Data Protection & Processing
This page explains how XenonCloud handles customer data in the context of our cloud hosting services, including how we act as a data processor and how you can exercise certain privacy rights.
Roles and responsibilities
For most workloads, you are the data controller. You decide what data is stored, who it belongs to, and how it is processed. XenonCloud acts primarily as a data processor, providing infrastructure and platform services.
For account-related data (billing, panel login, contact information), XenonCloud may act as a data controller for the limited purpose of operating your account and fulfilling legal obligations.
Types of data we handle
Depending on how you use our services, XenonCloud may process:
- Account data: contact details, billing information, and communication history.
- Service data: IP addresses, instance identifiers, configuration details.
- Operational data: logs and telemetry from our infrastructure (for example, performance metrics and error logs).
- Customer content: the data you choose to store on your servers or services (databases, files, application data, etc.).
Where data is stored
Customer instances and data are stored in the datacenter region(s) you select when deploying services. Account and operational data may be replicated across multiple secure locations for resilience and backup purposes.
We use reputable datacenter and service providers and implement appropriate technical and organizational measures to protect data against unauthorized access, loss, or misuse.
Sub-processors and third parties
XenonCloud may use carefully selected third-party providers to assist in delivering our services (for example, payment processors, monitoring tools, or support systems). These providers are required to handle data securely and only for the purposes we define.
Data subject rights
Depending on your jurisdiction (for example, under the GDPR or similar regulations), you may have the right to:
- Request access to account-related personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of certain personal data, subject to legal or contractual limitations.
- Object to or restrict certain types of processing.
For data you control on your own instances (such as your customers’ data), you are responsible for handling data subject requests. We will reasonably assist you in fulfilling those requests where our infrastructure is involved.
Retention and deletion
We retain account and billing data for as long as necessary to provide services and comply with legal, accounting, or reporting requirements. Service logs and telemetry may be kept for operational and security purposes for a limited period.
When you close your account or delete services, associated data is removed or anonymized according to our retention schedules, except where we are required to retain certain records.
Requests and questions
To submit a data-related request (access, correction, deletion) or to ask questions about how we handle data, please contact us via the contact page and mention “Data Protection” in the subject line.
This page is intended to provide high-level information and does not replace the full legal terms in our Privacy Policy and Terms of Service.