Legal · Privacy Policy

Privacy Policy

What we collect, why, and how long we keep it. Nothing leaves the EEA, and nothing is sold.

Version 1.0 Effective 6 August 2026 Hola Money S.L.

01Who is responsible for your data

For your account and billing data, the data controller is Hola Money S.L., NIF B26671347, C/ Granada 7, 04820 Vélez-Rubio, Almería, Spain. Contact: privacy@cleverotter.eu.

For the content you host and the Visitors to your Sites, you are the controller and we are your processor. Those arrangements are set out in our Data Processing Agreement.

We have not appointed a Data Protection Officer, as we are not required to. CONFIRM: still true as you grow

02What we collect, and why

AccountName, email, password hash
AuthenticationSSH public keys, token hashes
BillingAddress, VAT number, invoices
UsageBandwidth, storage, request counts
Deployment logsTimestamps, source IP, outcome
SupportEmails you send us

Our legal bases are: performance of a contract for account, authentication and usage data; legal obligation for invoices and tax records; and legitimate interests for security logs and abuse prevention, where our interest in keeping the Service secure is balanced against your rights.

We do not collect special category data, and we do not use your data for automated decision-making or profiling.

03What we do not do

We do not sell your data. We do not share it with advertisers. We do not inject analytics, tracking scripts or cookies into the Sites you host, and we do not build profiles of your Visitors.

Our marketing website sets no cookies at all. The dashboard sets a single session cookie, strictly necessary to keep you logged in, plus a CSRF token. Neither is used for tracking and neither requires consent.

Analytics on our own website

We measure traffic to our marketing pages using Umami, self-hosted on our own infrastructure. It records the page visited, the referring page, screen size, browser language and country, and derives a daily-rotating hash so that returning visits in a single day are not double-counted.

It sets nothing on your device: no cookie, no local storage, no cross-site identifier. Your full IP address is never stored, and no data is shared with a third party or used for advertising. That combination is why there is no consent banner on this site — there is nothing stored on your device to ask permission for.

Our lawful basis is legitimate interests: knowing which pages are read is how we decide what to write next, balanced against a measurement that cannot identify you. To opt out entirely, any tracker blocker or your browser’s Do Not Track setting will do it, and nothing on the site depends on the script running.

This applies to our pages only. We still inject nothing whatsoever into the sites we host for you.

04Visitors to hosted sites

When someone visits a Site we host, our servers process their IP address and request details in order to serve the response and to protect the Service from abuse. We aggregate this into counts for billing.

Request logs containing IP addresses are retained for 14 days and then deleted. Aggregated counts, which do not identify anyone, are retained for billing and capacity planning.

If your Site collects personal data itself, that is your responsibility as controller, and your own privacy notice must cover it.

Form submissions

If you create a form endpoint, we store what your visitors submit so that you can read it. This is your data about your visitors: you decide what your form asks for and why, and we hold it on your behalf and on your instructions. Our Data Processing Agreement governs that relationship.

For each submission we store the field values sent, the address of the page it came from, the visitor's IP address, and their browser's user-agent string. The IP address and user-agent are kept because they are what makes spam and abuse identifiable; the rest is simply your enquiry.

We keep submissions until you delete them, so that a message is never lost on a timer. Submissions caught by the spam checks are deleted after 30 days. You can export or delete anything at any time from the dashboard, and deleting a form deletes every submission it collected.

If your form asks for personal data, your own privacy notice must tell visitors what you collect and why — we cannot do that for you, because only you know what you are asking and what you will do with it.

05Who we share it with

We use a small number of providers, all within the EEA:

Hetzner Online GmbHServers & object storage · Germany
Scaleway SASEncrypted backups · France
Payment providerCONFIRM
Email providerCONFIRM

We may also disclose data where legally required, or to establish or defend legal claims. We will tell you first unless prohibited from doing so.

06International transfers

Your data does not leave the European Economic Area as part of normal operation. Servers and object storage are in Germany; backups are in France. If that ever changes we will update this notice and rely on an appropriate transfer mechanism under Chapter V of the GDPR.

07How long we keep it

Account dataLife of the account + 30 days
Hosted content30 days after termination
Backups35 days, rolling
Request logs with IPs14 days
Invoices and tax records6 years (Spanish law)
Abuse and security records12 months

08Your rights

You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent where we rely on it.

Exercise any of these by emailing privacy@cleverotter.eu. We will respond within one month. We will not charge you, and we will not make the Service worse for you because you asked.

If you are not satisfied you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority where you live.

09Security

Data is encrypted in transit with TLS and at rest in object storage. Passwords are hashed and never stored in recoverable form; deploy tokens are stored only as hashes. Administrative access is restricted, key-based and logged.

If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the AEPD within 72 hours and tell you without undue delay where the risk is high.

10Changes

We will post any change here and update the version above. For changes that materially affect how we handle your data, we will email you at least 30 days beforehand.

Questions about this document

Ask a person, not a form.

We would rather answer a question before you sign up than argue about a clause afterwards.