1.
Introduction
1.1.
This Privacy Policy (hereinafter, the "Policy") delineates the modalities by which RUBYVOID LTD, a corporate entity duly registered in the Republic of Bulgaria ("Provider"), collects, processes, stores, and safeguards Personal Data in connection with the utilization of our website, customer portal, or infrastructure services by you, the User.
1.2.
The processing of Personal Data shall be conducted in strict compliance with the following legislative instruments:
a)
Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter "GDPR")
b)
The Bulgarian Personal Data Protection Act
c)
The ePrivacy Directive and all relevant national implementing legislation.
1.3.
The purview of this Policy extends to the following categories of data subjects:
a)
Existing and prospective Customers.
b)
Visitors utilizing the corporate website.
c)
Users of our infrastructure services.
d)
Individuals initiating contact with the Provider for the purpose of support or inquiries.
1.4.
This Policy governs exclusively the capacity of the Provider as a Data Controller in relation to its proprietary business operations.
1.5.
Where the Provider undertakes the processing of Personal Data on behalf of a Customer, such processing shall be governed by the terms stipulated in the Data Processing Addendum (DPA).
•
All applicable data-processing protocols are set forth herein: Data Processing Addendum.
2.
Data Controller
2.1.
The designated Data Controller for all activities described herein is:
•
RUBYVOID LTD
2.2.
In respect of inquiries pertaining to the GDPR, you may direct correspondence to the Provider’s dedicated privacy team via electronic mail at: privacy@rubyvoid.com.
3.
Categories of Personal Data
3.1.
The Provider may process the ensuing categories of Personal Data, contingent upon the specific engagement of the data subject with our services:
3.2.
Identity and Account Data
•
Name, address, and country of residence
•
Electronic mail address and telephonic contact number
•
Corporate designation, Value Added Tax (VAT) number, and invoicing particulars
•
Documents for identity verification (Know Your Customer-KYC), when mandated by statutory requirement or for the fulfillment of anti-fraud obligations.
3.3.
Operational and Service Utilization Data
•
Internet Protocol (IP) addresses assigned to the provisioned services
•
Location of Data Storage: The physical country and/or data center region selected by the Customer for the hosting of their provisioned server instance.
•
Authentication logs and timestamps of system access
•
Metrics relating to resource consumption (e.g., Central Processing Unit (CPU), bandwidth, storage capacity)
•
Reports concerning service abuse and events linked to security
•
Metadata generated through your interaction with the Provider’s systems.
3.4.
Financial and Transactional Data
•
Method of payment (in a masked format)
•
History of transactions
•
Records of invoices
•
Full credit card numbers are not retained by the Provider; all such data is handled by external payment processors compliant with Payment Card Industry Data Security Standard (PCI DSS).
3.5.
Correspondence Data
•
Support tickets and electronic correspondence
•
Messages transmitted to our support personnel
•
Notifications pertaining to abuse and compliance-related communications.
3.6.
Web Presence and Customer Portal Data
•
Session identifiers and Cookies
•
Access logs
•
Browser metadata (inclusive of user agent and referrer information)
•
Analytical data (processed solely where explicit consent has been furnished).
4.
Basis for Processing
4.1.
The processing of Personal Data is conducted strictly pursuant to the permissions granted under the GDPR. Depending on the factual matrix, the processing may lawfully rely upon the following bases:
4.2.
Performance of a Contract (Article 6(1)(b) of the GDPR)
•
The establishment and management of customer accounts
•
The provisioning of services and associated invoicing
•
The provision of technical support and necessary customer communications.
4.3.
Compliance with Legal Obligation (Article 6(1)(c) of the GDPR)
•
Adherence to statutory tax and accounting mandates
•
Screening for sanctions and the prevention of fraud
•
Responding appropriately to legally binding requests emanating from competent governmental or regulatory authorities.
4.4.
Legitimate Interests (Article 6(1)(f) of the GDPR)
•
Maintenance of network security and the mitigation of abuse
•
Enhancement of service offerings and internal analytics
•
Protecting the integrity and operational stability of the infrastructure
•
Preclusion of unauthorized access or service misuse.
4.5.
Consent (Article 6(1)(a) of the GDPR)
•
Non-essential cookies
•
Marketing communications (where applicable and appropriate).
5.
Limitations on Access
5.1.
Given the Provider’s role as an unmanaged infrastructure service provider, the Provider shall not access, inspect, or otherwise interact with the following categories of data:
a)
Data stored by the Customer on Virtual Private Servers (VPS) or dedicated physical servers
b)
Customer-deployed applications, databases, or electronic files
c)
Content subject to cryptographic encryption or private cryptographic keys.
