Privacy Policy
Last updated: May 13, 2026
1. Information We Collect
Account Information
When you create an account, we collect your name, email address, and organization name. Enterprise organizations may additionally configure SAML or OIDC single sign-on, in which case we receive the user attributes their identity provider asserts (typically name, email, group memberships).
Billing Information
Payment information (credit card details) is collected and processed by Stripe. We do not store your full card number, only the last four digits and expiration date for display purposes.
Usage Data
We collect data about your use of the Service, including: desktop creation and lifecycle events, login timestamps, IP addresses, browser user agent, streaming session metrics (FPS, latency), and feature usage. This data is used to operate the Service, generate billing records, and improve performance.
Desktop Contents
We do not access, monitor, or analyze the contents of your virtual desktops. Your files, applications, and desktop activity are yours. The exception is session recordings, which are enabled by your organization administrator and stored encrypted.
2. How We Use Information
- Providing and operating the Service
- Processing payments and generating invoices
- Sending transactional emails (verification, password reset, trial reminders)
- Monitoring service health and performance
- Enforcing our Terms of Service and Acceptable Use Policy
- Responding to support requests
- Generating anonymized, aggregate analytics to improve the Service
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Data Storage and Security
Encryption at rest
Desktop storage volumes (ZFS datasets) are encrypted with AES-256-GCM using ZFS native encryption. Shared-drive storage (SeaweedFS) is backed by the same ZFS pools and inherits the encryption.
Encryption in transit
All traffic between your browser and Canvex (including dashboard, file uploads, and browser-based desktop streaming via Apache Guacamole) is encrypted with TLS. Direct RDP connections use standard RDP encryption to the regional Caddy gateway, which terminates TLS and proxies to the desktop. Inter-server communication (cross-region replication, host-to-host control plane) uses WireGuard.
Multi-tenant isolation
Each organization runs in a dedicated Incus project, on a dedicated per-organization OVN logical network. Tenant desktops, VPN containers, and shared-drive credentials are scoped to that project, with no cross-organization filesystem, memory, or network path exists by design. Network ACLs explicitly default-deny cross-tenant traffic at the OVN level.
Operational controls
We implement industry-standard security measures including: role-based access controls, tenant-scoped and platform-scoped audit logging, two-factor authentication (TOTP with recovery codes), rate limiting on auth endpoints, IP allowlisting (Enterprise), and signed JWTs with httpOnly refresh-token cookies.
4. Data Processing Addendum
Enterprise customers can request a Data Processing Addendum (DPA) that incorporates Standard Contractual Clauses for international data transfers and binds Canvex to GDPR-aligned processing obligations. Email legal@canvex.io to request a signed copy.
5. Data Residency and International Transfers
Customer data is currently stored in data centers in Ohio, USA. We do not yet operate EU-resident regions. For European customers transferring personal data outside the EEA, the DPA referenced above incorporates the EU Commission's Standard Contractual Clauses (SCCs, June 2021) as the lawful transfer mechanism.
We do not transfer customer data to any country subject to a GDPR adequacy decision withdrawal at the time of this writing.
6. Security Incident Notification
In the event of a security incident affecting your data, we will notify the organization's primary administrator without undue delay and, where the incident triggers GDPR Article 33 reporting obligations, within 72 hours of becoming aware of it. Initial notice may be preliminary; we will update affected parties as the investigation progresses.
Suspected vulnerabilities can be reported to security@canvex.io. We commit to acknowledging reports within 5 business days and coordinating disclosure on a 90-day timeline.
7. Data Retention
- Account data: retained while your account is active, deleted 30 days after account closure
- Desktop data: retained while the desktop exists, deleted when the desktop is deleted
- Audit logs: retained for 1 year
- Session recordings: retained per your organization's configured retention period
- Billing records: retained for 7 years per financial reporting requirements
- Usage metering data: retained for the current billing period plus 90 days
8. Subprocessors
Canvex uses the following subprocessors to operate the platform. The data shared with each is limited to what its function requires.
- Stripe, Inc.: payment processing and subscription management. Receives billing contact, card tokens, transaction amounts.
- Postmark (ActiveCampaign / Wildbit, LLC): transactional email delivery (verification, password reset, trial reminders, desktop ready notifications, invoices). Receives recipient email address and message content.
- Cloudflare, Inc.: DNS management for tenant subdomains under
*.canvex.io. Receives DNS records only; no application data. - Let's Encrypt (Internet Security Research Group): TLS certificate issuance. Receives only public hostname/cert-request information.
Each subprocessor has its own privacy policy. Updates to this list will be reflected here and, for Enterprise customers with a signed DPA, notified per the DPA's change-of-subprocessor clause.
9. Cookies
We use essential cookies for authentication (JWT refresh tokens stored as httpOnly cookies) and session management. We do not use tracking cookies, advertising cookies, or third-party analytics scripts. No cookie consent banner is needed because we only use essential cookies required for the Service to function.
10. Your Rights
You have the right to:
- Access: request a copy of the personal data we hold about you
- Correction: update inaccurate personal information via your account settings
- Deletion: request deletion of your account and associated data
- Export: download your data from your virtual desktops at any time
- Objection: object to processing of your data for specific purposes
To exercise these rights, contact us at privacy@canvex.io or through in-app support.
11. Children's Privacy
The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
Questions about this policy? Contact us at privacy@canvex.io.