Legal
Privacy Policy
Last updated: 9 July 2026
1. Who is responsible for your data
For the personal data described here, IntoClouds is the data controller. IntoClouds is operated from Chișinău, Republic of Moldova. For any privacy question, or to exercise your rights, contact hello@intoclouds.io.
This policy covers the personal data of our own customers and account holders. Where you store other people's personal data on your servers or in your mailboxes, you are the controller of that data and we act as your processor — see our Data Processing Addendum.
2. What we collect
We collect only what we need to provide and secure the service:
- Account details — your email address, your name, and your organisation name.
- Credentials — your password, stored only as an argon2id hash (never in plain text), and, if you enable it, your two-factor authentication secret.
- Session data — a session cookie holding a random token; we store only a hash of that token on our side.
- Technical logs — IP addresses appear in our server logs and are used by our rate-limiting to protect against abuse.
- Resource metadata — the servers you create (hostnames, IP addresses, region, plan), your domains and DNS records, and your mailbox addresses.
- Audit log — a record of every action that changes something in your account (who did what, to which resource, and when), which we keep for security and accountability.
- Billing metadata — subscriptions, invoices and amounts. We do not receive or store your card number or other payment credentials — those go directly to Polar (see section 4).
- Support messages — anything you send us by email or through our Telegram support bot.
3. Why we use it, and our legal basis
Under the GDPR, we rely on the following legal bases:
- Performance of a contract — to create and run your account, provision and operate your servers, domains, DNS and email, and handle billing.
- Legitimate interests — to keep the platform secure and to prevent and investigate fraud and abuse (for example, IP addresses in logs and rate limits, and the audit log).
- Legal obligation — to meet requirements such as keeping invoices for tax purposes, and providing accurate registrant details to domain registries as ICANN and registry rules require.
4. Who else processes your data
We share personal data only with the service providers we need to run IntoClouds. Each acts under a contract and only for the purposes below:
- Hosting — Hetzner
- Hetzner Online GmbH (Germany) provides the cloud infrastructure your servers and our systems run on. Our own systems and your account data sit in EU data centres; the servers you create sit in the region you chose for them, which may be outside the EU (see section 5).
- Payments — Polar
- Polar acts as our merchant of record and payment processor. Polar collects your payment details and billing information directly; we receive only billing metadata (such as subscription status and invoice amounts) and never your card data.
- Domains — registrar & registry
- When you register or transfer a domain, the relevant registrar and domain registry process the registrant details required to operate the domain, as ICANN and registry policies mandate.
- DNS lookup — Cloudflare public resolver
- When you ask us to import an existing domain's DNS zone, we query Cloudflare's public DNS-over-HTTPS resolver to read that domain's current public records. This sends only a standard DNS query for your domain — no account data — and only for domains you ask us to import.
- Support — Telegram
- If you contact us through our Telegram support bot, Telegram processes those messages as part of delivering the conversation.
We do not sell your personal data, and we do not share it for advertising.
5. Where your data is stored
Your account data — everything in section 2 — is stored in the European Union (Germany and Finland). That is where our own systems run and it does not depend on any choice you make.
The servers you create are separate, and you choose where they run. We offer regions in Falkenstein and Nuremberg (Germany), Helsinki (Finland), Ashburn, Virginia and Hillsboro, Oregon (United States) and Singapore. If you deploy outside the EU, any personal data you put on that server is stored in that country: you are the controller of that data, so that transfer and its legal basis are yours to make. Pick an EU region if EU residency matters to you.
Some processors named above may also operate from outside the EU; where that involves a transfer of personal data we are responsible for, it is carried out under an appropriate legal safeguard such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
- Account data — for as long as your account is open, and for up to 90 days after it is closed, after which it is deleted or anonymised.
- Audit logs — kept for 12 months for security and accountability.
- Invoices and tax records — kept for as long as tax and accounting law requires us to.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten"), subject to our legal retention duties;
- port your data — receive it in a structured, common, machine-readable format;
- object to or restrict processing based on our legitimate interests.
To exercise any of these, email hello@intoclouds.io. We will respond within the time the law allows (normally one month).
8. Cookies & tracking
We use a single strictly-necessary session cookie to keep you logged in. It holds a random session token and is set with the HttpOnly and SameSite flags so it cannot be read by scripts or sent from other sites.
We do not use analytics, advertising, fingerprinting, or any third-party tracking cookies or scripts. There is genuinely no analytics code in the product — so there is no tracking to opt out of and no cookie-consent banner to click through.
9. Automated decision-making
We do not carry out automated decision-making that produces legal or similarly significant effects about you. Automated processes like abuse rate-limiting and non-payment suspension follow fixed, published rules and are not profiling.
10. Children
IntoClouds is a business service for adults and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Complaints
If you have a concern about how we handle your data, please contact us first at hello@intoclouds.io — we would like the chance to put it right. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU country where you live or work.