Privacy Policy
Partiri — partiri.cloud
At Partiri, we take your privacy seriously. Please read this Privacy Policy to learn how we treat your personal data. By using or accessing our Services in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your information as described in this Privacy Policy.
Your use of Partiri's Services is at all times subject to our Terms of Service, available at https://partiri.cloud/terms, which incorporates this Privacy Policy. Any terms we use in this Policy without defining them have the definitions given to them in the Terms of Service.
As we continually work to improve our Services, we may need to change this Privacy Policy from time to time. We will notify you of material changes by placing a notice on the Partiri website, by sending you an email, or by other appropriate means at least 30 days before the changes take effect. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.
1. Controller and Contact Information
The controller responsible for the processing of your personal data within the meaning of the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (Bundesdatenschutzgesetz — BDSG) is:
Partiri
Email: [email protected] Website: https://partiri.cloud
2. What This Privacy Policy Covers
This Privacy Policy covers how we treat Personal Data that we gather when you access or use our Services. "Personal Data" means any information that identifies or relates to a particular individual, as defined under the GDPR (Art. 4(1)). This Privacy Policy does not cover the practices of companies we do not own or control, or people we do not manage.
3. Personal Data We Collect
3.1 Categories of Personal Data
We collect and process the following categories of Personal Data:
a) Profile and Contact Data workspace names, email address, username, and password.
b) Payment Data Full payment card details are processed by our payment processing partner and are not stored on our servers.
c) Commercial Data Such as purchase history, subscription details, and service usage records.
d) Device and Connection Data Such as IP address, type of device, operating system, and browser used to access the Services.
e) Third-Party Account Data Such as email address, username, and other publicly available profile information provided when you authenticate via a third-party service (e.g., GitHub, GitLab).
f) Communication Data Such as any information you voluntarily provide in emails, support tickets, or other correspondence with us.
3.2 Information We Do Not Intentionally Collect
We do not intentionally collect special categories of personal data as defined in Art. 9 GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation. If you store any such information in your applications hosted on our platform, you are solely responsible for ensuring that such storage complies with applicable law.
We do not intentionally access the content of your applications or repositories unless required for security or maintenance purposes, or for support reasons with your consent.
4. How We Collect Your Personal Data
We collect Personal Data from the following sources:
a) Directly from you — when you create an account, use our Services, fill in forms, communicate with us, or respond to surveys.
b) Automatically — through cookies and similar technologies when you interact with our website and Services (see Section 10 below).
c) From third parties — such as authentication providers (e.g., GitHub, GitLab), analytics providers, and payment processors, where you have authorised such sharing.
5. Legal Bases for Processing
Under the GDPR, we process your Personal Data only when we have a lawful basis to do so. The legal bases we rely on include:
a) Performance of a Contract (Art. 6(1)(b) GDPR) We process Profile and Contact Data, Payment Data, Third-Party Account Data, and Communication Data as necessary to perform our contract with you — i.e., to provide the Services you have requested. Without this data, we cannot provide you with access to our platform.
b) Legitimate Interests (Art. 6(1)(f) GDPR) We process Commercial Data, Device and Connection Data, Usage and Analytics Data, and Professional or Employment-Related Data where we have a legitimate interest in doing so, provided your rights and freedoms do not override those interests. Our legitimate interests include:
- Providing, customising, and improving the Services.
- Ensuring the security and integrity of our platform.
- Understanding how our Services are used.
- Communicating with you about your account and the Services.
- Enforcing our legal rights and terms.
c) Consent (Art. 6(1)(a) GDPR) Where we process Personal Data based on your consent (e.g., for marketing communications or non-essential cookies), you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
d) Legal Obligation (Art. 6(1)(c) GDPR) We may process your Personal Data to comply with legal obligations to which we are subject, such as tax and commercial record-keeping requirements under German law (e.g., Abgabenordnung, Handelsgesetzbuch).
6. How We Use Your Personal Data
We use your Personal Data for the following purposes:
- Providing the Services: Creating and managing your account, processing transactions and billing, delivering the platform features you have requested.
- Improving the Services: Conducting research, testing, internal analytics, and product development to enhance performance and user experience.
- Security and Fraud Prevention: Detecting, investigating, and preventing security incidents, fraud, and abuse.
- Communication: Responding to your enquiries, sending you service-related notifications, and (with your consent) marketing communications.