5.2.
Notwithstanding the foregoing, system metadata may be accessed solely where such access is strictly necessary to effectuate the following purposes:
a)
Mitigate active security threats
b)
Ensure compliance with applicable legal obligations
c)
Investigate verified reports of network abuse.
5.3.
Notwithstanding the restrictions in 5.1, the Provider may access Customer data on an exceptional basis solely at the explicit, verifiable request and instruction of the Customer for the purpose of technical support, maintenance, or service restoration. Any such access constitutes processing undertaken on behalf of the Customer and is strictly governed by the terms of the Data Processing Addendum (DPA).
•
Comprehensive policies governing abuse handling are documented herein: Network & Abuse Policy.
6.
Subprocessors
6.1.
The Provider may engage the services of subprocessors to facilitate the provision of services, including, but not limited to, the following types of entities:
a)
Upstream infrastructure vendors
b)
Payment processing entities
c)
Electronic mail delivery services
d)
Vendors specializing in security and system monitoring.
6.2.
Each subprocessor is contractually obligated to adhere to standards and duties consistent with the GDPR.
6.3.
A complete register of all utilized subprocessors is formally maintained within the DPA. Reference the following for all subprocessor details: Data Processing Addendum.
7.
Data Transfers
7.1.
In circumstances necessitating the transfer of Personal Data outside the territory of the European Union (EU) or European Economic Area (EEA), the Provider shall rely upon the following legally recognized transfer mechanisms:
a)
Adequacy decisions promulgated by the European Commission
b)
Standard Contractual Clauses (SCCs)
c)
The implementation of requisite supplementary technical and organizational safeguards.
8.
Data Retention
8.1.
Personal Data shall be retained exclusively for the duration requisite to fulfill the specific purposes enumerated within this Policy.
8.2.
Precise retention durations applicable to each discrete category of data are explicitly defined within the standalone Data Retention Policy.
•
All rules governing retention are accessible herein: Data Retention Policy.
9.
Data Subject Rights
9.1.
Pursuant to the provisions of the GDPR, data subjects possess the ensuing legal rights:
•
The Right of Access (Article 15)
•
The Right to Rectification (Article 16)
•
The Right to Erasure ("Right to be Forgotten") (Article 17)
•
The Right to Restriction of Processing (Article 18)
•
The Right to Data Portability (Article 20)
•
The Right to Object to Processing (Article 21)
•
The Right to withdraw consent at any juncture without detriment.
9.2.
To formally exercise any of the aforementioned rights, kindly submit a written request via electronic mail to: privacy@rubyvoid.com.
10.
Cookies
10.1.
We deploy strictly essential cookies for the necessary functioning of the service, including the following objectives:
a)
User authentication
b)
Management of session state
c)
Security protocols.
10.2.
Non-essential cookies, such as those utilized for analytics or marketing purposes, shall be deployed exclusively upon receipt of the data subject's explicit, unambiguous consent.
10.3.
The management of cookie preferences may be executed by the data subject either through their respective web browser settings or via the interface of the dedicated cookie consent banner.
11.
Technical and Organizational Security Measures
11.1.
The Provider maintains and implements appropriate and robust technical and organizational security measures, which include, but are not limited to:
a)
Encryption applied to data both in transit and at rest (where contextually appropriate)
b)
Strict access control mechanisms and multi-factor authentication protocols
c)
Network segmentation architecture and protective firewalls
d)
Intrusion detection systems and continuous abuse monitoring
e)
Execution of routine security audits and comprehensive vulnerability assessments.
•
All detailed system-level security mandates are delineated herein: System Policies.
12.
Disclosure
12.1.
The Provider reserves the right and duty to disclose Personal Data when legally compelled to do so, including, but not limited to, disclosures required by:
a)
Judicial court orders
b)
Requests formally issued by law enforcement agencies
c)
Mandates arising from regulatory compliance obligations
d)
Investigations concerning fraudulent activities.
12.2.
Prior to any disclosure, all requests shall undergo rigorous review to ascertain legality, proportionality, and strict adherence to the requirements of the GDPR.
13.
Data Pertaining to Minors
13.1.
Our services are not intended or directed toward individuals who have not attained the age of eighteen (18) years.
13.2.
We do not knowingly solicit or collect Personal Data from minors.
14.
Changes
14.1.
The Provider reserves the right to amend or update these Policies periodically.
14.2.
Continued utilization of the Provider's services subsequent to any such amendment shall constitute the Customer's acceptance of the updated Policies.



