Notice
Privacy Policy
What we collect, why we have it, who else touches it, how long we keep it, and how to make us delete it.
- Effective
- 31 July 2026
- Controller
- Vijay, trading as VijayCloud
- Frameworks
- GDPR · CCPA · DPDP
- Requests
- privacy@vijaycloud.com
Contents
The short version
We collect what we need to run your account, bill you and keep the platform secure — nothing more. We never see your card number. We don’t sell your data and we don’t share it for advertising. We don’t log into your instance unless you ask us to or there’s a confirmed security incident. Email privacy@vijaycloud.com and we’ll delete what we hold.
We do not use your Customer Content, your datasets or your model weights to train our own models or those of any third party. Set out in full in section 2.3.
This Privacy Policy explains how Vijay, trading as VijayCloud (“VijayCloud”, “we”, “us”) collects, uses, shares and protects personal data when you visit vijaycloud.com or use our GPU compute services (the “Services”).
We are the data controller for the personal data described in this policy. Our contact details are in section 12.
01Two different roles
It matters which of these applies to you:
- We are the controller of personal data about our website visitors, account holders and billing contacts — the data described in section 2.
- We are a processor for anything you choose to put on your Instance. If your datasets, application databases or logs contain personal data, you decide what that is and why it is there; we only host it. We do not access the contents of your Instance except as described in section 5. If you need a data processing agreement covering that relationship, email privacy@vijaycloud.com.
02What we collect
2.1 Information you give us
- Account data — name, email address, password (stored hashed, never in plain text), company name and country.
- Billing data — billing name and address, tax or VAT/GST identifier where applicable, and the invoice history associated with your account.
- Support and sales communications — the contents of emails, contact form submissions and demo requests, including any technical detail or logs you send us.
Card data
We do not collect or store payment card details. Card data is captured and processed directly by WooCommerce Payments (powered by Stripe) and never reaches our servers. We receive only a tokenised reference, the card brand, the last four digits and the expiry date, so we can display and charge your saved payment method.
2.2 Information we collect automatically
- Service usage and telemetry — Instance identifiers, provisioning and termination events, resource metrics such as GPU, CPU, memory, storage and network utilisation, and the timestamps of these events. We use this to bill accurately, to detect faults and abuse, and to plan capacity.
- Access logs — IP address, timestamp, user agent, and the pages or API endpoints requested, for security, fraud prevention and diagnostics.
- Cookies and analytics — see section 7.
2.3 What we do not do
We do not sell personal data. We do not share it with third parties for their own advertising. We do not use Customer Content, your datasets or your model weights to train our own models or those of any third party.
03Why we use it, and our legal bases
| Purpose | Data used | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and administer your account; provide the Services | Account data, usage data | Performance of a contract |
| Take payment, issue invoices, collect unpaid amounts | Billing data, usage data | Performance of a contract; legal obligation |
| Provide support and respond to enquiries | Support communications, account data | Performance of a contract; legitimate interests |
| Keep the platform secure; detect fraud and abuse | Access logs, usage data | Legitimate interests; legal obligation |
| Meet tax, accounting, export control and sanctions obligations | Billing data, account data | Legal obligation |
| Send service and security notices you cannot opt out of | Account data | Performance of a contract; legitimate interests |
| Send marketing email about our products | Account data | Consent, or legitimate interests where permitted, with opt-out in every message |
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, solvent and functioning service does not override your rights. You can object — see section 8.
04Who we share it with
We share personal data only with service providers who need it to help us operate, each bound by contract to protect it and to use it only on our instructions:
| Provider | What it does for us | Data involved | Location |
|---|---|---|---|
| WooCommerce Payments (powered by Stripe) | Payment processing, subscription billing, fraud screening | Billing data, card data (held by them, not us) | United States / EU |
| Hostinger International Ltd | Website and application hosting | Account data, access logs | EU / India |
| Own hardware at our own premises in Mumbai, India | Data centre and GPU infrastructure on which Instances run | Instance metadata, Customer Content at rest | India |
| Hostinger (transactional email) | Transactional and support email delivery | Name, email address, message content | EU |
We keep this list current. If we add or change a provider handling personal data, we will update this page.
We may also disclose personal data where we are legally required to — in response to a valid court order, subpoena or lawful request from a regulator or law enforcement — or where necessary to establish or defend legal claims, or to protect the rights and safety of our customers or the public. Where we are legally permitted to tell you about such a request, we will. If our business is involved in a merger, acquisition or sale of assets, personal data may transfer as part of that transaction, and we will notify you before it becomes subject to a different privacy policy.
