Aether Platform
Terms of Service Create an account Sign in

Contents

  1. 01 Who controls your data
  2. 02 What we process, and why
  3. 03 Payments
  4. 04 How long we keep it
  5. 05 Erasure, and the settlement step
  6. 06 Who else processes it
  7. 07 Cookies
  8. 08 Your rights
  9. 09 Changes to this policy

Privacy Policy

What personal data Aether Platform holds about you, why we hold it, who else sees it, and how long it stays. Section 4 and section 5 cover the two cases people ask about most: how long invoices live, and what survives when you delete your account.

Last updated: 9 September 2026

01 Who controls your data

The controller is EAGLE VERSE SRL, Baia Mare, Maramureș, Romania, trade register no. 2010000840245, CUI 27852110. For anything in this policy — including a request to exercise your rights under section 8 — write to legal@aetherplatform.cloud.

This policy covers the data we hold about you as our customer. It does not cover the data inside your own clusters or container images: there you are the controller and we are your processor, acting on your instructions and with no reason to look at its contents.

Data processing agreement. We do not offer a separate data processing agreement today: these Terms and this policy are the whole agreement between us, including for the workload data described above. A standard processing agreement is on our roadmap. If you need one before it ships, write to legal@aetherplatform.cloud.

02 What we process, and why

DataWhyLawful basis
Account and organizationEmail address, name, organization name and slug, role and membership, and the invitations you send. Needed to give you an account and to control who may do what.Contract (Art. 6(1)(b))
AuthenticationCredentials held in our self-hosted Keycloak: password hash, passkeys registered to your account, sessions and tokens.Contract
BillingBilling address, VAT identifier, legal name and contact; the card's brand, last four digits and expiry; issued invoices and their line items.Contract, and legal obligation (Art. 6(1)(c)) for issued invoices
Usage and meteringWhich clusters, pools and nodes existed, when, and at what size — the record your invoice is computed from.Contract
Audit recordsWho did what in your organization, with the IP address the action came from.Legitimate interest (Art. 6(1)(f)): security, and answering "who changed this"
Operational logs, metrics and tracesRecords our systems emit while running the platform, so we can detect faults and abuse. They carry internal identifiers and your organization's slug; they are not used to profile you.Legitimate interest: operating and securing the service
SupportSupport tickets, their messages and any files you attach, plus emails you send us.Contract

Sign-in providers. We do not offer sign-in through a third-party identity provider today. You sign in with a password or a passkey held in our own Keycloak, so no sign-in data is exchanged with anyone else. If we enable a third-party provider, this policy will say what is exchanged with it and link to that provider's own privacy policy before you can use it.

We do not sell personal data, we do not use it for advertising, and we do not make automated decisions with legal effect about you. The one automated refusal we do operate — declining a registration linked to an unpaid balance — is explained in section 5 and can be reviewed by a person if you ask.

03 Payments

Card payments are processed by Stripe, acting as our processor. Your card details are entered directly into Stripe's payment form and are held by Stripe. We never receive or store a full card number. What we store is the card's brand, its last four digits, its expiry date and an identifier that lets us charge it — plus your billing address, which we need for the invoice.

When you save a card, Stripe asks your bank to authenticate you (3-D Secure). That authentication is what makes the later monthly charges described in the Terms possible while you are not present.

Stripe keeps its own record of payments, charges and refunds under its own legal obligations as a payment institution; deleting your account with us does not erase Stripe's financial records.

What Stripe does with the data it holds is described in Stripe's privacy policy.

04 How long we keep it

  • Account, organization and usage data — for as long as your account exists, then deleted when you close it (section 5).
  • Operational logs, metrics and traces — retained for a limited period, not exceeding 30 days, for security and operations. They carry your organization's slug and internal identifiers, not message content.
  • Issued invoices — retained for the period Romanian accounting and tax law requires, which outlives your account. A retained invoice keeps the buyer details it was issued with, because an invoice stripped of them is not a valid accounting document. It is detached from your account, taken out of every portal and API read path, and is thereafter reachable only through our accounting records.
  • Support tickets and attachments — for as long as your account exists, then deleted with it.

