Gerdoo Cloud privacy policy
Last update: July 1405
This policy explains what information Gerdoo Cloud receives when you visit the website, create an account or use the platform, add-ons, servers and related tools; why it is needed; and your choices. Gerdoo does not sell personal data or use it for third-party behavioral advertising.
1. Information we receive
- Account and identity: Name, phone number, email, national identity number or company registration details, and verification results, only as needed to create accounts, provide services and meet legal requirements.
- Payment and billing: Transactions, invoices, wallet balance, usage and information needed for refunds. Payment gateways process full card details; Gerdoo does not store them.
- Usage and security: IP address, request time, browser and device, login events, administrative activity, resource usage, errors and traffic data needed for security, billing and troubleshooting.
- Projects and services: Project names, environment settings, domains, service and volume specifications, variables, build and runtime logs, releases, backups and add-on connection details.
- Source code and development integrations: When deploying from Git or CLI, the platform receives code, Dockerfiles, dependency manifests and files needed for the build. Git connections also process repository IDs and the access tokens needed for the selected operation.
- Communications with Gerdoo: Tickets, messages, attachments, support calls, abuse reports and notification preferences.
2. Why do we use this information?
Service delivery
Creating, building and running services, connecting domains and add-ons, backups and technical support.
Security
Authentication, access control, suspicious behavior detection, abuse prevention and incident response.
Billing
Usage measurement, invoicing, payment processing, plan management and refund processing.
Communication
Sending operational messages, security and financial alerts, replying to tickets and announcing important changes.
Product improvement
Analyzing aggregated errors and usage patterns to improve reliability and usability.
Legal obligation
Retaining required records, responding to valid requests from competent authorities and meeting legal requirements.
3. When information is shared with others
Gerdoo does not sell personal data or project content. Information is shared only to the extent necessary with the following groups:
- Infrastructure, data center, payment, SMS, email, identity verification, Git and support providers needed to deliver the selected feature.
- Project members based on roles and access levels defined by the project owner or manager.
- Competent judicial or legal authority, when a valid and enforceable request is received, or to the extent necessary to defend the rights and security of users and the infrastructure.
- During a merger, business transfer or change of ownership, subject to confidentiality and appropriate notice before changes affect user rights.
Workloads and their data are hosted in the selected execution location. Some account, billing, support and operational control data may be processed separately at essential providers' locations.
4. Data retention and deletion
- We retain data as long as needed for service delivery, security, financial settlement, disputes or legal obligations. Retention periods vary by data and service type.
- After a service or account is deleted, data is removed from active systems or normal access. Backups and legally required records remain in restricted, nonpublic storage until their retention period ends, then are deleted.
- Hosting and computer crime laws may require the retention of certain user data after subscription termination and certain traffic data or content changes for a specified period. During this time, their use is limited to the same legal purpose.
- Deleting a resource may be immediate and irreversible. Export or back up what you need before deleting a service, volume, add-on or environment.
5. Protection of information
- Dashboard and API connections use TLS. Passwords are stored as one-way hashes; cryptographic controls and restricted access protect tokens and secrets.
- User services are isolated, and staff access to operational systems is restricted by role, job requirements and activity logging.
- No system is completely secure. Gerdoo maintains appropriate technical and organizational controls and notifies users of incidents affecting their information according to legal requirements and the incident's severity.
6. Cookies and browser storage
The website and dashboard may use cookies or local storage for sessions, security, language, theme and essential preferences. These are needed for account functionality. Before introducing nonessential analytics or advertising tools, we will update this policy and the consent mechanism.
7. Your rights and choices
- View your profile and project members in the dashboard and update editable information.
- Revoke a Git connection, token, SSH key, domain, or member access that is no longer needed.
- Manage optional notifications. Security, billing and essential account messages cannot be disabled.
- Request a copy of disclosable information, corrections or account deletion. Requests may require identity verification, account settlement and compliance with legal retention exceptions.
8. Your end users' data
If your application collects other people's data, you determine its purpose and processing method. You are responsible for notices, necessary consent, data-subject requests and access controls. Gerdoo processes it only to provide infrastructure according to your settings and requests, unless the law requires otherwise.
Privacy questions and security reports
For privacy questions, requests related to your information, or to report a security incidentinfo@gerdoo.cloudsend a message. We may verify your identity before responding to prevent unauthorized disclosure. Significant policy changes are announced here and, where needed, by email or SMS.