1. Roles
You are the controller of the personal data in your instances, boxes and servers. Obsidian Peaks Technologies AB is your processor for the limited purpose of hosting it. For your own account data we are the controller; the privacy policy covers that.
2. Subject matter and purpose
Hosting the compute you rent: GPU instances and dedicated boxes in Sweden and, when you order them, CPU servers and extra IP addresses. We process only what running that service requires, and only on your documented instructions. Renting the service and configuring it in the Console are your instructions.
3. Duration
For as long as you rent from us. When an instance or box ends, its disk is deleted permanently after the grace period shown in the Console; we keep no copies.
4. Kinds of data and data subjects
Whatever you choose to process: it is your workload. Special categories of data need our written agreement first (section 6 of the customer terms).
5. Our obligations
- We access what runs in your instance only under section 7 of the customer terms: at your request, to restore a service, to apply urgent security maintenance, to investigate an incident or a suspected breach, or when the law requires it. Every use of the operations key is logged.
- The people who operate the service are bound by confidentiality.
- We tell you without undue delay when we become aware of a personal-data breach that concerns your data, and give you what we know so you can meet your own obligations.
- We help you answer data-subject requests and carry out impact assessments where they concern data we hold for you, at cost if the work is substantial.
- We delete your data at the end of the service as described in section 3, and confirm it on request.
- We make available what you need to show that these obligations are met, and allow audits you reasonably request, at your cost and with notice.
6. Security
Access to instances is by SSH key. Hardware you rent is not shared with another customer during your term. Instance disks are deleted at teardown, and that teardown is verified. Card data is held by Stripe, not by us. We do not claim measures we have not verified; ask info@obsidianpeaks.com for the current description.
7. Sub-processors
We use these sub-processors. We tell you in the Console before adding one; you may object within 30 days, and end the service if we cannot accommodate the objection.
- Stripe Payments Europe Ltd (Ireland): payments. Touches your billing identity and card details.
- Cloudflare, Inc. (USA, with EU data centres): the site, DNS, and the edge in front of the Console. Touches traffic in transit, your IP address, and the contact form.
- Hetzner Online GmbH (Germany; our server is in Finland): the Console server and the model mirror. Touches account data, billing records, logs and support messages. When you order a CPU server or an extra IP, Hetzner also runs that server or relay in the country you chose (Germany, Finland, the United States or Singapore).
- Google (Google Workspace): email. Touches what you write to us and what we write to you.
- Resend, Inc. (USA): delivery of contact-form messages from the site. Touches the name, email and message you send.
The GPU boxes are our own hardware in Sweden, operated by us. No sub-processor has access to them.
8. Transfers
Your GPU data stays in Sweden. We do not move it out of the EU/EEA. A CPU server or extra IP in the United States or Singapore is placed there because you chose it; that choice is your instruction, and the data on it is stored where the server is. Where a sub-processor is outside the EU/EEA, the transfer rests on the EU Standard Contractual Clauses or an adequacy decision, as that sub-processor’s own terms provide.
9. Law
Swedish law applies, and this agreement follows Article 28 of the GDPR. Where this agreement and the customer terms differ, this agreement wins for personal data.
