• Overview
    Frameworks
    • Drupal
    • WordPress
    • Symfony
    • Magento
    • See all frameworks
    Features
    • Observability
    • Auto-scaling
    Solutions
    • Marketing Teams
    • Retail
    • Higher Education
  • Pricing
  • Featured articles
    • Switching to Platform.sh can help IT/DevOps organizations drive 219% ROI
    • Organizations, the ultimate way to manage your users and projects
  • Support
  • Docs
  • Contact
  • Login
  • Free Trial

Privacy

Looking for our GDPR DPA? Find it here.


(1) Introduction
(2) Information We Collect
(3) Our use of Cookies and Urchin Tracking Modules (UTMs)
(4) How We Use Your Information
(5) Legal Basis for Processing Personal Information Under General Data Protection Regulation (GDPR)
(6) Your Data Protection Rights Under GDPR, Canada’s PIPEDA, and California's Consumer Privacy Act
(7) Storing, Securing, and Transfer of your Personal Data and Information
(8) Disclosing Your Personal Information
(9) Data Breaches
(10) Accessing and Updating Your Personal Information
(11) Third-party Links
(12) Children’s Privacy
(13) About Us
(14) Contact Us
(15) Changelog

(1) Introduction

Platform.sh offers many services, products, software, and offerings on related Platform.sh websites (the “Services”), including but not limited to, all information, tools and services available from this site to you, the user, conditioned upon your acceptance of all terms, conditions, policies and notices stated herein (the “Privacy Policy”). Through these Services, including software available for download, we obtain certain information from and about you. This Privacy Policy is specific to the Services that are run under the brand “Platform.sh” including but not limited to: https://platform.sh, https://docs.platform.sh, https://status.platform.sh, https://accounts.platform.sh, and https://console.platform.sh/. Note that this Privacy Policy explicitly excludes customer sites. These sites are subdomains under .platform.sh and .platformsh.site.

We value your privacy and are committed to safeguarding and preserving the privacy of our visitors. This Privacy Policy explains what information we collect, how we use that information, and other policies regarding your information and privacy. We have tried to make it as simple as possible, but if you do not understand something, please contact us. This Privacy Policy was written in English (US) and may be translated to other languages solely for the convenience of our site visitors. In all cases and specifically if a potential conflict between versions arises, the English version of this Privacy Policy controls.

(2) Information We Collect

We collect information that you give us or that we get from your use of our sites and Services, including without limitation, the following:

  • Information about your use of our Services, including details of your visits to our sites, pages viewed, and the resources that you accessed. Examples of information include device, IP address, browser information, cookie information, geographic location, and traffic data.

  • Information specifically provided by you, including your name, telephone number, email address, physical address, login username, password, or other information that you voluntarily share with us.

(3) Our use of Cookies and Urchin Tracking Modules (UTMs)

Cookies are small pieces of data stored on your device (computer or mobile device). Cookies can be used to provide you with a tailored user experience and to make it easier for you to use a site upon a future visit. When used, cookies are downloaded and stored on your device. Such information, on its own, will not identify you personally. It is statistical data. Generally, you can turn off the cookie function on your device, but that may prevent you from using our sites and Services. We may use such cookies to deliver and improve our Services. Some third-party services that we use to improve the Services (including usage, measuring performance, and advertising), such as Google Analytics, may also place cookies on your device.

Examples of Cookies we use:

  • Session Cookies. We use session cookies to operate our Services.

  • Preference Cookies. We use preference cookies to remember your preferences and various settings.

  • Advertising and Marketing Cookies. We use advertising and marketing cookies to deliver and measure the effectiveness of our marketing campaigns.

  • Security Cookies. We use security cookies for security purposes.

