Last updated July 24, 2026

Privacy & Cookie Policy

This policy explains what personal data BitQate collects, why, and the rights you have over it under the UK/EU General Data Protection Regulation (GDPR).

1. Data Controller

BitQate (“we”, “us”, “our”) is the data controller responsible for your personal data. You can reach us for all privacy-related matters at:

  • Email: privacy@bitqate.com
  • Support portal: portal.bitqate.com/tickets

We have not appointed a Data Protection Officer as we are not required to do so under applicable law. Enquiries can be sent to the contact above.

2. Data We Collect

We collect the following categories of personal data depending on how you interact with us:

Account data
Email address, hashed password, display name, and account preferences when you register.
Billing data
Credit balance, transaction history, invoices, and payment method metadata (e.g. card last 4 digits) returned by Polar, our payment processor. We do not store raw card numbers.
Service data
Virtual machine configurations, Server logs, resource usage metrics, and IP addresses allocated to your services.
Technical data
Your IP address, browser type and version, operating system, referring URL, and pages visited. Collected automatically when you access our website or portal.
Security data
Authentication logs, recognized login IP addresses and locations, two-factor authentication setup, passkey (WebAuthn) credentials, and session identifiers. We store a history of IP addresses from which you have successfully logged in to detect and prevent unauthorized access attempts.
Communications
Support tickets and any messages you send to us.

4. Cookies

We only use strictly necessary cookies required for the site and portal to function, such as session management. We do not use cookies for analytics, advertising, or tracking, and we do not show a cookie consent banner because we do not set any non-essential cookies.

5. Data Processors & Third Parties

We engage the following third-party processors who handle personal data on our behalf under data processing agreements:

Cloudflare
Hosts our website and dashboard web interface only. May process technical data (IP address, request metadata). Also operates an automated CSAM Scanning Tool that hashes cached images and compares them against databases of known child sexual abuse material; if a match is found, the affected URL is blocked and we are notified. Privacy policy: cloudflare.com/privacypolicy.
Polar
Handles payment card data, checkout, and billing on our behalf. We receive only tokenised metadata (card brand, last 4 digits, expiry). We never store raw card numbers. Privacy policy: polar.sh/legal/privacy.

We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.

6. International Transfers

Our infrastructure and processors may be located outside the European Economic Area (EEA) or UK. Where we transfer personal data internationally, we ensure adequate protections are in place through one or more of:

  • An adequacy decision by the UK Secretary of State or European Commission.
  • Standard Contractual Clauses (SCCs) approved by the relevant authority.
  • Another appropriate safeguard under applicable data protection law.

You may request a copy of the relevant safeguard by contacting privacy@bitqate.com.

7. Data Retention

We retain personal data only as long as necessary for the purpose it was collected or as required by law:

Account data
Retained while your account is active. If you request deletion, we delete your personal data within 30 days of a verified request (see Section 8), except where we must retain certain records for longer to meet a legal obligation.
Billing records
Retained for 7 years to comply with tax and accounting obligations.
Server and access logs
Retained for as long as necessary for security and abuse investigations, targeted at around 90 days, after which they are deleted or anonymised.
Support communications
Retained for as long as necessary to maintain service continuity and resolve recurring issues, typically around 3 years.
Recognized login IPs
Retained indefinitely to provide ongoing protection against unauthorized access. You can view and revoke individual trusted IPs or clear all recognized locations at any time. All recognized IPs are deleted when you delete your account.

Where a retention period above is a target rather than an automatic deletion, you can always request deletion sooner under your erasure right in Section 8.

8. Your Rights

Under the UK/EU GDPR you have the following rights. We will respond to verified requests within 30 days (extendable by a further 2 months in complex cases with notice).

Access (Art. 15)
Request a copy of the personal data we hold about you.
Rectification (Art. 16)
Request correction of inaccurate or incomplete data.
Erasure (Art. 17)
Request deletion of your personal data where no overriding legal ground applies.
Restriction (Art. 18)
Request we restrict processing while a dispute is resolved.
Portability (Art. 20)
Receive your data in a structured, machine-readable format and have it transferred to another controller.
Objection (Art. 21)
Object to processing based on legitimate interests. We will cease unless we demonstrate compelling legitimate grounds.
Lodge a complaint (Art. 77)
You have the right to lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In Ireland: dataprotection.ie. In Germany: the relevant Landesbeauftragter für den Datenschutz.

To exercise any right, email privacy@bitqate.com with your account email and the right you wish to exercise. We may ask for verification before processing your request.

9. Automated Decision-Making

We do not use fully automated decision-making (including profiling) that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. Abuse detection heuristics may flag accounts for human review but no automated action is taken without manual oversight.

10. Security

We implement technical and organisational measures to protect your personal data, including:

  • Passwords stored using a one-way cryptographic hash.
  • Transport Layer Security (TLS/HTTPS) for all data in transit.
  • Access controls limiting which team members can access user data.
  • Audit logging for administrative actions.

No method of transmission over the internet or electronic storage is completely secure. In the event of a personal data breach likely to result in a high risk to your rights, we will notify you without undue delay as required by Art. 34 GDPR.

11. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. Where the changes are material, we will notify registered users by email at least 14 days before the new policy takes effect. The “Last updated” date at the top of this page always reflects the most recent revision.

12. Contact

For any questions about this policy or to exercise your rights:

Last updated July 24, 2026 — BitQate