Legal
Privacy Policy
This policy describes how CLM Cloud Solutions S.L. (“we”, “KubeBolt”) handles the personal data we collect through kubebolt.io. It is written to comply with the GDPR and Spanish data protection law (LOPDGDD).
It covers data processing for the website kubebolt.io. Processing of your cluster data inside the KubeBolt Cloud product — where you are the controller and we act as processor — is described in section 9 and governed by a Data Processing Agreement (DPA).
1. Who is the data controller
The controller is CLM Cloud Solutions S.L., a company incorporated in Spain. To exercise any right or ask questions about this policy, write to hello@kubebolt.io.
2. What we collect
We only collect what's strictly needed to operate the site, the release-updates list, the feedback channel, and the Kobi assistant:
- Waitlist: your email address when you submit the
waitlist form. We also record your IP address, browser
User-Agent, and the page that originated the request (Referer) for security and abuse-prevention purposes. - Feedback form: your email address and the message you
write us at kubebolt.io/feedback, along with
the optional category you pick. We also record IP,
User-Agent, andRefererfor security and abuse prevention. We use your email solely to reply to your message. If you tick the contact checkbox (design-partner program), we treat that consent as the legal basis to contact you for commercial purposes; you can withdraw it at any time by writing to hello@kubebolt.io. - Kobi chat on the site: the Kobi panel that appears on every page sends what you type, and the history of that same conversation, to the Anthropic API to generate the reply. We record your IP address to apply the per-instance rate limit and, when abuse protection is configured, we send it to Cloudflare Turnstile to verify the first message of each conversation. In Vercel KV we store only a daily message counter, with no content whatsoever. We do not keep the transcript: the conversation lives in your browser, is processed transiently to answer you, and is never stored on our systems.
- Kobi usage metrics: for each answer we store one technical row to measure cost and quality: how many tokens it took, how long it took, whether the answer was cut off, the language, the page you asked from, and a random identifier that groups the turns of one conversation and is tied to no person. If you rate an answer with the thumbs, we store that rating and, if you pick one, the reason, drawn from a closed list. We store neither your question, nor the answer, nor your IP address in these records: they are built to hold no personal data.
- Anonymous usage metrics: we use
Vercel Web Analytics
(cookieless), and — if you consent — also Google
Analytics 4 via Google Tag Manager. GA4 uses cookies
(
_ga,_ga_*) that activate only after you accept the banner. When enabled, PostHog operates under the same condition: it does not load until you accept. Until then we operate under Consent Mode v2 with every category denied by default. - Server logs: our providers retain technical logs (IP, timestamps, HTTP errors) for limited periods to diagnose operational issues.
3. How we use it
- To send your signup confirmation and, occasionally, product updates and your invitation to KubeBolt Cloud once available.
- To prevent form abuse (per-IP rate limiting).
- To understand aggregate site traffic (page views, sources), never at the individual level.
4. Legal basis
We process your data under the following Article 6 GDPR bases:
- Consent (Art. 6.1.a): when you sign up for the waitlist and agree to receive our emails, or when you tick the contact checkbox on the feedback form.
- Legitimate interest (Art. 6.1.f): for service security, abuse prevention, and improving the site through aggregate metrics.
5. Subprocessors
To operate the site we rely on the following providers, each subject to their own data protection guarantees:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Site hosting and cookieless analytics | USA / EU |
| Google LLC | Google Tag Manager + Google Analytics 4 (consent-gated) | USA / EU |
| Resend | Transactional email delivery | USA |
| Managed Postgres (via Vercel Marketplace) | Release-updates list storage | EU |
| Anthropic PBC | The language model behind the Kobi chat on this site | USA |
| Cloudflare Inc. | Turnstile, abuse verification of Kobi's first message | USA / EU |
| Vercel KV | Daily Kobi message counter (no content) | USA / EU |
| PostHog | Product analytics, only when enabled and subject to consent | USA / EU |
6. Retention periods
- Waitlist email: for as long as you want to stay subscribed. You can unsubscribe at any time.
- Signup metadata (IP, User-Agent, Referer): up to 24 months, then anonymized or deleted.
- Server logs: according to the provider's policy, typically 30 days.
7. Your rights
As the data subject you can exercise the following rights:
- Access: know what data we hold about you.
- Rectification: correct inaccurate data.
- Erasure: have your data deleted (“right to be forgotten”).
- Portability: receive your data in a structured format.
- Objection and restriction: object to processing or have it restricted.
