Privacy Policy
Intrvll Cloud Technologies GmbH ("Intrvll", "we", "us", or "our"), Unter den Linden 1, 10117 Berlin, Germany, operates the website intrvll.cloud and associated cloud services. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website or use our services, in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable national law.
1. Controller
- Company
- Intrvll Cloud Technologies GmbH
- Address
- Unter den Linden 1, 10117 Berlin, Germany
- Legal e-mail
- legal@intrvll.cloud
- Data Protection Officer
- dpo@intrvll.cloud
2. Data we collect
2.1 Automatically collected data
When you visit our website, our servers automatically record certain information:
- IP address (anonymised after 24 hours)
- Browser type and version
- Operating system
- Referrer URL
- Date and time of access
- Pages visited and time spent
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) — security, fraud prevention, and service optimisation.
2.2 Account and billing data
When you create an account or purchase services, we collect your name, e-mail address, billing address, and payment information (processed exclusively by our PCI-DSS compliant payment processor; we do not store card numbers). Legal basis: Performance of contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
2.3 Support communications
If you contact support, we process message content, metadata, and any attachments you provide. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) — customer service.
2.4 Cookies
We use cookies and similar technologies. See our Cookie Policy for details. Consent-based cookies are activated only after you provide consent (Art. 6(1)(a) GDPR).
3. How we use your data
- Providing and operating our cloud services
- Processing payments and issuing invoices
- Sending transactional e-mails (service alerts, receipts)
- Responding to support requests
- Preventing fraud, abuse, and security incidents
- Complying with legal obligations (e.g., tax records)
- Improving and developing our services (aggregated/anonymised analytics)
- Marketing communications (only with your explicit consent)
4. Data sharing & third parties
We do not sell your personal data. We share data only where necessary:
- Payment processors (Stripe Inc., Braintree) — to process payments
- Infrastructure vendors — hardware manufacturers under strict NDAs; no personal data sharing
- Legal obligations — if required by law, court order, or regulatory authority
- Business transfers — in the event of a merger or acquisition, subject to equivalent protections
All processors are bound by Data Processing Agreements (DPAs) compliant with Art. 28 GDPR.
5. International transfers
Your personal data is stored exclusively within the European Economic Area (EEA). For any transfer outside the EEA (e.g., via Stripe), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data retention
- Account data: retained for the duration of the contract + 6 years (legal retention)
- Server logs: 30 days, then deleted
- Support tickets: 3 years from resolution
- Billing records: 10 years (German tax law § 147 AO)
- Marketing consent: until withdrawn
7. Your rights
Under the GDPR, you have the following rights:
- Access (Art. 15): Request a copy of the data we hold about you
- Rectification (Art. 16): Correct inaccurate data
- Erasure (Art. 17): Request deletion ("right to be forgotten")
- Restriction (Art. 18): Limit how we process your data
- Portability (Art. 20): Receive your data in a machine-readable format
- Objection (Art. 21): Object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)): At any time for consent-based processing
To exercise any right, contact dpo@intrvll.cloud. We will respond within 30 days. You also have the right to lodge a complaint with the supervisory authority — in Germany, the Berliner Beauftragte für Datenschutz und Informationsfreiheit (www.datenschutz-berlin.de).
8. Security
We implement appropriate technical and organisational measures to protect your data, including TLS 1.3 encryption, AES-256 encryption at rest, strict access controls, penetration testing, and ISO 27001-certified processes.
9. Changes to this policy
We may update this policy periodically. Material changes will be communicated via e-mail or a prominent notice on our website at least 14 days before they take effect. Continued use of our services after the effective date constitutes acceptance.
10. Contact
- Privacy enquiries
- dpo@intrvll.cloud
- Postal address
- Intrvll Cloud Technologies GmbH, Unter den Linden 1, 10117 Berlin, Germany