TuployTuploy

Privacy Policy

Effective date: April 13, 2026 · Last updated: April 13, 2026

This Privacy Policy describes how ALIADO EXTERNO, SLU (hereinafter, "Tuploy", "we", "us" or "our"), a company incorporated under the laws of the Principality of Andorra, with company ID L-719104-A and registered office at Passatge Arnaldeta de Caboet, 11 Ed. La Torre 2-1, AD700 Escaldes-Engordany, Andorra, operator of the website tuploy.com and of the Tuploy Platform-as-a-Service (the "Platform"), processes personal data in its capacity as data controller. You may contact us at privacy@tuploy.com for any question regarding this Policy or to exercise your rights.

Tuploy is committed to protecting personal data and complies with Andorran Qualified Law 29/2021, of 28 October, on the protection of personal data ("LQPD") and, where applicable to EU residents, with Regulation (EU) 2016/679 ("GDPR"). The European Commission has recognized Andorra as offering an adequate level of data protection (Decision 2010/625/EU), which allows personal data to flow freely between the EU/EEA and Andorra.

1. Applicability of this Privacy Policy

This Privacy Policy applies exclusively to the processing of personal data carried out by us as a data controller. This Privacy Policy does not deal with the processing methods and data protection practices of third parties for which we are not responsible. If, for certain purposes, we process personal data as a data processor, you need to check the privacy information provided by the respective data controller. When we provide you with cloud services, we act as your processor towards your data in the cloud. This however does not impact other processing operations, when we act as a data controller. This Privacy Policy explains how we will use your personal data obtained directly from you. In accordance with Article 12 of Andorran Qualified Law 29/2021 (LQPD), we do not knowingly process personal data of persons younger than 14 years old without the authorization of the holders of parental responsibility.

2. Scope

This Policy applies to all personal data we process about:

  • Website visitors of tuploy.com and its subdomains.
  • Registered users of the Platform (accounts created via email, Discord OAuth or Google OAuth).
  • Customers with active subscriptions (App, Database or Website services).
  • Business contacts (partners, suppliers, prospects).
  • End users of applications deployed by our customers — only to a limited extent, as described in section 8.

It does not cover the content that customers deploy through Tuploy: for that content, the customer is the data controller and Tuploy acts as data processor under the Data Processing Agreement ("DPA"), which is incorporated by reference into the Terms and Conditions.

3. Categories of personal data we process

Depending on how you interact with us, we may process:

3.1 Account data

  • Email address
  • OAuth identifier (Discord / Google), display name and avatar (when you sign in with a third-party provider)
  • API keys and CLI authentication tokens
  • Organization / team name

3.2 Billing data

  • Name and billing address
  • VAT number (for business customers)
  • Subscription plan, services purchased (Apps, Databases, static Websites), usage records
  • Payment status and invoice history

Card details and bank information are not processed by Tuploy. All payments are handled by Paddle.com Market Limited (Paddle), acting as Merchant of Record. Paddle is an independent controller for payment data. See paddle.com/legal/privacy.

3.3 Technical / usage data

  • IP address, user-agent, device and browser information
  • Timestamps of logins, deployments and API calls
  • Deployment logs, build logs and runtime logs of your applications
  • Audit logs (account changes, domain changes, subscription changes)

3.4 Content data

  • Source code, container images, static assets and environment variables that you upload to deploy
  • Content of managed databases (PostgreSQL, MySQL, MongoDB) provisioned through Tuploy
  • Custom domain names and DNS configuration

For content data Tuploy acts as processor on behalf of the customer.

3.5 Communications

  • Support tickets, emails, chat messages with our team
  • Feedback and survey responses

4. Purposes and legal basis

We process the categories described in section 3 for the following purposes and on the following legal bases (LQPD Art. 6 / GDPR Art. 6):

CategoryPurposeLegal basis
Account data (3.1)Create and operate your account, authenticate you, provide the PlatformPerformance of the contract — Art. 6(1)(b)
Billing data (3.2)Charge for subscribed services, issue invoices, comply with tax and accounting obligationsContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Technical / usage data (3.3) — operational logsOperate, secure, debug and improve the Platform; detect abuse; enforce acceptable useLegitimate interest in operating and securing the service — Art. 6(1)(f)
Content data (3.4)Host, build, deploy and serve your Apps, Databases and Websites on your instructionsProcessed on behalf of the customer (processor role) — legal basis determined by the customer as controller
Communications (3.5)Respond to support and process feedbackContract — Art. 6(1)(b); legitimate interest in providing support — Art. 6(1)(f)
Service notifications (security, billing, legal)Send account, security and legal notices required to operate your subscriptionContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c)
Marketing communicationsSend optional product updates or commercial messagesConsent — Art. 6(1)(a); withdrawable at any time
Cookies and similarSee Cookies PolicySee Cookies Policy (consent or strictly necessary depending on type)

5. How we collect data

  • Directly from you: when you sign up, deploy a project, contact us, or fill forms on our website.
  • From your device/browser: cookies and similar technologies — see Cookies Policy.
  • From third parties: OAuth providers (Discord, Google) that share your basic profile upon login; Paddle, which shares limited billing metadata after a payment; abuse-intelligence services.

