Legal

Privacy notice

Effective: 18 September 2026

Who is responsible for your data

The controller of the personal data described in this notice is:

Andrii Co.
doing business as Andrii Cloud
11826 NE 167th St
Bothell, WA 98011-5456
United States
UBI number: 604505773
Telephone: +1 877 987 7987 (voice; this line does not accept SMS)

Privacy questions and requests: privacy@andrii.cloud. We aim to respond within 14 days.

This notice covers andrii.cloud — the website and the interest form on it. Andrii Co. also operates andrii.co, a notary and apostille practice with its own privacy notice, its own systems and its own retention rules. The two are the same company and separate processing; nothing you send this site is merged into a notary record.

What this site is, and what it therefore does not collect

This is a pre-launch interest register. There is no account, no sign-in, no portal, no checkout and no payment on this site, so we hold no password, no payment details and no identity documents from it, and we never ask for any. There is nothing here to compromise in that direction, which is a design decision rather than a temporary state.

What the interest form collects

Only three fields are required: your name, your email address, and whether your enquiry is about colocation or is a plain question. Everything else on the form is optional, and the form works if you leave all of it blank.

The optional fields are the qualification detail: your company or network, a telephone number, the space, power and bandwidth you would need, whether you have your own autonomous system number or address space and what they are, whether you need IPv4, what you need from denial-of-service handling, whether you want managed services, your timeline, a budget band, whether an annual prepayment is of interest, your location, the language you would like to be supported in, a free-text question, and a separate unticked box if you would like to be kept posted.

Three things are collected without being typed, and they are listed here because a field you did not fill in is exactly the one a privacy notice should disclose:

  • How you reached us. Campaign and click attribution taken from the address of the page you landed on and from the referring page: utm_source, utm_medium, utm_campaign, utm_term, the advertising click identifiers gclid, gbraid and wbraid, the referring URL, and the path you first landed on. We record these alongside your enquiry to understand which descriptions of this service reach the people it is for. They are not uploaded anywhere.
  • The internet address the submission came from. Kept with the enquiry record, for abuse handling and to recognise duplicate submissions, for the same period as the record. This is separate from the short-lived web-server log described below.
  • Your browser's language preference, so that we reply in a language you can read.

We also carry the identifiers our own analytics script generated for your visit, when it is running, so that an enquiry can be counted once rather than twice. When it is not running — because you sent Global Privacy Control, because you are in a region where we do not measure, or because you have JavaScript off — the enquiry is stored and nothing is counted, which is the correct outcome and not a degraded one.

The form carries a hidden field that a human never sees and never fills in. If it arrives filled in, the submission is discarded as automated and nothing is stored at all.

Why we are allowed to use it

Where the General Data Protection Regulation or the UK GDPR applies to you, our legal bases are:

  • Article 6(1)(b) — steps taken at your request before entering into a contract. Replying to your enquiry is the whole of it.
  • Article 6(1)(f) — our legitimate interests in understanding demand for a service we are deciding whether to build, in protecting our systems from abuse, and in keeping a record of what we were asked for. The attribution fields above serve this basis. You can object to processing on this basis at any time, and we will stop unless we have compelling grounds not to.
  • Article 6(1)(a) — your consent, and only for the "keep me posted" box, which is unticked by default and which you can withdraw at any time through the unsubscribe link in any message it produces, or by writing to us.

Where United States state privacy law applies to you instead, we process this data to provide and improve a service you asked us about, and for security. We do not sell it and we do not share it for cross-context behavioural advertising — see below.

How we measure this site, and why there is no cookie banner

We measure this site with our own script, served from this domain. You can read it: it is at /s.js, it is under 1.5 kilobytes, and it is deliberately small enough that reading it is a reasonable thing to ask of you.

It sets one first-party cookieac_cid, a random visit identifier, with a two-year lifetime — and no third-party cookie. It sends page and form events to our own API at andrii.net. Your browser also reports blocked-content errors to our own endpoint at report.andrii.net, which is there so that a content-security-policy violation on this site reaches us rather than nobody.

We forward a summary of those events to Google Analytics from our server. The consequence is the point: your browser never contacts Google, and we never send Google your IP address — only the country and region we resolved from it ourselves. There is no Google script on this site, no tag manager, no advertising tag and no cross-site identifier. The fonts are ours too, served from this domain, so no font provider sees your address either.

If your browser sends Global Privacy Control, or if you are in the European Economic Area, the United Kingdom or Switzerland, we set no cookie and send no event at all. Not a reduced set — none. The check happens in your browser before the cookie is written, and again on our server before anything is forwarded.

Those are the only three hosts this site talks to: andrii.cloud itself, andrii.net and report.andrii.net, all of them ours. That is the whole list, which is why there is no cookie banner. The site's own content-security-policy names those three and nothing else, and a browser would block a fourth; you can read the policy in the response headers, and you can watch the list in your browser's network panel. We would rather be checkable than reassuring.

Google LLC acts as our analytics processor for the summarised events we forward. On the Google Analytics property behind this site, Google Signals is off, sharing with Google products and services is off, and user and event data retention is set to 14 months. There is no advertising processor, and no data from this site is uploaded to an advertising platform. If that ever changes, this paragraph changes with it, in the same edit.

What the web server logs

Serving a page writes a log line at our edge. Those logs record no request headers and no query strings — by design, in the server we wrote — and they are kept for 14 days, after which they are gone. They exist for debugging and for abuse handling, and they are not joined to your enquiry.

A submission you make also reaches our API, which records the fact of the request for rate-limiting and audit under a fixed vocabulary of event names and identifiers. Your name, your email address and the text you wrote are not written into that audit record.

