Privacy Policy

Sarpius

Last Updated: September 24, 2026

This translation is for convenience only - the English version is authoritative.

1. Introduction

This Privacy Policy explains how Sarpius ("we", "our", "us"), a trading name of Synthwave-technologies.nl, processes your personal data when you use our platform: app hosting (deploy from git, static and container apps), managed PostgreSQL databases, S3-compatible object storage (buckets), managed messaging queues, scheduled jobs, custom domains with TLS and edge caching, our in-browser code editor, and API/MCP access for developers and AI agents (collectively the "Services"). Synthwave-technologies.nl is registered with the Dutch Chamber of Commerce (KVK) under number 73239038. We comply with the General Data Protection Regulation (GDPR) and other applicable Dutch and EU data-protection laws.

2. Who We Are

Synthwave-technologies.nl (KVK 73239038) is an eenmanszaak based at Arnhemseweg 127, 7331BE Apeldoorn, the Netherlands. Sarpius is its trading name for the Services described in this policy. Our primary domains are sarpius.eu (website and console) and sarpius.dev (platform endpoints, such as your apps and API/MCP access); the legacy domains synthcloud.nl and synthwave-technologies.nl still redirect to sarpius.eu or serve some endpoints. Our VAT identification number is NL002410192B67.

3. Data We Collect

Account information - name, company name, billing address, email, VAT number (if applicable).
Social login data - if you sign up or sign in with GitHub, GitLab or Gitea, we receive the account id, username, email and name from the provider you choose.
Payment details - transaction IDs and last four digits of card/IBAN (processed by our payment partner).
Service-operation data - IP addresses, access and error logs, and resource-consumption metrics.
Device and browser fingerprint - a hashed technical fingerprint used only for fraud and abuse prevention, see "Device and Browser Fingerprinting" below.
Identity verification data - if you complete identity verification, see "Identity Verification (KYC)" below.
Referral code - a ?ref= code you arrive with is kept only in page memory until you register; we do not set a cookie for it.
Contact-form messages - anything you send us through a contact or support form.
Self-hosted diagnostics and product telemetry - we operate our own Sentry and Matomo instances. Session Replay records a sample of sessions, plus sessions where an error occurs, with all on-screen text, form inputs and media masked as configured, so it shows clicks, navigation, page addresses (URLs) and page structure, and is set up not to capture what you typed or read; a replay is not linked to your account. Matomo runs without cookies. This telemetry remains under our control; we do not send it to an external analytics or observability provider, use it for advertising, or sell it.
Support communications - tickets, chat logs, and email correspondence.
Abuse-prevention signals - telemetry generated by automated tools that detect malware, cryptomining, or other misuse.

Account information is required to provide the Services: it is what our contract with you is built on, and without it we cannot create or operate your account. Identity verification is optional; see "Identity Verification (KYC)" below for what happens if you decline.

4. Why We Process Your Data (Legal Bases)

PurposeLegal basis (GDPR)
Provide and maintain ServicesArt. 6(1)(b) - contract performance
Social loginArt. 6(1)(b) - contract performance
Billing & paymentsArt. 6(1)(b) & (c) - contract & legal obligation
Fraud & abuse preventionArt. 6(1)(f) - legitimate interest
Device and browser fingerprinting for fraud preventionArt. 6(1)(f) - legitimate interest
Identity verificationArt. 6(1)(f) - legitimate interest
Customer supportArt. 6(1)(b) - contract performance
Service reliability and product improvement through our self-hosted telemetryArt. 6(1)(f) - legitimate interest
Legal compliance (tax, accounting)Art. 6(1)(c) - legal obligation

5. Data Sharing

We do not sell, rent, trade, or use personal data for advertising. We share personal data only where necessary to provide or protect the Services:

  • Mollie, our payment processor, to complete transactions.
  • Cloudflare, for DNS, CDN, and DDoS protection. Cloudflare receives the network data needed to protect and route traffic.
  • Other essential sub-processors listed on our Sub-processors page, where required to operate a service.
  • Authorities or courts when legally required.
Our self-hosted Sentry and Matomo installations are operated by us and are not external analytics or observability providers. Discord receives notifications about platform events but no personal data, so it is not a sub-processor.

6. Where Your Data Is Hosted

Our core infrastructure and stored account and application data are hosted within the European Union, primarily in the Netherlands. We operate our compute and storage regions exclusively within the EU / European Economic Area (EEA), and any regions we add in the future will remain within the EU/EEA.

We use Cloudflare's globally distributed DNS, CDN, and DDoS-protection network because reliable network protection is essential to a public PaaS. In providing that protection, Cloudflare may process limited network data, such as IP addresses, hostnames, headers, and traffic metadata, outside the EEA. Where a transfer occurs, we rely on GDPR-approved safeguards such as adequacy decisions (including the EU-US Data Privacy Framework where applicable), Standard Contractual Clauses, or other lawful transfer mechanisms.

