SYS > PRIVACY POLICY  ·  DATA PROTECTION · NO DATA SOLD
Legal Document — Privacy Policy

Personal Data Protection Notice

This page explains how VukCloud collects, uses, stores, and protects personal data when you use vukcloud.com, the console, and related services. Together with the User Service Agreement, it forms your complete agreement with us.

DOC INFO
Version Date
March 25, 2026
Core Commitment
We do not sell user personal information. The version date reflects the latest update; major changes will be communicated separately. Your rights to access, correct, delete, and opt out of marketing communications are detailed in the full policy.
Related Document
Best read alongside the Terms of Service
Table of Contents 00Before You Begin 01What Data We Access 02Purpose & Legal Basis 03When & With Whom We Share 04How Long We Keep It 05How We Protect It 06Cookie 07Your Controls 08Children 09Cross-Border Deployment 10Third-Party Sites 11Policy Updates 12Contact
00

Before You Begin

Last updated: March 25, 2026 · Applies site-wide

VukCloud (referred to as "we") treats privacy protection as an integral part of our product. This policy explains the scope of personal data processing, its purposes, and retention rules.

By continuing to use the website, console, or API, you confirm that you have read and agreed to this policy. If you do not agree, please stop using the service. This policy and the User Service Agreement are complementary and apply together.

01

What Data We Access

Two categories: data you actively provide, and data generated automatically by the system

Information You Actively Provide

  • Account details: Email address, optional name, password stored as a hash
  • Payment records: Card numbers are handled by licensed payment processors; we only store transaction outcomes, amounts, dates, and masked billing fields
  • Support content: Issue descriptions, attachments, and correspondence in tickets and emails
  • Order parameters: Hardware configuration, data center node, billing cycle

System-Generated Records

  • Access logs: IP address, HTTP metadata, timestamps, referrer, browser, and OS information
  • Device identifiers: Device type and client identifiers (SSAID) we issue, used for risk control and anomaly detection
  • Usage data: Login times, feature clicks, console activity logs, bandwidth and compute consumption statistics
  • Cookies / Local storage: Used to maintain login sessions, remember language preferences, etc. (see Section 6 for details)
02

Purpose & Legal Basis

Contractual necessity and legitimate interests as the legal basis for processing

Data collected is used for the following purposes:

  • Delivery & Operations: Creating accounts, activating instances, processing payments and renewals
  • Identity & Risk Control: Verifying login identity, detecting abuse, blocking unauthorized access
  • Customer Support: Responding to ticket requests and helping troubleshoot issues
  • Experience Improvement: Analyzing usage patterns in aggregated or anonymized form to optimize performance and develop new features
  • Transactional Notifications: Sending billing, expiry reminders, maintenance announcements, and security notification emails
  • Product Updates: Sending product-related updates or offers until you opt out
  • Compliance: Cooperating with law enforcement, meeting regulatory requirements, and protecting the platform's legal interests
  • Technical Research: Using anonymized technical logs for system stability analysis and optimization
03

When & With Whom We Share

Minimal-necessity disclosure; personal information is never sold

We do not sell your personal information. We only disclose it to third parties in the following circumstances:

Service Processors & Infrastructure Partners

To complete necessary functions like payment, email delivery, and network access, we share the minimum required fields with:

  • Payment gateway (subject to its own privacy policy)
  • Email delivery service (for verification codes and notifications)
  • Self-hosted Matomo analytics (data stored on our own servers)
  • Data center and bandwidth providers

We enter into data processing agreements with these parties, limiting the purpose of use and requiring equivalent security standards.

Legal Requirements

We may disclose necessary information when required by law, court order, or government directive, or when necessary to protect the legitimate rights and interests of us and our users.

Mergers & Restructuring

In the event of a merger, acquisition, asset sale, or bankruptcy, user information may be transferred as part of the assets. We will provide advance notice and require the successor to provide equivalent protection.

With Your Consent

We will only share your information with third parties outside the scope of this policy after obtaining your separate consent.

