Skip to content
New NVIDIA B200 now available Reserve capacity
reviosa cloud
Legal

Privacy Policy

Last updated July 1, 2026

This Privacy Policy describes how Reviosa, Inc. (“Reviosa,” “we,” or “us”) collects, uses, and shares personal information when you visit cloud.reviosa.com or use the Reviosa Cloud console, CLI, and APIs (the “Services”). It does not cover the contents of workloads you run on the Services (“Customer Content”), which are addressed separately in Section 4.

1. Information we collect

  • Account information — name, work email address, company name, and password hash when you create an account.
  • Billing information — payment details are collected directly by Stripe, our payment processor. We store only the card brand, last four digits, expiration date, and billing country.
  • Usage and telemetry — instance metadata (type, region, status, run time), API request logs, IP addresses, browser and device information, and console activity.
  • Communications — support tickets, emails, and survey responses you send us.

2. How we use information

We use personal information to:

  • provide, operate, and secure the Services, including per-second usage metering and invoicing;
  • detect and prevent fraud, abuse, and violations of our Terms of Service;
  • respond to support requests and service incidents;
  • plan capacity and improve the reliability and performance of the platform; and
  • comply with legal obligations, including tax and accounting requirements.

We do not sell personal information, and we do not use it for third-party advertising.

3. Payment processing

Payments are secured and processed by Stripe, Inc. as a PCI-DSS Level 1 certified processor. When you add a payment method, your card details are transmitted directly to Stripe and never touch Reviosa’s servers. Stripe processes this information under its own privacy policy and our data processing agreement with them.

4. Customer Content

The data, models, and code inside your instances, volumes, and object storage buckets belong to you. Customer Content is encrypted at rest with AES-256 and in transit with TLS 1.3. Our personnel do not access Customer Content except at your request, as necessary to investigate a security incident, or as required by law — and any such access is logged and reviewed. Content stored in a region stays in that region unless you move it.

5. Cookies and analytics

We use essential cookies to keep you signed in and remember preferences, and first-party analytics to understand aggregate usage of our marketing site and console. We do not use third-party advertising trackers. You can control cookies through your browser settings; blocking essential cookies may prevent the console from functioning.

6. Sharing and subprocessors

We share personal information only with service providers acting on our behalf — payment processing (Stripe), email delivery, and cloud tooling that supports our internal operations — each bound by contractual confidentiality and data-protection obligations. A current list of subprocessors is available on request at privacy@reviosa.com. We may also disclose information if required by law or valid legal process; where lawful, we will notify you before doing so. If Reviosa is involved in a merger or acquisition, information may be transferred subject to this policy.

7. Security and retention

Reviosa maintains a SOC 2 Type II audited security program, including role-based access controls, hardware-backed key storage, and 24/7 monitoring across our four regions. We retain account information for the life of your account plus 90 days, usage telemetry for 13 months, and invoices for 7 years as required by tax law. Customer Content is deleted within 30 days of account termination.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. For customers in the European Economic Area and the United Kingdom (including users of our Frankfurt region), we process personal information under the GDPR and rely on standard contractual clauses for transfers outside the EEA. California and other US state residents may exercise applicable rights without discrimination. To make a request, email privacy@reviosa.com; we respond within 30 days and may need to verify your identity first.

9. Changes and contact

We may update this policy as the Services evolve. For material changes we will give notice by email or in the console at least 14 days before the changes take effect. Questions or requests can be directed to privacy@reviosa.com or to Reviosa, Inc., Privacy Office, Ashburn, VA, USA.