Last updated: 5 August 2026 · Effective: 5 August 2026
MDRCloud is the data controller responsible for your personal data collected through the use of this website (mdrcloud.com) and our hosting services managed via the MDRCloud ONE client portal (one.mdrcloud.com).
This Privacy Policy describes how MDRCloud collects, uses, stores, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For any privacy-related enquiries, please contact: privacy@mdrcloud.com
We collect the following categories of personal data when you use MDRCloud services:
| Category | Data Points | Source |
|---|---|---|
| Account & Identity | Full name, email address, username, date of birth (for age verification) | Registration via MDRCloud ONE |
| Billing & Payment | Billing address, invoice history, payment method token (card last 4 digits, expiry) | Stripe payment processor; never stored raw on MDRCloud servers |
| Service Usage | Provisioned services, resource consumption metrics (CPU, RAM, storage, bandwidth), server IP addresses | MDRCloud infrastructure monitoring |
| Support Communications | Support ticket contents, email correspondence, chat logs | MDRCloud ONE support portal |
| Technical & Log Data | IP address, browser type, OS, pages visited, session duration, referral URL | Matomo analytics (self-hosted), server access logs |
| Cookies | Session cookies, preference cookies, analytics cookies | Browser; see Section 7 for details |
We do not collect or store raw payment card numbers, CVV codes, or full card details. All payment data is handled exclusively by Stripe in accordance with PCI DSS standards.
MDRCloud uses your personal data for the following purposes:
We do not use your personal data for profiling, advertising, or marketing to third parties.
Under the UK GDPR, MDRCloud relies on the following lawful bases for processing your personal data:
| Processing Activity | Legal Basis (UK GDPR Art. 6) |
|---|---|
| Account creation & service provisioning | Art. 6(1)(b) — Performance of a contract |
| Billing & payment processing | Art. 6(1)(b) — Performance of a contract |
| Sending service & maintenance notifications | Art. 6(1)(b) — Performance of a contract; Art. 6(1)(f) — Legitimate interests |
| Fraud detection & network security | Art. 6(1)(f) — Legitimate interests |
| Compliance with legal obligations | Art. 6(1)(c) — Legal obligation |
| Analytics (Matomo, anonymised) | Art. 6(1)(f) — Legitimate interests (privacy-preserving, self-hosted) |
Where we rely on legitimate interests, we have carried out a balancing test and determined that our legitimate interests are not overridden by your rights and interests as a data subject.
MDRCloud works with a small number of carefully selected third-party processors to deliver our services. Each processor is bound by a Data Processing Agreement (DPA) and is required to handle your data in compliance with UK GDPR:
| Processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Name, billing address, payment method details | USA (EU-US DPF / UK adequacy) |
| Matomo (self-hosted) | Website analytics | Anonymised IP, pages visited, session data | MDRCloud servers (UK/EU) |
| Infrastructure Providers | Physical hosting & network (e.g. Proxmox VE, VMware) | Server resource data (no personal client data shared) | EU / UK datacentres |
MDRCloud does not sell, rent, or share your personal data with third parties for marketing purposes.
MDRCloud uses Matomo, a self-hosted, open-source analytics platform, to understand how visitors use our website. Unlike third-party analytics tools (such as Google Analytics), Matomo is hosted entirely on MDRCloud’s own infrastructure at analytics.mdrcloud.com. Your data does not leave our control.
You may opt out of Matomo tracking at any time. If your browser has “Do Not Track” enabled, Matomo will not track you. You may also use browser extensions such as uBlock Origin to block the analytics tracker.
MDRCloud retains your personal data only for as long as is necessary for the purposes set out in this Privacy Policy, and in accordance with our legal obligations:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account & identity data | Duration of account + 2 years after closure | Fraud prevention and dispute resolution |
| Billing & invoice records | 6 years from date of transaction | UK tax law (HMRC requirements) |
| Support ticket history | 3 years after account closure | Quality assurance and dispute resolution |
| Server access logs | 90 days | Security monitoring and incident investigation |
| Analytics data (Matomo) | 24 months (anonymised) | Service improvement; no identifiable data retained |
| Service data (on terminated servers) | 7 days after termination, then deleted | See Section 9 of the Terms of Service |
After the applicable retention period, personal data is securely deleted or anonymised so it can no longer be associated with you.
MDRCloud implements appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures include:
MDRCloud’s primary infrastructure and analytics (Matomo) are hosted within the United Kingdom and European Union.
The only third-party processor that may involve an international transfer is Stripe, Inc., which is headquartered in the United States. Stripe participates in the EU-US Data Privacy Framework and has a valid UK international data transfer mechanism in place, ensuring your payment data is protected to UK GDPR standards.
We do not transfer your personal data to countries that do not provide adequate protection under UK GDPR without appropriate safeguards in place.
As a data subject under the UK GDPR, you have the following rights with respect to your personal data held by MDRCloud:
To exercise any of your rights, please submit a request to privacy@mdrcloud.com. We will respond within one calendar month of receiving your request. In complex cases we may extend this by a further two months, and will inform you accordingly.
Where required, we may ask you to verify your identity before processing your request.
MDRCloud services are intended for individuals aged 18 and over. We do not knowingly collect personal data from persons under the age of 18. If we become aware that we have collected personal data from a minor without appropriate consent, we will take steps to delete that data promptly.
If you believe that a child has provided personal data to MDRCloud, please contact us at privacy@mdrcloud.com.
MDRCloud may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or services. Where changes are material, we will notify registered Clients via the email address associated with your MDRCloud ONE account.
The “Last updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.
Your continued use of MDRCloud services following notification of changes constitutes your acceptance of the updated Privacy Policy.
For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:
If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection: