Skip to content
HomeCloud VMTransitCDNEdge CDNLocationsPricing
Home Cloud VM Transit CDN Edge CDN Locations Pricing
  1. Home
  2. Privacy Policy
Legal

Privacy Policy

Last updated 2026-09-03

What we collectAccount, billing, payment tokens, service configuration, security logs and anti-fraud device signals — Section 2.How long we keep itRetention periods for accounts, invoices, sign-in logs, tickets and eSIM records — Section 8.Your rightsAccess, correction, deletion, export and complaints, and how to close your account — Section 10.
On this page
1Who We Are and Scope2Information We Collect3How We Use Information4Legal Bases for Processing5Cookies and Local Storage6How We Share Information7International Transfers8Data Retention9Security10Your Rights11Customer Content and Your Own Users12Children13Changes to This Policy14Contact

On this page

1Who We Are and Scope2Information We Collect3How We Use Information4Legal Bases for Processing5Cookies and Local Storage6How We Share Information7International Transfers8Data Retention9Security10Your Rights11Customer Content and Your Own Users12Children13Changes to This Policy14Contact

This Privacy Policy explains how ISIF (“we”, “us”, “our”) collects, uses, shares and protects personal data when you visit https://cloud.isif.net, create an account, or use any of our services — including cloud virtual machines, IP transit and network services, CDN, tunnels, ASN and IP address resources, travel eSIMs, and the support and billing tools that come with them (together, the “Services”).

We have tried to write this policy the way we would want to read it: in plain language, describing what we actually do rather than everything we could theoretically do. If anything here is unclear, please ask us before you rely on it.

This policy forms part of our Service Agreement & Terms of Service. Capitalised terms not defined here have the meaning given to them in the Terms.


Section 1 – Who We Are and Scope

The Services are provided by the following ISIF entities, which act as the controller of your personal data:

  • ISIF OÜ, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia — for customers located in the European Economic Area, the United Kingdom and Switzerland;
  • ISIF LIMITED, Unit A7, 12/F Astoria Building, 34 Ashley Road, Tsim Sha Tsui, Hong Kong — for all other customers.

Both entities share the same platform and the same security controls, and either may process your data on behalf of the other. This policy applies to personal data we process as a controller. Where you use our infrastructure to process other people’s data (for example, on a virtual machine you rent from us), you are the controller of that data and we act as your processor — see Section 11.


Section 2 – Information We Collect

2.1 Information you give us

  • Account details — name, email address, password (stored only as a salted hash), preferred language, and optionally a nickname, phone number, date of birth and organisation name.
  • Billing details — billing address, company name, VAT / tax identification number and the contact person on invoices. We are required to keep accurate invoicing records for tax purposes.
  • Payment details — when you pay by card, the card number is entered directly into our payment processor’s secure form and never touches our servers. We store only the token the processor returns, the last four digits, the card brand and expiry date, so that you can recognise a saved card. Payments made through PayPal, WeChat Pay, Alipay, bank transfer or cryptocurrency gateways give us a transaction reference and the payer identifier the gateway shares with merchants.
  • Identity and network resource documents — when you register an ASN, announce IP prefixes, request a Letter of Authorisation or open a BGP session, we collect the resource identifiers, registry contact details and any supporting documents you upload.
  • Service configuration — hostnames, operating-system choices, SSH public keys, cloud-init user names and passwords (encrypted at rest and only forwarded to your machine), DNS records, CDN origins, tunnel endpoints and similar settings needed to build what you ordered.
  • Support communications — the content of tickets, attachments and messages you send us, and our replies.
  • Affiliate programme data — if you join our affiliate programme, the payout details you provide and the referral activity attributed to your code.

2.2 Information we collect automatically

  • Access and security logs — IP address, approximate location derived from it, browser and device type, the time and outcome of sign-in attempts, the sign-in method used (password, two-factor code, passkey or a linked social account) and security-relevant actions such as password, email or two-factor changes.
  • Device signals for fraud prevention — our web application generates a device fingerprint (a hash derived from browser and hardware characteristics) and sends it with requests. We use it, together with IP data and payment signals, to detect duplicate accounts, stolen payment instruments and abuse of free or trial offers. It is not used for advertising and is not shared with advertisers.
  • Service telemetry — resource usage of the Services you rent (for example CPU, bandwidth, traffic volume, eSIM data consumption) and operational logs of our network equipment. This is metadata about your use of the Services; we do not inspect the content of traffic passing through them except where strictly required to investigate abuse, outages or a lawful request.
  • Website analytics — we use a self-hosted instance of Umami, a privacy-focused analytics tool. It does not use cookies, does not build cross-site profiles and stores only aggregated page-view statistics with the IP address truncated.

2.3 Information from third parties

  • Social sign-in — if you sign in or link an account with GitHub, Google, Discord or WeChat, the provider sends us your provider user ID, display name, email address and avatar. We do not receive your password for that provider.
  • Payment processors — fraud-risk indicators and dispute information about a transaction.
  • Public registries — data about ASNs and IP prefixes published by Regional Internet Registries (such as RIPE NCC and APNIC), used to validate resource ownership.
  • eSIM connectivity partners — the ICCID, activation state, network attachment and data-usage counters of eSIM profiles we provision for you.

