Privacy Policy
What personal data RDPForge collects, why, how long we keep it, who we share it with, and the rights you have over it.
Effective 20 May 2025. The short version: we hold as little about you as we can, we do not look inside your servers, we do not sell anything to anyone, and we do not run advertising or analytics trackers on this website.
What we collect
| Data | Why | Retention |
|---|---|---|
| Email address | Delivering credentials, invoices, renewal reminders, incident notices | Life of account + 24 months |
| Order and invoice records | Accounting and tax obligations | 7 years (statutory) |
| Support tickets | Providing support, historical context on your services | 36 months after closure |
| Client-area authentication logs (IP, timestamp) | Detecting account takeover | 90 days |
| Hypervisor resource metrics (CPU, RAM, disk, network volume) | Capacity planning, fault detection, your usage graphs | 13 months, aggregated after 30 days |
| Sampled netflow headers | DDoS detection and mitigation only | 72 hours, then discarded |
No KYC โ what that means concretely
We do not operate any identity-verification process. We have never asked a customer for, and do not hold, any of the following:
- Legal name, date of birth or nationality
- Government identification, passport or driving licence
- Photograph, selfie or liveness check
- Home, billing or business address
- Telephone number
- Company registration or tax identification number
- Payment card or bank account details
- Source-of-funds declaration or stated reason for purchase
There is no spend level, account age or service type at which this changes. It is possible because we accept cryptocurrency only: card fraud is what obliges most hosting providers to verify identity, and we carry no card-fraud exposure. Data that is never collected cannot be breached, sold or produced under compulsion.
An account holds exactly two fields you supply: an email address and a password (stored as an scrypt hash we cannot reverse). An optional display alias is cosmetic, never verified, and need not resemble your name.
What we do not collect
- Anything inside your instance. No agent, no introspection, no filesystem access. We cannot read your files and we do not want to.
- Traffic contents. Netflow sampling records headers for attack detection. Payloads are never captured or stored.
- Payment card or bank details. We do not accept cards, so we never hold them.
- Government identification. We do not perform KYC for standard orders.
- Advertising, analytics or fingerprinting data. This website sets no third-party cookies and loads no third-party scripts.
Cookies
Two first-party cookies: a session cookie for client-area authentication and a preference cookie remembering your billing-term selection. Both are strictly necessary, neither is shared, and there is nothing to consent to because we do not track you.
Who we share with
- OxaPay โ payment processing. They receive the invoice amount, order reference and, if you supply it, your email for the receipt. They do not receive your server details.
- Datacenter operators โ physical hosting. They have no access to customer records and cannot map an instance to an identity.
- Transactional email provider โ delivering credentials and invoices. They process your email address and message content.
That is the complete list. We do not sell, rent or trade personal data, and we have no advertising partners.
Legal requests
We respond to valid legal process issued by an authority with jurisdiction over Atlas Cloud Networks LLC or the relevant facility. We require the process to be specific, and we push back on overbroad requests. Where we are lawfully permitted to notify you, we do so before disclosing anything. The aggregate number of requests received and complied with is published in our annual network report.
Your rights
Wherever you are, you may ask us to: confirm what we hold about you, provide a copy, correct it, delete it (subject to the statutory retention on invoices), or export it in a portable format. Email [email protected] from your account address and we respond within 30 days, usually within two working days. There is no charge.
Customers in the EEA and UK have these rights under GDPR/UK GDPR; we extend the same handling to everyone rather than operating two standards. Our lawful basis is performance of a contract for service data, legitimate interest for security and abuse prevention, and legal obligation for accounting records.
Security
TLS 1.2+ everywhere with HSTS preload. Mandatory TOTP two-factor on client-area accounts with active services. Passwords stored with scrypt. Internal access to customer records is role-limited and audited. Physical access is controlled by the facility operators under their own certifications.
Data location
Billing and account records are stored in the European Union. Your instance data lives in whichever region you selected and is never migrated between regions without your instruction. Choosing one of our six offshore regions โ Iceland, Switzerland, Panama, Romania, Bulgaria or the Netherlands โ additionally places the instance in a jurisdiction with no blanket retention mandate for hosting providers; the acceptable use policy sets out how notices and requests are handled per region.
Contact
Privacy questions and rights requests: [email protected]. Postal: Atlas Cloud Networks LLC, 1209 Orange Street, Suite 400, Wilmington, DE 19801, United States.
Version history
We keep every version of this document on record. Material changes are emailed to active customers 30 days before they take effect.
- v3.0May 2025Added netflow retention detail and DPO contact.
- v2.1Aug 2023Removed analytics cookies entirely.
- v2.0Feb 2022Updated for crypto-only billing; card data no longer processed.
- v1.0Mar 2020Initial publication.