Politique de confidentialité

Dernière mise à jour: 2026-08-01

1. Controller

Exotik Cloud OÜ, Sepapaja 6, 15551 Tallinn, Estonia is the controller for personal data processed through exotik.cloud. Contact: privacy@exotik.cloud.

2. What we process and why

Account data (email, name, country, language, password hash) — to provide the service (contract). Billing data (wallet ledger, orders, invoices, payment references) — contract and legal retention duties. Service data (hostnames, IP addresses, provider references, encrypted credentials) — contract. Support data (tickets, contact messages) — contract and legitimate interest. Security logs (auth events, admin audit trail, request metadata) — legitimate interest in securing the platform.

3. What we deliberately avoid

No card numbers ever touch our systems: crypto payments are processed by Cryptomus, bank transfers by your bank. We run no third-party advertising or cross-site tracking; the only cookies are strictly-necessary session and language cookies.

4. Processors and transfers

Fulfilment involves upstream infrastructure providers (for example Virtualizor-managed nodes, Vultr, Hetzner, Linode) and the domain registrar platform; each receives only the technical data required to operate the resource you ordered. Where a processor is outside the EEA, transfers rest on adequacy decisions or standard contractual clauses.

5. Retention

Account and ledger data are kept while the account exists and thereafter as required by Estonian accounting law (7 years for accounting records). Service data is deleted after the termination retention window. Security logs rotate within 12 months.

6. Your rights

You can access, correct, export or delete your data, object to or restrict processing, and lodge a complaint with a supervisory authority (in Estonia: Andmekaitse Inspektsioon). Most data is directly visible and editable in your panel; for the rest, email privacy@exotik.cloud and we answer within 30 days.

7. Security

Passwords are hashed with bcrypt, sessions are short-lived and rotated, provider credentials and server passwords are encrypted at rest, admin actions are audited, and services are network-isolated behind a single hardened gateway.