Privacy
# Privacy Policy
## 1. Who is responsible
VPS Client Desk is the trading name operated by Vultr VPS hosting with a client billing dashboard. It is responsible for personal information it decides to collect and use for its dashboard and subscription. Depending on the activity, we may act as a processor or service provider for information an agency customer puts into the service about its own clients. This notice explains both roles in plain language. Use the support or contact route shown on the VPS Client Desk website or in your account to make a privacy request.
## 2. Information we handle
We may handle account details such as name, business name, email, login and account settings; subscription, invoice and payment-status information (card details are handled by the payment processor, not stored by us unless clearly disclosed); support messages; and technical information such as IP address, browser/device details, timestamps, audit and error logs, and service activity. If you connect a provider account, we may process the account identifier, instance information, and API credentials or tokens needed for the feature you enable. Do not place passwords, payment-card details, or unnecessary personal or sensitive information in support messages or server names. Customers control and are responsible for information they load about their own clients.
## 3. Why we use information and legal bases
We use information to create and secure accounts, deliver and support requested features, manage subscriptions and billing, prevent abuse and fraud, troubleshoot and improve reliability, meet legal obligations, and respond to requests. Where GDPR/UK GDPR applies, our bases are contract performance, legitimate interests in operating a secure service, legal obligations, and consent where required (for example, optional cookies). Under POPIA we process for a lawful purpose, in a reasonable and not excessive manner, with appropriate safeguards. US state privacy laws may give residents rights described below. We do not sell personal information or share it for cross-context behavioral advertising.
## 4. Service providers and disclosures
We disclose only what is reasonably needed to: providers you connect to (such as Vultr, when your enabled integration requires it); payment processors; hosting, security, email, support and analytics providers actually used to operate the service; professional advisers; or authorities and other parties when required by law or needed to protect rights and safety. Providers are expected to protect information and use it for their service, subject to their own terms and privacy notices. We do not claim a particular provider is in use unless identified in the service or checkout. We may disclose or transfer information as part of a business restructuring, subject to applicable law and safeguards.
## 5. Credentials and security
Where an active feature requires an API token, we will request only the access needed for that feature and use reasonable organizational and technical safeguards appropriate to the risk. Do not connect an account until the feature's credential-handling instructions are available. No internet service can guarantee absolute security. You should use restricted tokens where supported, keep your own credentials secure, and revoke access if you suspect compromise. We will notify affected people and authorities when required by law.
## 6. Retention and international transfers
We retain information only as long as reasonably needed for the purposes above, account operation, security, dispute resolution and legal recordkeeping. When an account closes, we will delete or de-identify information that is no longer needed, subject to lawful retention, backups and security records. We may process information in countries other than yours. Where a transfer law requires safeguards, we will use a recognized mechanism such as adequacy decisions or standard contractual clauses, as applicable, and take additional steps where required.
## 7. Your choices and rights
Depending on your location, you may request access to, correction of, deletion of, or a copy of personal information; object to or restrict certain processing; withdraw consent; ask for portability; or complain to a privacy regulator. POPIA provides rights concerning access, correction, objection, deletion and complaints to the Information Regulator. GDPR/UK GDPR rights include access, rectification, erasure, restriction, objection, portability and complaint to a supervisory authority. US state laws may provide access, correction, deletion, portability, and opt-out rights for sale, targeted advertising or certain profiling; we do not sell information or use it for targeted advertising. We will not discriminate against you for exercising a right. We may verify your identity and may need to refer a request about data controlled by an agency customer to that customer. Use the support or contact route displayed on our website or in your account. You may appeal a denied request using that route.
## 8. Cookies, children and updates
Essential cookies or similar storage may be used to maintain sessions and protect accounts. Optional analytics or advertising cookies, if introduced, will be handled as described in the Cookie Policy and will require consent where required. The service is for business users and is not directed to children under 16; we do not knowingly collect children's information. We may update this policy and will provide notice of material changes where required. The effective version will be published with the service.