Privacy policy
Last updated: July 7, 2026
1. Who we are
The data controller for personal data processed via stackbastion.com and the Stackbastion service is AKTAI LTD, a company registered in England and Wales. See company details.
Two roles. For your Stackbastion account (your name, email, billing details, and the audit data described below), we are the controller. For the data inside the application and database you host with us (your own users' names, emails, or any other personal data your app stores in the Postgres database we run for you), you are the controller, and Stackbastion acts as your processor: we handle that data only to run the infrastructure, and only on your instructions. You are responsible for having a lawful basis to process your own users' data and, where required, for signing a Data Processing Agreement with us (TICKET-088).
Other brands. AKTAI LTD also operates Aktai, software for SEBI-registered Research Analysts, under its own separate privacy policy. This policy covers Stackbastion only.
1a. Lawful basis for processing (GDPR Art. 6)
- Performance of a contract: creating and running your account, provisioning and operating your infrastructure, backups, deploys, monitoring, incident response, and support.
- Legitimate interests: aggregate product analytics, abuse prevention, rate limiting, and security monitoring of our own infrastructure. We do not use this basis to build advertising profiles.
- Legal obligation: retaining payment and invoicing records for the periods required by HMRC and the Companies Act 2006.
We do not process any special-category data within the meaning of Art. 9.
1b. Your rights (GDPR Art. 15–22)
You can exercise any of the rights below by emailing [email protected]. We respond within 30 days, free of charge unless a request is manifestly unfounded or excessive.
- Access: a copy of the personal data we hold about you.
- Rectification: correction of inaccurate or incomplete data.
- Erasure: deletion of your account and associated data, subject to the retention needed for tax and billing records.
- Restriction: pause processing while a dispute or accuracy check is resolved.
- Portability: a machine-readable export of the data you gave us.
- Objection: object to processing based on our legitimate interests.
- Automated decision-making: we do not make any decision about you using solely automated means.
- Complaint: to the UK Information Commissioner's Office (ico.org.uk), or your local EU data protection authority.
If your request concerns data inside an application we host for someone else, we will direct you to that customer, since they are the controller of that data.
2. Data we collect
Account data you provide:
- Name, email address, and company name
- Billing and invoicing details (card payments are processed by Stripe; we never store your full card details)
- Infrastructure access details needed to operate your hosting: repository access, environment variables, and DNS records you hand over during onboarding
The audit form (/audit): your app URL, platform, email address, and a free-text description of your biggest worry, used to deliver your audit report and follow up about our services.
Data inside your hosted application (you are the controller; we are the processor): whatever your app stores in the Postgres database and file volumes we host for you. We do not read, export, or use this data for any purpose other than running your infrastructure, and we access it only when needed for support, backup verification, or an incident you have raised.
Collected automatically: IP address and device information for security and abuse prevention, and aggregate page-view analytics via Plausible or self-hosted Umami.
What we do NOT collect: payment-card numbers (handled by Stripe), or any data from your hosted application beyond what is needed to run the infrastructure itself.
3. How we use your data
- To run your account and provide the hosting, deploy, backup, monitoring, and incident-response service you signed up for
- To deliver your free production audit and follow up about it
- To send billing, account, and incident-notification emails
- To process payments and manage your plan
- To improve the product, prevent abuse, and enforce our terms of service
- To comply with our legal obligations
We do not sell your data or your application's data. We do not use it for advertising.
4. Sub-processors
We share data only with the sub-processors necessary to operate the platform. We notify account holders by email at least 14 days before adding a new one.
Infrastructure
- Hetzner, processor, Germany/EU. Server hosting for your application, database, and backups. Your application data is stored at rest in the EU by default.
Payments
- Stripe, processor, USA (Standard Contractual Clauses apply). Subscription and one-off payments. Stripe receives your payment-card data directly; we never store it.
Analytics
- Plausible or self-hosted Umami. Cookieless, aggregate page-view analytics for stackbastion.com. No cross-site tracking, no cookie banner needed.
- A transactional email provider (Postmark, Resend, or Amazon SES) for audit-report delivery and account notifications.
A full list of sub-processors with region and transfer mechanism is available on request: [email protected].
5. Data retention
- Account data, for the duration of your account.
- Application data you host with us, until you cancel. On cancellation, we deliver a full export (database dump, volumes, environment template, DNS notes) within 48 hours, and confirm deletion in writing once it completes (GDPR Art. 17).
- Audit-form data, until you ask us to delete it.
- Payment and tax records, 6 years, as required of a UK company by HMRC and the Companies Act 2006.
- Server and access logs, 30 days, then auto-deleted.
6. Cookies and tracking
We use cookieless, privacy-respecting analytics (Plausible or self-hosted Umami) on stackbastion.com. This does not use cookies or track you across other sites, so no cookie banner is shown here. Stripe may set its own cookies during checkout, governed by Stripe's own privacy policy. If we later add a customer dashboard with sign-in, it will use a strictly necessary session cookie, and this section will be updated before that ships. See the Cookies Policy for the full detail.
7. Data security
- TLS encryption for all data in transit, encryption at rest for backups
- Least-privilege access to customer infrastructure; access to your environment is logged
- Nightly automated backups with periodically tested, non-destructive restores
- Rate limiting and abuse prevention on public-facing endpoints
In the event of a data breach affecting your personal data, we will notify you within 72 hours of becoming aware, as required by GDPR.
8. International data transfers
We host your application infrastructure in the EU (Hetzner, Germany) by default. Some sub-processors, such as Stripe and our email providers, are US-based; transfers to them rely on Standard Contractual Clauses or an equivalent safeguard.
9. Children's privacy
Stackbastion is a business-to-business service and is not directed at persons under 18. We do not knowingly collect data from minors.
10. Changes to this policy
We may update this policy. We will notify account holders of material changes by email with at least 14 days' notice. Continued use after changes take effect constitutes acceptance.
11. Contact & complaints
Data controller: AKTAI LTD, see company details.
Data protection enquiries: [email protected]
Response time: 30 days, free of charge unless a request is manifestly unfounded or excessive.
Supervisory authority: the UK Information Commissioner's Office (ico.org.uk), or your local EU data protection authority if you are in the EU/EEA.
This policy is drafted from a standard UK-focused template and covers analytics, the audit form, and our role as processor for hosted application data, per TICKET-003. Flagged for full lawyer review, including a signable Data Processing Agreement, at the first Business-tier customer (TICKET-088).