Privacy Policy
Last updated: September 10, 2026
This Privacy Policy explains what information Omnicloud collects when you use the console and API, why we collect it, and how it is handled.
1. Information we collect
- Account information — name, email address, company name, and authentication details (password hash, and TOTP status if you enable two-factor authentication).
- Billing information — invoices, payment status and transaction references from our payment processor. We do not store full card or bank credentials ourselves.
- Usage and infrastructure metadata — the resources you provision (instances, volumes, networks, clusters and similar), resource metering used for billing, and API/console activity logs, including IP address and user agent.
- Customer Data — the content of the workloads you run on provisioned resources. We do not inspect this beyond what is needed to operate, secure or support the Service.
2. How we use this information
To provide and operate the Service (provisioning, metering, billing and support), to secure accounts and infrastructure against misuse, to communicate service and security notices, and to meet legal and tax obligations. We do not sell personal information.
3. Sharing
We share information with infrastructure and payment providers strictly to deliver the Service (for example, our payment gateway processes transactions), with law enforcement or regulators when legally required, and with your explicit consent for any other purpose. Team members you invite can see information relevant to shared projects within your team.
4. Data retention
We keep account and billing records for as long as your account is active and for the period required by applicable tax and accounting rules afterward. Infrastructure and audit logs are retained for a limited period for security and troubleshooting, then deleted or anonymized.
5. Security
Passwords are stored using a salted hash (Argon2), sensitive credentials such as your cloud API secrets are encrypted at rest, and two-factor authentication is available — and may be required by your administrator. No method of transmission or storage is completely secure, but we take reasonable technical and organizational measures to protect your data.
6. Your choices
You can review and update your account information from Account settings, manage active sessions and API tokens, and export or delete resources you control. To request deletion of your account or data we hold beyond what is needed for legal retention, contact us using the details below.
7. Changes to this policy
We may update this policy as the Service evolves. Material changes will be communicated through the console or by email before they take effect.
8. Contact
Questions about this policy or your data can be sent to support@omnicloud.co.id.