Privacy Policy
What we collect, why, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be defensible — if anything here is unclear, ask and we will explain it.
Vallic is established in Croatia. We are the data controller for the information described under Your account. For everything inside your environments — your database, your uploads, your visitors — you are the controller and we are your processor, acting on your instructions.
Your account
What we collect: name, email address, company name and billing address; VAT number where you have one; the SSH keys and OAuth identities you connect; your IP address when you sign in.
Why, and on what basis: to give you an account and to bill you (performance of our contract), and to meet the accounting obligations that come with billing you (legal obligation).
How long: for as long as you have an account, then 30 days — except invoices and the records behind them, which Croatian tax law requires us to keep for eleven years.
Payments
We do not hold card numbers. Payments are processed by Stripe, who receive your card details directly and give us a token, the last four digits, the card brand and the country. Stripe acts as an independent controller for fraud prevention and its own compliance obligations.
On larger card orders Stripe may ask you to verify your identity. Stripe runs that check and holds what it collects for it.
If you pay by invoice, you pay by bank transfer and no card details are involved.
We keep invoices, amounts, dates and the billing address on them. Fiscal invoices are issued through e-računi, which receives the billing details that appear on them.
Your sites, and the people who visit them
Your application's data — its database, its uploaded files, its own logs — is yours. We store it, back it up and move it between machines on your instruction. We do not read it, mine it, or use it to train anything.
Staff access it only when you ask us to help and only for as long as that takes. Every such access is logged and you can ask for the log.
Request logs. By default the proxy records only what is needed to count and time requests: which environment, the request path without its query string, how long it took, what status your site answered, when, and the bytes each way. No visitor IP address, no user agent, no headers, no query string. There is nothing in it that identifies a visitor.
The full line — addresses and all — is written only where you switch it on, which you would do to ship logs to your own destination. That is your decision and, once made, your disclosure to your visitors.
Either way the machine keeps its own copy for 7 days and the agent deletes what is older. Nothing is sent to us beyond per-minute counts: requests, errors, response-time percentiles and bytes, per environment. Those counts are what the console draws.
Backups. Encrypted on the machine before they leave it, and kept to the schedule your plan states. Production is copied to two places: object storage on the continent your machines are on, and a cold copy with a different provider in the EU.
Each copy has its own key. Every destination is a separate encrypted repository with a key generated for it alone, so one key opens one copy and nothing else. The keys are stored encrypted, under a platform key held outside our database. Where you add storage of your own, that copy is its own repository too, and you can download its key.
A deletion in your application reaches the backups as they age out rather than immediately — this is what backups are for, and it is worth understanding before you promise a visitor otherwise.
Operating the platform
We collect what is needed to run machines and keep them up: resource samples, agent heartbeats, deployment records, task logs. These describe your infrastructure rather than your visitors. Resource samples are kept for 7 days; the rest for 90 days. The basis is our legitimate interest in operating a reliable service.
To measure availability, our monitoring service receives each environment's hostnames and project name, and checks the sites from three providers' networks the way any visitor would.
Security and audit logs — who signed in, what they changed, which environment they touched — are kept for one year, so that a question about what happened has an answer.
Who else sees it
| Who | What they get | Where |
|---|---|---|
| Hetzner, UpCloud, Gcore | The machines and what runs on them | The region you chose |
| Cloudflare | Encrypted backups (R2 object storage) | The continent your machines are on |
| Scaleway | The cold copy of encrypted backups | France (EU) |
| Stripe | Payment details, billing address, identity checks on larger card orders | EU / US, under SCCs |
| e-računi | Billing details on fiscal invoices | EU |
| MailerSend | Recipient address and content of platform mail | US, EU-U.S. Data Privacy Framework |
| Proton | Correspondence with us, including support | Switzerland, adequacy decision |
| GitHub | Serves our container images to your machines, and reads the repositories you connect. Receives nothing from inside your environments | Global |
| Bunny CDN | Requests to cached assets, visitor IP | Global edge |
| Error monitoring | Stack traces from the platform's own software | EU |
Each is a processor under a data processing agreement, except Stripe where noted. We do not sell data and we do not share it for anyone else's advertising.
The full list is in Annex III of the Data Processing Agreement, and we give 30 days' notice before adding one that touches customer data.
Choosing a region is choosing a jurisdiction. An environment in Frankfurt keeps its data in Germany; one in Ashburn keeps it in the United States. The configurator says which before you buy. Transfers outside the EEA rely on the European Commission's standard contractual clauses.
What you can ask for
Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to someone else in a portable format. You may object to processing we do on the basis of legitimate interest, and withdraw consent where consent is what we rely on.
Write to us and we answer within 30 days, at no charge. Most of it you can also do yourself from the console, which is faster.
If you are unhappy with how we handled a request you may complain to the Croatian Personal Data Protection Agency (AZOP), or to the authority where you live. We would rather you told us first.
Cookies
The console uses a session cookie to keep you signed in and a preference cookie for things like your chosen theme. Neither is optional and neither tracks you off this site.
We run no advertising cookies on the console. What your own sites run is your decision and your disclosure.
Security
Data is encrypted in transit and at rest. Credentials, tokens and environment secrets are encrypted in our database with keys held outside it. Access to production requires a second factor and is logged.
If a breach affects personal data we notify the supervisory authority within 72 hours as the GDPR requires, and tell you without undue delay — what happened, what it touched, and what we are doing.
Changes
Material changes are announced by email to account owners at least 30 days before they take effect.