MDRCloud LogoMDRCloud← Back to Home
🔒 Privacy & GDPR

Privacy Policy &
GDPR Compliance

Last updated: 5 August 2026 · Effective: 5 August 2026

1

Data Controller

MDRCloud is the data controller responsible for your personal data collected through the use of this website (mdrcloud.com) and our hosting services managed via the MDRCloud ONE client portal (one.mdrcloud.com).

This Privacy Policy describes how MDRCloud collects, uses, stores, and protects personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Our Commitment: We believe in privacy by design. We only collect data that is necessary to provide our services and we do not sell your personal data to any third party, ever.

For any privacy-related enquiries, please contact: privacy@mdrcloud.com

2

Data We Collect

We collect the following categories of personal data when you use MDRCloud services:

CategoryData PointsSource
Account & IdentityFull name, email address, username, date of birth (for age verification)Registration via MDRCloud ONE
Billing & PaymentBilling address, invoice history, payment method token (card last 4 digits, expiry)Stripe payment processor; never stored raw on MDRCloud servers
Service UsageProvisioned services, resource consumption metrics (CPU, RAM, storage, bandwidth), server IP addressesMDRCloud infrastructure monitoring
Support CommunicationsSupport ticket contents, email correspondence, chat logsMDRCloud ONE support portal
Technical & Log DataIP address, browser type, OS, pages visited, session duration, referral URLMatomo analytics (self-hosted), server access logs
CookiesSession cookies, preference cookies, analytics cookiesBrowser; see Section 7 for details

We do not collect or store raw payment card numbers, CVV codes, or full card details. All payment data is handled exclusively by Stripe in accordance with PCI DSS standards.

3

How We Use Your Data

MDRCloud uses your personal data for the following purposes:

  • Service Delivery — To provision, manage, and maintain your hosted services (LXC Containers, KVM Servers, Game Servers), including generating invoices and processing payments via Stripe.
  • Account Management — To create and manage your MDRCloud ONE account, authenticate you, and manage your service subscriptions.
  • Customer Support — To respond to your support tickets and provide technical assistance from our engineering team.
  • Service Communications — To notify you of scheduled maintenance, infrastructure incidents, billing alerts, and changes to these policies.
  • Fraud Prevention & Security — To detect and prevent fraudulent activity, unauthorised access, and abuse of our infrastructure.
  • Legal Obligations — To comply with applicable legal and regulatory requirements, including responding to valid law enforcement requests.
  • Service Improvement — To analyse aggregate, anonymised usage data to improve our services, infrastructure performance, and client experience.
  • Analytics — To measure website traffic and user behaviour via our self-hosted Matomo analytics platform (see Section 6).

We do not use your personal data for profiling, advertising, or marketing to third parties.

5

Third-Party Processors

MDRCloud works with a small number of carefully selected third-party processors to deliver our services. Each processor is bound by a Data Processing Agreement (DPA) and is required to handle your data in compliance with UK GDPR:

ProcessorPurposeData SharedLocation
Stripe, Inc.Payment processingName, billing address, payment method detailsUSA (EU-US DPF / UK adequacy)
Matomo (self-hosted)Website analyticsAnonymised IP, pages visited, session dataMDRCloud servers (UK/EU)
Infrastructure ProvidersPhysical hosting & network (e.g. Proxmox VE, VMware)Server resource data (no personal client data shared)EU / UK datacentres

MDRCloud does not sell, rent, or share your personal data with third parties for marketing purposes.

Stripe: Stripe is PCI DSS Level 1 certified. Raw card data never touches MDRCloud servers. For more information, see Stripe’s Privacy Policy.
6

Analytics & Tracking (Matomo)

MDRCloud uses Matomo, a self-hosted, open-source analytics platform, to understand how visitors use our website. Unlike third-party analytics tools (such as Google Analytics), Matomo is hosted entirely on MDRCloud’s own infrastructure at analytics.mdrcloud.com. Your data does not leave our control.

What Matomo Collects

  • Anonymised IP address (the last octet is masked before storage);
  • Pages visited and navigation path;
  • Browser type and operating system;
  • Referral source (the website that linked you here);
  • Session duration and interaction events.

Privacy-First Configuration

  • IP anonymisation enabled (last octet truncated);
  • No data is shared with Matomo Cloud or any third party;
  • Do Not Track (DNT) browser headers are respected;
  • No cross-site tracking or fingerprinting.

Opt-Out

You may opt out of Matomo tracking at any time. If your browser has “Do Not Track” enabled, Matomo will not track you. You may also use browser extensions such as uBlock Origin to block the analytics tracker.

