Privacy Policy
The short version
- We are an Irish company. Maxinodes Ltd is the controller of your account, billing and website-visitor data, and a processor of the Content you host with us (that processing is governed by our Data Processing Agreement).
- Your data stays in Europe. We store and back up data within the EU/EEA only, with primary infrastructure in the Netherlands. We do not transfer hosted service data to third countries.
- We do not sell your data. We share it only with a short list of vetted subprocessors needed to run the Services.
- Card details never touch our servers. Payments are handled by our payment provider.
- You are in control. You can access, correct, export or delete your personal data, object to certain processing, and withdraw consent. Email [email protected] and we respond within one month.
This summary is for convenience only. The numbered clauses below are the binding agreement.
1. Who we are & our role
Maxinodes (“we”, “us”, “our”) is Maxinodes Ltd, a private company limited by shares, registered in Ireland, with its registered office at 1 Ballycoolin Road, Dublin 15, Ireland. Our Companies Registration Office (CRO) number is in the process of being issued and will be published once available.
This Privacy Policy explains how we handle personal data relating to our customers, the individuals who use our customers’ accounts, prospective customers, and visitors to our website. In this policy, Customer (“you”, “your”) means the person or entity that orders the Services we provide.
Your role and ours depend on the data in question:
- We are the controller of the personal data we collect to run our business and our relationship with you — in particular account data, billing data, support and contact-form data, Status-Page subscription data, and the operational logs generated by our systems. As controller, we decide why and how that data is processed, and this Privacy Policy governs it.
- We are a processor of the Content (also called Customer Data) that you store on, or transmit through, the Services. We process that Content only on your documented instructions, in order to provide the Services. Where you are a Customer, you are the controller of that Content and you remain responsible for the personal data it contains. That processing is governed by our Data Processing Agreement (DPA), not by this policy.
If you have any question about this policy or about how we handle your personal data, contact our privacy team at [email protected]. Support is available in English and Russian every day.
2. The data we collect, by source
We collect the following categories of personal data, grouped by where it comes from. We keep collection to what we genuinely need.
Account data
When you create an account or place an Order through the Client Area at my.maxinodes.com, we collect your name, the name of the organisation you represent (where applicable), your email address, postal address, telephone number, account login credentials (passwords are stored only in hashed form), and your settings and preferences. This data identifies you, secures your account and lets us communicate with you about the Services.
Billing data
To take payment and meet our accounting obligations we collect your billing name and address, the plan you have purchased, your invoices, payment records and transaction history. We do not store full payment-card numbers on our servers. Card and other payment-instrument data is collected and processed directly by our payment provider, which specialises in securely handling payment data; we receive only a token and limited details (such as the card type and last four digits) needed to identify a payment method and process renewals and refunds.
Support & ticket data
When you contact us through a support ticket, by email to one of our role inboxes, or via any live-chat channel we operate, we collect the contents of your message, your contact details, and any account or technical information you share so that we can investigate and respond. We also keep a record of our correspondence with you.
Contact-form data
If you submit our website contact form, we collect the name, email address and message you provide so that we can reply to your enquiry. We use this data only to respond and to follow up where relevant.
Advertising-measurement data (only with your consent)
If — and only if — you opt in to the Marketing category in our cookie banner, we load the Meta pixel and share with Meta Platforms Ireland Ltd the fact that you visited or converted, your IP address, browser details, the pages you viewed, the _fbp/_fbc identifiers, and — where you have given it to us, for example by submitting the contact form — a hashed (scrambled) form of your email address. We send the same events from our own server as well as from your browser; the information is the same either way. If you do not opt in, none of this is collected or sent. See our Cookie Policy for the full detail.
Status-Page subscription data
If you choose to subscribe to incident notifications from our Status Page at status.maxinodes.com, we collect the email address (or other contact endpoint) you provide so that we can send you the updates you asked for. You can unsubscribe at any time.
Server & operational logs
When you and your end users access the Services and our website, our systems automatically generate operational records such as IP addresses, timestamps, request and error logs, authentication and access logs, and performance and security metrics. We use these to operate, secure, troubleshoot and plan the capacity of the platform.