Who else processes it

We keep the list short on purpose, and every entry is here because it is unavoidable rather than convenient.

  • Google Cloud (Google LLC, USA) — the virtual machine our API runs on, and the storage behind this website. They host; they do not use what is stored.
  • Google Workspace (Google LLC, USA) — our email. An enquiry arrives as mail, so our correspondence with you lives there.
  • Google LLCanalytics processor, for the summarised events our server forwards, as described above. Your browser does not contact them and they do not receive your IP address. Their handling is governed by the Google Analytics data-processing terms.
  • Our own network. This site is served by software we wrote, on machines we run, in Seattle and Amsterdam. No content delivery network sits in front of it and no third-party edge terminates your connection.

We may also disclose data where the law requires it — see abuse and legal process, which describes what we hold, what process we require, and our default of telling the affected person unless we are prohibited from doing so.

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not use it for automated decision-making that produces legal or similarly significant effects. We do not add you to a mailing list unless you tick the box.

Text messages, and the published number

Our published number, +1 877 987 7987, is a voice line for this site. We will not text you about an andrii.cloud enquiry, and giving us your number on the form is not a consent to be texted.

The same number is also used by Andrii Co.'s notary practice, which does run an SMS programme. A text you send to it is handled under andrii.co's terms and its SMS programme, with the consent, frequency, opt-out and privacy terms published there — not under this notice.

How long we keep it

  • Your enquiry record, including the attribution fields, the submitting IP address and your locale: 24 months, or until you ask us to erase it, whichever is sooner.
  • Our correspondence with you about an enquiry: 18 months after the matter is closed.
  • Edge request logs: 14 days.
  • Google Analytics user and event data: 14 months, which is the retention set on the property.
  • The ac_cid cookie: we ask for two years, and it is yours to delete at any time. Two browser behaviours shorten it, and we work around neither: Chrome and Firefox cap every cookie at about 400 days, and Safari shortens a cookie written by a script to a few days.
  • Suppression records — the fact that you asked not to be contacted: kept for as long as we operate, because the alternative is contacting you again.

Keeping it safe

The enquiry record lives in a database on a machine we administer, reachable only over our own network, and access to it is limited to the people who answer enquiries. Everything in transit is encrypted: your browser to this site, your browser to our API, our server to anything downstream.

We do not claim more than that. Enquiry records are stored as ordinary rows, not separately encrypted at rest, and the decision is a deliberate one: field-level encryption here would protect against a threat the deployment does not face while making erasure, audit and your own access request harder to perform correctly. What protects the record is that it is small, that it is short-lived, that it contains nothing sensitive by design, and that very few people can reach it. If we later hold something that warrants more, we will do more and we will say so here.

No method of transmission or storage is perfectly secure. If you believe something about this site is not secure, please tell us at the address in our security.txt.

International transfers

We are in Washington State, in the United States, and our processing happens in the United States and in the Netherlands, on machines we operate. If you contact us from elsewhere, your data is transferred to those places.

Where the GDPR or UK GDPR applies to you, we rely on the appropriate safeguards available to us for the processors named above, including the standard contractual clauses our hosting and mail provider makes available. And note what is not transferred: because we set no cookie and send no event for a visitor in the EEA, the UK or Switzerland, no measurement data about that visit reaches us or anyone else at all.

Your rights

Depending on where you live, you may have the right to:

  • access the personal data we hold about you;
  • correct it, or ask us to delete it;
  • object to processing based on our legitimate interests, and ask us to restrict processing while your objection is considered;
  • withdraw consent to the "keep me posted" messages at any time, through the unsubscribe link in any of them or by writing to us — withdrawing it does not affect anything done before;
  • receive a copy of your data in a portable format; and
  • complain to a regulator — for example the Washington State Attorney General, the U.S. Federal Trade Commission, or your own data protection authority in the EU, the UK or Switzerland.

To exercise any of these, email privacy@andrii.cloud. We will not charge you, we will not make you create an account to ask, and we will not treat you differently for asking. We may need to ask you something that lets us match your request to a record — usually the email address you used.

Global Privacy Control. We honour it. A browser that sends it gets no cookie and generates no measurement event on this site, which is also the opt-out signal recognised under several state privacy laws. We publish that at /.well-known/gpc.json.

Washington's My Health My Data Act

We state this plainly because the Act is broad and the honest answer is short: we do not collect, use, store, share or sell consumer health data as Washington's My Health My Data Act defines it. Nothing this site asks for, and nothing our measurement records, bears on physical or mental health, health conditions, treatment, diagnosis, reproductive or sexual health, gender-affirming care, biometric data, or precise location — we do not collect precise location at all, only a country and region resolved from an IP address. We hold no consumer health data, so there is nothing for a consumer health data privacy policy to describe.

Children

This site is for network operators and businesses. It is not directed to children, we do not knowingly collect personal data from anyone under 16, and if we learn that we have, we will delete it. If you believe a child has sent us something, write to privacy@andrii.cloud and we will remove it.

Changes, and how to reach us

We will update this notice as the site changes — in particular when the measurement described above ships, and when the retention mechanism behind the 24-month line is in place. A change is published with a new version number and effective date across the whole legal set, so the documents never disagree with each other about which edition you are reading.

Privacy: privacy@andrii.cloud. Enquiries: hello@andrii.cloud. Abuse and legal process: /abuse/. Telephone: +1 877 987 7987, a voice line.

Andrii Co., a Washington for-profit corporation (UBI 604505773), doing business as Andrii Cloud
11826 NE 167th St, Bothell WA 98011-5456
United States

Version 2026.09.18 · Effective 18 September 2026

Back to andrii.cloud