Two things survive an erasure, and only these: the issued invoices just described (Art. 17(3)(b)), and — in one specific case — the debtor record in section 5.

05 Erasure, and the settlement step

You may request deletion of your account at any time, and an organization owner may delete the whole organization. We honour erasure requests fully — your personal data goes from our systems, including your account and organization records, your identity and sign-in credentials, your container registry and the images in it, support tickets and their attachments, your clusters and their storage, and your customer record at Stripe. The accounting records the law requires us to keep — numbered invoices — are retained with your account reference removed, as described in section 4.

Outstanding balances are settled first

Erasure is subject to settling anything you still owe. When an account closes with a balance, we issue a final invoice for it and charge it to the payment method on file, as you agreed in the Terms. Erasure is not withheld indefinitely: we complete it within one month of your request, whether or not the balance was collected. What we keep afterwards depends on the size of an uncollected balance:

  • At or below a small write-off threshold: we write the balance off and erase everything, keeping nothing that identifies you beyond the invoice itself.
  • Above that threshold: we still erase your data, but the debt remains an ordinary receivable and we keep the minimum needed to pursue or defend that claim — the invoice number, the amount, your billing address, and a non-reversible fingerprint of the payment card. A fingerprint is derived from the card; it is not a card number and cannot be turned back into one. Its only purpose is to recognise the same card if it is presented again.

The lawful basis for that debtor record is Art. 17(3)(e) and Art. 6(1)(f) — establishing and exercising a legal claim. It is deleted when the claim ends: on settlement, on write-off, or when the claim becomes time-barred, the card fingerprint and the billing address are erased and only the invoice number, the amount and our own note of the outcome remain. If a registration of yours is ever refused on the strength of that record, we tell you the invoice it relates to, how to settle it, and how to reach a person about it.

Not every deletion is instantaneous, and we would rather say so than imply otherwise: container image data is reclaimed at the registry's next scheduled cleanup, and operational logs, metrics and traces age out on the retention window in section 4 rather than being picked out individually.

06 Who else processes it

  • Stripe — payment processing and card storage (section 3).
  • Hetzner — hosting for our production infrastructure, in EU data centres in Finland. Your clusters and our databases run there.
  • Transactional email — invoices, alerts and verification messages are sent from our own mail infrastructure, not a third-party marketing platform.

We also disclose data where the law requires it, or to establish or defend a legal claim. Otherwise, nobody else receives it.

International transfers. Our infrastructure and your data are in the EU. Stripe may transfer payment data outside the EU under the European Commission's standard contractual clauses.

07 Cookies

The portal sets essential cookies only: the session and CSRF cookies that keep you signed in and protect form submissions, and a cookie remembering whether you chose the light or dark theme. One exception involves a third party: when you add a payment card, the card form is served by Stripe, and Stripe may set its own fraud-prevention cookies (__stripe_mid, __stripe_sid) on that page — they exist to protect you and us from card fraud, not to track you. There are no advertising cookies and no analytics cookies on this site, which is why you are not being asked to consent to any.

Registering sets one more essential cookie: when you create an account we store the email address you registered with for 60 seconds. It cannot be read by scripts in the page, no page reads it today, and it is discarded a minute later whether or not you sign in. It is reserved for pre-filling the sign-in page.

Clearing these cookies signs you out and resets the theme to its default; nothing else is affected.

08 Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and get a copy;
  • rectify data that is wrong or incomplete — most of it you can edit yourself in the portal;
  • erase your data, subject to the settlement step and the retained records in section 5;
  • restrict or object to processing we base on legitimate interest;
  • portability — receive the data you gave us in a machine-readable form.

Exercise any of them by writing to legal@aetherplatform.cloud. We answer within one month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month.

If you think we have handled your data wrongly, you can complain to the Romanian supervisory authority — ANSPDCP, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (www.dataprotection.ro). We would rather you told us first so we can fix it.

09 Changes to this policy

When this policy changes we update the date at the top, and we tell you in advance — in the portal and by email — if the change affects what we do with your data rather than only how we describe it.

Terms of Service · Create an account · Home

© 2026 Aether Platform