Who this notice covers
OneClient is operated by SansaVision. “OneClient,” “we,” and “us” refer to the provider identified in your checkout record, order form, or service communication. Contact us at support@sansavision.com for privacy questions or rights requests.
For account, website, billing, and service-administration information, we generally act as controller or business. For personal information that a customer submits to its OneClient project, the customer determines the purpose and generally acts as controller or business; OneClient acts as processor or service provider under the customer’s instructions.
Information we handle
- Account and organization: name, email, authentication records, organization membership, roles, and audit events.
- Billing: customer and subscription identifiers, product selections, invoice/payment status, tax-related location signals, credit ledger entries, and usage. Payment-card data is collected by Stripe rather than stored in OneClient application databases.
- Developer activity: projects, configuration, deployment metadata, domains, keys metadata, build/runtime logs, support communications, and security events.
- Customer project data: content customers place in databases, object storage, KV, authentication, email, analytics, jobs, and AI requests, according to their instructions.
- Website and device: IP address, browser/device information, requested pages, referrer, diagnostics, security signals, and optional analytics only after applicable consent.
Why we use it
We use information to provide and secure the service; authenticate users; provision resources; process subscriptions, top-ups, taxes, and domains; meter and limit usage; deliver requested email and AI operations; support customers; prevent abuse; comply with law; and improve the service where permitted.
Where EU/EEA or UK law applies, our legal bases may include performing a contract, legitimate interests in operating and securing the service, compliance with legal duties, and consent for optional cookies or communications where required.
Sharing and subprocessors
We share information only as needed with infrastructure, payments/tax, email, source-control, support, security, and professional-service providers; with customer-authorized integrations; during a corporate transaction; or when legally required. Key infrastructure and payments providers currently include Cloudflare and Stripe. A customer may also select third-party AI providers using its own credentials.
Providers process information under contracts and access restrictions appropriate to their role. International transfers use available legal mechanisms where required. Contact us for current transfer and subprocessor details applicable to your service.
Retention
We retain account and service records while an account is active and as needed for security, disputes, financial records, and legal obligations. Product logs and build artifacts follow plan-specific periods. When a project is suspended for unfunded usage, funded export access and retained project data are maintained for the stated 30-day period before an idempotent deletion workflow, unless law, a dispute, or a customer agreement requires otherwise. Backups and provider deletion queues may take additional time to age out.
Your rights and choices
Depending on location, you may have rights to access/know, correct, delete, receive a portable copy, object to or restrict processing, withdraw consent, opt out of sale/sharing or targeted advertising, limit certain sensitive-information uses, and receive non-discriminatory service after exercising a right. We do not sell personal information for money. The marketing site does not activate optional analytics until consent where required.
Send a request to support@sansavision.com. We may verify identity and authority, and may retain information where an exception applies. Authorized agents should identify the person represented and provide legally sufficient authority. You may also complain to your local supervisory or privacy authority.
Children
The service is intended for organizations and developers, not children. We do not knowingly collect personal information from children in circumstances requiring parental consent. Contact us if you believe a child provided information improperly.
Security
We use tenant isolation, scoped credentials, encryption in transit, secrets controls, audit trails, prepaid reservations, runtime limits, and monitoring intended to protect information. No system is completely secure; customers remain responsible for their application configuration, access policies, end-user notices, and lawful instructions.
Changes
We will update the date above when this notice changes. Material changes may also be communicated in the console or by email when appropriate.