Skip to content
Privacy

Privacy policy

What we collect, why we collect it, how long we keep it, and what you can ask us to do about it.

Last updated 1 August 2026

Two different roles

CloudContainer AS handles personal data in two distinct roles, and it matters which one applies.

  • As controller — for personal data about our website visitors, trial users and customers. That is the data described in this policy.
  • As processor — for personal data your application stores inside your CloudContainer. You decide what that data is and why it is collected. We process it only to run the service, on your instructions, under a data processing agreement.

What we collect as controller

When you visit cloudcontainer.io

We use privacy-friendly, cookie-free analytics that does not track individuals across sites and does not build a profile of you. It records aggregate page views, referrer, approximate country, and device type. We do not set advertising cookies and we do not sell data.

When you contact us

Your name, email address, company name and the content of your message, so that we can answer you and keep a record of the conversation.

When you have an account

  • Account details: name, email address, GitHub account identifier, password hash.
  • Billing details: company name, address, VAT number, invoice history. Card details are held by our payment processor, not by us.
  • Service data: environments you create, deployments, configuration, and audit records of actions taken in the dashboard.
  • Technical logs: IP address, user agent and timestamps for security, abuse prevention and troubleshooting.

Why we are allowed to process it

PurposeLegal basis
Providing the service you signed up forPerformance of a contract
Answering your enquiriesLegitimate interest
Billing, accounting and tax recordsLegal obligation
Security, abuse prevention and platform integrityLegitimate interest
Product and service emails to customersLegitimate interest, with opt-out
Marketing email to non-customersConsent

Where data is stored

CloudContainer compute runs on Norwegian infrastructure, and account and billing records are held within the EEA.

One important exception. AI Security Review and AI Operations analyse code diffs and log excerpts using an external AI model provider. Those requests leave your environment, and depending on the provider may be processed outside the EEA under an appropriate transfer mechanism. If your application's logs may contain personal data and this matters for your assessment, contact us for the current provider and terms before relying on these features.

Who else is involved

We use a small number of subprocessors: Norwegian infrastructure providers for compute and storage, an AI model provider for the Security Review and Operations analysis, a payment processor for card handling and invoicing, an email provider for transactional messages, and an analytics provider for aggregate website statistics. A current list, with locations, is available on request and before you sign a data processing agreement. We will tell you before we add one that processes customer data.

How long we keep it

  • Account data: for as long as the account exists, then 90 days.
  • Customer environments and backups: deleted after cancellation, following the notice period in the terms.
  • Contact enquiries: 24 months.
  • Technical and security logs: 12 months.
  • Invoices and accounting records: five years, as required by Norwegian bookkeeping law.

Your rights

Under the GDPR you can ask us for a copy of your personal data, correct it, delete it, restrict or object to processing, and receive it in a portable format. Write to [email protected] and we will respond within one month.

If the data in question sits inside a customer's application, we will refer you to that customer, who is the controller for it.

You may also complain to the Norwegian Data Protection Authority (Datatilsynet) if you believe we have handled your data incorrectly.

Security

Transport is encrypted with TLS. Data at rest is encrypted at the volume level and secrets are encrypted individually. Access to production systems is limited to personnel who need it, is logged, and requires multi-factor authentication. See the security page for how the platform is built.

Breach notification

If a personal data breach occurs that is likely to result in a risk to individuals, we notify Datatilsynet within 72 hours and affected customers without undue delay.

Changes

We update this policy when the service changes. Material changes are announced by email to account holders at least 30 days in advance.

Note on this document

This policy describes our intended practice and is provided for transparency. It is not legal advice, and it should be reviewed by qualified counsel before being relied upon in a contractual context.

Questions about this document? Write to [email protected]. CloudContainer AS, Kongens gate 12, 7011 Trondheim, Norway. Org. nr. 934 512 887.