This notice covers Nodara Systems, Inc. and Nodara GmbH (jointly “Nodara”). If you're in the EU/UK, Nodara GmbH is your controller. Everywhere else, Nodara Systems, Inc. is.
1. What we collect
We collect the least amount of data needed to run the service:
- Account: email, name, hashed password (Argon2id), and — if you sign in with Google/GitHub — the OAuth subject ID.
- Billing: business address if you request an invoice, a Stripe customer ID, and the last 4 digits of your card. We never store full card numbers — Stripe does.
- Usage: which regions/plans you deploy, aggregate bandwidth counters, and product analytics (page views on nodara.host). No third-party trackers.
- Support: any content you send us over email or chat.
What we don't collect
- The contents of your instances. We can technically access the storage layer for recovery purposes; we don't inspect it.
- Your network traffic content. Only volume counters.
- Third-party ad or analytics identifiers. There are none on this site.
2. Legal basis (GDPR)
Under Article 6 of the GDPR, we rely on:
- Contract (6(1)(b)): to provide the service you've signed up for.
- Legitimate interest (6(1)(f)): for security, fraud prevention, and product analytics of an aggregate kind.
- Legal obligation (6(1)(c)): for tax records (kept 10 years in DE, 7 years in US).
3. How long we keep it
- Account data: while your account exists, plus 90 days.
- Billing records: 10 years (German tax code § 147 AO).
- Support conversations: 3 years.
- Server logs (control plane): 30 days, then aggregated to daily counts.
- Backup data on customer instances: 30 days after instance destruction, then permanently deleted.
4. Where the data sits
Account and billing data is stored in Frankfurt (FRA1) with a cross-region cold backup in São Paulo (GRU1). Support data is stored in Frankfurt. Sub-processor list is on the legal hub.
We don't transfer data outside the EU/EEA except to our US parent company (under the EU-US Data Privacy Framework) and to Stripe for payment processing (SCCs in place).
5. Your rights
You can, at any time:
- Request a copy of your data (in JSON, from the dashboard).
- Correct any inaccurate data yourself in the dashboard.
- Delete your account. Data is purged within 90 days except for tax records.
- Object to legitimate-interest processing (analytics, security). Email privacy@nodara.host.
- File a complaint with your local data protection authority. In Germany that's the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
6. Cookies
We use one session cookie and one CSRF cookie, both strictly necessary, both HttpOnly and SameSite=Lax. No advertising cookies. No consent banner because we don't need consent to run a login session.
7. Contact
Data protection officer: dpo@nodara.host. General privacy questions: privacy@nodara.host.