Skip to main content

Privacy Policy

Last updated: April 2026

IMPORTANT: This is a template. Have a lawyer review before launching.

1. Information We Collect

Personal Information (PII)

  • Account data: name, email, company name, username
  • Billing data: managed by Stripe (we do not store card numbers)
  • Authentication: managed by Keycloak (SSO provider)

Usage Data

  • File metadata: filenames, sizes, types, upload dates (NOT file content, except as described below)
  • Workflow metadata: workflow names, run times, completion status
  • Resource metrics: CPU usage, RAM, GPU utilization, network throughput — anonymized, used for scheduling optimization
  • API access logs: IP addresses, endpoints called, timestamps

Content Analysis

Some processing nodes inspect file content as part of their function:

  • Thumbnail generation reads image content
  • Blur detection analyzes pixel data
  • Format detection examines file headers
  • AI-powered nodes may send data to third-party inference services (configurable per node)

We do not systematically read, scan, or analyze the content of your files beyond what the processing nodes you select require.

2. How We Use Your Data

  • Service delivery: processing your files through workflows
  • Scheduling optimization: anonymized resource metrics train our ML scheduling model
  • Billing: usage tracking for credit consumption and storage quotas
  • Communication: service emails (welcome, payment, usage alerts)
  • Security: audit logging, anomaly detection

3. Data Sharing

We share data only with:

  • Stripe: payment processing (name, email, payment method)
  • Keycloak: authentication (email, name)
  • Worker infrastructure: your files are processed on worker machines (yours or platform-managed)

We do NOT sell personal data. We do NOT share data with advertisers.

4. Data Storage and Security

  • Data stored in MinIO (S3-compatible object storage) with tenant-isolated buckets
  • Secrets encrypted via HashiCorp Vault with tenant-scoped keys
  • Database access controlled by Vault dynamic credentials (rotated hourly)
  • All API traffic encrypted via TLS
  • Audit logs maintained per ISO 27001 AU-2/AU-3 with HMAC integrity verification

5. Data Retention

  • Active accounts: data retained as long as account is active
  • Deleted accounts: PII anonymized immediately, files purged after 30 days, anonymized billing/audit records retained for legal compliance (7 years)
  • ML training data: anonymized resource metrics (no PII) retained indefinitely to improve scheduling

6. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

  • Access: request a copy of your data (GET /me/data-export)
  • Rectification: update your profile in the Dashboard
  • Erasure: request account deletion (DELETE /me/account)
  • Portability: export your data in JSON format
  • Object: opt out of ML training data collection (contact us)

We respond to GDPR requests within 30 days.

7. Cookies

The Dashboard uses session cookies for authentication (Keycloak). We do not use tracking cookies or third-party analytics cookies.

8. Children

The Service is not intended for users under 18. We do not knowingly collect data from minors.

9. Changes

We may update this policy. Material changes are communicated via email. Continued use constitutes acceptance.

Contact

Data Protection Officer: privacy@modtechlabs.com