Urchin Tracking Module ("UTM") tags are distinct from cookies as defined above. UTM works as a custom Uniform Resource Locator (“URL”) parameter for marketing campaigns and reports can be viewed in platforms like Google Analytics. UTM tags are appended as part of the visible URL in marketing programs to understand the specific instance of a link. UTM tag reports are observed in Google Analytics or Marketo to better understand how our visitors are getting to our websites, and as such, who our visitors are. Such data is collected at an aggregate level, and will not identify you personally. Customizing the URL with UTM tags allows us to better understand marketing activity, which then allows us to better serve our customers and audience.

As part of this process, non-identifying and non-profiling information (source, medium, campaign, and Click ID), will be stored in your browser in local storage. No Personally Identifiable Information (“PII”) or personal data will be stored. This information would only be used by Platform.sh if you sign up for and consent to our service. At that point in time, campaign attribution information would be made available to Platform.sh to gauge the effectiveness of the campaign. You may clear your browser cache prior to signing up for our service to opt-out.

For any questions or preferences on cookie or UTM opt-outs, or about our policy listed here, please contact us.

(4) How We Use Your Information

We use the information we collect from you to provide, maintain, protect, and improve our sites and Services, and to develop new ones.

In addition, we may use the information for one or more of the following purposes:

  • To provide information to you that you request from us relating to our products or services

  • To provide information to you related to products or services provided by us

  • To inform you of any changes, offers, updates, or other announcements about our Services

  • To allow you to participate in interactive features of our Services when you choose to do so

  • To provide customer support

  • To gather analysis or valuable information so that we can improve our services

  • To monitor the usage of our Services

  • To detect, prevent, and address technical issues

  • To provide you with new Services offers and relevant Services information and events unless you have opted not to receive such information

Platform.sh provides tools to make your development workflow more productive, such as our command-line interface (CLI). Also, Platform.sh will occasionally provide application-specific modules or libraries, which you may opt into, for integration into your software project in order to make its configuration simpler. Such applications, libraries, or modules may report usage information to us, which we may collect. Information collected may contain the type of actions performed, log data of API activity, as well as configuration information. This information may be linked to you, and we may use this information to better provide technical support to you and to improve our Services.

If you are from the European Economic Area (EEA), Platform.sh’s legal basis for collecting and using the personal information described in this Privacy Policy depends on the data we collect and the specific context in which we collect it. For purposes of this Privacy Policy and compliance with the GDPR, personal information is data which alone or in combination with other information in Platform.sh’s possession, or likely to come into Platform.sh’s possession, can be used to identify a living individual.

Platform.sh may process your personal information because:

  • We need to perform a contract with you

  • You have given us permission to do so

  • The processing is in our legitimate interest and it’s not overridden by your rights

  • For payment processing purposes

  • To comply with applicable law

(6) Your Data Protection Rights Under GDPR, Canada’s PIPEDA, and California's Consumer Privacy Act

Your Rights Under GDPR: If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Platform.sh aims to take all reasonable steps to allow you to correct, amend, delete, or limit the use of your personal information and data. If you wish to be informed of what personal information and data we hold about you, and if you want it to be removed from our systems, please contact us. For existing customers, please file a support ticket.

In certain circumstances, you have the following data protection rights:

  • The right to access, update, or delete the information we have on you. Whenever made possible on your account settings, you can access, update, or request deletion of your personal information and data directly within your account settings section. Please also file a support ticket to confirm any account changes, or contact us to assist you.

  • The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.

  • The right to object. You have the right to object to our processing of your personal information or data.

  • The right of restriction. You have the right to request that we restrict the processing of your personal information.

  • The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable, and commonly used format.

  • The right to withdraw consent. You also have the right to withdraw your consent at any time when Platform.sh relied on your consent to process your personal information.

Please note that we may ask you to verify your identity before responding to such requests.

Your Rights Under Canada’s PIPEDA (Privacy Rights): The Personal Information Protection and Electronic Documents Act (PIPEDA) is the Canadian federal privacy law that regulates how private-sector organizations handle personal information in the course of commercial activity.

