Information we collect
When you create an account, request a quote, or purchase a service, we collect the information you provide directly: name, email, company, billing address, and payment details (processed by our payment partners — we do not store full card numbers). Colocation and custom bare metal inquiries may include additional technical details about your intended deployment.
We automatically collect standard technical data when you use our website or services: IP address, browser type, pages visited, and timestamps, used for security, analytics, and troubleshooting.
For colocation customers, physical access to our facilities is logged, including badge entry timestamps and video retention at data hall and cabinet level, as described in Section 8 of our Terms of Service.
How we use it
- To provision, operate, and support the services you've purchased.
- To send billing, provisioning, and account security communications.
- To respond to support tickets and quote requests.
- To detect and prevent fraud, abuse, and acceptable-use violations.
- To improve our services and website based on aggregate usage patterns.
We do not sell your personal information. We do not use the contents of your VPS, bare metal server, or colocated equipment for any purpose beyond providing the service you've requested.
Data sharing
We share information with subprocessors necessary to run the business: payment processors, email delivery providers, and infrastructure vendors supporting facilities we don't own outright. Each is bound by contract to use your data only to provide their service to us. We disclose information to law enforcement only when required by valid legal process, and will notify affected customers unless legally prohibited from doing so.
Data retention
Account and billing records are retained for as long as your account is active and for a period afterward as required for tax and legal purposes, typically seven years. Facility access logs are retained for 12 months. Data on VPS instances and bare metal servers is deleted or securely wiped within 30 days of cancellation, consistent with our data destruction policy.
Security
We apply encryption in transit for account and payment data, role-based access controls for internal systems, and the physical security measures described on our Datacenters page. No system is perfectly secure, and we'll notify affected customers promptly in the event of a breach affecting their data, consistent with applicable law.
Cookies
Our website uses functional cookies necessary for account login and session management, and limited analytics cookies to understand aggregate site usage. We don't use third-party advertising trackers.
Your rights
Depending on where you're located, you may have the right to access, correct, export, or delete the personal information we hold about you. To exercise any of these rights, contact us using the details below — we'll respond within 30 days.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email at least 30 days before taking effect.
Contact
Questions about this policy or a data request can be sent to privacy@xervera.net.