04

How Long We Keep It

Retention periods set according to compliance requirements and business needs
  • Account fields: Retained during account lifetime and for a reasonable period after cancellation, up to approximately 12 months to meet audit requirements
  • Financial records: Invoices and payment proof are retained for at least 7 years as required by law
  • Access logs: Typically retained for approximately 90 days for security audits and troubleshooting
  • Tickets: Retained during the account lifetime and for 12 months after cancellation
  • Instance disk: Permanently deleted within 72 hours of service termination

If law requires a longer retention period, that requirement takes precedence.

05

How We Protect It

Technical safeguards and access controls working in tandem

We follow industry-standard security practices, including but not limited to:

  • Encryption in transit: TLS 1.2 and above
  • Password storage: Strong hashing algorithms such as bcrypt — original passwords are irreversible
  • Internal access: Employees follow the principle of least privilege; all sensitive actions are logged
  • Physical security: 7×24 access control and video surveillance at data centers
  • Security operations: Regular internal reviews and vulnerability scans
No internet system can guarantee absolute security. If a security incident occurs that may affect your rights, we will notify you promptly as required by law.
06

Cookies & Local Identifiers

Managed by category; essential cookies cannot be disabled

We currently use the following types of technical identifiers:

Essential
Maintains login state and service availability. Disabling will prevent normal use.
Functional
Remembers language and interface preferences to reduce repeat configuration.
Analytics
Self-hosted Matomo tracks usage paths. Data is not sold to external ad networks.
Security Identifiers
Locally stored SSAID, used to verify logins and detect anomalous behavior.

You may disable cookies in your browser settings. However, disabling essential cookies may prevent the console and checkout from functioning correctly.

07

Your Controls

Under applicable law, you may have the following rights

Please submit a request via ticket — we will respond within approximately 30 days:

  • Right of Access: Obtain a copy of the personal information we hold about you
  • Right of Correction: Request corrections to inaccurate information (basic fields can also be self-updated in the console)
  • Right of Deletion: Request data deletion after account cancellation, excluding transaction records required by law
  • Marketing Opt-Out: Unsubscribe from promotional communications via the link in email footers; billing and security notices are not affected
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing conducted prior to withdrawal

While your account is active and services are within their contracted period, some deletion requests may be deferred to balance service delivery and statutory retention obligations.

08

Children

Service designed for adults

This service is intended for individuals 18 years of age and older. We do not knowingly collect information from minors. If you are a guardian and believe a minor has submitted personal information without authorization, please contact us via ticket and we will delete it promptly.

09

Cross-Border & Multi-Region Deployment

Data centers span multiple jurisdictions

We operate data centers in Hong Kong, Japan, Korea, the US, and other locations. Your data may be stored or processed outside your country of residence. Privacy laws vary by jurisdiction.

To manage cross-border transfer risks, we enter into data processing agreements with recipients, apply standard encryption and access controls, and comply with applicable cross-border data transfer rules.

10

Third-Party Sites

External links for reference only — please review their privacy policies

This site may contain links to third-party websites. We have no control over their content, privacy practices, or security measures, and accept no responsibility for them. Please read their privacy statements before visiting.

11

How This Policy Evolves

The online version on this page is authoritative; major changes will be communicated separately

We may revise this policy from time to time. Revised versions will be published on this page with an updated date at the top.

If changes materially affect how your data is used or shared, we will notify you in advance via your registered email or an in-platform message. Continued use of the service after a policy update constitutes acceptance of the revised terms. If you do not agree, please stop using the service and cancel your account.

12

Privacy Contact

For inquiries, complaints, or rights requests, contact us by email or ticket

For personal assistance, reach us through any of the following channels:

Email: [email protected]

Ticket: Log in to the console → Submit a ticket (recommended, trackable)

Response time: General inquiries within approx. 2 business days; rights requests within 30 days

Want to know about billing rules and liability boundaries?
The Terms of Service details usage restrictions and liability caps. For questions on overlapping clauses, our support team can help.
Terms of Service Contact Support