- Legal Compliance: Fulfilling our obligations under applicable laws, regulations, or legal processes, and enforcing our Terms of Service.
7. How We Disclose Your Personal Data
We do not sell your Personal Data to third parties. We may share your Personal Data in the following circumstances:
a) Service Providers We share Personal Data with a limited number of third-party service providers who process it on our behalf to provide or improve our Services. These include payment processors (currently Stripe), hosting and infrastructure providers, analytics services, and customer support tools. Our service providers are contractually bound to process your data only on our instructions and in accordance with applicable data protection law, including through Data Processing Agreements pursuant to Art. 28 GDPR.
b) Third Parties You Authorise We may share Personal Data with third parties where you have explicitly authorised such sharing (e.g., through OAuth integrations).
c) Legal Requirements We may disclose Personal Data to law enforcement authorities or other government bodies when required by law, regulation, court order, or other legal process, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
d) Corporate Transactions In the event of a merger, acquisition, reorganisation, or sale of assets, your Personal Data may be transferred as part of that transaction. We will notify you before your Personal Data is transferred and becomes subject to a different privacy policy.
We do not host advertising on partiri.cloud and do not share your Personal Data with advertising networks.
8. International Data Transfers
Our Services are hosted and operated within the European Union. Where it is necessary to transfer your Personal Data to countries outside the European Economic Area (EEA) — for example, to a sub-processor located in a third country — we ensure that appropriate safeguards are in place, including:
- Transfers to countries with an adequacy decision by the European Commission (Art. 45 GDPR).
- Standard Contractual Clauses (SCCs) approved by the European Commission (Art. 46(2)(c) GDPR).
- Other lawful transfer mechanisms as permitted by the GDPR.
You may request a copy of the safeguards in place by contacting us at [email protected].
9. Data Retention
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Specifically:
- Account Data: We retain your profile information and credentials for as long as your account is active. If you delete your account, we will delete your Personal Data within 30 days, except as required by law.
- Billing and Transaction Data: We retain this data for the duration required by German tax and commercial law (generally 6 to 10 years under the Abgabenordnung and Handelsgesetzbuch).
- Device and Usage Data: We retain this data for as long as reasonably necessary for security, analytics, and service improvement purposes.
- Communication Data: We retain correspondence for as long as necessary to resolve the matter and for a reasonable period thereafter.
After the applicable retention period expires, we will securely delete or anonymise your Personal Data.
10. Cookies and Tracking Technologies
Partiri uses cookies and similar technologies to make interactions with our Services easy and meaningful.
a) Essential Cookies These cookies are strictly necessary for the operation of our website and Services (e.g., keeping you logged in and remembering your preferences). They do not require your consent.
b) Analytics Cookies We may use analytics services to collect anonymised information about how our website is used. These cookies are only set with your prior consent.
c) Cookie Consent When you visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your preferences at any time through our cookie settings. You may also configure your browser to refuse cookies, though this may affect your ability to use certain features of the Services.
We do not use retargeting or advertising cookies. We do not serve interest-based advertisements.
11. Data Security
Partiri takes all measures reasonably necessary to protect your Personal Data from unauthorised access, alteration, or destruction, and to maintain data accuracy. We implement appropriate technical and organisational measures (Art. 32 GDPR), including encryption of data in transit and at rest, access controls, regular security assessments, and staff training.
However, no method of transmitting data over the internet or storing data electronically is completely secure. While we strive to protect your Personal Data, we cannot guarantee its absolute security. You should also help protect your account by selecting a strong password and limiting access to your devices.
12. Personal Data of Children
Our Services are not directed at children. We do not knowingly collect Personal Data from children under the age of 18 (or such lower age as applicable under the law of the relevant EU Member State pursuant to Art. 8 GDPR). If we learn that we have collected Personal Data from a child under this age without valid parental consent, we will take steps to delete that information promptly. If you believe that a child may have provided Personal Data to us, please contact us at [email protected].
