This policy describes what data we collect when you use TurtleGuard, how we process and store it, and who it can be shared with. Using the service means you accept this policy.
1. What we collect
Account data
- name, email, a contact channel (Telegram or phone, if you give one);
- credentials (a password hash, two-factor secrets);
- billing details needed to issue invoices.
Domain and DNS data
- domain names, DNS records, the addresses of your own servers;
- SSL/TLS certificates and keys, when you upload them yourself.
Network data and logs
- request metadata seen at the edge (source address, user agent, URI, method, status, response size);
- inspection incidents and the rules that fired;
- attack metrics and aggregates by network and country.
2. Why we process it
- to provide protection, CDN and DNS;
- for analytics and to investigate security incidents;
- for billing, support and communication with the Customer;
- to meet obligations under applicable law.
3. How long we keep it
- Request logs — from 7 to 90 days depending on the plan.
- Inspection incidents — up to 12 months.
- Billing documents — for as long as the law requires.
- The account — until the Customer deletes it, plus 30 days of technical reserve.
4. Sharing with third parties
We do not sell personal data. It may only be passed to:
- payment providers, to take payments;
- certificate authorities (Let's Encrypt and others), to issue certificates;
- public authorities, where applicable law requires it.
5. Storage and security
Data is stored encrypted on servers in the EU. Access is limited to verified TurtleGuard engineers. Passwords are kept as Argon2 hashes; two-factor secrets are encrypted with AES-256.
6. Cookies
The site uses strictly necessary cookies for the session and for CSRF protection. Analytics cookies are only set with explicit consent. Details will be in the banner shown on a first visit, which is added before the public launch.
7. Your rights
The Customer may:
- ask for a copy of their data;
- ask for it to be corrected or deleted;
- withdraw consent to processing.
Send requests to privacy@turtleguard.cloud. We answer within 30 days.
8. Data protection contact
For anything about personal data, write to dpo@turtleguard.cloud.
This document is a working draft. Before a public launch it must be aligned with the GDPR and/or Russian federal law 152-FZ, depending on the jurisdiction, and reviewed by a lawyer.