Privacy Policy
Last updated: 10 August 2026
Who we are
CloudOps is operated by Devops Team SRL, a company registered in Romania, European Union. We are the data controller for the personal data described here. As an EU company, we operate under the General Data Protection Regulation (GDPR). You can reach us at [email protected].
What we collect, and why
- Account data — when you create an account: your name, email address, and organization membership. Used to authenticate you, operate your organization's access controls, and contact you about your account. Legal basis: performance of a contract.
- Quote requests — when you use the form on our pricing page: the name, work email, company, and message you submit. Used solely to reply to your request. Legal basis: taking steps at your request prior to a contract.
- Infrastructure data — the servers, virtual machines, networks, and jobs you manage through the platform, including hardware inventory produced by scans you initiate. Processed to provide the service you configure; we never scan or modify machines you have not connected and authorized.
- Billing data — for paid usage and marketplace transactions: invoicing details and an itemized ledger of charges. Card details are handled by our payment processor (Stripe) and never touch our servers. Legal basis: performance of a contract and legal (accounting) obligations.
- Operational logs — every provisioning action runs as a recorded job with an audit trail (what changed, when, by whom). This is a core feature of the product and also serves security. Legal basis: legitimate interest in operating a secure, auditable service.
What we do not do
- We do not sell personal data, to anyone, for any purpose.
- Our public website uses no advertising trackers and no third-party analytics. The console sets cookies only to keep you signed in.
- We do not read the contents of your servers, disks, or databases. The platform touches machines only through the jobs you can see in your own audit trail.
Where your data lives
The platform and its data are hosted on infrastructure in Romania, European Union. Traffic to our public endpoints is proxied through Cloudflare (CDN and DDoS protection). Transactional email is delivered via Amazon SES. Payments are processed by Stripe. These providers process data on our behalf under their own GDPR commitments.
How long we keep it
Account and infrastructure data: for as long as your account is active, then deleted on request or after account closure. Quote requests: until handled, then archived in our support mailbox. Billing records: as long as accounting law requires. Audit logs: retained while the resources they describe exist, because they are the record of what was done to your infrastructure.
Your rights
Under the GDPR you can ask us for access to, correction of, export of, or deletion of your personal data; you can object to or ask us to restrict processing; and you can withdraw consent where processing is based on it. Write to [email protected] — we respond within 30 days. You also have the right to lodge a complaint with your supervisory authority; in Romania that is ANSPDCP (dataprotection.ro).
Changes
If this policy changes materially, we will note it here with a new "last updated" date, and notify account holders by email for significant changes.
Questions? Contact us.