Section 3 – How We Use Information

We use personal data for the following purposes:

  • Providing the Services — creating your account, provisioning and operating what you order, and letting you manage it through the dashboard and API.
  • Billing — issuing invoices and receipts, collecting payments, calculating taxes, processing refunds and credits, and pursuing unpaid amounts.
  • Security and fraud prevention — verifying sign-ins, protecting accounts with two-factor authentication and passkeys, detecting account takeover, identifying duplicate or fraudulent accounts, and investigating abuse of our network.
  • Support — answering tickets, diagnosing faults and notifying you of maintenance or incidents that affect your Services.
  • Service and security notices — sending transactional email such as invoices, renewal reminders, verification codes and security alerts. These are part of the Service and cannot be opted out of while you hold an account.
  • Legal compliance — keeping accounting records, responding to lawful requests, sanctions screening, and meeting our obligations as a network operator and as a provider of telecommunications-adjacent services such as eSIMs.
  • Improving the Services — understanding which pages and features are used, in aggregate, so that we can prioritise what to build and fix.

We do not sell personal data, we do not use it for third-party advertising, and we do not make decisions with legal or similarly significant effects on you based solely on automated processing. Fraud-detection signals may place an order on hold, but a person reviews the case before an account is closed or a refund is refused.


Section 4 – Legal Bases for Processing

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract — account, billing, service configuration and support data (Article 6(1)(b)).
  • Legal obligation — invoicing and accounting records, tax reporting, and responses to lawful requests (Article 6(1)(c)).
  • Legitimate interests — security logging, fraud and abuse prevention, network operations and aggregate analytics (Article 6(1)(f)). We have balanced these interests against your rights and believe they are what a reasonable customer of an infrastructure provider would expect.
  • Consent — optional profile fields and anything else we ask you to opt in to explicitly. You can withdraw consent at any time without affecting the lawfulness of earlier processing (Article 6(1)(a)).

Where the Hong Kong Personal Data (Privacy) Ordinance applies, this policy also serves as our Personal Information Collection Statement. Providing the data marked as required during registration and checkout is necessary to supply the Services; if you choose not to provide it, we cannot open an account or fulfil an order.


Section 5 – Cookies and Local Storage

We keep browser storage to a minimum. The dashboard uses:

PurposeWhat is storedLifetime
Keeping you signed inAn API access token issued when you sign inUntil you sign out, the token expires, or you revoke it from Account → Security
Remembering your preferencesInterface language, light/dark theme, layout settingsUntil cleared by you
Affiliate attributionThe referral code from the link you arrived onUntil you register or clear storage
Fraud preventionA cached copy of the device fingerprint described in Section 2.2Until cleared by you
Payment Cookies set by our payment processors on their own hosted pages and embedded forms, as described in their policies Set by the processor

We do not use advertising cookies or third-party tracking pixels. Our analytics (Umami) is cookie-free. Because the items above are strictly necessary for the Service or are non-tracking preferences, we do not show a cookie consent banner. You can clear browser storage at any time; doing so will sign you out.


Section 6 – How We Share Information

We share personal data only with parties that need it to deliver the Services, and only as much as they need:

  • Payment processors and banks — Stripe, PayPal, WeChat Pay, Alipay/Antom, cryptocurrency payment gateways and our banks receive the data required to take a payment, prevent fraud and handle chargebacks. They are independent controllers for the data they collect on their own pages.
  • Infrastructure and connectivity partners — the data centres that house our equipment, the upstream carriers that provide transit and cross-connects, and the mobile network operators and eSIM platform behind our travel eSIMs. They see the technical identifiers needed to deliver a circuit, an IP announcement or a mobile data session (for example your IP addresses, ASN, ICCID or MSISDN), not your account profile.
  • Internet registries — when you ask us to register or announce network resources, the contact details and route objects you supply are published in the relevant public registry (RIPE, APNIC and similar) as required by those registries’ policies. Registry records are public by design.
  • Service providers acting for us — hosting and content-delivery providers (including Cloudflare for our public website), transactional email delivery, error and uptime monitoring, and ticketing tools. These providers process data under contract and only on our instructions.
  • Identity providers — when you use social sign-in, the provider learns that you signed in to ISIF Cloud.
  • Legal and safety — courts, regulators, law-enforcement bodies and other parties where we are legally required to disclose data, or where disclosure is necessary to protect our network, our customers or the public from fraud, abuse or harm. We review every request for validity and scope, and we push back on requests that are overbroad.
  • Corporate transactions — if ISIF is involved in a merger, acquisition or sale of assets, your data may be transferred as part of that transaction, subject to this policy and with notice to you.

We never sell personal data and never share it with data brokers or advertising networks.


Section 7 – International Transfers

We operate infrastructure in several countries, and the two ISIF entities are established in Estonia and Hong Kong. Your data may therefore be stored or accessed outside the country you live in, including outside the EEA.

