Legal
Privacy Policy
This policy explains what information Anested Cloud collects, why we collect it, how we use and protect it, who we share it with, and the choices and rights you have. It applies together with our Terms of Service.
Last updated: 20 July 2026
1. Scope of this Policy
This Privacy Policy applies to the Anested Cloud website, the customer dashboard, our APIs, and every service we sell — Cloud VPS, Web Hosting, Managed Databases (MySQL, PostgreSQL, MongoDB), Nest Storage and file serving, AI Chatbots, Web Analytics and DNS management (together, the “Services”).
It covers your personal data as our customer. Data belonging to your own users (visitors to sites you host, records in your databases, files in your storage) is your content — we process it only on your behalf, as described in Section 8.
2. Who We Are (Data Controller)
The entity responsible for your personal data is Anested Cloud (part of the Anested group), 5th Floor, Maurya Lok, Near Dak Bunglow Chowk, Patna 800001, Bihar, India. You can reach us at support@anested.com.
3. Information We Collect
3.1 Information you give us directly
- Account data — name, email address, and password (stored only as a salted hash) when you register; or your Google account email and display name if you sign in with Google.
- Verification data — one-time passwords (OTPs) sent to your email during registration or sensitive actions; these expire quickly and are not reused.
- Billing details — the plans you buy, coupon codes you apply, and any billing name/GST details you provide for invoices.
- Support communications — emails and messages you send us, including attachments.
- Service configuration — server names, site names, domain names, database names, chatbot knowledge you upload, and similar settings you create in the dashboard.
3.2 Information collected automatically
- Payment metadata — for fraud prevention we record the IP address and browser/device string (user agent) used at the moment a payment is completed, along with gateway identifiers (order ID, payment ID, refund ID) returned by our payment partner.
- Operational logs — API request logs, authentication events, audit logs of administrative actions on your resources, and error logs. These may include IP addresses and timestamps.
- Resource usage metrics — CPU hours, bandwidth/transfer, storage consumption and similar meters needed to enforce plan limits and show you usage dashboards.
- Cookies — see Section 6.
3.3 Information we do NOT collect
- We never see or store your full card number, card CVV, UPI PIN or banking passwords — these go directly to our payment gateway (Razorpay).
- We do not scan or read the private content of your servers, databases or storage buckets in the ordinary course of business (see Section 8 for the narrow exceptions).
- We do not buy data about you from data brokers, and we do not sell your personal data to anyone.
4. How We Use Your Information
- To create and administer your account, authenticate logins (including Google sign-in and OTP verification), and secure access to the dashboard and APIs.
- To provision, operate, meter and bill the Services you purchase — creating servers, sites, databases, storage buckets, chatbots and analytics sites, and generating invoices.
- To process payments, autopay mandates, renewals and refunds through our payment gateway, and to detect and prevent payment fraud (using the payment IP/device data described above).
- To send essential service communications — OTPs, invoices and receipts, renewal and expiry reminders, suspension warnings, security alerts and incident notices.
- To respond to your support requests and abuse reports.
- To monitor infrastructure health, investigate abuse of our Acceptable Use Policy, and protect the platform, other customers and third parties.
- To comply with legal obligations, including tax and accounting record-keeping.
- To improve the platform using aggregated, de-identified usage statistics that do not identify you.
5. Legal Basis for Processing
- Contract — most processing is necessary to deliver the Services you purchased under our Terms of Service.
- Legitimate interests — securing the platform, preventing fraud and abuse, and keeping operational logs.
- Legal obligation — retaining invoices and tax records, and responding to lawful orders.
- Consent — optional communications (if any) and any processing where the law requires consent; you may withdraw consent at any time without affecting prior processing.
We process personal data in accordance with applicable Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, to the extent applicable.
7. Payment Data
- All payments are processed by Razorpay Software Pvt. Ltd. Your card/UPI/netbanking credentials are entered directly into Razorpay's PCI-DSS-compliant checkout and never touch our servers.
- We receive and store only transaction metadata: order ID, payment ID, amount, currency, payment method label (e.g. “UPI”, “card ending 1234”), mandate/subscription IDs for autopay, and refund IDs.
- For recurring services, an autopay mandate is registered with the gateway; you can view its status on the invoice page and it is cancelled automatically when the related service is refunded or terminated.
- The IP address and device string captured at payment time are used solely for fraud prevention and dispute resolution, and are visible to you on your own invoice detail page.
8. Your Hosted Content & Customer Data
Everything you run or store on the Services — files on your VPS, website code, database records, storage objects, chatbot knowledge bases — is your content. For that data we act as a processor/intermediary on your behalf:
- We access your content only when strictly necessary: to execute actions you request (e.g. deploying a site, restoring access), to investigate a specific, evidenced abuse complaint or security incident, or when legally compelled.
- Automated systems may inspect resource usage patterns (CPU, network volume, connection counts) — not the substance of your data — to detect attacks and abuse.
- Our staff are bound by confidentiality obligations and access is logged.
- You are the controller of personal data belonging to your own users. You are responsible for having a lawful basis, your own privacy policy, and any consents required to process their data on our infrastructure.
