Privacy
A plain-language summary of how CustomerNode handles personal data. For the formal legal documents, use the links below. For a per-tenant data agreement, see the Data Processing Addendum.
Privacy Policy
The formal privacy policy — what we collect, how we use it, your rights.
Read →Data Processing Addendum
Controller/processor terms for customer data, including GDPR provisions.
Read →Data deletion & subject requests
Submit a deletion request or other data subject request.
Submit requestWhat we collect
Two broad categories: (1) account data we collect to operate the service — name, email, organization, authentication metadata; and (2) customer data that tenants and their users upload into the platform to do their work. The Customer (tenant) acts as Controller of customer data; CustomerNode acts as Processor.
International transfers
Production data is currently stored in the United States. Where data originates in the EEA and is transferred outside it, we rely on Standard Contractual Clauses approved by the European Commission, as detailed in Section 11 of the DPA. We do not currently offer contractually committed in-region residency for the EU/EEA.
Data retention
Customer data is retained for the duration of the service agreement. Tenant administrators and individual users can delete data through the platform at any time. On termination or written request, CustomerNode deletes or returns customer data within 30 days, except where applicable law requires continued retention.
Deleted data leaves live systems immediately, encrypted and immutable backups within 9 days, and all archive copies within 90 days. Off-site backups are encrypted before upload, with keys that never leave CustomerNode's infrastructure, and are held under an immutability lock for ransomware protection. The same lock means no credential, including CustomerNode's own, can erase a backup before it ages out.
- Live systems
- Data deleted through the platform is removed from live systems immediately.
- Backups
- Deleted data ages out of encrypted, immutable backups within 9 days.
- Archives
- All archive copies age out within 90 days.
- Security logs
- Logs containing personal data, such as IP addresses, are retained for 30 days.
- After termination
- Customer data is deleted from live systems within 30 days of termination or a verified written request; backups and archives then age out on the schedules above.
Cookies
The CustomerNode site uses cookies for session management, theme preference, and basic analytics. Cookie behavior can be managed through your browser. We do not sell personal information to third parties for advertising purposes.
Data subject requests
Individuals may exercise access, rectification, erasure, restriction, portability, and objection rights as provided by applicable law. Requests can be initiated through the data deletion request form or by emailing [email protected]. Where CustomerNode is the Processor, we route the request to the relevant Controller (the tenant) and assist as described in the DPA.