Legal
Privacy Policy
Last updated: 24 July 2026
1. Who we are
Handled Cloud is a trading name. For the purposes of the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR), Handled Cloud is the data controller of the personal data described in this policy.
Contact: hello@handled.cloud
2. Data we collect
We collect and process the following categories of personal data:
| Category | Data |
|---|---|
| Account | Email address, display name |
| Authentication | User ID, federated ID, login timestamps, customer role |
| Session | Split-token cookie values, token sets |
| Security | IP address, browser characteristics |
| Infrastructure | IP address, user agent, request path |
| Audit | Customer user lifecycle events, config changes |
3. Cookies
This section describes the cookies used across the handled.cloud domain. All cookies are first-party, strictly necessary for authentication and security, and do not track you across sites.
No analytics, advertising, or tracking cookies are used on any handled.cloud domain.
| Name | Provider | Purpose | Duration | Category |
|---|---|---|---|---|
handled_session | Handled Cloud | Carries split JWT token segments used to reconstruct access tokens from server-side storage | 2 hours | Strictly necessary |
handled_session_pkce | Handled Cloud | PKCE code verifier for the authorisation-code exchange | 10 minutes | Strictly necessary |
handled_session_state | Handled Cloud | OAuth state for CSRF protection on auth callback — also carries the post-login destination during the login round trip | 10 minutes | Strictly necessary |
__Host-pending_session | Handled Cloud | Carries a pending-session UUID across the cross-origin bounce during signup | 2 minutes | Strictly necessary |
All cookies are set with HttpOnly, Secure, and SameSite=Lax attributes. The session cookie uses a split-token architecture: the cookie alone is insufficient to reconstruct a complete token, as the other half is stored server-side.
4. Security
We take the security of your personal data seriously. Our safeguards include:
- Encryption of data in transit (TLS) and at rest
- Access to personal data restricted to personnel who require it to operate the service
- Ongoing monitoring for unauthorised access
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required by law.
5. Legal basis for processing
| Category | Basis |
|---|---|
| Account, authentication, session cookies | Contract necessity (Art 6(1)(b) GDPR) — required to provide the service you have requested |
| Turnstile (signup/login) | Legitimate interests (Art 6(1)(f) GDPR) — security and bot prevention on interactive signup and login forms |
| Infrastructure logs | Legitimate interests (Art 6(1)(f) GDPR) — security, operations, and debugging |
| Audit log | Legitimate interests (Art 6(1)(f) GDPR) — security and compliance |
6. Data retention
| Category | Retention period |
|---|---|
| Account, authentication, audit | Lifetime of the account. After deletion, account, authentication, and audit data is purged within 30 days; backups are purged within 90 days. |
| Session cookies | 2-hour session cookie; 10-minute temporary cookies (PKCE, state, redirect) |
| Turnstile | Cloudflare-retained per their policy; no server-side storage by Handled Cloud |
| Infrastructure logs | Cloudflare-retained; auto-expires (7-30 days default) |
7. Your rights
Under UK GDPR and EU GDPR, you have the following rights:
- Access — request a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your personal data
- Restriction — request restricted processing of your data
- Portability — receive your data in a structured, commonly used format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, email hello@handled.cloud. We will respond within one month.
Account deletion can only be requested by email. We will action erasure within 30 days of verifying your identity.
You also have the right to lodge a complaint with a supervisory authority: the Information Commissioner's Office (ICO) in the UK, or your local EU supervisory authority.
8. Third-party sharing
We share data with Cloudflare, Inc. only — our underlying infrastructure provider. This sharing is necessary for service delivery.
We do not share your data with analytics vendors, advertising networks, or data brokers. We do not sell personal data.
9. International transfers
Cloudflare infrastructure may process data globally (US, EU). These transfers are covered by:
- The EU-US Data Privacy Framework (Cloudflare is DPF-certified)
- UK adequacy regulations (UK Extension to the DPF, and/or UK International Data Transfer Agreement) where applicable
No other international transfers occur.
10. Children's privacy
This service is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at hello@handled.cloud and we will delete it.
11. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
12. Changes to this policy
This policy may be updated from time to time. Material changes will be notified on the Site. We encourage you to review this page periodically.
13. Contact
For data protection inquiries, contact us at hello@handled.cloud.