1. Who is responsible
Pwnera SAS (see the legal notice) is the controller of the personal data described here. Write to hello@artbucket.io for anything about your data.
This policy covers the people who visit artbucket.io and who use Artbucket Cloud. For the content your organization puts in Artbucket (files, metadata, portals), your organization is the controller and we are its processor: the data processing agreement covers that, and your organization's own policy applies to you.
2. What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| Name, email, password (stored hashed) or single sign-on identity, organization and role | Your account, sign-in and access | Contract |
| Sign-in codes and emails about your account, billing and plan | Running the account and telling you what changes | Contract |
| Billing contact, plan, invoices; card details stay with Stripe | Selling paid plans, tax and accounting | Contract, legal obligation |
| Actions in the app, kept as an audit log for your organization's admins | Security and accountability inside your organization | Legitimate interest |
| IP address, user agent and request details in server logs | Security, rate limits and fixing errors | Legitimate interest |
| Messages you send us | Answering you | Legitimate interest, or contract |
| Your GitHub account, if you connect a repository | Brand as code | Contract |
We do not sell personal data, show ads, or train models on it.
3. Cookies
artbucket.io sets no cookies and loads no trackers or analytics. The app sets only the cookies it needs to keep you signed in and remember interface choices; they need no consent, and there are no advertising or analytics cookies.
4. Who else processes it
Our subprocessors are listed on the trust page: Cloudflare, Fly.io, Neon, Resend, Stripe, Grafana Labs, and GitHub if you connect it. Each processes data only on our instructions, or, for Stripe as merchant of record, under its own privacy policy for the purchase.
The app, its database and your files are hosted in the EU (Frankfurt). Some subprocessors are based in the United States; transfers to them rely on the EU-US Data Privacy Framework where the company is certified, or on the European Commission's standard contractual clauses.
5. How long we keep it
- Account data: while the account exists, then deleted within 30 days of its deletion.
- Deleted files and records: in the trash for 30 days, then purged; backups expire within a further 30 days.
- Server logs: up to 30 days.
- Invoices and billing records: 10 years, as French accounting law requires.
- Emails with us: up to 3 years after the last exchange.
6. Your rights
You may ask to access, correct, delete or export your personal data, to restrict or object to its use, and withdraw any consent you gave. Write to hello@artbucket.io; we answer within a month. You may also set out instructions for your data after your death.
If you think we got it wrong, you can complain to the CNIL (cnil.fr) or your own data protection authority.
7. Security
Traffic is encrypted in transit, stored data is encrypted at rest by our providers, and access is limited to the people who run the Service. See the trust page for how to report a vulnerability.
8. Changes
When this policy changes in a way that matters, we update the date above and tell account holders by email.