10. Third-Party Processors
We rely on a small number of infrastructure and service providers, each processing only what is needed for its role:
- Razorpay — payment processing, autopay mandates and refunds.
- Google — optional Google sign-in (we receive your email and display name only).
- Cloud infrastructure providers — the data centres and virtual machines on which our platform, your servers and databases run.
- Managed database hosting — our own control-plane database is hosted on a managed cloud database service.
- Email delivery provider — sending OTPs, invoices and service notifications to your registered email.
Each provider is bound by its own security and privacy commitments; we choose providers with industry-standard safeguards and share the minimum data necessary.
11. Data Retention & Deletion
- Account data is retained for as long as your account is active.
- Service data lifecycle: when a paid service expires it is suspended with data retained; if not renewed within 30 days, the service and all its data are permanently deleted (as described in the Terms of Service). Deleted service data cannot be recovered.
- When a refund is approved, everything purchased under that invoice is permanently deleted at the time of approval.
- Invoices, payment records and tax-relevant data are retained for the period required by Indian tax and accounting law (generally up to 8 years), even after account closure.
- Operational and security logs are retained for a limited period appropriate to security investigation needs, then rotated out.
- If you close your account, we delete or de-identify your personal data within a reasonable period, except records we must keep by law or need to resolve disputes.
12. How We Protect Your Data
- Encryption in transit: dashboard, APIs and service endpoints are served over TLS (HTTPS).
- Passwords are stored only as salted hashes; server and database credentials are generated per-resource and shown to you at creation.
- Tenant isolation: every VPS, database project and hosting site runs in its own isolated environment, separated from other customers at the kernel/network level.
- Access controls: administrative access to production systems is restricted, authenticated and logged; audit logs record administrative actions.
- Payment isolation: card data is handled exclusively by our PCI-DSS-compliant payment gateway.
- No system is 100% secure. In the event of a data breach affecting your personal data, we will notify you and the relevant authorities as required by applicable law, without undue delay.
13. Your Rights & Choices
Subject to applicable law, you have the right to:
- Access — ask for a copy of the personal data we hold about you. Much of it is already visible in your dashboard (profile, invoices, resources).
- Correction — update inaccurate account details, either in the dashboard or by writing to us.
- Erasure — request deletion of your account and personal data, subject to the legal-retention exceptions in Section 11. Note that deleting your account deletes all your services and data.
- Portability — your content is always yours: you can export databases, download files and copy site code at any time while a service is active.
- Objection — object to processing based on legitimate interests; we will stop unless we have compelling grounds.
- Complaint — lodge a complaint with the relevant data protection authority if you believe we have mishandled your data. We would appreciate the chance to resolve it directly first.
To exercise any right, email support@anested.com from your registered address. We may need to verify your identity before acting, and we respond within the timelines required by applicable law.
14. Emails & Communications
- Transactional emails — OTPs, invoices, payment confirmations, renewal/expiry reminders, suspension and deletion warnings, refund updates and security notices are essential to the service and cannot be opted out of while you hold an account.
- Marketing or product-announcement emails, if we ever send them, will always include a working unsubscribe link, and unsubscribing never affects transactional emails.
- Keep your registered email deliverable — critical notices (e.g. the 30-day deletion warning) are sent there, and missing them does not extend any deadline.
15. Our Analytics Product & Your Visitors
- Our Web Analytics product is designed to be privacy-friendly for your site visitors: it collects aggregate metrics (page views, referrers, UTM parameters, custom events) without third-party advertising cookies or cross-site profiles.
- Analytics data collected from your sites belongs to your account; it is not shared with other customers and never sold.
- You remain responsible for your own legal obligations to your visitors (notices, consents where required by the laws that apply to you).
- Similarly, conversations your users have with your AI chatbots are stored under your account for your review and are processed only to operate the bot.
16. Children's Privacy
The Services are intended for adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.
17. Where Data Is Stored & Transfers
- Our infrastructure is primarily hosted in data centres located in India.
- Some processors (e.g. email delivery, sign-in providers) may process limited data outside India; where that happens, we ensure the transfer is protected by appropriate safeguards consistent with applicable law.
- The physical location of your own service (e.g. VPS region) is shown at purchase where a choice is available.
18. Disclosures to Authorities
- We disclose customer data to government or law-enforcement authorities only in response to a valid legal demand (court order, statutory notice, or equivalent) addressed to us, after reviewing it for legal sufficiency.
- Where legally permitted, we will notify you of a demand concerning your account before complying, so you may challenge it.
- We may voluntarily report content or activity when we in good faith believe it involves imminent danger to life, child exploitation, or terrorism.
19. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date above reflects the latest revision. Material changes will be announced via the platform or email at least 7 days before taking effect where reasonably practicable. Continued use of the Services after the effective date constitutes acceptance of the revised policy.
20. Contact & Grievance Officer
For any privacy question, data request, or grievance under applicable Indian law:
- Email: support@anested.com (subject line “Privacy” helps us route it faster).
- Address: Grievance Officer, Anested Cloud, 5th Floor, Maurya Lok, Near Dak Bunglow Chowk, Patna 800001, Bihar, India.
See also our Terms of Service and Terminology guide.