failkit
How it worksPricingDocsSign in
Sign inStart trial

On this page

  1. Scope
  2. What we collect
  3. Why we collect it
  4. Sharing & sub-processors
  5. Retention
  6. Your rights
  7. Children's data
  8. International transfers
  9. Security
  10. Contact
  11. Changes

Legal

Privacy Policy

Last updated: 2026-04-28

Draft pending counsel review. This document describes how Failkit, Inc. handles personal data. Where it conflicts with a signed Data Processing Agreement (DPA), the DPA controls.

1. Scope

This policy covers personal data Failkit collects when you visit failkit.com, register for an account, use the Service, or contact us. It does not cover replicated VM payloads — those remain in Customer’s own cloud accounts and Failkit does not take custody of them. See the Security page for the data architecture.

2. What we collect

Account information

Name, work email, company name, role, and the password hash for accounts you create. For paid accounts, billing contact and payment-method metadata (we do not store card numbers; payment is handled by Stripe).

Telemetry

Technical metadata about your use of the Service: IP address, user-agent, request paths, error rates, feature-usage counts, drill timestamps, and replication-job metadata (source/target, RPO observed, byte counts — not the bytes themselves).

What we do not collect

Failkit does not collect or store the contents of your VMs. Replicated VM data is encrypted by the agent and written directly to your cloud-provider object store (S3, Azure Blob, GCS). Failkit’s management plane only handles metadata about those payloads — sizes, hashes, timestamps, target locations.

3. Why we collect it

We process personal data on the following legal bases:

  • Contract: account information and telemetry are needed to deliver the Service you signed up for.
  • Legitimate interest: aggregated, non-identifying usage patterns help us improve reliability and detect abuse.
  • Consent: we ask before sending product-marketing email; you can opt out at any time.
  • Legal obligation: we retain billing records for the period required by tax law.

4. Sharing & sub-processors

We share personal data with sub-processors that help us run the Service. Each is bound by data-protection terms equivalent to those we offer Customer.

Sub-processorPurposeData location
OVHcloudTenant cluster compute & storage (control plane)EU / US (per cluster)
CloudflareDNS, TLS termination, WAF for failkit.comGlobal CDN
AWS / Azure / GCPCustomer-selected cloud target for replicationCustomer-controlled region
StripePayment processingUS / EU
ResendTransactional email (provisioning, alerts)US

We never sell personal data. We do not share personal data with advertisers.

5. Retention

Account data is retained while your account is active and for 30 days after termination, after which it is deleted unless legally required to be retained (typically billing records, retained 7 years per US tax law). Telemetry is retained for 90 days in identified form, then aggregated into anonymous metrics.

6. Your rights

Depending on your jurisdiction, you may have the right to:

  • Access: request a copy of personal data we hold about you.
  • Rectification: correct inaccurate data.
  • Deletion: ask us to delete your data, subject to legal-retention exceptions.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interest.
  • No automated decisions: Failkit does not make automated decisions with legal effect.
  • CCPA opt-out: California residents may opt out of any “sale” of personal data — but as noted, we don’t sell.

To exercise any of these rights, email [email protected]. We respond within 30 days.

7. Children’s data

Failkit is a B2B product not directed at users under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.

8. International transfers

Personal data may be transferred to the United States and other jurisdictions where our sub-processors operate. We rely on the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where applicable. EU/UK customers may request our SCCs by emailing [email protected].

9. Security

We follow commercially reasonable security practices, including encryption in transit and at rest, per-tenant database isolation, least-privilege access controls, and a documented incident-response plan. The full posture is on the Security page.

10. Contact

Privacy questions, DSAR requests, or anything else: [email protected]. An EU representative will be designated when we begin offering the Service in the EEA at scale; until then, EU/UK individuals may contact [email protected] directly.

11. Changes

We may update this policy. Material changes will be announced at least 30 days in advance via email and a notice on the customer portal. The effective date is shown above.

© 2026 Failkit
TermsPrivacySecurityDocs

Signed by failkit