Privacy Policy

Skip to main content

Privacy Policy

What we collect, why, how long we keep it, and what you can ask us to do about it. Written to be read rather than to be defensible — if anything here is unclear, ask and we will explain it.

Vallic is established in Croatia. We are the data controller for the information described under Your account. For everything inside your environments — your database, your uploads, your visitors — you are the controller and we are your processor, acting on your instructions.

Your account

What we collect: name, email address, company name and billing address; VAT number where you have one; the SSH keys and OAuth identities you connect; your IP address when you sign in.

Why, and on what basis: to give you an account and to bill you (performance of our contract), and to meet the accounting obligations that come with billing you (legal obligation).

How long: for as long as you have an account, then 30 days — except invoices and the records behind them, which Croatian tax law requires us to keep for eleven years.

Payments

We do not hold card numbers. Payments are processed by Stripe, who receive your card details directly and give us a token, the last four digits, the card brand and the country. Stripe acts as an independent controller for fraud prevention and its own compliance obligations.

On larger card orders Stripe may ask you to verify your identity. Stripe runs that check and holds what it collects for it.

If you pay by invoice, you pay by bank transfer and no card details are involved.

We keep invoices, amounts, dates and the billing address on them. Fiscal invoices are issued through e-računi, which receives the billing details that appear on them.

Your sites, and the people who visit them

Your application's data — its database, its uploaded files, its own logs — is yours. We store it, back it up and move it between machines on your instruction. We do not read it, mine it, or use it to train anything.

Staff access it only when you ask us to help and only for as long as that takes. Every such access is logged and you can ask for the log.

Request logs. By default the proxy records only what is needed to count and time requests: which environment, the request path without its query string, how long it took, what status your site answered, when, and the bytes each way. No visitor IP address, no user agent, no headers, no query string. There is nothing in it that identifies a visitor.

The full line — addresses and all — is written only where you switch it on, which you would do to ship logs to your own destination. That is your decision and, once made, your disclosure to your visitors.

Either way the machine keeps its own copy for 7 days and the agent deletes what is older. Nothing is sent to us beyond per-minute counts: requests, errors, response-time percentiles and bytes, per environment. Those counts are what the console draws.

Backups. Encrypted on the machine before they leave it, and kept to the schedule your plan states. Production is copied to two places: object storage on the continent your machines are on, and a cold copy with a different provider in the EU.

Each copy has its own key. Every destination is a separate encrypted repository with a key generated for it alone, so one key opens one copy and nothing else. The keys are stored encrypted, under a platform key held outside our database. Where you add storage of your own, that copy is its own repository too, and you can download its key.

A deletion in your application reaches the backups as they age out rather than immediately — this is what backups are for, and it is worth understanding before you promise a visitor otherwise.

Operating the platform

We collect what is needed to run machines and keep them up: resource samples, agent heartbeats, deployment records, task logs. These describe your infrastructure rather than your visitors. Resource samples are kept for 7 days; the rest for 90 days. The basis is our legitimate interest in operating a reliable service.

To measure availability, our monitoring service receives each environment's hostnames and project name, and checks the sites from three providers' networks the way any visitor would.

Security and audit logs — who signed in, what they changed, which environment they touched — are kept for one year, so that a question about what happened has an answer.

Who else sees it

WhoWhat they getWhere
Hetzner, UpCloud, GcoreThe machines and what runs on themThe region you chose
CloudflareEncrypted backups (R2 object storage)The continent your machines are on
ScalewayThe cold copy of encrypted backupsFrance (EU)
StripePayment details, billing address, identity checks on larger card ordersEU / US, under SCCs
e-računiBilling details on fiscal invoicesEU
MailerSendRecipient address and content of platform mailUS, EU-U.S. Data Privacy Framework
ProtonCorrespondence with us, including supportSwitzerland, adequacy decision
GitHubServes our container images to your machines, and reads the repositories you connect. Receives nothing from inside your environmentsGlobal
Bunny CDNRequests to cached assets, visitor IPGlobal edge
Error monitoringStack traces from the platform's own softwareEU

Each is a processor under a data processing agreement, except Stripe where noted. We do not sell data and we do not share it for anyone else's advertising.

The full list is in Annex III of the Data Processing Agreement, and we give 30 days' notice before adding one that touches customer data.

Choosing a region is choosing a jurisdiction. An environment in Frankfurt keeps its data in Germany; one in Ashburn keeps it in the United States. The configurator says which before you buy. Transfers outside the EEA rely on the European Commission's standard contractual clauses.

What you can ask for

Under the GDPR you may ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or hand it to someone else in a portable format. You may object to processing we do on the basis of legitimate interest, and withdraw consent where consent is what we rely on.

Write to us and we answer within 30 days, at no charge. Most of it you can also do yourself from the console, which is faster.

If you are unhappy with how we handled a request you may complain to the Croatian Personal Data Protection Agency (AZOP), or to the authority where you live. We would rather you told us first.

Cookies

The console uses a session cookie to keep you signed in and a preference cookie for things like your chosen theme. Neither is optional and neither tracks you off this site.

We run no advertising cookies on the console. What your own sites run is your decision and your disclosure.

Security

Data is encrypted in transit and at rest. Credentials, tokens and environment secrets are encrypted in our database with keys held outside it. Access to production requires a second factor and is logged.

If a breach affects personal data we notify the supervisory authority within 72 hours as the GDPR requires, and tell you without undue delay — what happened, what it touched, and what we are doing.

Changes

Material changes are announced by email to account owners at least 30 days before they take effect.