Legal
Privacy Policy
Last updated: 2026-07-15
This Privacy Policy explains how CloudGenie Ltd, registered in England and Wales with its registered office in Durham, United Kingdom ("CloudGenie", "we", "us"), collects, uses, shares and protects personal data when you use our websites, the CloudGenie platform, APIs and command-line tools (the "Service"). CloudGenie Ltd is the data controller for account and website data, and a data processor for personal data contained in Customer Data (see our DPA).
1. Data we collect
Account data. Name, business email address, password hash, role, organisation membership and profile settings.
Cloud connection data. Credentials you provide to connect AWS, Azure or Google Cloud accounts (stored encrypted), plus resource metadata, cost and usage data, configuration and logs retrieved from those accounts. This data is primarily technical; we do not intentionally collect personal data from your cloud environments, but resource names or tags you create may contain it.
Billing data. Plan, invoices and payment status. Card details are processed and stored by Stripe — we never store full card numbers.
Usage data. Product interactions, device/browser type, IP address, and diagnostic logs (with request identifiers) used for security, debugging and service improvement.
Support data. Communications you send to our support and sales addresses.
2. How we use data
We use personal data to: (a) provide, operate and secure the Service; (b) authenticate users and enforce role-based access; (c) process payments and send transactional messages; (d) provide support; (e) analyse aggregate usage to improve the product; (f) comply with legal obligations; and (g) with your consent, for any other purpose described at collection.
Legal bases (UK GDPR / EU GDPR): performance of a contract, legitimate interests (security, product improvement, fraud prevention), legal obligation, and consent (marketing communications, withdrawable at any time).
3. AI features
Certain features send prompts and relevant context to large-language-model providers to generate responses. We send the minimum context needed, do not permit these providers to train on your data under our agreements with them, and never send your stored cloud credentials to AI providers.
4. Sharing and sub-processors
We do not sell personal data. We share data only with: (a) sub-processors who help us operate the Service — the current list is published at /legal/subprocessors; (b) your organisation — tenant administrators can see users, roles and audit activity within their tenant; (c) authorities where required by law or valid legal process; and (d) a successor entity in connection with a merger or sale of assets, subject to this Policy.
5. International transfers
Where personal data is transferred outside the UK or EEA, we rely on appropriate safeguards including the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, and adequacy regulations where applicable.
6. Security
We protect data using encryption in transit (TLS) and at rest, encrypted credential storage, tenant isolation, role-based access control, audit logging and secret-scanning in our development pipeline — see the Security page. Report vulnerabilities via our responsible disclosure programme.
7. Retention
We retain account data while your account is active. After termination, Customer Data is available for export for 30 days and then deleted from active systems; backups are purged on a rolling schedule. Billing records are retained as required by UK tax and accounting law (generally 6 years). Diagnostic logs are retained for a limited period appropriate to security investigation needs.
8. Your rights
You may have rights to access, correct, delete, restrict or port your personal data, and to object to certain processing. Where processing is based on consent, you may withdraw it at any time. To exercise rights, contact privacy@cloudgenie.co. You may also lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority. If you use the Service through an organisation, we may direct your request to your tenant administrator, who controls the account.
9. Cookies
We use strictly necessary cookies for authentication and session management (for example, the session cookie shared across cloudgenie.co subdomains for single sign-on). We do not use third-party advertising cookies on the platform. Where analytics cookies are used on this marketing site, you can control them through your browser settings.
10. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal data.
11. Changes to this policy
We will post updates to this page and, for material changes, notify you by email or in-product notice before they take effect.
12. Contact
Data protection enquiries: privacy@cloudgenie.co · General: hello@cloudgenie.co
CloudGenie Ltd, Durham, United Kingdom