7

Cookies Policy

MDRCloud uses a minimal number of cookies to operate our website and services. We do not use advertising or tracking cookies from third parties.

Cookie NameTypePurposeRetention
_pk_id.*Analytics (Matomo)Distinguishes unique visitors for analytics13 months
_pk_ses.*Analytics (Matomo)Tracks user session for analytics30 minutes
Session cookiesFunctional (MDRCloud ONE)Maintains your authenticated session in the client portalSession
Preference cookiesFunctionalStores UI preferences (e.g. plan tab selection)30 days

By continuing to use the MDRCloud website and client portal, you consent to our use of functional and analytics cookies as described above. You can manage cookie preferences through your browser settings at any time.

8

Data Retention

MDRCloud retains your personal data only for as long as is necessary for the purposes set out in this Privacy Policy, and in accordance with our legal obligations:

Data TypeRetention PeriodReason
Account & identity dataDuration of account + 2 years after closureFraud prevention and dispute resolution
Billing & invoice records6 years from date of transactionUK tax law (HMRC requirements)
Support ticket history3 years after account closureQuality assurance and dispute resolution
Server access logs90 daysSecurity monitoring and incident investigation
Analytics data (Matomo)24 months (anonymised)Service improvement; no identifiable data retained
Service data (on terminated servers)7 days after termination, then deletedSee Section 9 of the Terms of Service

After the applicable retention period, personal data is securely deleted or anonymised so it can no longer be associated with you.

9

Data Security

MDRCloud implements appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction. These measures include:

  • All data transmitted between your browser and MDRCloud is encrypted using TLS 1.2+;
  • MDRCloud ONE client portal sessions are authenticated and protected with industry-standard security measures;
  • Access to personal data is restricted to MDRCloud personnel on a need-to-know basis;
  • Payment data is handled exclusively by Stripe (PCI DSS Level 1 certified); MDRCloud does not store raw card data;
  • Infrastructure is protected by multi-terabit DDoS mitigation at the network level;
  • Regular security reviews and patch management are conducted on all MDRCloud systems.
Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, MDRCloud will notify the Information Commissioner’s Office (ICO) within 72 hours and will inform affected individuals without undue delay.
10

International Data Transfers

MDRCloud’s primary infrastructure and analytics (Matomo) are hosted within the United Kingdom and European Union.

The only third-party processor that may involve an international transfer is Stripe, Inc., which is headquartered in the United States. Stripe participates in the EU-US Data Privacy Framework and has a valid UK international data transfer mechanism in place, ensuring your payment data is protected to UK GDPR standards.

We do not transfer your personal data to countries that do not provide adequate protection under UK GDPR without appropriate safeguards in place.

11

Your Rights Under UK GDPR

As a data subject under the UK GDPR, you have the following rights with respect to your personal data held by MDRCloud:

👁
Right of Access
Request a copy of the personal data we hold about you (Subject Access Request).
✏️
Right to Rectification
Request correction of inaccurate or incomplete personal data.
🗑️
Right to Erasure
Request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
🔒
Right to Restriction
Request that we restrict the processing of your data in certain circumstances.
📤
Right to Portability
Receive your personal data in a structured, machine-readable format.
🚫
Right to Object
Object to processing based on legitimate interests, at any time.

To exercise any of your rights, please submit a request to privacy@mdrcloud.com. We will respond within one calendar month of receiving your request. In complex cases we may extend this by a further two months, and will inform you accordingly.

Where required, we may ask you to verify your identity before processing your request.

No Charge: Exercising your data rights is free of charge. However, if requests are manifestly unfounded, excessive, or repetitive, we may charge a reasonable administrative fee.
12

Children's Privacy

MDRCloud services are intended for individuals aged 18 and over. We do not knowingly collect personal data from persons under the age of 18. If we become aware that we have collected personal data from a minor without appropriate consent, we will take steps to delete that data promptly.

If you believe that a child has provided personal data to MDRCloud, please contact us at privacy@mdrcloud.com.

13

Changes to This Policy

MDRCloud may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or services. Where changes are material, we will notify registered Clients via the email address associated with your MDRCloud ONE account.

The “Last updated” date at the top of this page indicates when this policy was last revised. We encourage you to review this policy periodically.

Your continued use of MDRCloud services following notification of changes constitutes your acceptance of the updated Privacy Policy.

14

Contact & Complaints

Privacy Enquiries

For any questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact us:

Complaints to the ICO

If you are unhappy with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection:

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We’re Here to Help: We encourage you to contact us directly before escalating to the ICO, as we are committed to resolving any privacy concerns quickly and fairly.