Privacy Policy
What personal data we hold, why, who processes it, and how to exercise your rights.
Version 1 · Effective from
Who is responsible
FDO Software, registration number TODO, registered office TODO, is the controller of the personal data described here.
We offer services to people in the European Union and the United Kingdom, so the GDPR and the UK GDPR apply to us in full despite our being established outside those territories.
Our representative in the European Union under Article 27 GDPR is TODO. Our representative in the United Kingdom is TODO. You may contact either, or us at privacy@fdosoftware.com.
An important distinction
This policy covers data we hold about YOU as our customer. It does not cover the data you put on a server you rent from us. For that data you are the controller and we are your processor — those terms are in the Data Processing Addendum, and we do not access that data except where you ask us to or where we must to keep the platform safe.
What we collect and why
- Account data — email address, password hash, name, country. Lawful basis: performance of our contract with you.
- Billing data — subscriptions, invoices, amounts, and a payment-provider reference. We do not store your full card number; our payment provider holds it. Lawful basis: performance of contract, and legal obligation for accounting records.
- Server metadata — which servers you have, their region, IP addresses, and resource usage. Lawful basis: performance of contract.
- Support correspondence — what you asked and what we answered. Lawful basis: performance of contract and our legitimate interest in improving support.
- Technical and security logs — IP addresses, access times, and abuse signals. Lawful basis: our legitimate interest in securing the platform and investigating abuse.
- Marketing preferences, where you opt in. Lawful basis: consent, withdrawable at any time.
What we do not do
We do not sell personal data. We do not share it with advertising networks. We do not read the contents of your servers for any purpose other than responding to a support request you raised or investigating a specific abuse report.
Sub-processors
We use a small number of processors, each under a data processing agreement. They are listed with their function and processing location on our Sub-processors page, which we keep current and which is the authoritative list.
International transfers
Personal data is processed outside the European Economic Area and the United Kingdom. Where that happens we rely on the European Commission's standard contractual clauses together with the UK Addendum, and we assess whether additional measures are needed in each case.
Your server data stays in the region you selected unless you move it.
How long we keep it
- Account and server metadata: for the life of your account, then 90 days.
- Invoices and accounting records: 7 years, because tax law requires it. This obligation takes precedence over a deletion request for those specific records.
- Security and abuse logs: 12 months.
- Support correspondence: 3 years.
- Server contents after termination: 14 days, then permanently deleted, as described in the Terms of Service.
Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. Email privacy@fdosoftware.com and we will respond within 30 days.
Where we have to retain something — an invoice, for instance — we will tell you specifically what has been kept and why, rather than declining the request as a whole.
You may also complain to a supervisory authority in the country where you live or work.
Security
Server root credentials shown in your dashboard are encrypted at rest with a key held separately from the database, and every occasion on which they are decrypted and displayed is logged. Account passwords are hashed and are never stored in a recoverable form.
We will notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach that meets the notification threshold, and will notify you where the breach is likely to result in a high risk to your rights.