Privacy & Cookie Policy
This policy explains what personal data BitQate collects, why, and the rights you have over it under the UK/EU General Data Protection Regulation (GDPR).
1. Data Controller
BitQate (“we”, “us”, “our”) is the data controller responsible for your personal data. You can reach us for all privacy-related matters at:
- •Email: privacy@bitqate.com
- •Support portal: portal.bitqate.com/tickets
We have not appointed a Data Protection Officer as we are not required to do so under applicable law. Enquiries can be sent to the contact above.
2. Data We Collect
We collect the following categories of personal data depending on how you interact with us:
- Account data
- Email address, hashed password, display name, and account preferences when you register.
- Billing data
- Credit balance, transaction history, invoices, and payment method metadata (e.g. card last 4 digits) returned by Polar, our payment processor. We do not store raw card numbers.
- Service data
- Virtual machine configurations, Server logs, resource usage metrics, and IP addresses allocated to your services.
- Technical data
- Your IP address, browser type and version, operating system, referring URL, and pages visited. Collected automatically when you access our website or portal.
- Security data
- Authentication logs, recognized login IP addresses and locations, two-factor authentication setup, passkey (WebAuthn) credentials, and session identifiers. We store a history of IP addresses from which you have successfully logged in to detect and prevent unauthorized access attempts.
- Communications
- Support tickets and any messages you send to us.
3. Legal Basis for Processing
Under the UK/EU GDPR, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing hosting and portal services | Contract performance (Art. 6(1)(b)) |
| Account registration and authentication | Contract performance (Art. 6(1)(b)) |
| Processing payments and issuing invoices | Contract performance (Art. 6(1)(b)) |
| Sending transactional emails (security alerts, billing notices) | Contract performance (Art. 6(1)(b)) |
| Detecting and preventing fraud, abuse, and security threats | Legitimate interests (Art. 6(1)(f)) |
| Automated CSAM detection on cached images (via Cloudflare) | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
| Improving our services using aggregated usage data | Legitimate interests (Art. 6(1)(f)) |
| Complying with legal and tax obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, you have the right to object. We have balanced our interests against yours and consider the processing necessary and proportionate. See Section 8 for how to object.
5. Data Processors & Third Parties
We engage the following third-party processors who handle personal data on our behalf under data processing agreements:
- Cloudflare
- Hosts our website and dashboard web interface only. May process technical data (IP address, request metadata). Also operates an automated CSAM Scanning Tool that hashes cached images and compares them against databases of known child sexual abuse material; if a match is found, the affected URL is blocked and we are notified. Privacy policy: cloudflare.com/privacypolicy.
- Polar
- Handles payment card data, checkout, and billing on our behalf. We receive only tokenised metadata (card brand, last 4 digits, expiry). We never store raw card numbers. Privacy policy: polar.sh/legal/privacy.
We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.
6. International Transfers
Our infrastructure and processors may be located outside the European Economic Area (EEA) or UK. Where we transfer personal data internationally, we ensure adequate protections are in place through one or more of:
- •An adequacy decision by the UK Secretary of State or European Commission.
- •Standard Contractual Clauses (SCCs) approved by the relevant authority.
- •Another appropriate safeguard under applicable data protection law.
You may request a copy of the relevant safeguard by contacting privacy@bitqate.com.
7. Data Retention
We retain personal data only as long as necessary for the purpose it was collected or as required by law:
- Account data
- Retained while your account is active. If you request deletion, we delete your personal data within 30 days of a verified request (see Section 8), except where we must retain certain records for longer to meet a legal obligation.
- Billing records
- Retained for 7 years to comply with tax and accounting obligations.
- Server and access logs
- Retained for as long as necessary for security and abuse investigations, targeted at around 90 days, after which they are deleted or anonymised.
- Support communications
- Retained for as long as necessary to maintain service continuity and resolve recurring issues, typically around 3 years.
- Recognized login IPs
- Retained indefinitely to provide ongoing protection against unauthorized access. You can view and revoke individual trusted IPs or clear all recognized locations at any time. All recognized IPs are deleted when you delete your account.
Where a retention period above is a target rather than an automatic deletion, you can always request deletion sooner under your erasure right in Section 8.
8. Your Rights
Under the UK/EU GDPR you have the following rights. We will respond to verified requests within 30 days (extendable by a further 2 months in complex cases with notice).
- Access (Art. 15)
- Request a copy of the personal data we hold about you.
- Rectification (Art. 16)
- Request correction of inaccurate or incomplete data.
- Erasure (Art. 17)
- Request deletion of your personal data where no overriding legal ground applies.
- Restriction (Art. 18)
- Request we restrict processing while a dispute is resolved.
- Portability (Art. 20)
- Receive your data in a structured, machine-readable format and have it transferred to another controller.
- Objection (Art. 21)
- Object to processing based on legitimate interests. We will cease unless we demonstrate compelling legitimate grounds.
- Lodge a complaint (Art. 77)
- You have the right to lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In Ireland: dataprotection.ie. In Germany: the relevant Landesbeauftragter für den Datenschutz.
To exercise any right, email privacy@bitqate.com with your account email and the right you wish to exercise. We may ask for verification before processing your request.
9. Automated Decision-Making
We do not use fully automated decision-making (including profiling) that produces legal or similarly significant effects on you within the meaning of Article 22 GDPR. Abuse detection heuristics may flag accounts for human review but no automated action is taken without manual oversight.
10. Security
We implement technical and organisational measures to protect your personal data, including:
- •Passwords stored using a one-way cryptographic hash.
- •Transport Layer Security (TLS/HTTPS) for all data in transit.
- •Access controls limiting which team members can access user data.
- •Audit logging for administrative actions.
No method of transmission over the internet or electronic storage is completely secure. In the event of a personal data breach likely to result in a high risk to your rights, we will notify you without undue delay as required by Art. 34 GDPR.
11. Changes to This Policy
We may update this policy to reflect changes in our practices or applicable law. Where the changes are material, we will notify registered users by email at least 14 days before the new policy takes effect. The “Last updated” date at the top of this page always reflects the most recent revision.
12. Contact
For any questions about this policy or to exercise your rights:
- •Email: privacy@bitqate.com
- •Support tickets: portal.bitqate.com/tickets
- •X (Twitter): @bitqate
- •GitHub: github.com/BitQate
Last updated July 24, 2026 — BitQate