Last updated:
1. Purpose
This policy sets out the technical and organisational details of the processing summarised in the Privacy Policy.
2. Processing activities
| Activity | Data | System | Legal basis |
|---|---|---|---|
| Account management | E-mail, password hash, language | Colitu control panel database | Contract |
| E-mail verification | E-mail, code hash | Control panel, e-mail provider | Contract, legitimate interest |
| VPN access | Per-user connection credential, device record | Control panel, VPN servers | Contract |
| Traffic accounting | Byte counters per user and server | VPN server agent, control panel | Contract, legitimate interest |
| Security and abuse prevention | IP, country, device hash, refused attempts | Control panel | Legitimate interest |
| Payment | Order, amount, transaction status | Control panel, payment provider | Contract, legal obligation |
| Support | Messages, attachments, diagnostics | Control panel | Contract |
| Colitu Bot | Questions, answers, feedback | Control panel, AI provider | Legitimate interest |
| Service health | Server CPU, memory, disk, core state | Control panel | Legitimate interest |
3. Data processed on VPN servers
VPN servers identify users only by a per-user connection credential and count the bytes transferred for it. The servers do not record or send to the control panel the tunnel contents, visited domain names, DNS queries or destination IP addresses. Server addresses are not shown to users; the apps connect through domain names.
4. Processors (sub-processors)
| Provider | Service | Data shared |
|---|---|---|
| Platega | Payment processing | Order amount, transaction details |
| Resend | E-mail delivery | E-mail address, message content |
| DeepSeek | Colitu Bot AI answers | Questions asked to the bot and related article text |
| Cloudflare | DNS; CDN and security for docs.colitu.com | Visitor IP address and request data (docs.colitu.com only) |
| Hosting providers | Server infrastructure | Data stored on the servers |
5. Technical and organisational measures
- All communication is encrypted with TLS; mutual TLS (mTLS) is used between servers and the panel.
- Passwords are stored with Argon2id and secret settings (API keys) encrypted with AES-256-GCM.
- Administrator access is role-based, protected by two-step verification, and every administrative action is written to an audit log.
- The database is backed up regularly; backups are kept in an access-restricted environment.
- Data past its retention period is deleted hourly by an automatic job.
- Country lookup from IP uses a local database on our server; the IP address is not sent to a third party.
6. Data breaches
If we detect a security breach affecting personal data, we act immediately to contain it and, where the law requires, notify the competent authorities and affected users without undue delay.
7. Requests
For requests about data processing: support@colitu.com
Questions? Write to support@colitu.com.