1. Scope and controller
This Privacy Policy governs MaxBackups websites, applications, customer portals, support channels, and backup services (collectively, the “Service”). The Service is provided by Server Host Inc., located at 1309 STE1200, Coffeen Avenue, Sheridan, WY 82801, USA (“MaxBackups,” “we,” “us,” or “our”), which acts as controller of account and commercial data and as processor or service provider for backup content submitted by customers.
If an organisation provides the Service to its personnel, that organisation controls the backup content and related account instructions. Individual users should direct content-access or deletion requests to that organisation.
2. Data collected
We may collect:
- Account data: name, email address, authentication records, organisation, membership, and account preferences.
- Billing data: plan, subscription, invoices, tax information, transaction identifiers, payment status, and limited payment-method metadata. Payment-card data is processed by our payment processor and is not stored in full by MaxBackups.
- Device and service data: device identifiers, operating system, application version, IP address, job configuration, backup status, storage consumption, timestamps, error reports, and security events.
- Backup content: files, folders, filenames, paths, metadata, versions, and other data selected for backup.
- Communications: support requests, correspondence, feedback, and records reasonably necessary to resolve an issue.
3. Processing purposes
We process data to provide, secure, maintain, bill, support, and improve the Service; authenticate users and devices; execute backup and restore instructions; detect abuse and fraud; communicate operational notices; comply with law; and establish, exercise, or defend legal claims. Where required, marketing communications are sent only with consent and may be withdrawn at any time.
4. Backup content and encryption
Backup content is encrypted in transit and at rest. MaxBackups uses managed key custody. The Service is not zero-knowledge, and its architecture may permit authorised access to or decryption of backup content when reasonably necessary to deliver a customer-requested restore or support operation, protect the Service, investigate abuse, or comply with binding law. Access is restricted, logged where practicable, and limited to personnel or processors with a need to know.
We do not sell backup content or use it for advertising, profiling, or training general-purpose artificial intelligence models.
5. Legal bases
Where applicable law requires a legal basis, processing is based on performance of contract, compliance with legal obligations, protection of legitimate interests in operating and securing the Service, consent where requested, or another basis permitted by law.
6. Disclosures and processors
We may disclose data to affiliated entities and vetted providers supporting hosting, storage, payments, communications, fraud prevention, monitoring, customer support, and professional advice. Such recipients may process data only for the contracted purpose and subject to appropriate confidentiality and security duties. We may also disclose data pursuant to valid legal process, to protect rights or safety, or in connection with a merger, financing, reorganisation, or sale of assets.
Data may be processed outside the user’s state or country. Where required, we use lawful transfer mechanisms and contractual safeguards.
7. Retention and deletion
We retain account, billing, audit, and security records for so long as reasonably necessary for the purposes stated above, including legal, tax, fraud-prevention, and dispute obligations. Backup content is retained according to the customer’s plan, configured retention policy, account status, and applicable deletion process.
Following termination, expiry, or deletion of an account or repository, backup content may be deleted and may not be recoverable. Residual encrypted copies may persist temporarily in backups or recovery systems until overwritten in the ordinary course. Customers must restore or export required data before termination.
8. Security
We maintain administrative, technical, and organisational safeguards proportionate to the nature of the data and risk. No system is infallible. Customers remain responsible for securing credentials, devices, recovery access, and endpoint permissions, and for promptly notifying us of suspected compromise.
9. Cookies and local storage
The public marketing site does not require advertising cookies. The customer portal and applications may use strictly necessary cookies or local storage for authentication, security, preferences, and session continuity. Disabling such technologies may prevent the Service from functioning.
10. Rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, portability, withdrawal of consent, or objection to certain processing. We may verify identity, refuse or limit requests where permitted, and retain data where legally required. A user whose account is controlled by an organisation must ordinarily submit content-related requests to that organisation.
11. Children
The Service is not directed to persons under 18 years of age. We do not knowingly permit minors to contract for the Service.
12. Changes and contact
We may amend this Policy. Material changes will be notified through the Service, by email, or by another legally sufficient method. Continued use after the effective date is subject to the revised Policy.
Privacy requests and complaints must be submitted through the authenticated support facilities at maxbackups.cenmax.in. Include sufficient information to identify the account and request. You may also complain to the competent data-protection authority where applicable.