Privacy Policy — InfraMole Cloud
DRAFT — needs legal review before publication. Effective date:
[EFFECTIVE DATE].
[COMPANY LEGAL NAME], [ADDRESS] ("we") operates InfraMole Cloud. For data
our customers put into their workspaces we act as processor on their
behalf (see the DPA); for account and billing data we act as controller.
Contact: [DPO / PRIVACY CONTACT].
1. What we process
Account data (controller): name, email address, password hash (we never store passwords), two-factor authentication secrets (encrypted), passkey public keys, sign-in events (time, IP address, browser/OS summary), when you accepted the Terms of Service and which version, and — if you use Google or Microsoft sign-in — the provider account identifier.
Workspace data (processor, on behalf of the customer): the infrastructure inventory the customer creates or imports (resource names, types, IP addresses, hostnames, notes, relationships), data reported by the InfraMole agent (hostname, OS, network interfaces, running services, listening ports, aggregated TCP connections with process names — never passwords, file contents, command-line arguments, environment variables or user documents), member names and emails, invitations, and the workspace audit log.
Integration credentials (processor, optional): read-only cloud API credentials the customer chooses to store, encrypted with AES-256-GCM and never shown again.
Billing data (controller): handled by our payment provider; we keep the subscription status and plan, not card numbers.
We do not use workspace data for advertising, profiling or training models, and we do not sell data.
2. Why (legal bases)
- Providing the service you signed up for — contract (Art. 6(1)(b) GDPR).
- Security of the service: sign-in events, audit log, rate limiting — legitimate interest (Art. 6(1)(f)) and legal obligations (Art. 32).
- Transactional emails (verification, password reset, invitations) — contract.
- Billing and accounting records — legal obligation (Art. 6(1)(c)).
3. How long
We follow the retention table in our documentation (summary): raw agent
reports 7 days; connection observations 30 days after last seen; change
history 30, 90 or 365 days depending on the plan; audit log 365 days; ended invitations 30 days; expired sessions
and tokens deleted on expiry. Deleting a workspace deletes all its data
immediately; deleting your account deletes your user data and the workspaces
where you were the only member. Encrypted backups keep deleted data for up
to [BACKUP_KEEP_DAYS, default 14] days. Billing records are kept as long
as tax law requires.
4. Where and who
Data is hosted in the European Union by [HOSTING PROVIDER]. Sub-processors
are listed on the sub-processors page. Transfers outside the EEA, if any, rely on
the European Commission's adequacy decisions or Standard Contractual Clauses.
5. Your rights
Access, rectification, erasure, restriction, portability (Settings › Data › Export) and objection; you can delete your account yourself (Account & security › Delete account). For workspace data, contact the workspace owner (the controller); we assist them. You may complain to your data protection authority.
6. Security
Summary of measures: TLS everywhere, encrypted secrets, database-enforced tenant isolation (Row Level Security), two-factor authentication and passkeys, an append-only audit log, encrypted backups and least-privilege access by our staff (every database session is logged with a reason). Our technical and organisational measures (DPA Annex II) are available on request.
7. Cookies
Only strictly necessary cookies: the session cookie and the security cookies of the sign-in process. No analytics, advertising or tracking cookies.
8. Changes
We will announce material changes by email to account holders at least
[30] days in advance.
