Privacy Policy
Last updated: July 2026 · Voltro UG (haftungsbeschränkt)
1. Controller
The controller responsible for data processing on this website and the Voltro Cloud service within the meaning of Art. 4(7) GDPR is:
Voltro UG (haftungsbeschränkt)
Kollwitzstr. 76
10435 Berlin, Germany
support@voltro.cloud
Represented by its managing director, Mario Ludwig. For any privacy enquiry, contact support@voltro.cloud.
2. Hosting and server logs
Our websites and the Voltro Cloud control plane run on serverless infrastructure operated by Scaleway SAS (France, EU). When you access them, the infrastructure automatically records technical access data — IP address, date and time, requested URL, HTTP status, and user agent — in server logs. We use these logs solely to operate, secure, and troubleshoot the service (legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure and reliable operation). Log data is retained briefly and not merged with other data sources.
3. Cookies
We use no tracking, advertising, or third-party analytics cookies. The only cookie we set is the strictly necessary session cookie (voltro:session) that keeps you signed in to the Voltro Cloud dashboard (legal basis: Art. 6(1)(b) GDPR; § 25(2) TDDDG). It is not used for profiling. Because we set only strictly necessary cookies, no consent banner is required.
4. Account and contract data
When you create a Voltro Cloud account we process the data you provide — e.g. name, e-mail address, organisation, and the resources you configure — to provide the service under the Terms of Service (legal basis: Art. 6(1)(b) GDPR). Service data is stored in managed PostgreSQL databases operated by our database processor (Neon).
5. Developer and usage data (seat measurement)
Voltro is licensed per named user: a seat belongs to one identified natural person. To make that measurable — rather than asserted — we record, per organisation, which people did workand when they were last active. This applies to both the managed cloud and self-hosted installations.
What we process. For each person acting in an organisation:
- the account identifier and the organisation they acted in;
- a coarse activity timestamp (we keep the LAST activity per person per organisation — not a log of individual actions);
- whether the activity came through the dashboard, the command-line tool, or both;
- for self-hosted use additionally: the project name and the version of the command-line tool, bucketed to the calendar day.
What we do not process. No source code, no database schema, no application data, no file names, no command arguments, and no contents of your project — neither in the cloud nor from a self-hosted installation. The command-line tool transmits nothing at all unless you have signed in to Voltro Cloud with a personal credential.
Legal basis. Performance of the contract and its licence terms (Art. 6(1)(b) GDPR), since the fee depends on the number of named users. In addition our legitimate interest in verifying licence compliance and detecting circumvention (Art. 6(1)(f) GDPR), balanced by the minimisation described above. You may object under Art. 21 GDPR; note that we would then be unable to operate a per-seat licence for the account concerned.
Retention. Activity data is aggregated monthly into a per-organisation seat figure. The aggregate is retained for the statutory retention period applicable to invoicing records; the underlying per-person timestamp is overwritten by the next activity and is deleted when the membership ends.
If your employer or client uses Voltro. Where an organisation licenses Voltro and its staff or contractors work with it, we act as controller for this seat measurement, and the organisation is responsible for informing the people concerned (Art. 13/14 GDPR). We do not provide organisations with tooling to monitor individual productivity: administrators see who occupies a seat and the date of last activity — not what anyone did.
6. Newsletter
If you subscribe to our newsletter we process your e-mail address to send it, based on your consent (Art. 6(1)(a) GDPR). You can withdraw consent at any time using the unsubscribe link in every issue or by contacting support@voltro.cloud; withdrawal does not affect the lawfulness of processing before it.
7. Support enquiries
When you contact us (e.g. by e-mail), we process the data you include to handle your enquiry (Art. 6(1)(b) and (f) GDPR) and delete it once the matter is resolved, unless statutory retention duties apply.
8. Processors and international transfers
We share personal data only with processors bound by data-processing agreements under Art. 28 GDPR, each configured for EU data residency:
- Scaleway SAS (France, EU) — hosting and infrastructure;
- Neon — managed PostgreSQL databases (EU region);
- Upstash — managed cache and realtime infrastructure (EU region);
- WorkOS — sign-in and enterprise single sign-on, where you use it;
- Stripe — payment processing when you purchase a paid plan. Payment details go directly to Stripe; we never store full payment data.
Where a provider (or its parent company) is established outside the EEA, transfers rest on the safeguards of Art. 44 ff. GDPR — adequacy decisions (including the EU-US Data Privacy Framework) or EU standard contractual clauses. We do not sell personal data.
9. Retention
We retain personal data only as long as necessary for the purposes above or as required by statutory retention obligations, and delete or anonymise it afterwards.
10. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and — where processing is based on Art. 6(1)(f), the right to object at any time for reasons arising from your particular situation (Art. 21). To exercise any of these, contact support@voltro.cloud.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority competent for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
11. Changes
We update this policy when our service or the legal situation changes; the current version is always published here.