Privacy policy
How OneCloud handles personal information across this website, our consulting engagements and the ERAG and Stratum platforms.
01Who we are
OneCloud, LLC, a limited liability company registered in the State of Florida, United States (“OneCloud”, “we”, “us”) operates onecloudops.com and provides AI consulting services and two platforms: ERAG, an enterprise retrieval and agent platform, and Stratum, an AI-native legacy modernization platform.
This policy explains what personal information we handle, why, and what you can do about it. For questions or to exercise a right, write to [email protected].
02Two different roles
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
- As a controller — for our own website visitors, prospects, customer contacts and job applicants. We decide why and how that information is used, and this policy governs it.
- As a processor — for the documents, source code and records a customer loads into ERAG or Stratum. That content belongs to the customer; we process it only on their instructions under our Data Processing Addendum. If you are an employee or customer of one of our customers, contact them directly — they control that data, not us.
If you run ERAG yourself — it is Apache-2.0 licensed and self-hostable — your data never touches our systems at all, and this policy does not apply to that deployment.
03What we collect
When you visit this website
This site carries no analytics, no advertising pixels and no third-party tracking cookies. We do not profile visitors.
- Server logs — IP address, timestamp, page requested, user agent. Used to keep the site up and to spot abuse. Retained for 30 days.
- Local storage — a single key,
oc-theme, remembering whether you chose the light or dark theme. It never leaves your browser and we cannot read it. - Fonts — the typeface is served by Google Fonts, which receives your IP address as part of that request. If you would rather avoid it, self-hosting the font files removes the call entirely.
When you contact us
The contact form collects your name, work email, company and whatever you write in the message. It is delivered to us by email through Resend, our transactional email provider, and stored in our mailbox and CRM.
When you become a customer
- Account data — names, work emails, roles and authentication identifiers for the people you authorise.
- Billing data — company details, addresses and tax identifiers. Card details are handled by our payment processor; we never see or store full card numbers.
- Usage and audit records — sign-ins, queries run, scans started, jobs executed. These exist for security, billing and support.
- Support correspondence — tickets, emails and call notes.
04Customer content and AI models
The documents and source code you load into our platforms are customer content. We treat them as confidential and process them only to deliver the service you asked for.
- We do not train models on your data. Neither your documents nor your source code are used to train, fine-tune or improve any model, ours or anyone else’s.
- Model providers. When you use hosted models, the relevant content is sent to the provider routed for that workload under agreements that prohibit training on it. You can bring your own provider keys, or run local models on vLLM or Ollama so nothing leaves your network.
- Isolation. Hosted storage is isolated per organisation and encrypted at rest. Secrets are encrypted and never returned unmasked.
- Deployment choice. The Stratum VPC runner and self-hosted ERAG keep content entirely inside your own infrastructure.
05Why we use it, and on what basis
| Purpose | Information | Lawful basis (UK/EU GDPR) |
|---|---|---|
| Run and secure the website | Server logs | Legitimate interests — keeping the service available and safe |
| Answer enquiries and send proposals | Form and email content | Legitimate interests / steps before a contract |
| Deliver the services | Account, usage, customer content | Performance of a contract |
| Invoice and collect payment | Billing data | Performance of a contract; legal obligation |
| Security monitoring and fraud prevention | Logs, audit records | Legitimate interests; legal obligation |
| Product and service improvement | Aggregated usage metrics | Legitimate interests |
| Occasional updates to existing customers | Work email | Legitimate interests, with opt-out in every message |
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not make decisions producing legal effects about you by automated means.
07International transfers
We are established in the United States, so information from the UK, EEA or Switzerland may be transferred there and to other countries where our providers operate.
Where required, those transfers rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, supported by a transfer risk assessment and technical measures including encryption in transit and at rest. Customers may also pin processing to a chosen region, or deploy entirely inside their own infrastructure so no transfer occurs.
08How long we keep it
- Server logs — 30 days.
- Enquiries that do not become customers — 24 months, then deleted.
- Customer account and usage records — for the life of the contract and 12 months after.
- Customer content — for the life of the contract. On termination it is deleted within 30 days unless you ask for it sooner, or ask us in writing to hold it longer.
- Invoices and financial records — seven years, as tax law requires.
Customers can also configure their own retention policies and right-to-be-forgotten workflows inside the platforms.
09Your rights
Depending on where you live, you may have some or all of the following rights over the information we hold as a controller.
- Access — get a copy of what we hold about you.
- Correction — fix anything inaccurate or incomplete.
- Deletion — ask us to erase it, where no legal obligation requires us to keep it.
- Portability — receive it in a machine-readable format.
- Objection and restriction — object to processing based on legitimate interests, or ask us to pause it while a dispute is resolved.
- Withdraw consent — where we relied on consent, at any time, without affecting what came before.
- Non-discrimination — we will not treat you worse for exercising any of these.
Write to [email protected]. We answer within 30 days and may need to verify your identity first. Florida and other US state residents may exercise equivalent rights, including the right to know and to opt out of sale or sharing — we do neither. If you are in the UK or EEA and are unhappy with our response, you can complain to your supervisory authority, though we would rather you came to us first.
10Security
We encrypt data in transit and at rest, enforce access control inside retrieval rather than after it, support SSO, SCIM and MFA, and keep an audit trail that can be exported to your SIEM. The full picture is on our security page, including how to report a vulnerability.
No system is perfectly secure. If a breach affects your personal information we will notify you and any relevant regulator within the timeframes the law requires.
11Children
Our services are built for organisations, not consumers, and are not directed at anyone under 16. We do not knowingly collect information from children. If you believe we have, tell us and we will delete it.
12Changes to this policy
We will update this page when our practices change, and we will move the “last updated” date at the top. For material changes affecting customers we will give notice by email or in-product before they take effect.
13Contact us
OneCloud, LLC, a limited liability company registered in the State of Florida, United States
Privacy: [email protected]
Security: [email protected]
Everything else: [email protected]