Under the PIPEDA principles, individuals have the right to know why their personal information is being collected, how their personal information will be used, to whom their personal information will be disclosed, and to ask for access to, or correction of, their personal information. More details on the PIPEDA principles can be found on the Office of the Privacy Commissioner of Canada’s site.

  • Accountability and Openness. Platform.sh has a designated Security, Compliance, and Data Protection Officer who is accountable for the management of your personal information, including collection, usage, disclosure, retention, and transfer of personal information to third parties for processing. Contact us to be connected or email dpo@platform.sh. For existing customers, please file a support ticket.

  • Identifying Purposes. When your personal information is collected, it will be clearly identified what purpose it is being collected for (e.g. when you sign up for the Services and enter your contact information to have customer support).

  • Consent. Your individual consent or consent on behalf of the organization is required when we collect, use, or disclose any such personal information. In certain circumstances, we may disclose your personal information for legal, medical, or security reasons. If at any time you wish to withdraw your consent, you will be notified of any account implications.

  • Limiting Collection. Platform.sh collects only the personal information which is necessary for the purposes identified at the time of collection (e.g. to provide you with technical support, and to improve your Services).

  • Limiting Use, Disclosure, and Retention. Platform.sh does not use or disclose personal information for purposes other than those which it has identified and received consent for in line with this Privacy Policy and only retains personal information for as long as is necessary to fulfill such purposes. Usage data is generally retained for 14 months or less, except when such information requires a longer retention period due to a compliance reason, legal obligation, security purpose, or legitimate business reason, such as improving Services.

  • Accuracy and Individual Access. Your personal information we collect may be deleted, updated, and/or completed in your account settings at any time, or you may contact us for assistance with making sure your information is accurate and up-to-date. Most changes will be reflected in your account immediately. Your request for account change or deleted information may be verified or retained if we have legal basis for doing so in accordance with this Privacy Policy.

  • Safeguards. Platform.sh uses physical, organizational, technological methods and policies to protect and safeguard your personal information. For more on our security, please visit platform.sh/security.

  • Challenging Compliance. Our procedures are in place to receive and respond to any complaints and inquiries you may have. Contact us or email our Security, Compliance, and Data Protection Officer at dpo@platform.sh. For existing customers, please file a support ticket.

Your Rights Under California’s Privacy Laws: The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), hereafter "CCPA", give California Consumers/residents additional new privacy rights and impose corresponding, and independent, obligations on businesses processing California Consumers’ Personal Information (PI). Where applicable, we have added contractual requirements instructing our service providers to not further collect, sell, share, or use the Consumers’ Personal Information except as necessary to perform their respective business purpose.

  • Consumer Right No. 1: Abbreviated Disclosure Right Applicable to Businesses that Collect PI. A Consumer has the right to request that a business that collects a Consumer’s PI disclose to that Consumer the categories and specific pieces of PI the business has collected. The types of Consumer Personal Data to be Processed are:

  • The names, email addresses, and other contact details of Consumer with whom we need to liaise in the provision of Services.

  • We may also collect: (a) names; (b) addresses; (c) countries; (d) email addresses, (e) telephone numbers; (f) financial data relating to orders; (g) IP Addresses; and (h) log files; as may be necessary to perform the Services and/or bill for such Services.

  • Consumer Right No. 2: Expanded Disclosure Right Applicable to Businesses that Collect PI.

  • The names, email addresses, and other contact details of Consumer with whom we need to liaise in the provision of Services.

  • We may also collect: (a) names; (b) addresses; (c) countries; (d) email addresses, (e) telephone numbers; (f) financial data relating to orders; (g) IP Addresses; and (h) log files; as may be necessary to perform the Services and/or bill for such Services.

  • Consumer Right No. 3: Right to Request Information from Businesses that Sell or Share PI for a Business Purpose. We do not sell or share PI as defined under the CCPA.

  • Consumer Right No. 4: Right to Opt-out of Sale or Sharing of PI. We do not sell or share PI as defined under the CCPA.

