Privacy Policy
Last updated: 1 August 2026
Techiox LTD ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the OpenZapps platform ("Platform"). It applies to all users, regardless of location, and has been prepared with UK and EU data protection law (UK GDPR, EU GDPR) in mind.
1. Who We Are
Data controller: Techiox LTD, a company registered in England and Wales.
United Kingdom | Contact: support@openzapps.com
If you have questions about this Privacy Policy or how we handle your data, please contact our Data Protection Officer at the email address above.
2. What Data We Collect
We collect the following categories of personal data:
2.1 Account Information
When you register, we collect: email address, name (optional), and a password (stored as a salted hash — we never store your plaintext password). If you sign up via OAuth (e.g., GitHub), we receive basic profile information from the provider.
2.2 Billing Information
Payment processing is handled by our payment processor. We do NOT store your full payment card details on our servers. We receive and retain: billing address (if provided), payment confirmation tokens, subscription status, and transaction history. Their handling of your data is governed by their Privacy Policy.
2.3 Server & Usage Data
We collect technical data related to your VPS and Platform usage, including: server identifiers, IP addresses (for network routing and security logging), deployed application logs (aggregated, not content), resource usage metrics (CPU, RAM, storage), and error reports. This data is necessary for provisioning, maintenance, and troubleshooting.
2.4 AI Gateway Usage Data
If you use the AI Gateway, we collect: credit balance, model usage statistics (tokens consumed, models accessed), API key metadata (creation date, rate limits, not the raw keys), and aggregated usage patterns. We do not retain the content of prompts or responses beyond what is necessary for billing and abuse detection, typically 30 days.
2.5 Communication Data
If you contact support, we retain your messages, email correspondence, and any attachments to resolve your inquiry and improve our services.
2.6 Automatically Collected Data
We use third-party services for DNS, DDoS protection, and CDN. These services may process IP addresses and other connection metadata. See their Privacy Policy.
3. How We Use Your Data & Legal Basis
| Purpose | Legal Basis |
|---|---|
| To provide and maintain the Platform (account creation, VPS provisioning, app deployment) | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| To process payments and manage subscriptions | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| To monitor and maintain server health, prevent abuse, and ensure security | Legitimate interests (Art. 6(1)(f) UK GDPR) |
| To provide AI Gateway services and enforce usage limits | Performance of a contract (Art. 6(1)(b) UK GDPR) |
| To communicate with you about your account, service updates, or security incidents | Performance of a contract / Legitimate interests |
| To comply with legal obligations (e.g., tax, fraud prevention, law enforcement requests) | Legal obligation (Art. 6(1)(c) UK GDPR) |
| To analyse aggregated usage patterns and improve the Platform | Legitimate interests (Art. 6(1)(f) UK GDPR) |
4. Data We Do NOT Collect
We do not collect:
- The content of your deployed applications, databases, or files stored on your VPS
- The content of AI Gateway prompts or responses (beyond metadata for billing)
- Your payment card numbers (handled entirely by our payment processor)
- Precise geolocation data
- Biometric data
However, any data you choose to store on your VPS (including personal data of your own users or customers) is under your control and responsibility. You are the data controller for that data; we are a data processor only to the extent we host the infrastructure.
5. Who We Share Data With
We only share your personal data with third parties where necessary to provide the Platform or comply with legal obligations:
- Our payment processor — Payment processing. Data shared: billing contact details, transaction metadata. Location: USA (adequacy decision in place).
- Our DNS, CDN, and security providers — DNS, CDN, DDoS protection, and security. Data shared: IP addresses, connection metadata. Location: USA (adequacy decision in place).
- Our VPS infrastructure providers — Server provisioning and hosting. Data shared: server identifiers, provisioning metadata. Location: Germany / USA.
- Legal and regulatory authorities: We may disclose data if required by law, court order, or to protect our rights, property, or safety.
We do not sell your personal data to third parties. We do not share your data for marketing purposes without your explicit consent.
6. International Data Transfers
Some of our third-party providers process data outside the UK and EEA (e.g., providers in the USA). Where we transfer data internationally, we ensure appropriate safeguards are in place, such as:
- UK/EU adequacy decisions (e.g., USA under the UK Extension to the EU-US Data Privacy Framework)
- Standard Contractual Clauses (SCCs) approved by the UK ICO
- Contractual commitments from processors to maintain UK GDPR-equivalent protection
7. Data Retention
We retain your personal data only for as long as necessary for the purposes outlined above:
- Account data: Retained while your account is active. Deleted within 30 days of account termination, unless legal obligations require longer retention (e.g., tax records: 6 years under UK law).
