Privacy Policy
Version 2026-06-10
This Privacy Policy explains what personal data NuPaaS, operated by Type-Driven UG (haftungsbeschränkt), Germany ("we"), processes about users of the platform and how we handle it. We act as a data controller for account and billing data, and as a data processor for any application data you deploy through the service.
Data We Collect
- Account data: name, email address, organization name, hashed authentication credentials, optional phone number.
- Session and security data: IP address, user-agent string, session tokens, audit-log entries for authentication and administrative actions.
- Usage data: deployment metadata, resource consumption (vCPU-hours, storage, build minutes), API access logs.
- Billing data: billing plan, invoice history, payment method (handled by Mollie — we do not store card numbers), optional VAT identifier.
- Consent record: the timestamp and policy version you accepted at signup (GDPR Art. 7).
We do not deploy analytics or tracking cookies, and we do not purchase data from third-party brokers.
Lawful Bases (GDPR Art. 6)
- Performance of a contract — to provide the platform you signed up for (account creation, deployments, billing).
- Legitimate interests — keeping the platform secure, debugging incidents, and preventing abuse (logs, audit trail, rate limiting).
- Legal obligation — German commercial and tax law retention for invoices.
- Consent — where required for optional features (e.g. marketing email); withdrawable at any time.
Where Your Data Lives
All platform data is stored and processed within the European Union, on Hetzner Online GmbH infrastructure in Germany. Backups remain in-cluster on EU infrastructure and are encrypted at rest.
Sub-processors
| Processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Infrastructure (compute, storage) | Germany (EU) |
| Mollie B.V. | Payment processing | Netherlands (EU) |
| Cloudflare, Inc. | DNS management (operational metadata only) | United States |
| Resend, Inc. | Transactional email delivery | United States |
Cloudflare and Resend process operational data (DNS records, email delivery) and do not store tenant application data. EU-only SMTP delivery is available on request for teams with strict residency requirements.
Retention
- Account data: kept for the lifetime of the account; erased on account deletion (see below).
- Session tokens: access tokens 15 minutes; refresh tokens 30 days rolling.
- Audit logs: retained for security and compliance investigations; rows belonging to deleted users are pseudonymized (IP and user-agent removed) but the event record is retained.
- Invoices: retained as required by German commercial and tax law (currently 10 years).
Your Rights (GDPR Chapter III)
You have the right to access, rectify, port, restrict, and erase your personal data, and to object to processing based on legitimate interests. Account deletion erases your auth credentials, sessions, passkeys, and identity links; audit-log rows are pseudonymized.
To exercise any of these rights, contact our Data Protection Officer at privacy@nupaas.com. You also have the right to lodge a complaint with your local supervisory authority.
Security
We hash passwords with Argon2id, encrypt secrets and signing keys at rest with AES-256-GCM, enforce TLS for all external traffic, and support TOTP and WebAuthn / passkey multi-factor authentication. We operate Pod Security Standards on the Kubernetes cluster and isolate tenant workloads.
Changes
Material changes to this Privacy Policy will be communicated to active customers by email and require renewed acceptance at signup for new accounts.
Contact
Type-Driven UG (haftungsbeschränkt), Germany.
Data Protection Officer: privacy@nupaas.com
See also the Terms of Service.