Privacy Policy
Last updated: July 30, 2026
This Privacy Policy explains how RottenCloud LLC (“RottenCloud”, “we”, “us”), a Florida limited liability company at 11620 NW 1st Avenue, Miami, FL 33168, United States, collects, uses, stores and protects personal data.
It covers our website rottencloud.com, our client dashboard and the software and hosting we operate for clients. We never sell personal data.
1. Data we collect
- Enquiry data. Name, email address, company, website and the content of the message you send us through the contact form or by email.
- Account data. Domain name, contact details, plan, dashboard credentials (passwords are stored hashed) and support history.
- Billing data. Billing name, address, tax identifiers, invoices and payment status. Card details are handled directly by our payment processor and are never stored on our servers.
- Technical data. Server logs including IP address, user agent, requested URL and timestamp, retained for security and troubleshooting.
- Client data. Content, files and end-user data that you or your users place into the software we host for you. For this data you are the controller and we act as your processor.
2. Why we use it
- To reply to your enquiry and prepare a scope and quote.
- To provide, host, back up, monitor and support the services.
- To invoice you and collect payment.
- To secure our infrastructure, detect abuse and comply with legal obligations.
- To send operational notices about your subscription, maintenance windows and incidents.
Our legal bases, where the GDPR applies, are performance of a contract, our legitimate interests in operating and securing the services, and compliance with legal obligations.
3. Where your data is stored
We host on dedicated servers we operate in Miami (United States), Frankfurt (Germany) and Singapore. Where you need your data to stay in a particular region, tell us at scoping and we will provision it there. Backups are encrypted and stored in the same region as the primary server unless agreed otherwise.
Transfers of personal data out of the European Economic Area are made under Standard Contractual Clauses or an equivalent lawful transfer mechanism.
4. Sharing
We do not sell, rent or trade personal data. We share it only with:
- Payment processors, for the sole purpose of billing and fraud prevention.
- Domain registrars and certificate authorities, where needed to register or secure your domain.
- Data-centre and connectivity providers that host our machines.
- Cloudflare, which serves this website and runs the Turnstile bot check on our contact form. Turnstile receives your IP address and basic request signals for that check only.
- Our own internal messaging system, which is where contact-form submissions are delivered to the team.
- Professional advisers, or authorities where required by law or valid legal process.
5. Retention
- Enquiry data: up to 24 months from the last contact.
- Account and billing records: 7 years, for tax and accounting.
- Server logs: 90 days.
- Client data and backups: for the life of your subscription, then 30 days after termination before permanent deletion.
6. Security
We use TLS in transit, encrypted backups, hardened server configurations, least-privilege access and audit logging. Access to client environments is limited to the RottenCloud engineers working on your project. No system is perfectly secure, but we treat client data as if it were our own.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict processing of your personal data, to object to processing, and to lodge a complaint with a supervisory authority. California residents have the right to know, delete and opt out of “sale” or “sharing” of personal information — we do neither.
To exercise any right, email [email protected]. We respond within 30 days. Where we process data on behalf of a client, we will forward your request to that client.
8. Cookies
rottencloud.com uses only what is strictly necessary to serve the page and to keep bots off the contact form. There are no analytics or advertising cookies and no consent banner. The client dashboard uses a first-party session cookie to keep you signed in. See our Cookie Policy for details.
9. Children
Our services are directed at businesses and are not intended for children under 16. We do not knowingly collect their personal data.
10. Changes
We may update this policy. The “last updated” date at the top always reflects the current version, and material changes are communicated by email or through the dashboard.
11. Contact
RottenCloud LLC, 11620 NW 1st Avenue, Miami, FL 33168, United States · [email protected]