6. Recipients of personal data

We share personal data only with the following categories of recipients, and only to the extent necessary for the purposes listed in section 4:

  • Our subprocessors — third-party vendors that provide hosting and networking. The current list is published at /legal/subprocessors. These recipients act as our processors and only process data on our instructions.
  • Paddle.com Market Limited — Merchant of Record, acting as an independent controller of payment data (card details, bank information, fraud scoring). See paddle.com/legal/privacy.
  • Discord and Google — OAuth providers acting as independent controllers for the login flow when you choose to sign in with them. See Discord privacy policy and Google privacy policy.
  • Public authorities and courts — where we are required to disclose data by a valid legal request, subpoena or court order under applicable law.
  • Professional advisors (lawyers, accountants, auditors) bound by professional confidentiality, where strictly necessary to protect our rights.
  • Successors in the context of a merger, acquisition, reorganization or sale of assets, subject to equivalent data protection commitments.

We do not sell personal data and do not share it with advertisers or data brokers.

7. Retention

CategoryRetention
Account dataFor the lifetime of the account + 12 months after deletion
Billing and invoices6 years (Andorran tax and accounting obligation)
Deployment / build / runtime logs30 days rolling
Security / audit logs12 months
Support tickets24 months after the ticket is closed
Marketing dataUntil consent withdrawal or 24 months of inactivity
Paused Resource data (wallet reached €0)7-day grace window, then permanent deletion
BackupsAccording to the retention window of the subscribed Database tier

Once retention expires we delete or irreversibly anonymize the data.

Welcome credit and wallet lifecycle

New accounts receive €1 of welcome credit in their prepaid wallet after email verification, a valid payment method on file, and automated anti-abuse checks (email, IP, payment method, device fingerprint). The welcome credit is starting balance, not a time-boxed trial, and may be granted only once per person.

When the wallet reaches €0 — whether the welcome credit has been consumed or a paid balance has run out — the customer's metered Resources are paused immediately (container stopped, database made inaccessible) and enter a 7-day grace window. During that window, container state and database content are retained so that a wallet top-up reactivates the Resources in place. If no top-up occurs within the 7-day window, the Resources and their associated data are permanently deleted.

8. End users of customer applications

When customers deploy applications through Tuploy, end users of those applications interact directly with the customer. Tuploy processes incidental technical data (IP address, request headers for routing/SSL/abuse protection, load-balancer access logs) strictly to operate the reverse proxy and to comply with legal obligations.

For any personal data processed inside a customer's application or database, the customer is the sole controller. End users should contact the customer for rights requests related to that data.

9. International transfers

Tuploy infrastructure is primarily located in the European Union. In limited cases personal data may be processed outside the EU/EEA. In those cases we rely on:

  • Adequacy decisions of the European Commission (where available, e.g. EU–US Data Privacy Framework for certified US recipients), or
  • Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented by additional technical and organizational measures where required.

A copy of the transfer safeguards is available upon request at privacy@tuploy.com.

10. Security

We implement technical and organizational measures appropriate to the risk, including:

  • TLS 1.2+ for all external connections, with automated certificate issuance and renewal.
  • Private container registry authenticated with per-user tokens.
  • Strict IP allow-lists.
  • Role-based access control for staff, principle of least privilege, unique accounts, audit logging.
  • Regular backups of the Tuploy control plane and of customer databases according to the subscribed tier.
  • Monitoring and intrusion detection on the load balancer.
  • Incident response plan with breach notification to affected parties without undue delay after becoming aware of a personal data breach.

No system is perfectly secure. You must also keep your credentials, API keys and CLI tokens safe.

11. Your rights

Under the LQPD and, where applicable, the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten");
  • Restrict processing;
  • Object to processing based on legitimate interest or for direct marketing;
  • Data portability (receive your data in a structured, machine-readable format);
  • Withdraw consent at any time, without affecting the lawfulness of prior processing;
  • Lodge a complaint with the Andorran Data Protection Agency (Agència Andorrana de Protecció de Dades — APDA), c/ Dr. Vilanova 15-17, Edifici Della Silva, AD500 Andorra la Vella — https://www.apda.ad — or, if you reside in the EU/EEA, with your local supervisory authority.

To exercise any of these rights, write to privacy@tuploy.com. We will answer within one month from receipt of the request (extensible by two further months for complex cases).

12. Automated decision-making and profiling

We do not carry out automated individual decision-making, including profiling, that produces legal effects or similarly significant effects on you within the meaning of Article 22 GDPR. Abuse-protection, rate-limiting and fraud signals are used strictly to secure the Platform and never as the sole basis for a decision with legal effects.

13. Cookies

See our Cookies Policy.

14. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date above reflects the latest revision. Material changes will be communicated via email or through the dashboard at least 15 days before they take effect.

15. How can you contact us?

If you would like to exercise any of your rights set out above, if you would like to make a complaint about how we process your personal data, or if you have any other questions about how we process your personal data, you can contact us using the following email address: privacy@tuploy.com

Tuploy has not appointed a formal Data Protection Officer (DPO), as its processing activities do not meet the thresholds of Article 37 GDPR or Article 35 LQPD. Data protection queries are handled directly by the team at the address above.