Ecstaticloud

Initializing0%
Ecstaticloud Logo

Legal & Compliance

Privacy Policy

Last Updated: October 15, 2026

At Ecstaticloud ("we", "us", or "our"), we engineer enterprise-grade cloud infrastructure with absolute zero-trust security. This Privacy Policy governs your use of our website, services, and B2B/B2C cloud architectures. We recognize that in our industry, data integrity and privacy are not just legal requirements—they are fundamental engineering principles.

1. Information We Collect

We collect information strictly necessary to provision, optimize, and secure your cloud infrastructure:

  • Account Data: Corporate email addresses, billing information, and role-based access control (RBAC) definitions.
  • Telemetry & Edge Metrics: Latency logs, request counts, CDN edge-cache hits, and generic network telemetry to maintain our 99.999% SLA.
  • Support Data: Technical logs, stack traces, and communication metadata when you engage our engineering support team.

2. Processing of Protected Health Information (PHI)

For clients utilizing our HIPAA-compliant infrastructure (such as the ArogyaHit PHR platform), Ecstaticloud acts strictly as a Business Associate. All PHI is encrypted at rest using AWS KMS (AES-256) and in transit via TLS 1.3. We do not access, mine, or process PHI for any purpose other than routing and secure storage as dictated by the Business Associate Agreement (BAA).

3. Zero-Trust Architecture & Data Storage

Our infrastructure defaults to zero-trust. Internal employee access to client infrastructure is strictly blocked unless explicitly granted via temporary, audited cryptographic tokens. Your data is stored within the geographic regions you select during cluster provisioning (e.g., `us-east-1`, `eu-central-1`) and never replicates outside those boundaries without explicit configuration.

4. Data Retention and Deletion

We retain operational telemetry for a maximum of 30 days for debugging purposes. Client database clusters and block storage volumes remain active for the duration of the contract. Upon termination, all data is cryptographically shredded within 72 hours via automated infrastructure-as-code pipelines.

5. Third-Party Subprocessors

To deliver our global edge network, we utilize industry-standard subprocessors (e.g., AWS, Google Cloud, Datadog). All subprocessors are strictly vetted for SOC2 Type II compliance and are legally bound to uphold the same rigorous privacy standards outlined in this policy.

6. Contact the Security Team

If you have questions regarding our cryptographic standards, data sovereignty practices, or this Privacy Policy, please contact our Chief Information Security Officer (CISO) directly at:

Email: security@ecstaticloud.com
PGP Key: Available upon request for secure transmission.