Unio Cloud: Privacy Policy
Last updated: 2026-07-22
1. Controller
WHITECLOUD PROJECT S.R.L., Str. Ardealului 62, Sector 1, 013436 Bucharest, Romania, email support@uniocloud.eu.
2. What we process, and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account data: email, hashed password | account creation, login, essential service email | Art. 6(1)(b) contract |
| Billing data: top-ups, credit ledger, usage records (resource IDs, hours, amounts) | billing, tax compliance | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation |
| Payment data: handled by our payment provider (Mollie B.V., NL); we store only payment references and status, never card numbers | payment processing | Art. 6(1)(b) contract |
| Technical identifiers we provision for you: OpenStack project/user, S3 access keys, saved SSH public keys | operating your resources | Art. 6(1)(b) contract |
| Logs: portal access logs, API request logs, platform logs including IP addresses | security, abuse prevention, troubleshooting | Art. 6(1)(f) legitimate interest |
| Country/location evidence at top-up (billing country, IP-derived country) | VAT place-of-supply rules (OSS) | Art. 6(1)(c) legal obligation |
| Waitlist email (pre-launch) | launch communication | Art. 6(1)(a) consent, revocable |
Content you store on the service (server disks, volumes, buckets) is processed on your behalf and under your instructions only. Where it contains personal data, we act as processor under a Data Processing Agreement .
3. Where data lives, and who helps us
All customer content and platform data is stored and processed within the European Union. We deliberately use only European sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| OVH SAS (compute nodes) and Hetzner Online GmbH (backup storage) | physical infrastructure hosting | DE / FR / EU |
| Mollie B.V. | payment processing | NL |
| Brevo (Sendinblue SAS) | transactional email | FR |
The customer portal and its database run on orkestr, a platform operated by WHITECLOUD PROJECT S.R.L. itself (the same legal entity as Unio Cloud, so not a third-party sub-processor); its underlying servers fall under the infrastructure hosting row above.
We do not transfer personal data outside the EU/EEA and do not use sub-processors subject to non-EU access laws for content storage. If a sub-processor changes, we update this list and notify account holders.
4. Retention
- Account and billing records: for the life of the account, then as long as tax/commercial law requires (10 years for invoices and accounting records under Romanian law).
- Logs with IP addresses: 90 days, longer only while needed for an ongoing security investigation or legal obligation.
- Your stored content: deleted when you delete the resource; residual copies in platform backups expire within 30 days.
- Waitlist emails: until launch communication is done or you unsubscribe.
5. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR), exercisable via support@uniocloud.eu. You can lodge a complaint with your local supervisory authority; ours is ANSPDCP (Romania).
6. Cookies and analytics
The portal uses only strictly necessary cookies (session login). The landing page uses no analytics and sets no tracking cookies. There is no third-party advertising or tracking.
7. Security
TLS everywhere, passwords stored hashed, tenant isolation enforced by OpenStack/Keystone and Garage per-key grants, encrypted off-site platform backups, access to production restricted to the founder. Report security issues to support@uniocloud.eu.