#1. Who we are and what this policy covers
CryptGPU (“we”, “us”) rents dedicated GPU servers by the month through cryptgpu.com. We are responsible, as controller, for the personal data described in this policy.
This policy covers the personal data we process when you:
- visit the website or use the public pricing API;
- send us a message through the contact form;
- order, pay for and use a server.
It does not cover the data you store or process on your own servers. You decide what that data is and how it is used, and you are responsible for it. We only host it and, apart from the limited cases described in section 3, we do not access it.
This policy takes effect on 23 September 2026. The contract for the service itself is set out in our Terms of Service.
#2. What we collect
When you visit the website or use the pricing API
Every request to cryptgpu.com passes through Cloudflare, which acts as our content delivery network and security proxy, and, when needed, reaches our own servers. Cloudflare and our servers record technical data about each request:
- your IP address;
- the date and time, the page or API address requested, and the response;
- technical information sent by your browser or software, such as its user agent and the referring page.
The website uses no analytics, no advertising trackers and no third-party scripts. Its fonts and scripts are served from our own domain.
Cookies
The website sets one cookie of its own:
| Name | Purpose | Duration |
|---|---|---|
cg_annc | Remembers that you closed the announcement banner, so that it is not shown again. It is set only when you close the banner, and it contains the name of that announcement, which is the same for every visitor. | 30 days |
We consider this cookie strictly necessary to remember a choice you made, so we do not ask for separate consent. You can delete it at any time in your browser; the announcement may then appear again.
Cloudflare may also set its own security cookies, for example when your browser completes a security check. They are used only to protect the website against bots and attacks.
When you contact us
- your email address;
- your name, if you choose to give it;
- the topic you select and your message;
- our replies and any follow-up exchanges.
When you order a server
- the email address linked to your account;
- order and billing records: the configurations you order, prices, invoices, dates and renewals;
- cryptocurrency payment data: the currency and network used, the amounts, and public blockchain identifiers such as transaction IDs and wallet addresses;
- the address you give us for a refund, if one is due;
- your messages with us about your orders and servers.
We do not collect card or bank details: payment is in cryptocurrency only. Payments made on a public blockchain are visible to anyone and cannot be changed or deleted, by us or by anyone else.
When you use a server
To operate and protect the service, we process technical metadata about your servers. This can include their configuration and IP addresses, their status, hardware health and resource usage, and network traffic metadata such as volumes, addresses and ports. It does not include the contents of your servers or of your communications.
What you need to give us
You can browse the website without giving us any personal data. To get an answer to a message, we need your email address. To order a server, we need an email address and the order and payment data described above; without them, we cannot provide the service.
#3. What we do not do
- We do not sell or rent your personal data, and we do not share it with advertisers.
- We do not profile you for advertising. The website has no analytics, no advertising trackers and no third-party scripts.
- We do not read the contents of your servers, such as your files, datasets, models or workloads. We access them only where necessary to operate or secure the service, to comply with the law, or when you ask us to (see section 9 of the Terms of Service).
- We never ask for the private keys or recovery phrase of your wallet.
#4. Why we use your data and on what legal basis
We use personal data only for the purposes below. Where data-protection law requires a legal basis, the table shows the one we rely on.
| Purpose | Legal basis |
|---|---|
| Delivering the website and the pricing API, and protecting them against attacks and abuse | Our legitimate interest in running a secure, working website |
| Answering your messages and requests | Our legitimate interest in answering you or, when your message concerns an order, steps you ask us to take before a contract, or the contract itself |
| Taking and delivering orders, running and renewing your servers, handling payments and refunds, and sending you notices about the service | Performance of our contract with you |
| Keeping accounting and tax records, complying with export-control and sanctions laws, and answering lawful requests from authorities | Compliance with our legal obligations |
| Preventing and investigating fraud, abuse and security incidents, enforcing our terms and policies, and establishing or defending legal claims | Our legitimate interest in protecting the service, our customers, third parties and ourselves |
Where we rely on our legitimate interests, you can object (see section 9). We do not use your data for any purpose that requires your consent, such as marketing. If that ever changes, we will ask for your consent first, and you will be able to withdraw it at any time.
