Data Processing Rules

Privacy Policy

This policy explains how HexVM processes personal information and service data when providing its website, console, orders, dedicated cloud Macs, and support services. We use information only for clear purposes and to the extent necessary, and provide practical channels for exercising data rights.

Current version Effective: Upon publication Scope: HexVM website and services
01

Policy scope

This policy applies to data processing that occurs when you visit the HexVM website, use the console, create or manage orders, rent a cloud Mac, submit a support ticket, send email, or receive service-related notifications.

Covered service scenarios

  • Website access: Browse pages, choose a language, review rental plans, read help documentation, and use essential website features.
  • Account and console: Register, sign in, verify your identity, view subscriptions, manage nodes, handle billing, and submit support tickets.
  • Orders and delivery: Choose a model, region, rental term, and add-ons; confirm payment; assign a dedicated physical node; and send connection details.
  • Support and communications: Handle troubleshooting, renewal questions, security reports, enterprise deployment needs, and essential service-status notifications.

This policy does not change your rights in uploaded code, build artifacts, configuration files, or other customer data. You decide what data to process on a dedicated physical node and should manage member permissions, keys, and log contents according to your internal policies.

Service data and customer content are handled separately

Data used for accounts, orders, security, and support is governed by this policy; you control the purpose and access scope of repositories, build inputs, and artifacts deployed to your nodes.

02

Information we collect

We collect the information needed to provide our services based on the features you use. Not every category below is generated during every visit or for every user.

Account and contact information

This may include registration identifiers, email address, verification status, account settings, and information about the team or organization you represent. Passwords are handled securely; we will never ask you to send passwords, private keys, or complete access tokens by ordinary email.

Order and node information

This may include order numbers, selected models, regions, rental terms, add-ons, order status, node identifiers, delivery records, renewal results, and audit records related to node operations.

Payment result records

This may include the amount, USD settlement currency, payment method category, transaction status, time, and reference identifiers used to reconcile an order. Payment card details are handled by the relevant payment processor; HexVM receives only the results needed for settlement and reconciliation.

Device and access logs

This may include IP address, browser and device type, access time, request path, sign-in result, session security events, and necessary error records, used to protect account, console, and platform security.

Support request content

This may include issue descriptions in tickets or email, node ID, region, time of occurrence, reproduction steps, impact, and redacted logs you provide. Remove keys, tokens, and unrelated personal information before submitting.

Information you provide voluntarily

This may include background materials you voluntarily provide for pre-sales assessments, team deployments, security reports, or data-rights requests. We process this content only for the purposes stated when it is submitted.

Content we will not request for support

Routine troubleshooting usually requires only an order number, node ID, region, time of occurrence, reproduction steps, and redacted logs. HexVM will not ask you to submit real private keys, complete access tokens, unredacted key files, or unrelated repository content in an ordinary support message.

03

How we use information

We do not repurpose collected information arbitrarily. We mainly use it for the following activities:

  1. 01

    Provide and deliver services

    Create accounts, process orders, confirm payments, assign nodes, send connection details, manage rental terms and renewals, and show order-related status in the console.

  2. 02

    Verify account and order ownership

    Check order status, process node-operation requests, detect suspicious sign-ins, and complete necessary identity verification for sensitive actions or data-rights requests.

  3. 03

    Protect the platform and nodes

    Detect unauthorized access, malicious requests, credential risks, and behavior affecting platform operations; record necessary security events; and apply isolation, restriction, or recovery measures.

  4. 04

    Handle support and service communications

    Troubleshoot connection, delivery, build-environment, or billing issues; respond to tickets and email; and send notifications directly related to orders, security, or service continuity.

  5. 05

    Improve the service experience

    Analyze whether pages and features work properly, assess whether help documentation resolves issues, and improve delivery workflows and troubleshooting steps. Materials used for improvement are designed to minimize direct identifiers where possible.

  6. 06

    Meet legal obligations

    Retain necessary transaction records, respond to requests from authorized parties, handle disputes, and maintain records needed to demonstrate service performance, to the extent required by applicable rules.

04

Data sharing and processors

HexVM does not sell personal information. We disclose limited information to relevant processors only when necessary to deliver services, process payments, operate security, or meet legal requirements.

Recipients, purposes, and minimum disclosure
Recipient category Processing purpose Information that may be involved Safeguards
Infrastructure and service delivery providers Operate the website, console, communications, and node delivery processes Account identifiers, order status, and necessary technical logs Access provided according to service responsibilities and least privilege
Payment processors Process USDT-TRC20 or Visa / Mastercard / Amex (via Stripe) payments and confirm results Order reference, amount, currency, and payment result Payment information is handled by the relevant processor under its security rules
Security and operations support providers Detect attacks, suspicious sign-ins, abuse, and operational failures IP address, time, request characteristics, errors, and security events Limited purpose, authorized members, and retention scope
Professional advisers or legally authorized bodies Handle audits, disputes, compliance obligations, or valid legal requests Necessary records directly related to the matter Verify the request scope and avoid disclosure beyond what is necessary

Processors may use information only for agreed purposes and within the scope of authorization. We assess access controls, confidentiality obligations, transmission safeguards, and incident-response capabilities based on the processing activity. In the event of a corporate reorganization or service transition, relevant data will be transferred only as needed to continue existing services and meet legal obligations, and will remain subject to appropriate protection.

05

Data retention and deletion

Retention periods are not uniform. We determine how long to retain data based on whether the service continues, the purpose of the records, dispute-resolution needs, security risks, and applicable obligations, then delete, anonymize, or restrict access when the purpose ends.

