Last updated: 2026-06-10
This notice explains what personal data the NuPaas platform ("Service", operated by Type-Driven UG (haftungsbeschränkt), Germany) processes, on what legal basis, where it is stored, who it is shared with, how long it is kept, and how you can exercise your rights under the EU General Data Protection Regulation (GDPR).
1. Controller and contact
The controller for the personal data described below is Type-Driven UG (haftungsbeschränkt), Germany. For privacy questions, data subject requests, or to reach our data protection contact, write to privacy@nupaas.com.
We act as a controller for account, billing, audit, and operational data, and as a processor for Customer Content that you deploy on the platform.
2. Categories of personal data
- Account data — name, email, hashed password, MFA material (TOTP, passkeys), organization and project memberships, role assignments.
- Session data — short-lived access tokens (~15 min), rolling refresh tokens (~30 days), session identifiers, OAuth/OIDC linkage, and rate-limit counters.
- Audit and security logs — actor user ID, IP address, user agent, action, target, timestamp. Recorded for authentication events, administrative changes, and sensitive platform operations.
- Billing data — billing contact email, VAT number (if provided), plan, usage metrics, invoice line items, and payment-provider customer/mandate references (no card numbers are stored by us).
- Product telemetry — see section 6.
- Customer Content — source code, container images, environment variables, secrets, deployment metadata, and any data your workloads write to platform-managed storage. We treat this as your data and access it only as described under section 4.
3. Lawful bases
We rely on the following GDPR lawful bases (Art. 6 GDPR):
- Contract (Art. 6(1)(b)) — to create and operate your account, run the platform you signed up for, and send essential service messages (invoices, security notices, password resets, invitations).
- Legal obligation (Art. 6(1)(c)) — to keep invoices and accounting records, and to retain audit/security evidence where required.
- Legitimate interests (Art. 6(1)(f)) — to operate the platform securely (rate limiting, abuse detection, audit logging), to provide product telemetry for reliability and debugging, and to investigate incidents. You may object to processing based on legitimate interests by contacting us.
4. Where your data lives
All platform data is stored and processed within the European Union. Primary infrastructure runs on Hetzner Online GmbH in Germany.
| Data type | Location |
|---|---|
| Platform metadata, accounts, sessions | Hetzner — Germany (EU) |
| Secrets and credentials (OpenBao) | Self-hosted on Hetzner — Germany (EU) |
| Source repositories (Gitea) | Self-hosted on Hetzner — Germany (EU) |
| Object storage and backups | Self-hosted on Hetzner — Germany (EU) |
| Observability (logs, traces, metrics) | Self-hosted on Hetzner — Germany (EU) |
5. Subprocessors
We use the following subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Compute, storage, network | Germany (EU) |
| Mollie B.V. | Payment processing | Netherlands (EU) |
| Cloudflare, Inc. | DNS management (operational data only) | United States |
| Resend, Inc. | Transactional email (fallback; per-org EU SMTP override available) | United States |
Transfers to Cloudflare and Resend rely on the EU Commission's Standard Contractual Clauses. Customer organizations can switch email delivery to an EU SMTP relay; see your organization settings.
6. Product telemetry (in-app)
When you use the in-product dashboard, your browser sends telemetry to our self-hosted observability stack on Hetzner. This telemetry is used to debug errors, measure performance, and trace user-visible failures across browser and server. We do not sell or share this data with advertising networks; we do not use third-party analytics or ad trackers.
The telemetry payload includes:
- Your authenticated user ID and organization ID/slug
- The current page path (not query strings)
- Browser language and user agent
- Web Vitals (LCP, CLS, INP, FCP, TTFB), navigation timing, slow resource timings, RPC fetch timings
- Unhandled JavaScript errors and promise rejections
You can disable in-app telemetry at any time. The setting is stored in your browser and applies only to you on this device. No telemetry leaves your browser while opt-out is enabled.
7. Retention
Retention windows are defined in our internal retention policy. Indicative windows:
- Account and tenancy data: kept while the organization is active; deleted on organization closure subject to legal-hold review.
- Sessions and short-lived auth tokens: minutes to weeks; refresh tokens expire after ~30 days of inactivity.
- Audit and security logs: at least 12 months; longer where required by incident or legal hold.
- Metrics and logs (observability): ~90 days for metrics, ~30 days for logs in production.
- Backups: 30 days in primary EU storage; up to 90 days in off-site EU object storage where configured.
- Invoices and tax records: retained for the applicable statutory accounting period.
8. Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you (Art. 15);
- request correction of inaccurate data (Art. 16);
- request erasure, subject to legal-hold and statutory retention obligations (Art. 17);
- request restriction of processing or object to processing based on legitimate interests (Art. 18, 21);
- receive a portable copy of data you provided (Art. 20);
- withdraw consent at any time for any processing based on consent (Art. 7(3));
- lodge a complaint with a supervisory authority (Art. 77).
To exercise any of these rights, email privacy@nupaas.com from the address associated with your account. We respond within one month and may extend by two further months for complex requests, with notice.
9. Cookies
We use strictly necessary cookies for authentication, session continuity, and CSRF protection. We do not use advertising or cross-site tracking cookies. The product-telemetry opt-out flag in section 6 is stored in your browser's localStorage, not in a cookie.
10. Changes
We will update this notice as our processing evolves. Material changes will be communicated to active customers via email or the in-product notification system before they take effect.