  • Consumer Right No. 5: Right to Opt-in for Children: Business Obligation Not to Sell or Share Children’s PI unless there is Affirmative Authorization. We do not sell or share PI as defined under the CCPA.

  • Consumer Right No. 6: Deletion Rights. Whenever made possible on your account settings, you can access, update, or request deletion of your personal information and data directly within your account settings section. Please also file a support ticket to confirm any account changes, or contact us to assist you.

  • Consumer Right No. 7: Rights to Access and Portability. You have the right to be provided with a copy of the specific pieces of PI obtained from the consumer in a format that is easily understandable to the average consumer, and to the extent technically feasible, in a structured, commonly used, machine-readable format, which also may be transmitted to another entity at the consumer's request without hindrance.

  • Consumer Right No. 8: Not to be Discriminated Against for Exercising Any of the Consumer’s Rights under the Title. We do not use financial incentive practices that are unjust, unreasonable, coercive, or usurious, and do not retaliate against those who choose to exercise their rights.

  • Consumer Right No. 9: Right to Correct Inaccurate PI. You have the right to request that we correct any inaccurate PI about you.

  • Consumer Right No. 10: Right to Limit Use and Disclosure of Sensitive PI. You have the right to direct that we limit the use of sensitive PI to the use that is reasonably necessary to perform the services expected by you. We do not collect sensitive PI as defined under the CCPA.

(7) Storing, Securing, and Transfer of your Personal Data and Information

Platform.sh only collects personal information that is relevant to the purposes set out in this Privacy Policy, and does not collect more personal information than what is necessary for those purposes. Platform.sh also ensures that the information it collects is sufficient to properly fulfill those purposes. Platform.sh will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your personal information to the extent reasonably necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Platform.sh retains usage data for a reasonable period of time to pursue legitimate business interests, or for internal analysis purposes. Usage data is generally retained for up to 14 months, except when this data is used to strengthen security, improve the functionality of our Services, or we are legally obligated to retain this data for longer time periods.

We take all reasonable measures to:

  • Protect your personal data and information, as well as our Services from, unauthorized access to, or unauthorized alteration, disclosure or destruction of, information we maintain.

  • Ensure that we are in compliance with the EU General Data Protection Regulation (GDPR), Canada's PIPEDA, the California Consumer Privacy Act, the Australian Privacy Act, and other privacy regulations as described in this Privacy Policy.

We may transfer personal data outside the European Economic Area (EEA) to countries with and without an EU adequacy decision to enable customers to rapidly deploy projects in any geographical region. Customer name, email, and ssh keys may be transferred from the Platform.sh Accounts portal located in Ireland to clusters in France, Ireland, USA, Australia, Canada, the UK, and Germany using securely encrypted transfer channels (TLS) and encrypted at rest. We transfer this data to companies that are GDPR compliant. Platform.sh signs Data Processing Agreements (DPAs) or Standard Contractual Clauses (SCCs) with all processors, and has replaced vendors who fail security, compliance, or privacy assessments. We also conduct Supplementary Measures Assessments on vendors who store personal data in non-adequate countries.

If you are an EEA customer, and you have agreed to our online Terms of Service, our EU DPA is automatically part of your agreement. We have adopted the European Commission's official, standardized, DPA clauses for controllers and processors in the EU, with minimal customizations that are listed out here.

If you are located in a country outside of the EEA or are bound strictly by paper terms, please Contact Us if you have any questions.

(8) Disclosing Your Personal Information

We will not disclose your personal information to any other party other than in accordance with this Privacy Policy and in the circumstances detailed below:

  • Consent:

    • We may disclose personal information if we have your specific consent to do so.
  • Co-sponsored activities:

    • When you sign up for a webinar or other activity that is co-sponsored by another company, we may share your registration information with that company.
  • Third-party Services:

    • We use trusted third-party service providers, consultants, and other agents to help us provide, maintain, protect, and improve our Services. We may provide your personal information to such third-party service providers to perform certain tasks based on our instructions and in compliance with this Privacy Policy.

