Privacy Policy

This policy explains what personal data [COMPANY LEGAL NAME] ("CapyArk", "we", "us") collects when you use capyark.com and the CapyArk backup service, why we collect it, and the rights you have over it. We are the data controller for the account data described below and can be reached at privacy@capyark.com.

The short version

1. Data we collect

CategoryWhatWhy (legal basis)
Account Email address, company name, hashed password, MFA settings, SSH public keys To provide the service you signed up for (contract)
Billing Plan, subscription status, invoice history. Card details are collected and stored by Stripe, never by us. Billing and tax compliance (contract, legal obligation)
Operational Storage usage, snapshot metadata (names, sizes, timestamps), daily ingress volume, connected device names and VPN status To operate quotas, snapshots, billing, and abuse prevention (contract, legitimate interest)
Security logs Portal login events, SSH session audit events (connection metadata and commands — never file contents), IP addresses Tenant security and incident investigation (legitimate interest)
Support Emails you send to support and our replies To help you (contract, legitimate interest)

2. Your backup contents

The files and datasets you back up may contain personal data of your own users or customers. For that content, you are the controller and we act as a processor: we store it on your instruction and do not access it except when strictly necessary to operate the service, at your explicit request for support, or where required by law. Where dataset encryption is enabled, contents are encrypted at rest with per-tenant keys. If you need a Data Processing Agreement, contact privacy@capyark.com.

3. Where data is stored

Backup data is stored on our servers located in [COUNTRY / EU REGION]. Account and billing records are stored with our infrastructure providers listed below. We do not transfer backup contents outside [EU/EEA or REGION].

4. Sub-processors and third parties

ProviderPurposeLocation
StripePayment processingUSA/EU (SCCs)
[EMAIL PROVIDER, e.g. Resend]Transactional email[LOCATION]
[HOSTING PROVIDER(S)]Server infrastructure[LOCATION]

Our VPN control plane is self-hosted — device coordination data does not pass through any third-party VPN service.

5. Retention

6. Cookies and analytics

The marketing website (capyark.com) sets no cookies. The client portal (app.capyark.io) uses only essential cookies/tokens required for login sessions. If we add analytics, we will use a privacy-friendly, cookieless tool and update this policy — we will never add third-party advertising or cross-site trackers.

7. Security

8. Your rights

Depending on your location (and always if you are in the EU/EEA or UK), you have the right to access, correct, export, restrict, object to the processing of, or delete your personal data. You can exercise most of these directly in the portal (profile editing, data deletion, account closure) or by emailing privacy@capyark.com. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

9. Changes

We will notify you by email of material changes to this policy at least 30 days before they take effect. The "Last updated" date at the top reflects the current version.

10. Contact

[COMPANY LEGAL NAME], [REGISTERED ADDRESS]
Privacy inquiries: privacy@capyark.com
General support: support@capyark.com