Privacy Policy
What personal data Aether Platform holds about you, why we hold it, who else sees it, and how long it stays. Section 4 and section 5 cover the two cases people ask about most: how long invoices live, and what survives when you delete your account.
Last updated: 9 September 2026
01 Who controls your data
The controller is EAGLE VERSE SRL, Baia Mare, Maramureș, Romania, trade register no. 2010000840245, CUI 27852110. For anything in this policy — including a request to exercise your rights under section 8 — write to legal@aetherplatform.cloud.
This policy covers the data we hold about you as our customer. It does not cover the data inside your own clusters or container images: there you are the controller and we are your processor, acting on your instructions and with no reason to look at its contents.
Data processing agreement. We do not offer a separate data processing agreement today: these Terms and this policy are the whole agreement between us, including for the workload data described above. A standard processing agreement is on our roadmap. If you need one before it ships, write to legal@aetherplatform.cloud.
02 What we process, and why
| Data | Why | Lawful basis |
|---|---|---|
| Account and organization | Email address, name, organization name and slug, role and membership, and the invitations you send. Needed to give you an account and to control who may do what. | Contract (Art. 6(1)(b)) |
| Authentication | Credentials held in our self-hosted Keycloak: password hash, passkeys registered to your account, sessions and tokens. | Contract |
| Billing | Billing address, VAT identifier, legal name and contact; the card's brand, last four digits and expiry; issued invoices and their line items. | Contract, and legal obligation (Art. 6(1)(c)) for issued invoices |
| Usage and metering | Which clusters, pools and nodes existed, when, and at what size — the record your invoice is computed from. | Contract |
| Audit records | Who did what in your organization, with the IP address the action came from. | Legitimate interest (Art. 6(1)(f)): security, and answering "who changed this" |
| Operational logs, metrics and traces | Records our systems emit while running the platform, so we can detect faults and abuse. They carry internal identifiers and your organization's slug; they are not used to profile you. | Legitimate interest: operating and securing the service |
| Support | Support tickets, their messages and any files you attach, plus emails you send us. | Contract |
Sign-in providers. We do not offer sign-in through a third-party identity provider today. You sign in with a password or a passkey held in our own Keycloak, so no sign-in data is exchanged with anyone else. If we enable a third-party provider, this policy will say what is exchanged with it and link to that provider's own privacy policy before you can use it.
We do not sell personal data, we do not use it for advertising, and we do not make automated decisions with legal effect about you. The one automated refusal we do operate — declining a registration linked to an unpaid balance — is explained in section 5 and can be reviewed by a person if you ask.
03 Payments
Card payments are processed by Stripe, acting as our processor. Your card details are entered directly into Stripe's payment form and are held by Stripe. We never receive or store a full card number. What we store is the card's brand, its last four digits, its expiry date and an identifier that lets us charge it — plus your billing address, which we need for the invoice.
When you save a card, Stripe asks your bank to authenticate you (3-D Secure). That authentication is what makes the later monthly charges described in the Terms possible while you are not present.
Stripe keeps its own record of payments, charges and refunds under its own legal obligations as a payment institution; deleting your account with us does not erase Stripe's financial records.
What Stripe does with the data it holds is described in Stripe's privacy policy.
04 How long we keep it
- Account, organization and usage data — for as long as your account exists, then deleted when you close it (section 5).
- Operational logs, metrics and traces — retained for a limited period, not exceeding 30 days, for security and operations. They carry your organization's slug and internal identifiers, not message content.
- Issued invoices — retained for the period Romanian accounting and tax law requires, which outlives your account. A retained invoice keeps the buyer details it was issued with, because an invoice stripped of them is not a valid accounting document. It is detached from your account, taken out of every portal and API read path, and is thereafter reachable only through our accounting records.
- Support tickets and attachments — for as long as your account exists, then deleted with it.
Two things survive an erasure, and only these: the issued invoices just described (Art. 17(3)(b)), and — in one specific case — the debtor record in section 5.
05 Erasure, and the settlement step
You may request deletion of your account at any time, and an organization owner may delete the whole organization. We honour erasure requests fully — your personal data goes from our systems, including your account and organization records, your identity and sign-in credentials, your container registry and the images in it, support tickets and their attachments, your clusters and their storage, and your customer record at Stripe. The accounting records the law requires us to keep — numbered invoices — are retained with your account reference removed, as described in section 4.
Outstanding balances are settled first
Erasure is subject to settling anything you still owe. When an account closes with a balance, we issue a final invoice for it and charge it to the payment method on file, as you agreed in the Terms. Erasure is not withheld indefinitely: we complete it within one month of your request, whether or not the balance was collected. What we keep afterwards depends on the size of an uncollected balance:
- At or below a small write-off threshold: we write the balance off and erase everything, keeping nothing that identifies you beyond the invoice itself.
- Above that threshold: we still erase your data, but the debt remains an ordinary receivable and we keep the minimum needed to pursue or defend that claim — the invoice number, the amount, your billing address, and a non-reversible fingerprint of the payment card. A fingerprint is derived from the card; it is not a card number and cannot be turned back into one. Its only purpose is to recognise the same card if it is presented again.
The lawful basis for that debtor record is Art. 17(3)(e) and Art. 6(1)(f) — establishing and exercising a legal claim. It is deleted when the claim ends: on settlement, on write-off, or when the claim becomes time-barred, the card fingerprint and the billing address are erased and only the invoice number, the amount and our own note of the outcome remain. If a registration of yours is ever refused on the strength of that record, we tell you the invoice it relates to, how to settle it, and how to reach a person about it.
Not every deletion is instantaneous, and we would rather say so than imply otherwise: container image data is reclaimed at the registry's next scheduled cleanup, and operational logs, metrics and traces age out on the retention window in section 4 rather than being picked out individually.
06 Who else processes it
- Stripe — payment processing and card storage (section 3).
- Hetzner — hosting for our production infrastructure, in EU data centres in Finland. Your clusters and our databases run there.
- Transactional email — invoices, alerts and verification messages are sent from our own mail infrastructure, not a third-party marketing platform.
We also disclose data where the law requires it, or to establish or defend a legal claim. Otherwise, nobody else receives it.
International transfers. Our infrastructure and your data are in the EU. Stripe may transfer payment data outside the EU under the European Commission's standard contractual clauses.
08 Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy;
- rectify data that is wrong or incomplete — most of it you can edit yourself in the portal;
- erase your data, subject to the settlement step and the retained records in section 5;
- restrict or object to processing we base on legitimate interest;
- portability — receive the data you gave us in a machine-readable form.
Exercise any of them by writing to legal@aetherplatform.cloud. We answer within one month. If a request is complex we may extend that by up to two further months, and we will tell you why within the first month.
If you think we have handled your data wrongly, you can complain to the Romanian supervisory authority — ANSPDCP, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (www.dataprotection.ro). We would rather you told us first so we can fix it.
09 Changes to this policy
When this policy changes we update the date at the top, and we tell you in advance — in the portal and by email — if the change affects what we do with your data rather than only how we describe it.