05Access to your Instance
Your Instance is yours. Our personnel do not log into it, inspect its filesystem or read Customer Content in the ordinary course of operating the platform. We will access it only:
- when you ask us to, for support you have requested;
- where strictly necessary to investigate a confirmed security incident, an active threat to the platform or to other customers, or a credible abuse report; or
- where we are compelled to by law.
Access under the second and third grounds is limited to the minimum necessary, is logged, and — except where the law forbids it — we will tell you.
06How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 12 months after closure |
| Invoices and financial records | 8 years, as required by tax and accounting law |
| Access and security logs | 90 days |
| Usage and billing telemetry | 13 months |
| Support correspondence | 24 months |
| Customer Content on Instances | Until the export window in our Terms closes — deletion is irreversible |
| Marketing contact records | Until you unsubscribe, then suppression-list only |
07Cookies and analytics
We use strictly necessary cookies only — to keep you logged in, remember your cart and protect against cross-site request forgery. These cannot be switched off and do not require consent. A visit that does not involve logging in or adding something to a cart sets no cookies at all.
We do not currently run website analytics of any kind. We set no analytics, advertising or cross-site tracking cookies, and no third party receives your browsing activity on this site. If that ever changes we will update this policy before switching anything on.
You can block or delete cookies in your browser settings, though blocking the strictly necessary ones will break login and checkout. We do not respond to Do Not Track signals, because there is no agreed standard for how to do so.
08Your rights
Depending on where you live, you may have some or all of the following rights: to access the personal data we hold about you; to correct it; to delete it; to restrict or object to our processing; to receive it in a portable format; to withdraw consent where consent is the basis; and not to be subject to a decision based solely on automated processing that has legal or similarly significant effects. We do not make such automated decisions.
If you are in the EEA or UK
Under the GDPR and UK GDPR you may exercise the rights above and may lodge a complaint with your national supervisory authority. Our EEA/UK representative, where required, is not applicable – we do not currently target the EEA or UK.
If you are in California
Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and why, to request deletion or correction, to request a copy, and to limit use of sensitive personal information. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is no “Do Not Sell or Share” action to take. We will not discriminate against you for exercising these rights. You may use an authorised agent.
If you are in India
Under the Digital Personal Data Protection Act, 2023 you have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a grievance redressal mechanism. Our Grievance Officer is Mukesh Gadkari, reachable at privacy@vijaycloud.com, and will respond within 30 days.
How to exercise a right
Email privacy@vijaycloud.com. We will verify your identity — usually by confirming control of the account email — and respond within 30 days, or within the shorter period your local law requires. There is no charge unless a request is manifestly excessive or repetitive.
09International transfers
We and our providers operate in multiple countries, so your personal data may be transferred to and processed outside the country where you are located, including in India, the European Union and the United States. Where we transfer personal data out of the EEA or UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with additional technical and organisational measures. You may request a copy of the relevant safeguards from privacy@vijaycloud.com.
10Security
We protect personal data with measures appropriate to its sensitivity, including TLS encryption in transit, encryption at rest for stored credentials and backups, hashed passwords, role-restricted administrative access, multi-factor authentication on administrative accounts, network isolation between customer Instances, and logging of administrative activity.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities within the timeframes our applicable law requires. We make no claim to hold any certification or audit report we have not actually obtained; if you need details of our current security posture for a vendor review, contact security@vijaycloud.com.
Reporting a vulnerability
Email security@vijaycloud.com. We will acknowledge within 2 business days and will not pursue action against good-faith researchers who report responsibly, avoid privacy violations and service degradation, and give us reasonable time to fix the issue before disclosure.
11Children
The Services are for business and professional use and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@vijaycloud.com and we will delete it.
12Changes and contact
We may update this policy. We will post the revised version here with a new effective date, and will notify account holders by email before material changes take effect.
| Purpose | Address |
|---|---|
| Privacy and data protection | privacy@vijaycloud.com |
| Security | security@vijaycloud.com |
| Grievance Officer | privacy@vijaycloud.com |
Vijay, trading as VijayCloud
5th Floor, Technopolis Knowledge Park, Chakala, Andheri East, Mumbai, Maharashtra 400093, India
Vijay, trading as VijayCloud · 5th Floor, Technopolis Knowledge Park, Chakala, Andheri East, Mumbai, Maharashtra 400093, India
Effective 31 July 2026 · Legal index