Where data leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum), an adequacy decision where one exists, or another lawful transfer mechanism, together with supplementary measures such as encryption in transit and at rest. Data that must stay within a region to deliver a Service — for example a virtual machine you deliberately placed in a specific data centre — stays where you put it.


Section 8 – Data Retention

We keep personal data only for as long as one of the purposes in Section 3 requires it. In practice:

DataRetention
Account profile and settingsFor the life of the account, then deleted or anonymised within 90 days of closure
Invoices, receipts, payment records and related identity information 7 years after the end of the financial year in which they were issued, as required by accounting and tax law
Sign-in history and security logs12 months, or longer where an incident is under investigation
Device-fingerprint and fraud signals Up to 24 months after the last activity; longer for accounts closed for fraud or abuse, so the pattern can be recognised if it returns
Support tickets3 years after the ticket is closed
Service configuration and content on cancelled Services Deleted from production shortly after cancellation and purged from backups within 30 days, unless a refund dispute is open
Network operational logs (flow metadata, router logs) Typically 90 days; some network resource records must be kept as long as the resource is registered to you
eSIM provisioning records As required by the mobile network operator and applicable telecommunications rules, generally 12–24 months after the profile expires

Backups are rotated on a fixed schedule and are not searched or restored except to recover from a failure. Where a legal hold applies, retention is extended until the hold is lifted.


Section 9 – Security

We are an infrastructure company; protecting the platform is our day job. Measures include:

  • TLS for all traffic between your browser, our API and our internal services;
  • passwords stored as salted hashes, and secrets such as two-factor keys, cloud-init credentials and recovery codes encrypted at rest;
  • optional two-factor authentication and passkeys for every account, with recovery codes, and email alerts when a password, email address or second factor changes;
  • automatic pruning of expired sessions and the ability to review and revoke active sessions and API tokens yourself;
  • role-based access for staff, with administrative access limited to the people who need it and logged;
  • network segregation between customer workloads, and monitoring for abuse and anomalies.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority without undue delay, as the law requires. You can help by keeping your account credentials private, enabling two-factor authentication and telling us promptly if you notice anything unusual.


Section 10 – Your Rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify data that is inaccurate or incomplete — most profile and billing details can be edited directly in the dashboard;
  • erase your data, subject to the retention obligations in Section 8;
  • restrict or object to processing based on legitimate interests;
  • port data you provided to us to another provider in a machine-readable format;
  • withdraw consent where consent is the legal basis;
  • lodge a complaint with a supervisory authority — in Estonia the Data Protection Inspectorate (Andmekaitse Inspektsioon), in Hong Kong the Office of the Privacy Commissioner for Personal Data, or the authority in your own country.

To exercise any of these rights, open a support ticket from your account or use the contact channels listed at https://isif.net/contact. We may ask you to confirm your identity — usually by responding from the account’s email address or completing a two-factor challenge — before acting on a request. We respond within one month, and will tell you if we need longer for a complex request. There is no charge unless a request is manifestly unfounded or excessive.

To close your account entirely, cancel all active Services first so that no further charges accrue, then submit a closure request through a ticket. We will confirm what will be deleted and what must be retained.


Section 11 – Customer Content and Your Own Users

Data that you store or process on infrastructure rented from us — the contents of your virtual machines, the traffic crossing your circuits, the records you publish through our DNS or CDN — is your content. You decide what it is, how long it is kept and who may access it. For that content we act only as a processor: we store and transmit it on your instructions, we do not read it, and we do not use it for any purpose of our own.

If you process personal data belonging to other people on our Services, you are responsible for having a lawful basis to do so and for complying with the laws that apply to you. A data processing agreement setting out our obligations as your processor is available on request.


Section 12 – Children

The Services are business infrastructure and are not directed at children. We do not knowingly collect personal data from anyone under 18, or under the age at which a person can enter into a binding contract in their jurisdiction. If you believe a minor has created an account, contact us and we will remove it.


Section 13 – Changes to This Policy

We will update this policy when our practices change or the law requires it. The date at the top shows the current version. For material changes — for instance a new category of data, a new purpose, or a new type of recipient — we will notify account holders by email or a dashboard notice before the change takes effect. Continued use of the Services after that date means the updated policy applies.


Section 14 – Contact

Questions, requests and complaints about privacy can be sent to:

ISIF OÜ
Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia

ISIF LIMITED
Unit A7, 12/F Astoria Building, 34 Ashley Road, Tsim Sha Tsui, Hong Kong

The fastest route is a support ticket from your account; other contact channels are listed at https://isif.net/contact.


Dedicated to providing high-performance, reliable cloud computing for businesses and developers.

Cloud VMs, IP transit, CDN and travel eSIMs across Asia-Pacific and US-West metros — transparent pricing, self-service provisioning, cancel anytime.

Products & ServicesCloud VMIP TransitDedicated Internet AccessTravel eSIMCDNEdge CDNTunnel
Resources & SupportData CentersPricingAffiliateTerms of ServicePrivacy Policy
AccountSign InSign Up
© 2026 ISIF Cloud. All rights reserved.