3. Why we use your data & our legal bases
We process personal data only where we have a lawful basis to do so under Article 6 of the General Data Protection Regulation (GDPR). The table below sets out, for each purpose, an example and the legal basis we rely on. Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms.
| Purpose | Example | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Services & managing your account | Provisioning your Self-Managed or Managed plan, authenticating logins, applying your settings, and giving you access to the Client Area. | Performance of a contract (Art. 6(1)(b)) — processing necessary to deliver the Services you ordered. |
| Billing, payments & renewals | Issuing invoices, taking payment through our payment provider, processing renewals, credits and refunds. | Performance of a contract (Art. 6(1)(b)). |
| Keeping tax & accounting records | Retaining invoices and financial records for the period required by Irish law. | Legal obligation (Art. 6(1)(c)). |
| Providing support & responding to enquiries | Handling support tickets, answering contact-form messages, and keeping a record of our correspondence. | Performance of a contract (Art. 6(1)(b)) for account-related support; legitimate interests (Art. 6(1)(f)) for general or pre-sales enquiries — our interest in responding to and assisting the people who contact us. |
| Securing the platform & preventing fraud and abuse | Monitoring for intrusions and abuse, investigating reports to [email protected], maintaining access and security logs, and detecting fraudulent payments. | Legitimate interests (Art. 6(1)(f)) — our interest in keeping the Services, our customers and our infrastructure secure and free from fraud and abuse. Where applicable we also rely on legal obligation (Art. 6(1)(c)). |
| Capacity planning & improving the Services | Analysing aggregate performance and usage metrics to plan capacity and improve reliability. | Legitimate interests (Art. 6(1)(f)) — our interest in operating a reliable, well-sized platform. |
| Service communications | Sending essential notices about your account, security, billing, maintenance and Status-Page incidents you subscribed to. | Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) — our interest in keeping you informed about the Services you use. |
| Marketing | Sending optional newsletters or product news where you have asked to receive them. | Consent (Art. 6(1)(a)). You can withdraw your consent at any time, with no effect on the Services. |
| Establishing, exercising or defending legal claims | Retaining limited records where needed to resolve a dispute or enforce our terms. | Legitimate interests (Art. 6(1)(f)) — our interest in protecting our legal rights. |
We do not carry out automated decision-making that produces legal or similarly significant effects on you, and we do not engage in profiling for those purposes.
4. Resold Email
Where you purchase Resold Email through us — Microsoft 365 or Google Workspace mailboxes — those mailboxes and their contents live in your own tenant with Microsoft or Google. We act only as a reseller: we set up and bill the subscription. We are not the processor of your email content, that content does not sit on Maxinodes infrastructure, and it is not covered by our SLA or by our EU-only backup commitment.
The handling of your mailbox data is governed by the privacy notice, data processing agreement and service terms of the provider you choose (Microsoft or Google), and you contract with that provider for the email service through us. We process only the account and billing data needed to provision and invoice the subscription, as described in sections 2 and 3 above.
5. Sharing & subprocessors
We do not sell your personal data. Apart from the advertising measurement described below — which runs only if you opt in, and which you can switch off at any time — we do not share your personal data for anyone else’s marketing. We share personal data only where it is necessary to provide the Services, comply with the law, or protect our rights:
- Subprocessors. We use a small number of carefully vetted third parties to help us deliver the Services — for example our data-centre operator, our payment provider, and our monitoring and communications tooling. Each is bound by a written contract requiring appropriate security and confidentiality and permitting them to process the data only on our instructions. The current list is published on our Subprocessors page, and our DPA governs subprocessing of Content.
- Meta (advertising measurement) — only with your consent. Where you opt in to the Marketing category, we and Meta Platforms Ireland Ltd act as joint controllers for the collection and transmission of the measurement data described in section 2. That means Meta does not merely act on our instructions: it also uses that data for its own purposes under its own Data Policy, over which we have no control. Meta is therefore not a subprocessor and does not appear on our Subprocessors page. You can withdraw consent at any time using the Cookie settings control in our footer, which stops any further data being sent; to ask Meta to erase data it already holds, contact Meta directly, and we will help where we can.
- Professional advisers and authorities. We may disclose data to our accountants, auditors or legal advisers, or to a public authority, court or regulator, where we are legally required to do so or where it is necessary to establish, exercise or defend legal claims.
- Business transfers. If our business is reorganised, merged or sold, personal data may be transferred as part of that transaction, subject to the protections of this policy and applicable law. We will inform you of any such change that materially affects how your personal data is handled.
6. Where your data is stored & international transfers
We store and process personal data within the European Union / European Economic Area only. Our primary hosting infrastructure is located in enterprise data centres in the Netherlands, and our encrypted backups are stored within the EU/EEA. We do not transfer hosted service data to third countries outside the EU/EEA.