    • Examples of third-party services include data storage, maintenance services, database management, web analytics, and payment processing. For a list of all third-party services or providers using your personal information or data, or to opt-out at any time, please contact us. For existing customers, please file a support ticket.

  • Legal:

    • We will share personal information if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to:

      • under certain circumstances, comply with legal obligations, meet applicable laws, regulations, or legal processes, or enforceable governmental requests (however, we will use reasonable efforts to provide notice to Platform.sh’s customers when we receive a request for customer personal data unless Platform.sh is explicitly prohibited from doing so by applicable laws)

      • enforce applicable Terms of Service or any of our other agreements with you, including investigation of potential breaches

      • detect, prevent, or otherwise address fraud, security, or technical issues in connection with the Services

      • protect against harm to the rights, property, liability, or safety of Platform.sh, our users and customers, or the general public, as required or permitted by law

      • prevent an emergency when a person is at risk of potential imminent death or serious physical injury, and Platform.sh may have personal data necessary to prevent such emergency

      • protect against apparent instances of child exploitation or missing children detected on Platform.sh’s services

  • Succession:

    • If we are involved in a merger, acquisition, or asset sale, you agree that your personal information may be transferred to such third-party.

If you wish to withdraw your consent of having your personal information used for certain purposes, please contact us. For existing customers, please file a support ticket.

All information you disclose in your public profile, forum posts, blogs, comments, issue queues, or other public portions of our Services becomes public information. Please be careful about what you choose to disclose publicly.

(9) Data Breaches

We will report any unlawful data breach of this website’s database or the database(s) of our third-party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is reasonably apparent that personal information stored in an identifiable manner has been accessed. Should you have any complaint about a breach, or the way in which we will handle a breach, please contact us.

(10) Accessing and Updating Your Personal Information

You have the right to access your personal information that we hold, and correct, amend, or delete that information where it is inaccurate, except where the rights of persons other than you would be violated. Please contact us to assist you. Whenever made possible, you can access, update, or request deletion of your personal information and data directly within your account settings section. If you are unable to perform these actions yourself (e.g. you don’t have an account), please contact us using the various methods detailed below to assist you. For customers located in Australia, you may also email "dpo@platform.sh".

Our Services may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third-party's site. We do not endorse these sites, nor are we responsible for the content or accuracy of any information contained on them. We strongly advise you to review the privacy policies of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

(12) Children’s Privacy

To the extent prohibited by applicable law, our Service does not address anyone under the age of 16 (“Children”). By agreeing to our Terms of Service, you represent that you are the age of majority in your state, province, or country of residence, or 16 years of age, whichever is greater. We do not knowingly collect personally identifiable information from anyone under such age of majority. If you are a parent or guardian and you are aware that your Children have provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verifiable verification of parental consent, we will take steps to delete that information from our databases and servers.

(13) About Us

Platform.sh is operated by Platform.sh SAS, a French company located at 131, Boulevard de Sébastopol, Paris, 75002 France which may include its affiliates, subsidiaries, directors, officers, employees, agents, partners, contractors, and/or licensors (together, referred to throughout this Privacy Policy as “Platform.sh”, “us”, or “we”). Our GDPR Supervisory Authority is the Commission Nationale de l'Informatique et des Libertés. Platform.sh is also registered with the Information Commissioner's Office in the United Kingdom and the Office of the Australian Information Commissioner. All privacy issues, compliance requests, inquiries, and other requests will be handled by our French parent company, Platform.sh SAS.

(14) Contact Us

Platform.sh has a designated Security, Compliance, and Data Protection Officer who is accountable for the management of your personal information, including collection, usage, disclosure, retention, and transfer of personal information to third parties for processing.

If you have any questions, requests, feedback, data rectification, or concerns regarding this Privacy Policy, please contact us. For existing customers, please create a support ticket through your account to allow for identity verification.

