Legal
Privacy Policy
Last reviewed: 2026-08-01
The short version
Quick read: 3 things to know
- We don’t sell your data. Period.
- We collect only what we need to run your servers and bill you.
- You can request export or deletion of your data anytime — see Your Rights below.
What we collect and why
We don't sell your data. Period.
We collect the minimum needed to provision, run, and bill for your servers: account contact details, billing information (processed by our payment provider — we never store full card numbers), server configuration, and the connection metadata required to keep things online and secure.
Data retention post-cancellation: TBC — we are finalising the secure-erasure timeline. Processing region/country: TBC. Our sub-processors are limited to payment and infrastructure monitoring providers; a full sub-processor list and a B2B Data Processing Agreement (DPA) are available on request.
Breach notification: in the event of a confirmed personal-data breach, we will notify affected users without undue delay and within the timeframe required by applicable law.
Your rights under GDPR
If you're in the EU, UK, or another jurisdiction with GDPR-equivalent law, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data (“right to be forgotten”).
- Export your data in a portable, machine-readable format.
- Object to or restrict certain processing.
- Withdraw consent for consent-based processing at any time.
- Lodge a complaint with your supervisory authority if you believe we haven't handled your data correctly.
To exercise any of these rights, email security@juroot.com and we'll respond within the timeframe required by applicable law.