Privacy policy
This page explains what personal data we handle when you visit our website or use static egress or IP Tunnel, and what rights you have. It is written for the paid pilot and will grow with the service.
1. Who is responsible
The controller is [Legal entity name to be confirmed], [Registered address to be confirmed]. Privacy questions and requests go to privacy@penduses.com.
2. What we keep and why
We keep as little as we need to run the service, bill you and deal with abuse. We never keep the content (payload) of your traffic. Retention periods are fixed and short; when a period ends, the data is deleted.
| Data | Why we need it | Legal basis | How long |
|---|---|---|---|
| Account data: name, email, company, billing country, VAT number if you give one | Create your account, deliver the service, answer support | Contract | While your account is active, then as needed for legal claims |
| Billing data. Payments are handled by our payment provider; we receive plan, subscription status, payment result and invoice details, not full card numbers | Take payment, issue invoices, keep tax records | Contract, legal obligation | As tax and accounting law requires |
| Service configuration: destination allowlist, WireGuard public keys, assigned addresses. We do not store your WireGuard private key | Run the service you ordered | Contract | While your service is active |
| Static egress proxy connection metadata: time, your workspace, destination host or IP, port, bytes, result. No payload | Run and troubleshoot the service, protect the network, handle abuse reports | Legitimate interests | 30 days |
| IP Tunnel: we keep no flow logs, that is, no record of individual connections. We keep traffic counters and the last WireGuard handshake time per tunnel | Run the tunnel, apply fair use, handle abuse reports | Contract, legitimate interests | [Owner to confirm retention of counters.] |
| Allocation history: which customer held which IP address, and from when to when | Answer abuse reports and legal requests such as “who used this address at that time” | Legitimate interests, legal obligation | 12 months |
| Audit records of changes to accounts and services: who did what and when, including our own staff actions | Keep the service accountable, investigate incidents and disputes | Legitimate interests | 24 months |
| Support and abuse correspondence | Answer you and keep a record of what was agreed | Contract, legitimate interests | Up to 24 months after the last message |
| Website server logs: IP address, time, page requested | Keep the site running and spot attacks | Legitimate interests | 30 days [Owner to confirm.] |
3. What we do not do
- We do not decrypt, inspect or store the content of your traffic.
- We do not keep flow logs for IP Tunnel.
- We do not sell personal data or use it for advertising profiles.
- We do not ask for passwords or private keys in support. If you send one by mistake, tell us and we will rotate it.
4. Who receives data
We use service providers to run Penduses: a payment provider, an email and support tool, and the infrastructure providers that host our network nodes [Owner to list providers.]. They may only use the data to provide their service to us. We also share the minimum needed with affected parties and with authorities where the law requires it or to stop abuse.
5. Where data is processed
Our nodes are in the EU (Gravelines, France (GRA) and Limburg, Germany (LIM)). Some providers, such as the payment provider, may process data outside the European Economic Area under approved safeguards. [Owner to confirm transfer mechanisms.]
6. Your rights
Under the GDPR you can ask us for access to your data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interests. Email privacy@penduses.com. We answer within one month. You can also complain to your local data protection authority.
7. Protecting data
We use technical and organisational measures appropriate to the risk, such as access controls and encryption for our management systems. No system is free of risk, and we will tell you and the authorities about a breach where the law requires it.
8. Cookies and analytics
This site does not set cookies and does not run analytics. If that changes we will update this page first.
9. Changes
We may update this policy. We will email active customers about material changes before they apply to you.