13. Your Rights Under the GDPR
As a data subject, you have the following rights under the GDPR. To exercise any of these rights, please contact us at [email protected].
a) Right of Access (Art. 15 GDPR) You have the right to request confirmation of whether we are processing your Personal Data and to obtain a copy of that data.
b) Right to Rectification (Art. 16 GDPR) You have the right to request that we correct any inaccurate or incomplete Personal Data we hold about you. You may also correct some of this information directly through your account settings.
c) Right to Erasure (Art. 17 GDPR) You have the right to request that we delete your Personal Data, subject to certain legal exceptions (e.g., where retention is required by law).
d) Right to Restriction of Processing (Art. 18 GDPR) You have the right to request that we restrict the processing of your Personal Data in certain circumstances (e.g., while we verify the accuracy of your data following a rectification request).
e) Right to Data Portability (Art. 20 GDPR) You have the right to receive your Personal Data in a structured, commonly used, machine-readable format and to request that we transmit it to another controller, where technically feasible.
f) Right to Object (Art. 21 GDPR) You have the right to object to the processing of your Personal Data where we rely on legitimate interests as the legal basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims. You have an absolute right to object to processing for direct marketing purposes at any time.
g) Right to Withdraw Consent (Art. 7(3) GDPR) Where we process your Personal Data based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
h) Right to Lodge a Complaint You have the right to lodge a complaint with a supervisory authority. The competent supervisory authority in Germany is:
Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) Graurheindorfer Str. 153 53117 Bonn, Germany Email: [email protected] Website: https://www.bfdi.bund.de
You may also contact the supervisory authority of the German federal state (Landesdatenschutzbeauftragter) in which Partiri is established or in which you reside. A list of state-level data protection authorities is available at: https://www.bfdi.bund.de/DE/Service/Anschriften/Laender/Laender-node.html
We will respond to your request within one month of receipt. This period may be extended by two further months where necessary, taking into account the complexity and number of the requests, in accordance with Art. 12(3) GDPR. We will not charge you a fee for exercising your rights unless your request is manifestly unfounded or excessive.
14. Email Communication
We will use your email address to communicate with you only for the reasons you have agreed to. Service-related communications (e.g., account notifications, security alerts, billing information) are sent as part of the performance of our contract with you. Marketing communications are only sent with your prior consent and always include a clear unsubscribe option.
15. Sub-Processors
We use a limited number of sub-processors to help deliver our Services. A current list of sub-processors is available upon request by contacting [email protected].
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. For material changes, we will provide notice through our website or by email at least 30 days before the changes take effect. For minor changes, we encourage you to review this page periodically. Your continued use of the Services after any changes constitutes acceptance of the revised Privacy Policy.
17. MCP Connector (AI Agent Access)
Partiri offers an optional Model Context Protocol (MCP) server that allows AI agents (such as Claude) to access your Partiri account on your behalf. This section describes what data the connector accesses, how credentials are handled, and how long any state is retained.
Data accessed. When you authorise an AI agent through the MCP connector, the agent may read or write the following categories of data in your account: workspace and project configuration (names, IDs, billing email); service configuration (runtime, deploy type, repository URL, branch, build paths, environment variable names, health check path, active status); deployment jobs (status, type, timestamps); service logs (timestamped log lines); CPU, memory, and network metrics (Prometheus time-series); compute resource definitions (pods, regions); and your user profile (id, email, display name). The connector does not access payment or billing details, infrastructure credentials, or data stored inside your deployed applications.
Authentication. The connector supports two transport modes. In stdio mode, your Partiri API key is read from the PARTIRI_API_KEY environment variable or from the credentials file written by the partiri auth CLI, held in process memory, and sent to the Partiri API over HTTPS. In HTTP mode, the connector implements OAuth 2.1 with PKCE: you enter your API key through a browser authorisation form, which is validated against the Partiri API before any token is issued. Tokens are stateless — your API key is embedded inside AES-256-GCM encrypted tokens (12-byte random IV, 16-byte authentication tag) using a server-side encryption key that is never transmitted. There is no server-side token database.
Retention. The MCP connector is a pass-through to the Partiri REST API and does not log, cache, or store the content of requests or responses. In HTTP mode, active session state (transport handle, SHA-256 hash of the API key, timestamps) is held in server memory only and is removed automatically after 30 minutes of inactivity (configurable via MCP_SESSION_TTL_MINUTES). Sessions are also removed when the client closes the connection. If the optional MCP_DATA_DIR is configured, two files may be persisted: the token encryption key (so tokens survive server restarts) and dynamically registered OAuth client records. Neither file contains workspace data, service configuration, logs, metrics, or user content.
For questions about AI agent access to your account, contact us at [email protected]. Full technical documentation is available at https://partiri.cloud/documentation/mcp.
18. Contacting Us
If you have questions or concerns about this Privacy Policy or our data processing practices, please contact us at:
Email: [email protected]