Privacy notice
Who we are
The service is operated by 9000 AB, Sweden, which is the data controller for the personal data below. Questions and requests go to support@hyperspool.com.
What we hold
- Your account. Email address, display name, and the identifier your sign-in provider gives us: our own identity service today, and an external provider such as GitHub if and when that sign-in is offered. Sign-in sessions and any personal access tokens you mint.
- What your org produces. Workflow definitions, runs, their logs and artifacts, events, schedules, and the members of the org. Logs contain whatever your jobs print, so they may contain personal data you put there.
- Secrets and credentials you store for your workflows. They are encrypted at rest, the console and support tooling never show them, and they are opened only to hand them to your own jobs. The people who operate the cluster could technically reach them and do not.
- Billing. Your plan and usage. Payment details are held by Polar, the merchant of record; we never see a card number.
- Technical. Request logs at our edge with IP address, path and user agent, and server logs with user and org identifiers.
- What you tell us. Feedback sent from the console or the CLI, with your email, the org and project you were in, and the page you were on.
Why
To run the service you signed up for (performance of a contract), to keep it secure and abuse-free and to bill for it (our legitimate interests, and legal obligations for accounting), and to answer you when you write to us. We do not sell or share personal data for advertising, and there is no third-party analytics on the console.
Where, and who else
The service runs on servers rented from Hetzner in the European Union. Backups and transactional email go through Scaleway (France). Payments go through Polar. DNS for our domains is served by Cloudflare. The console and this site load their typeface from Google Fonts, so Google receives the request for the font files, including your IP address; that is the one transfer outside the EU and the EEA we make ourselves. If you connect a GitHub or other forge account, that provider processes what you authorise.
For how long
- Runs, logs and artifacts: the retention window of your org's plan, shown on its usage page; older ones are pruned automatically.
- Edge request logs: thirty days.
- Account data and memberships: until you delete your account or leave the org.
- Backups: a rolling thirty days, after which deleted data is gone from them too.
- Billing records: as long as accounting law requires.
Your rights
You can ask for a copy of your personal data, have it corrected or deleted, object to processing based on our legitimate interests, and take it with you. Deleting an org removes its runs, logs, artifacts and secrets; ask support and it is done. We answer within a month. You may also complain to the Swedish Authority for Privacy Protection (IMY) or the supervisory authority where you live.
Cookies
The console sets a session cookie, plus two short-lived ones that exist only while a sign-in or an account connection is in flight; the sign-in service sets its own session cookie. There are no tracking cookies.
Changes
When this notice changes materially we tell you by email before it applies. The date at the top says when it last did.