Visitors have the following options for correcting personal information or removing their information from our database in order to discontinue future communications from Platform.sh.

  • Click on the “Unsubscribe” link on any Platform.sh email

  • Contact us using our website contact form

  • Send a request by mail to: Attention Legal, Platform.sh, 131Boulevard de Sébastopol, Paris, 75002 France

Should you deem that we have not satisfactorily handled your complaint, you have the right to contact our Supervisory Authorities listed in the About Us section and file a complaint.

(15) Changelog

Platform.sh may update this Privacy Policy from time to time. When we materially change this policy, a prominent notice will be posted on our website along with the updated Privacy Policy. In accordance with the Terms of Service, in some cases, we will notify you in advance, and your continued use of the Services after the changes have been made will constitute your acceptance of the changes.

VersionDateChanges
1.02016-08-16
  • Original version
1.12017-10-25
  • Added information about GDPR compliance
1.22018-01-20
  • Added GDPR Supervisory Authority
2.02018-06-16
  • Updated from Legal Review
  • Added additional privacy-related compliance with GDPR, PIPEDA, and California
2.12018-11-05
  • Grammar and punctuation fixes
  • Added clause “and other privacy regulations as described in this Privacy Policy” to indicate that we take measures to ensure compliance with privacy regulations beyond just GDPR
  • Added toll-free contact number pursuant to the California Consumer Privacy Act of 2018
2.22019-04-23
  • Expanded Article 7 in regard to transferring your private data and information
2.32019-06-10
  • Added additional customer site information to the existing material in Section 1
3.02019-12-04
  • Expanded CCPA section with updated rights information
  • Removed toll-free number added in v2.1 as it is no longer required with recent CCPA revisions
  • Grammar and punctuation fixes
  • Converted changelog into table for readability
  • Revised "About Us" wording to include only our main office. Our full office list is available on our "Contact Us" page
  • Added information about how to file a complaint regarding a breach in compliance with the Australian Privacy Act
3.12019-12-05
3.22019-12-20
  • Additional Australian Privacy Act details
  • Fix spelling mistakes
  • Expand ways for filing complaints
  • Expand list of named privacy acts in Section 7
  • Clarify wording in Section 7 concerning where data is transferred to, including the explicit recognition of the UK
3.32020-01-09
  • Add DPO email address to Section 10 at the request of the Australian OAIC
  • Fix incorrect link to the OAIC in Section 13
3.42020-01-09
  • Fix grammar error
  • Add additional out-of-scope DNS entries to Section 1
3.4.12020-01-09
  • Add additional out-of-scope DNS entry to Section 1
3.52020-01-09
  • Wording and punctuation changes to improve clarity
  • Remove Privacy Shield
3.62021-03-29
  • Added development sites to list in Introduction section
  • Added data minimization language
3.72021-04-26
  • Add fr-4 region
  • Delete ovh-fr-1
3.7.12021-04-28
  • Add fr-3 region back to list after accidental deletion
3.82021-06-17
  • Expanded CCPA section to encompass CPRA rights
3.92021-09-03
  • Add au-2 region
4.02021-09-09
  • Remove regions list
  • Clarify in Section 1 what is excluded in this Privacy Policy
5.02021-09-24
  • Add EU DPA page link and applicability
6.02022-02-16
  • Update Section 3 to include UTMs and edit Section 8 to include new language regarding disclosing information to authorities
5
0
3
4
6
Deployments this week (including Fridays!)

Company

AboutSecurity and complianceTrust CenterBoard and investorsCareersPressContact us
5
0
3
4
6
Deployments this week (including Fridays!)
System StatusPrivacyTerms of ServiceImpressumWCAG ComplianceManage your cookie preferencesReport a security issue
© 2022 Platform.sh. All rights reserved.
Supported by Horizon 2020's SME Instrument - European Commission 🇪🇺