Account information

We retain information necessary for sign-in, verification, and service management while the account is active. After closure, if there are no outstanding orders, disputes, security investigations, or legal obligations, the information enters a deletion or de-identification process.

Order and payment results

We retain these for the periods needed to fulfill orders, reconcile accounts, maintain financial records, process refunds, and resolve disputes. We retain necessary transaction results, not complete payment-card data for our own processing.

Support records

We retain these to continue troubleshooting, confirm resolutions, and identify recurring issues. If a ticket contains information beyond what troubleshooting requires, you may ask us to assess deletion or redaction of that portion.

Access and security logs

We retain these for a limited period based on security analysis, anomaly investigations, and platform protection needs. During a security incident, dispute, or valid investigation, relevant records may be isolated until the matter is resolved.

Node release and customer data

Before your rental term ends or a node is released, export any build artifacts, configuration, and logs you need to keep, and delete sensitive materials you no longer need. Once the node enters the release process, we will revoke access credentials and dispose of customer data on the node according to our service procedures. After release is complete, you should not rely on HexVM to recover content you did not back up yourself.

Deletion request process

  1. 1

    Send a request from the email address registered to the account, or sign in to the console and submit a ticket specifying the data you want deleted.

  2. 2

    We verify account or order ownership and check whether any active service, dispute, security investigation, or required record must be retained.

  3. 3

    We delete or de-identify data eligible for deletion; for data that cannot yet be deleted, we explain its category, reason, and access restrictions.

  4. 4

    We reply through the original request channel when processing is complete. Complex requests may require additional scope or identity information.

06

Your rights and choices

To the extent permitted by applicable rules, you may submit the following requests concerning information about you. Specific rights may depend on the data type, processing purpose, and your location.

Access

Ask whether we process information about you and learn the main data categories, purposes, and recipient categories.

Correction

Update inaccurate or incomplete account and contact information. Some basic information can be managed directly in the console.

Deletion

Request deletion of information that is no longer needed, lacks a basis for continued processing, or must be deleted under applicable rules. Necessary transaction and security records may need to be retained.

Restriction of processing

Request restrictions on non-essential use of specific information while we verify accuracy, handle a dispute, or assess a deletion request.

Obtain a copy

Request an available copy of information associated with your account, orders, or support records. We will provide it in a reasonable format suited to the nature of the data.

Communication preferences

You can manage non-essential communication preferences. Order delivery, security alerts, billing, and service-operation notifications are required to provide the service and cannot all be disabled while the service continues.

Identity verification and authorized agents

To prevent unauthorized access to or deletion of data, we verify the registered email address, account status, order number, or other information that can establish ownership, based on the risk of the request. Do not send passwords, private keys, or complete access tokens by email. If an authorized representative submits a request, we may ask for proof of authorization and confirm directly with the account holder.

How to submit a request

You can email support@hexvm.com or sign in to the console to submit a ticket. Include the right involved, data scope, related order number, and account information that helps us verify your request. We will first confirm receipt, then process it based on its complexity and applicable requirements.

07

International Processing, Minors, Policy Updates, and Contact

International processing

HexVM provides node regions in Singapore, Japan (Tokyo), South Korea (Seoul), Hong Kong, the US East, and the US West. When you select a region, use the console, or contact support, account, order, connection metadata, and support information may be processed in regions required to deliver the service. We use access controls, transmission safeguards, separation of duties, and processor requirements suited to the data type to reduce unnecessary exposure during international processing.

A node region is not necessarily the sole storage location for all account and support data. Choose a suitable region based on your team’s data classification, customer contracts, and compliance requirements, and avoid including sensitive information beyond your build needs in support requests or public logs.

Minors

HexVM serves developers, engineering teams, and organizations with the capacity to enter into agreements, and does not target minors. Anyone below the age of independent consent in their location should not create an account or submit personal information independently. If a guardian believes a minor has provided information to us, they may request review and deletion through the channels listed on this page.

Security safeguards

We use identity verification, least privilege, transmission safeguards, audit logs, anomaly detection, and access revocation based on data sensitivity. No system can eliminate every risk, so you should also promptly rotate temporary credentials, prefer SSH keys, limit team-member permissions, and redact diagnostic materials before submission.

Policy updates

We may update this policy when service features, processing activities, or applicable requirements change. Material changes will be announced through the website, console, or service-related communication channels. The updated version applies from its stated effective time; processing that occurred before then remains governed by the rules and applicable requirements in effect at that time.

Applicable rules and dispute resolution

This policy is interpreted and enforced under the laws of the jurisdiction where the platform operator is based. If a privacy-related dispute cannot be resolved through the support process, it may be submitted to a court with jurisdiction in that jurisdiction, except where mandatory applicable data-protection rules provide otherwise.

Contact HexVM

Privacy questions, data-rights requests, security reports, or requests for a copy of this policy may be sent to support@hexvm.com. If your request concerns an existing order or node, we recommend signing in to the console and submitting a ticket so we can continue after verifying order ownership.

Prepare the following before submitting a privacy request

  • Account email address and request type
  • Related order number or node ID
  • Data scope you want to access, correct, delete, or restrict
  • Necessary supporting materials with sensitive information redacted
Privacy request options

Need to view or manage your data?

Contact us from your registered email address, or include your account and order details in a console ticket. Do not submit private keys, complete access tokens, or unredacted logs.