The commitment above is about the data we hold to run the Services. It does not cover the optional advertising measurement in section 2: if you opt in to the Marketing category, Meta may transfer the resulting data to the United States and other countries outside the EU/EEA under its own transfer mechanisms, including the EU–US Data Privacy Framework and Standard Contractual Clauses. The adequacy of that framework has been challenged and remains the subject of litigation before the EU courts. If you would rather no data left the EU/EEA on our account, simply decline the Marketing category — nothing else on this site depends on it.
There is one nuance to be aware of in relation to Resold Email (section 4). Because those mailboxes live in your own Microsoft 365 or Google Workspace tenant rather than on our infrastructure, the storage location and any international transfer of that mailbox data are determined by your chosen provider under its own arrangements (for example its Standard Contractual Clauses or adequacy mechanisms). For that email content, the provider — not Maxinodes — is the relevant party for transfers, and that data sits outside our EU-only backup commitment.
7. How long we keep it
We keep personal data only for as long as we need it for the purposes set out in this policy, and then delete or anonymise it. Our standard retention periods are:
| Category | Retention period |
|---|---|
| Server & operational logs | Approximately 90 days, after which they are deleted or aggregated, unless a specific log is retained longer to investigate a security incident or to establish, exercise or defend a legal claim. |
| Tax & accounting records (including invoices) | Approximately 6 years, as required by Irish tax and company law. |
| Account data | For the life of your account, plus the tax-retention period above for any records that also form part of our accounting and tax records. Other account data is deleted or anonymised once it is no longer needed after closure. |
| Support, ticket & contact-form data | For the duration of your relationship with us and a reasonable period afterwards to handle follow-up queries and disputes, after which it is deleted. |
| Status-Page subscription data | Until you unsubscribe or the subscription is no longer active. |
The Content you host with us is retained and deleted in accordance with your instructions and our DPA and Terms of Service, not under the periods above.
8. Your rights
Under the GDPR and Irish data-protection law you have the following rights in relation to your personal data:
- Access — to obtain confirmation that we process your personal data and a copy of it.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have your personal data deleted where there is no overriding reason for us to keep it (for example our legal retention obligations).
- Restriction — to ask us to limit how we use your personal data in certain circumstances.
- Portability — to receive the personal data you provided to us, where processing is based on consent or contract and carried out by automated means, in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection — to object to processing carried out on the basis of our legitimate interests (see the table in section 3). Where you object, we will stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You can object to direct marketing at any time, and we will stop.
- Withdrawing consent — where we rely on your consent (for example marketing), you can withdraw it at any time. This does not affect the lawfulness of processing carried out before you withdrew it.
To exercise any of these rights, email [email protected]. We may need to verify your identity before acting on a request. We will respond within one month of receiving your request; where a request is complex or you have made several, we may extend this by up to two further months and will tell you if we do. Exercising these rights is normally free of charge.
If you are not satisfied with how we have handled your personal data or a request, you have the right to lodge a complaint with the supervisory authority — in Ireland, the Data Protection Commission. Full details are in the Contact section below.
9. How we protect your data
We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration and disclosure. These measures include:
- Encryption of data in transit and encryption of backups at rest;
- Access controls and the principle of least privilege, so staff can access only the data they need for their role;
- Multi-factor authentication (MFA) on administrative and privileged access;
- Monitoring and logging of access and of platform activity to detect and respond to suspicious events;
- Storage of personal data and backups within the EU/EEA only.
No method of transmission or storage is completely secure, but we work to keep our measures appropriate to the risks involved. You are responsible for keeping your account credentials confidential and for the security choices you make within your own services.
10. Cookies
Our website uses a limited set of cookies and similar technologies. How we use them, and the choices available to you, are described in our Cookie Policy.
11. Children
The Services are intended for businesses and for adults, and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our Services or the law. When we do, we will revise the version and date at the top of the page. The version in force is always the one published at this URL. Where a change is material, we will take reasonable steps to notify you — for example by email or a notice in the Client Area — before it takes effect. For a map of our other legal documents, see the legal hub.
Contact
Privacy and data-protection enquiries: [email protected].
By post: Maxinodes Ltd, 1 Ballycoolin Road, Dublin 15, Ireland.
If you have a concern about how we handle your personal data that we have not been able to resolve, you have the right to lodge a complaint with the supervisory authority in Ireland:
Data Protection Commission
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
www.dataprotection.ie
You may also lodge a complaint with the supervisory authority in your own EU/EEA country of residence.