#5. Who processes your data for us
A small number of service providers (processors) handle personal data on our behalf and under our instructions:
- Cloudflare, which provides the content delivery network, reverse proxy and security for the website. Every request to the website passes through Cloudflare, which processes IP addresses and request data to deliver and protect it. See Cloudflare’s privacy policy.
- Hosting and infrastructure providers, which operate the data centers, servers and networks on which the website, our email and the service run.
We do not share your personal data with anyone else, except:
- when the law requires it, for example in response to a valid order from a court or a competent authority;
- when it is necessary to establish, exercise or defend legal claims, including with professional advisers such as lawyers and accountants, who are bound by confidentiality;
- if the CryptGPU business is transferred to a new operator. We would tell you, and your data would remain protected in line with this policy.
If we start using another processor, for example a payment service, we will update this policy before it receives any personal data.
#6. How long we keep your data
We keep personal data only as long as we need it for the purposes above:
- Website and API request logs: for a short period, for security and troubleshooting, and then deleted, unless they are needed to investigate a specific incident.
- The
cg_annccookie: stored on your device for 30 days after you close the banner. - Contact messages: as long as needed to deal with your request and any follow-up. Messages about an order or a dispute are kept with the related records.
- Account, order and billing records: while you are a customer, then for as long as tax, accounting and other laws require, or as long as needed to handle a claim.
- Payment data: kept with the billing records. Transactions recorded on a public blockchain stay there permanently; this is outside our control.
- Server metadata: as long as needed to operate and secure the service, and to handle any related incident or claim.
- Abuse and security records: as long as needed to investigate and resolve the case, and longer if the law requires it or if they are needed for a legal claim.
The disks of a server are wiped when its service ends, as described in the Terms of Service.
#7. How we protect your data
- Connections to the website and to the pricing API are encrypted with TLS (HTTPS).
- Access to personal data and to our systems is restricted to the people who need it to run the service.
- We collect as little personal data as we can: no analytics, no advertising trackers, and no card or bank details.
- The website runs behind Cloudflare, which filters attacks before they reach our servers.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will inform the competent authority and, where the law requires it, you.
The security of the software and data on your own servers is your responsibility, as explained in the Terms of Service and the Acceptable Use Policy.
#8. International transfers
Cloudflare operates a global network, so a request to our website may be handled in a data center outside your country. Our other providers may also process data in countries other than yours, where data-protection laws may differ.
Where the law requires safeguards for such transfers, we rely on the mechanisms it provides, such as adequacy decisions or standard contractual clauses in our providers’ data processing terms. The safeguards Cloudflare uses are described in its privacy policy.
#9. Your rights
You have the following rights over your personal data. We respect them wherever you live, within the limits and exceptions set by law.
- Access: ask whether we process your data, and get a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted, unless we must keep it, for example billing records that the law requires us to keep, or data needed for a legal claim.
- Restriction: ask us to limit how we use your data, for example while we check its accuracy or examine an objection.
- Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another provider where this is technically feasible, when we process it to perform our contract with you.
- Objection: object to processing based on our legitimate interests. We will then stop, unless we have compelling legitimate grounds or need the data for a legal claim.
- Complaint: lodge a complaint with a data-protection supervisory authority, in particular in the country where you live or work, or where you believe the problem occurred.
How to exercise your rights
Send your request through the contact form and say which right you want to exercise. To protect your data, we may ask you to confirm that the request comes from you, for example by replying from the email address linked to your account.
Exercising your rights is free, unless a request is manifestly unfounded or excessive. We answer within the time limits set by data-protection law.
You can complain to a supervisory authority at any time, but we would welcome the chance to address your concern first.
#10. Children
The website and the service are not intended for children, and you must be at least 18 to order a server (see the Terms of Service). We do not knowingly collect personal data from children. If you believe a child has sent us personal data, tell us through the contact form and we will delete it.
#11. Changes to this policy
We may update this policy, for example when we add a feature or change a provider, or when the law changes. We publish each new version on this page with its date. If a change materially affects how we use your data, we notify customers by email before it takes effect.
#12. Contact
For any question about this policy or your personal data, use the contact form. It is the only way to reach us.
