacy Policy

Last updated: 9 July 2026

In plain English

We collect the minimum we need to run your account and infrastructure: your email and name, your organisation and resources, and technical records like IP addresses in logs. Your account data lives in the European Union; the servers you create run in whichever region you pick, which may be outside the EU. Payment card details go straight to Polar — we never see them.

We use one strictly-necessary session cookie and no analytics or tracking of any kind. You can access, correct, export or delete your data — email hello@intoclouds.io.

On this page

  1. 1. Who is responsible
  2. 2. What we collect
  3. 3. Why we use it
  4. 4. Who else processes it
  5. 5. Where it is stored
  6. 6. How long we keep it
  7. 7. Your rights
  8. 8. Cookies & tracking
  9. 9. Automated decisions
  10. 10. Children
  11. 11. Complaints

1. Who is responsible for your data

For the personal data described here, IntoClouds is the data controller. IntoClouds is operated from Chișinău, Republic of Moldova. For any privacy question, or to exercise your rights, contact hello@intoclouds.io.

This policy covers the personal data of our own customers and account holders. Where you store other people's personal data on your servers or in your mailboxes, you are the controller of that data and we act as your processor — see our Data Processing Addendum.

2. What we collect

We collect only what we need to provide and secure the service:

  • Account details — your email address, your name, and your organisation name.
  • Credentials — your password, stored only as an argon2id hash (never in plain text), and, if you enable it, your two-factor authentication secret.
  • Session data — a session cookie holding a random token; we store only a hash of that token on our side.
  • Technical logs — IP addresses appear in our server logs and are used by our rate-limiting to protect against abuse.
  • Resource metadata — the servers you create (hostnames, IP addresses, region, plan), your domains and DNS records, and your mailbox addresses.
  • Audit log — a record of every action that changes something in your account (who did what, to which resource, and when), which we keep for security and accountability.
  • Billing metadata — subscriptions, invoices and amounts. We do not receive or store your card number or other payment credentials — those go directly to Polar (see section 4).
  • Support messages — anything you send us by email or through our Telegram support bot.

3. Why we use it, and our legal basis

Under the GDPR, we rely on the following legal bases:

  • Performance of a contract — to create and run your account, provision and operate your servers, domains, DNS and email, and handle billing.
  • Legitimate interests — to keep the platform secure and to prevent and investigate fraud and abuse (for example, IP addresses in logs and rate limits, and the audit log).
  • Legal obligation — to meet requirements such as keeping invoices for tax purposes, and providing accurate registrant details to domain registries as ICANN and registry rules require.

4. Who else processes your data

We share personal data only with the service providers we need to run IntoClouds. Each acts under a contract and only for the purposes below:

Hosting — Hetzner
Hetzner Online GmbH (Germany) provides the cloud infrastructure your servers and our systems run on. Our own systems and your account data sit in EU data centres; the servers you create sit in the region you chose for them, which may be outside the EU (see section 5).
Payments — Polar
Polar acts as our merchant of record and payment processor. Polar collects your payment details and billing information directly; we receive only billing metadata (such as subscription status and invoice amounts) and never your card data.
Domains — registrar & registry
When you register or transfer a domain, the relevant registrar and domain registry process the registrant details required to operate the domain, as ICANN and registry policies mandate.
DNS lookup — Cloudflare public resolver
When you ask us to import an existing domain's DNS zone, we query Cloudflare's public DNS-over-HTTPS resolver to read that domain's current public records. This sends only a standard DNS query for your domain — no account data — and only for domains you ask us to import.
Support — Telegram
If you contact us through our Telegram support bot, Telegram processes those messages as part of delivering the conversation.

We do not sell your personal data, and we do not share it for advertising.

5. Where your data is stored

Your account data — everything in section 2 — is stored in the European Union (Germany and Finland). That is where our own systems run and it does not depend on any choice you make.

The servers you create are separate, and you choose where they run. We offer regions in Falkenstein and Nuremberg (Germany), Helsinki (Finland), Ashburn, Virginia and Hillsboro, Oregon (United States) and Singapore. If you deploy outside the EU, any personal data you put on that server is stored in that country: you are the controller of that data, so that transfer and its legal basis are yours to make. Pick an EU region if EU residency matters to you.

Some processors named above may also operate from outside the EU; where that involves a transfer of personal data we are responsible for, it is carried out under an appropriate legal safeguard such as the European Commission's Standard Contractual Clauses.

6. How long we keep it

  • Account data — for as long as your account is open, and for up to 90 days after it is closed, after which it is deleted or anonymised.
  • Audit logs — kept for 12 months for security and accountability.
  • Invoices and tax records — kept for as long as tax and accounting law requires us to.

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • rectify data that is inaccurate or incomplete;
  • erase your data ("right to be forgotten"), subject to our legal retention duties;
  • port your data — receive it in a structured, common, machine-readable format;
  • object to or restrict processing based on our legitimate interests.

To exercise any of these, email hello@intoclouds.io. We will respond within the time the law allows (normally one month).

8. Cookies & tracking

We use a single strictly-necessary session cookie to keep you logged in. It holds a random session token and is set with the HttpOnly and SameSite flags so it cannot be read by scripts or sent from other sites.

We do not use analytics, advertising, fingerprinting, or any third-party tracking cookies or scripts. There is genuinely no analytics code in the product — so there is no tracking to opt out of and no cookie-consent banner to click through.

9. Automated decision-making

We do not carry out automated decision-making that produces legal or similarly significant effects about you. Automated processes like abuse rate-limiting and non-payment suspension follow fixed, published rules and are not profiling.

10. Children

IntoClouds is a business service for adults and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.

11. Complaints

If you have a concern about how we handle your data, please contact us first at hello@intoclouds.io — we would like the chance to put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.

Terms of ServiceAcceptable UsePrivacy PolicyData Processing Addendum
intoclouds.io

Servers, domains, DNS and email — one panel, one billing page.

Cloud serversBusiness emailDomains & DNSAbout IntoCloudsContactLog inCreate accountPricingStatusGuidesTermsPrivacyAcceptable UseData Processing Addendumabuse@intoclouds.iohello@intoclouds.io

© 2026 IntoClouds · Data centers in the EU, the US & Asia