- Withdraw consent at any time.
To exercise any of these rights, email hello@kubebolt.io. We will respond within the legal deadline of one month. If you are not satisfied with our response, you may file a complaint with the Spanish Data Protection Agency (AEPD).
8. International transfers
Some of our subprocessors (Vercel, Resend, Anthropic, Cloudflare, and PostHog when enabled) are based in the USA. Transfers are made under the EU-US Data Privacy Framework or the standard contractual clauses approved by the European Commission, as applicable.
9. KubeBolt Cloud: your cluster data
The sections above cover the website. In the KubeBolt Cloud product the processing is different: your infrastructure data is yours — you are the controller and we act as processor. This processing is governed by a Data Processing Agreement (DPA); we are finalizing the DPA and a public subprocessor list with the EU standard contractual clauses (SCCs), available on request at hello@kubebolt.io. The technical detail of what leaves your cluster, what never does, redaction and isolation is on the Trust page.
- Where it's processed and stored: the managed plane runs on Microsoft Azure (compute, a Postgres database, and Azure Blob storage). Today there is one configured region, in the United States: Azure East US 2 (Virginia), and all product data lives there wherever you are based. We do not offer EU residency today.
- Residency by region, planned: the destination is for the region to follow the customer. A region inside the European Union for European organizations; the current region for the Americas. A more specific region within the Americas, Chile for instance, will be an Enterprise-plan capability, on Cloud or self-hosted. None of this exists yet: we publish it as a plan, not a capability, and until it ships the honest answer to "can you host my data in the EU?" is no. If your organization needs it to sign, write to us first: that is what moves the priority.
- AI processing: in KubeBolt Cloud the AI is platform-managed, and the provider depends on the mode. Kobi Copilot uses the Anthropic API as its primary provider and the OpenAI API as a fallback, reached only when the primary does not answer. Kobi Autopilot uses Anthropic only, because it is built on their agent SDK. With both, the non-negotiable condition is that they operate under zero retention and no training: your data is processed transiently and is never stored or used to train models. On Cloud there is no option to bring your own key or point at a private endpoint: that exists only in the open source and self-hosted editions, where you choose the provider.
- Retention: product data (findings, insights, runtime events, and Kobi conversations) is kept according to your plan band: Free 15, Team 30, Business 90, and Enterprise 365 days, with a 30-day grace window on downgrade. Kobi conversations — the store with the most personal data — follow that same band, and you can permanently delete any of them from the product. Setting a shorter retention window at the organization level is planned and does not exist yet.
- Audit log: the record of who changed what is decoupled from the above, with its own retention for compliance reasons. There is no path for a user to edit or delete it, and it is isolated per organization at the database level. A retention job removes the oldest records: 90 days by default.
Product subprocessors. This is the committed list; we are finalizing the signing of their terms and their formal publication:
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure | Compute (AKS), Postgres, Blob, and key management | USA (Azure East US 2) |
| Anthropic PBC | Managed AI: primary provider for Kobi Copilot and the only one for Autopilot, under zero retention and no training | USA |
| OpenAI | Fallback AI for Kobi Copilot, under zero retention and no training | USA |
| Vercel Inc. | Hosting for the product's web interface | USA / EU |
| Stripe (and Stripe Tax) | Payments, subscriptions, and invoicing | USA / EU |
| Cloudflare Inc. | DNS and, on proxied domains, TLS termination | USA / EU |
| SendGrid (Twilio) | The product's transactional email | USA |
| Google, Microsoft, and GitHub | Social sign-in, identity only | USA / EU |
10. Cookies
Cookies fall into two groups. Strictly technical
cookies (load balancing and delivery-network security) are exempt from
consent under the GDPR and are always active.
Analytics cookies (Google Analytics 4:
_ga, _ga_*, and PostHog when enabled) require
explicit consent and run under Consent Mode v2 — denied by default,
activated only when you click Accept on the banner. Your choice is stored
in your browser's local storage, not in a cookie, and you can change it
from “Cookie preferences” in the footer of any page. See the
cookies page for per-cookie detail,
duration and purpose.
11. Minors
The site targets technology professionals. We do not knowingly collect data from children under 14.
12. Changes to this policy
If we change this policy materially, we'll notify you through the site itself and, where appropriate, by email. The “last updated” date in the header always reflects the current version.
13. Contact
CLM Cloud Solutions S.L.
Email: hello@kubebolt.io
Web: clmcloudsolutions.es