- Billing records: Retained for 6 years to comply with UK tax and accounting obligations.
- Server logs: Retained for 90 days for security and troubleshooting, then automatically purged.
- AI Gateway logs: Retained for 30 days for billing verification and abuse detection.
- Support communications: Retained for 2 years to assist with ongoing or follow-up support requests.
8. Your Rights Under UK GDPR
You have the following rights regarding your personal data:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your data, subject to legal retention requirements.
- Right to restrict processing: Request that we limit how we use your data in certain circumstances.
- Right to data portability: Request your data in a structured, commonly used format.
- Right to object: Object to processing based on legitimate interests. We will comply unless we have compelling legitimate grounds.
- Right to withdraw consent: Where we rely on consent, you may withdraw it at any time.
- Right to lodge a complaint: You have the right to complain to the UK Information Commissioner's Office (ICO) if you believe we have mishandled your data.
To exercise any of these rights, contact us at support@openzapps.com. We will respond within one month, or notify you if we need an extension.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
- All data in transit is encrypted using TLS 1.2 or higher
- Passwords are stored using bcrypt hashing with salt
- Databases are hosted on secured servers with access restricted to authorised personnel
- Regular security assessments and dependency updates
- API keys and secrets are encrypted at rest
Despite these measures, no internet-based service can guarantee absolute security. You are responsible for keeping your account password and API keys confidential.
10. Cookies & Tracking
We use only essential cookies necessary for the Platform to function:
- Session cookies: To maintain your login state and authenticate requests.
- CSRF tokens: To protect against cross-site request forgery attacks.
We do not use third-party analytics cookies, advertising cookies, or tracking pixels. Our security and CDN services may set cookies for security and performance purposes; see their privacy policy for details.
11. Children's Privacy
The Platform is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately and we will delete it.
12. Data Controller vs Processor & Article 28 DPA
For Platform services: Techiox LTD is the data controller of your account data, billing data, and Platform usage data.
For data on your VPS: You are the data controller of any data you deploy, store, or process on your VPS (including personal data of your own users). Techiox LTD acts as a data processor solely for the purpose of hosting the infrastructure, and only to the extent required to provide the VPS service.
If you process personal data on your VPS, you must ensure your own compliance with applicable data protection law, including having a lawful basis, providing privacy notices to your users, and implementing appropriate security measures. We do not monitor or police the content of your VPS.
Data Processing Agreement (UK GDPR Article 28)
When we act as your data processor for data on your VPS, the following terms apply pursuant to UK GDPR Article 28:
- Processing only on instructions: We process personal data only on your documented instructions, except where required by applicable law.
- Subject matter and duration: The subject matter is hosting your VPS and making it available via the Platform. Processing continues for the duration of your subscription plus any retention period required by law.
- Nature and purpose: Hosting, network routing, security monitoring, and maintenance of the virtual server infrastructure.
- Types of data and categories: The types of personal data and categories of data subjects are determined solely by you and depend on the applications you deploy and how you use them.
- Sub-processors: We engage sub-processors (listed in Section 5 above). We will notify you of any new sub-processors at least 30 days before they are engaged. You may object to a new sub-processor on reasonable grounds by notifying us within that 30-day window. If we cannot provide an alternative sub-processor acceptable to both parties, you may terminate your subscription with a pro-rata refund.
- Confidentiality: Our personnel are bound by confidentiality obligations regarding personal data they may encounter.
- Security: We implement appropriate technical and organisational security measures as described in Section 9 above.
- Assisting with data subject rights: We will use reasonable efforts to assist you in responding to data subject requests related to data on your VPS, provided your request gives us sufficient information to locate the relevant data.
- Breach notification: We will notify you without undue delay — and in any event within 24 hours of becoming aware — of any personal data breach that affects your data on our systems. We will provide you with details reasonably necessary to comply with your own ICO notification obligations.
- Return or deletion: Upon termination, we will delete or return your data in accordance with your instructions (unless retention is required by law). See our Terms of Service for details on post-termination data handling.
- Audit: You may request an audit of our compliance with this DPA once per calendar year by providing 30 days' written notice. We may provide a recognised third-party security attestation report as an alternative to an on-site audit.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified by email or through the Platform at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact Us
For privacy-related questions, data subject requests, or to contact our Data Protection Officer:
Email: support@openzapps.com
Techiox LTD — England and Wales