This translation is provided for convenience. The Russian version is legally binding.
Privacy Policy
What data we collect, why, who we share it with, how we protect it and how long we keep it.
1. Who processes the data
- 1.1
The personal data controller is QoCloud, the cloud division of the QoDev group of companies (hereinafter "QoCloud", the "Provider", "we"). Address: 17/F Sun Life Tower, The Gateway, Harbour City, 21 Canton Road, Tsim Sha Tsui, Kowloon, Hong Kong. Questions about data: info@qocloud.tech.
- 1.2
This policy applies to the qocloud.tech website, the account area, the app (PWA), the API and support.
2. What data we collect
- 2.1
Data you provide yourself:
- name and email address;
- password, which we store only as an irreversible hash and cannot see;
- the contents of tickets and requests, public SSH keys, and names of servers and API keys.
- 2.2
Data generated when you use the service:
- device and browser information at sign-in, the IP address from which an API key was last used;
- security log: sign-ins, settings changes, staff actions on your servers;
- payment and Balance transaction history; bank card data is processed by payment partners, and we do not receive it;
- server information: configuration, IP addresses, status, root password (stored encrypted);
- push notification subscriptions (the address of your browser's notification service).
- 2.3
We do not view or analyze the contents of your servers. Staff may access a server only in the cases described in the Offer and the Acceptable Use Policy, and every such access always appears in your security log.
3. Why we use data
- 3.1
We process data to:
- create and protect your account, verify sign-ins and detect compromise;
- provide and bill services and keep records of transactions;
- respond to requests and notify you about server status, payments and incidents;
- investigate abuse reports and comply with legal requirements.
- 3.2
The legal bases for processing are performance of our agreement with you, compliance with legal obligations, our legitimate interests in service security and, for news, your consent, which you can withdraw in the settings.
- 3.3
We do not sell data or use it for third-party advertising. The website has no advertising or analytics trackers.
4. Cookies and browser storage
- 4.1
We use only strictly necessary cookies:
- __Host-qc_session: sign-in session (secure, not accessible to page scripts), up to 30 days from your last visit;
- qc_cookies: a flag recording that you have seen the cookie notice, 180 days.
- 4.2
Browser storage (localStorage) keeps interface settings, such as dismissed tips. This data is not sent to the server.
- 4.3
We do not use cookies for advertising, analytics or cross-site tracking, so we do not ask for separate consent to them.
5. Who we share data with
- 5.1
Only to the extent necessary to provide the services:
- data center operators in EU countries (Netherlands, Germany, Poland, Estonia): data needed to host servers;
- payment partners: to accept payments;
- the email delivery service: addresses and email texts;
- Apple, Google, Mozilla and Microsoft push notification services: the text of notifications on your devices;
- the provider of the cloud platform that runs the website.
- 5.2
Data may be disclosed to government authorities where applicable law requires it, and to protect the rights of QoCloud and other clients when investigating violations.
- 5.3
Data is processed in Hong Kong and EU countries. When we share data with partners, we require them to provide a level of protection no lower than ours.
6. How we protect data
- 6.1
Personal data (email, name, contacts, 2FA secrets, root passwords, device information) is stored encrypted (AES-256-GCM). Encryption keys are stored separately from the database.
- 6.2
Passwords are stored only as Argon2id hashes; one-time codes and tokens are stored only as hashes. Connections are protected by HTTPS with HSTS.
- 6.3
Staff access to data is restricted, requires two-factor authentication and is logged.
7. How long we keep data
- 7.1
Account data: for as long as the account exists. After the account is deleted, we delete the data within 30 days, except information we are required to keep by law.
- 7.2
Payment and Balance transaction history: 5 years (accounting requirements).
- 7.3
Security log: 1 year; ticket correspondence: 3 years. Data of deleted servers, including disk contents, is deleted immediately when the server is deleted.
8. Your rights
- 8.1
You have the right to:
- obtain information about the data we process;
- correct inaccurate data (name and email in the account settings);
- delete your account and data unless the law requires us to keep them;
- withdraw consent to news and turn off notifications;
- lodge a complaint about data processing with a supervisory authority.
- 8.2
Send requests to info@qocloud.tech from the email address linked to your account. We respond within 30 days.
9. Changes to this policy
- 9.1
We publish the new version on this page with its date. We notify you of material changes by email.
- 9.2
Code word: money.
Sun Life Tower, Harbour City, Hong Kong · questions about this document: info@qocloud.tech