Servor.
Server operationsAI copilotMonitoringPricingBlog
Sign inGet started

Legal · GDPR · Version 2.0 · Effective 19 August 2026

Privacy policy

This policy describes how Servor processes personal data, in accordance with regulation (EU) 2016/679 (« GDPR ») and French law no. 78‑17 of 6 January 1978 as amended. It also serves as the data processing agreement within the meaning of article 28 GDPR for the data you entrust to us. This is a courtesy translation; in the event of a discrepancy, the French version prevails.

1. Two distinct roles

Servor's capacity differs depending on the nature of the data. This distinction determines who answers for what.

  • Servor acts as controller for data relating to the commercial relationship: account identification, billing, security logs, support.
  • Servor acts as processor for data contained in your content: command outputs, application logs from your servers, configurations, AI session content. You are the controller of that data; Servor acts only on your instructions, as expressed through your use of the Service.

Accordingly, it is your responsibility to have a legal basis for the personal data you introduce into the Service, to inform the data subjects, and not to submit special category data within the meaning of article 9 GDPR without prior agreement with Servor.

2. Controller and contact

BENODE, simplified joint-stock company (société par actions simplifiée), Trade and Companies Register of Le Havre 934 272 030, registered office 113 boulevard de Strasbourg, 76600 Le Havre, France.

  • Data protection contact: contact@benode.fr
  • Supervisory authority: Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France.

3. Data processed

3.1 Account data

  • business email address, first and last name where provided;
  • authentication provider identifier, optional avatar;
  • display language, team membership and associated role.

3.2 Technical and security data

  • IP address, user agent and request identifier, for security, rate limiting and diagnostic purposes;
  • timestamped, hash‑chained audit log of sensitive actions (server creation, command execution, team changes, billing operations);
  • technical application logs.

3.3 Secrets — inaccessible to Servor

Credentials for your infrastructure are encrypted in your browser before any transmission. Servor stores encrypted data for which it does not hold the decryption key: neither passwords, nor private keys, nor passphrases are accessible to us in clear form, at any time.

3.4 Execution content and AI sessions

Executed commands, their outputs and conversations with the copilot are retained so you can review them. This content may incidentally contain personal data present on your servers — this is the scope in which Servor acts as processor.

3.5 Payment data

No bank card data is processed or stored by Servor. Stripe collects it directly. We receive only the metadata needed to track the subscription: status, amount, transaction identifier, card brand and last four digits.

4. Purposes, legal bases and retention

PurposeLegal basisRetention
Providing the Service and performing the contractContract performance (art. 6.1.b)Term of the contract, then 30 days
Invoicing and accounting obligationsLegal obligation (art. 6.1.c)10 years (art. L.123‑22 Commercial Code)
Security, traceability, abuse preventionLegitimate interest (art. 6.1.f)Audit log: term of the contract. Technical logs: 7 days (info), 90 days (warning and error)
Metrics and execution historyContract performance (art. 6.1.b)Raw metrics: 7 days. Hourly aggregates: 90 days
Website audience measurementLegitimate interest (art. 6.1.f)Aggregate indicators, no individual identifier
Product communicationsLegitimate interest, or consent for marketingUntil objection or withdrawal

5. Sub‑processors

Servor uses the following sub‑processors, all bound by a processing agreement compliant with article 28 GDPR. Any change to this list will be brought to your attention, in accordance with article 28(2).

  • Vercel Inc. — website and dashboard hosting. Region: EU (fra1).
  • Railway Corp. — API, database, cache and object storage hosting. Region: EU West.
  • Clerk Inc. — authentication and MFA factor management. Region: USA.
  • Stripe Payments Europe Ltd. — payment processing. Region: EU.
  • Resend — transactional email delivery. Region: USA.
  • Vercel Inc. (Web Analytics) — cookieless audience measurement. Region: USA.
  • Anthropic PBC — AI copilot inference. Region: USA.

Requests sent to the AI copilot, together with the technical context of the server concerned, are transmitted to the inference provider. This data is not used to train models.

6. Transfers outside the European Union

Some sub‑processors are established in the United States. The corresponding transfers are governed by the European Commission's standard contractual clauses (decision 2021/914), supplemented by technical measures: end‑to‑end encryption of secrets, encryption in transit, and minimisation of the data transmitted.

7. Security

The following technical and organisational measures are actually implemented:

  • end‑to‑end encryption of secrets (Argon2id derivation, AES‑256‑GCM, X25519 key exchange), with the decryption key never leaving the browser;
  • cryptographic signing of execution orders from the browser, verified on the target machine;
  • encryption of communications in transit;
  • hash‑chained audit log, write‑protected at database level;
  • mandatory multi‑factor authentication, reinforced for sensitive operations;
  • data partitioning per team, with distinct encryption keys per team;
  • two‑person review of any change to cryptographic code.

In the event of a data breach likely to result in a risk to data subjects, Servor notifies the CNIL within 72 hours and, where the risk is high, informs the data subjects and the customer controllers concerned without undue delay.

8. Your rights

You have the following rights over your personal data:

  • access, rectification and erasure;
  • restriction of and objection to processing;
  • portability in a structured, machine‑readable format;
  • withdrawal of consent at any time, without retroactive effect;
  • setting directives on the fate of your data after your death.

These rights may be exercised by writing to contact@benode.fr. We respond within one month, extendable by two months for complex requests, with prior notice. Where the data relates to customer content for which Servor acts as processor, the request is forwarded to that customer, who is the sole controller.

You may lodge a complaint with the CNIL: cnil.fr/fr/plaintes.

9. Intended audience

The Service is intended exclusively for professionals. It is not directed at minors and no data concerning persons under 16 is intentionally collected.

10. Changes to this policy

This policy may be updated to reflect legal, technical or organisational developments. Material changes are notified by email or through the interface at least 30 days before they take effect.

Data protection contact: contact@benode.fr

Servor.

One console for all your servers. With an AI copilot as a bonus.

Product

  • Features
  • Security
  • Pricing
  • Blog

Topics

  • Server operations
  • AI copilot
  • Monitoring & status

Company

  • About
  • Contact
  • Legal notice

Legal

  • Terms
  • Sales terms
  • Privacy
  • Cookies

Resources

  • Articles
  • Get started
  • Sign in

© 2026 Servor. All rights reserved.

v1.0 · zero-knowledge · hosted in EU 🇪🇺