We deliberately limit dependency on this edge provider: our core control plane, stored data, compute, and storage remain independent, and our DNS and edge routing can be changed without changing the application platform. If we decide, after a documented assessment, to use another provider outside the EEA, we will use only what is necessary, minimise the personal data, access, and technical dependency involved, apply the required transfer safeguards, and update our Sub-processors page where applicable.

7. Device and Browser Fingerprinting

When you register or sign in, we collect a technical fingerprint, only at that moment and not while you use the Services: your browser's user agent, platform, language(s), timezone, screen and window size, pixel ratio, CPU core count, device memory, number of touch points, whether an automation/webdriver flag is present, browser plugin count, and canvas/WebGL/audio rendering characteristics. These signals are hashed and sent, together with your IP address, to Spectra, our in-house anti-fraud engine.

We use this only to prevent fraud and abuse: detecting duplicate or alternate accounts, suspension evasion, and free-tier or payment abuse. The legal basis is our legitimate interest, Art. 6(1)(f) GDPR. We never use this fingerprint for advertising, never share it across unrelated sites, and never sell it.

You have the right to object to this processing under Art. 21 GDPR; email [email protected]. Objecting may mean we cannot offer you the free tier or certain account trust levels, since this is how we tell a genuine new customer from repeated abuse.

8. Identity Verification (KYC)

We may ask you to verify your identity to lift a restriction on your account or to reach a higher trust tier; identity verification is never required simply to use the platform in general. Verification is handled in-house, without an external provider.

We ask for your name, date of birth, document type and expiry date, and an image of an accepted identity document: a passport, national ID card, or driving licence. When you submit a photo, please cover your citizen service number (BSN) and anything on the document beyond name, date of birth, document type and expiry; we recommend the Dutch government's KopieID app for this.

Document images are encrypted (AES-256-GCM) and access is limited to staff holding the reviewer role; every view is logged and watermarked with the reviewer's name. Images are deleted 30 days after the verification decision; the outcome itself (verified or not, and the date) is kept for as long as your account exists. The legal basis is our legitimate interest in fraud prevention, Art. 6(1)(f) GDPR.

Verification is voluntary: if you decline, the restriction or trust tier that already applies to your account simply stays as it is. The optional selfie-based verification route is not currently offered.

9. Automated Decisions

Spectra, our anti-fraud engine, can automatically restrict or suspend a container or account. It weighs factors such as payment and account signals, device signals, and resource-usage patterns like cryptomining. This is an automated decision within the meaning of Art. 22 GDPR. We rely on the exception in Art. 22(2)(a) GDPR: acting immediately on abuse such as cryptomining or malware is necessary to perform our contract with you and with our other customers, whose resources are shared. The safeguards below apply to every such decision.

You can ask for human review by contacting support or [email protected], explain your view, and contest the decision. We respond without undue delay, normally within two business days.

10. Data Retention

  • Account data - kept while your account exists; after closure, up to 6 months, then your personal data is deleted or made irreversibly unreadable. We keep only records we are legally required to retain, such as financial records under Dutch tax law (7 years), and records needed to establish or defend legal claims, for as long as that purpose requires.
  • Hosted content (apps, databases, buckets) - deleted when you delete the resource; after account closure, within 30 days. Backups age out in their normal rotation.
  • Security and access logs, including IP addresses - up to 12 months.
  • Device fingerprints - while the linked account trust record exists, at most 6 months after account closure.
  • Identity-document images - 30 days after the verification decision; the outcome for as long as the account exists.
  • Self-hosted diagnostics (Sentry) and product analytics (Matomo) - only as long as needed for diagnosis and analysis, then deleted automatically.

11. Security

We apply encryption in transit, network segregation, least-privilege access controls, and continuous monitoring. Automated systems flag and block malware, cryptomining, or other misuse. Access to identity documents is limited to staff holding the reviewer role, with every view logged and watermarked with the reviewer's name. Our Sentry and Matomo diagnostics are self-hosted and operated by us; they are not a route for selling or externally monetising customer data.

12. Your Rights

Under the GDPR you may request access to, correction or deletion of, or the export of your personal data; you may object to or restrict certain processing; and where processing relies on your consent, you may withdraw that consent at any time. If an automated decision affects you, you also have the right to request human review, see "Automated Decisions" above. You have the right to lodge a complaint with the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or the supervisory authority where you live. Email [email protected] with your request; we respond within one month.

13. Cookies & Similar Technologies

Our sites use a small number of first-party cookies for authentication, security, and language preference only; we do not use advertising or analytics cookies. The device and browser fingerprint described above is a "similar technology" used only for fraud prevention, never for tracking across sites. The full list of cookies and browser-storage keys we use is on our Cookies Policy page. If we introduce a non-essential cookie or comparable browser technology for which consent is required, we will ask for that consent before using it.

14. Changes to This Policy

We may update this Privacy Policy periodically. Significant changes will be announced on our website or by email.

15. Contact

For privacy questions or to exercise your rights, email [email protected] or write to Synthwave-technologies.nl, Arnhemseweg 127, 7331BE Apeldoorn, the Netherlands.