1Who is responsible
Deplium, established in the Netherlands, is the controller for the personal data described in this policy, except where the Data processing agreement makes Deplium a processor acting on a customer's instructions. You can reach us at privacy@deplium.com.
2What we collect
Account data: name, work email address, company, password hash, role in a workspace, sign-in times and IP addresses.
Billing data: billing email, legal name, VAT number, the currency and package you chose, statements and payment status. Card details are entered on our payment processor's pages and never reach Deplium.
Provider usage metadata: line items, quantities, regions and tags from the Providers we pay for. This describes your infrastructure spend, not the content of your applications.
Website data: quote and contact requests you send us, and aggregated, cookieless analytics about page views and performance. We do not build individual browsing profiles.
Support data: messages you exchange with the Desk.
3Why we use it and on what basis
To provide the Service, including creating your workspace, paying Providers, issuing statements and answering the Desk: performance of a contract.
To keep accounts secure, prevent fraud and abuse, and keep audit records: our legitimate interest in running a reliable, lawful service.
To invoice you and keep accounting records: legal obligations under Dutch tax law.
To answer quote and contact requests and to tell you about material changes to the Service or these documents: legitimate interest and, where required, your consent, which you can withdraw at any time.
We do not sell personal data and do not use it for advertising.
5International transfers
Several sub-processors are established in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU-US Data Privacy Framework. Copies of the relevant safeguards are available on request.
6How long we keep it
Account data: while the workspace exists and for 12 months after it closes. Billing records and statements: 7 years, as Dutch tax law requires. Provider usage metadata: 24 months rolling, then aggregated. Quote and contact requests: 12 months, or 30 days after a quote if you do not become a customer and ask us to delete them. Security and audit logs: 24 months. Desk correspondence: for the life of the workspace plus 12 months.
7Your rights
You can ask for access to, correction of, deletion of or a copy of your personal data, object to processing based on legitimate interest, and withdraw consent where processing is based on it. Write to privacy@deplium.com; we answer within one month. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority in your own country.
8Security
Passwords are hashed with a modern algorithm, sessions are short-lived and revocable, access to production systems is limited to named staff with multi-factor authentication, and every staff action affecting a customer is written to an audit log. Trust and security details are on the trust page.
9Changes and contact
We update this policy when our processing changes and announce material changes by email to workspace owners. The current version and effective date are shown at the top of this page. Questions: privacy@deplium.com.
Questions about this document: legal@deplium.com. Previous versions are available on request.