This policy explains how Halder Cloud handles personal data. It covers our website, the customer portal, and the managed hosting service.
This distinction determines your rights and our duties, so we state it plainly:
As controller, we collect:
As processor, we host whatever Customer Content you place in your instance, including its database and uploaded files. We do not inspect that content except as strictly necessary to operate the service or to comply with law.
We use personal data to provision and operate your instances, authenticate sessions, process billing, send service and security notifications, provide support, monitor performance, prevent abuse, and meet legal obligations.
We do not sell or broker personal data. We do not use Customer Content to train machine-learning or AI models. We do not use third-party advertising or cross-site tracking.
We rely on the following categories of provider, each bound by contract to appropriate confidentiality and security obligations:
A current list naming each sub-processor is available on request at the contact address below. We will give notice before adding a sub-processor that materially affects the processing of Customer Content.
We operate clusters in multiple regions and you may choose where your instance runs. Operating the platform may involve transfers outside your own country, including outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.
Account and billing records are retained while your account is active and afterwards for as long as required for tax, accounting, and limitation periods. Security and webhook records are purged after 30 days, and session and token records are removed as they expire. Build and deployment logs are retained with the deployment record for as long as your account is active. Backups follow your plan’s retention: the most recent 2 snapshots on Starter, 4 on Pro, and 8 on Enterprise.
Deleting an instance permanently removes its application, database, and backups. That action is irreversible and we cannot restore the data afterwards.
We apply namespace-level tenant isolation, encryption in transit, encrypted storage of secrets, hashed credentials, role-based access control, and rate limiting on authentication endpoints. Access to production systems is restricted to personnel who need it. No system is perfectly secure, and we cannot guarantee absolute security.
If a breach affects your personal data, we will notify the competent supervisory authority where legally required and, where the breach is likely to result in a high risk to you, we will notify you without undue delay.
Subject to local law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of or objection to processing, and portability. You may also withdraw consent where processing relies on it, and lodge a complaint with your local supervisory authority.
To exercise these rights, contact us at the address below. We respond within the period required by applicable law. If your request concerns data held inside another customer’s instance, we will direct you to that customer, who is the controller of it.
We use strictly necessary cookies for authentication and session security, including an HttpOnly refresh cookie. We do not use marketing or cross-site tracking cookies. Blocking necessary cookies will prevent you from signing in.
The service is not directed to children and is not intended for anyone under 18. We do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
We may update this policy. For material changes we will give reasonable notice by email or in-product and update the date above. Continued use after the effective date constitutes acceptance.
Privacy questions, rights requests, and deletion requests: beta@justbots.tech.
Data controller: Halder Cloud. For any data-protection query, or to reach our data-protection contact, email beta@justbots.tech.
While we are in public beta we also welcome bug reports and feature suggestions at the same address.