1. Who we are
Cenvero runs this website, stratum.cenvero.com, and the Cenvero Stratum service. Cenvero decides how the personal data described here is used; in data-protection terms, it is the controller.
To ask anything about your data, or to use one of your rights, write to us through the contact form.
2. The short version
- We collect what we need to run your account, sell you licences, license your nodes and keep the service secure.
- Your tenants’ traffic and data never pass through us.
- There are no analytics, advertising or tracking tools on this site, and only the cookies it needs to work.
- We use no payment processor: you pay using the instructions shown at checkout, and we check each payment by hand.
- The service is hosted in the EU, on a server in Nuremberg, Germany.
3. What we collect
Your account
Your name, email address, company (if you give one) and password. The password is stored only as a one-way hash, so no one can read it. We also record whether and when you confirmed your email address. If your organisation signs you in with single sign-on, we keep the identifier your sign-in provider gives you, so we can recognise you next time.
Orders, invoices and your wallet
The plan, number of nodes and term you order, the amounts, any coupon you use, the payment reference you give us, and the payment proof you upload. Proofs are stored privately and shown only to you and to Cenvero staff. Invoices are PDF files carrying your name, company, email address and the amounts. Your wallet keeps its balance and a history of top-ups, renewals and adjustments.
Licences and nodes
Your licence keys, and a record of each node activated against them.
Your tenants’ traffic and data never pass through us. Nodes contact us only to register and activate, to check their licence, and to fetch updates, certificates, their signed configuration and the plugins you choose.
To register and activate, a node sends its hostname, IP address, software version and a hardware fingerprint hash, plus the network settings we build its signed configuration from (with the local API token, if you switch that API on). We record which nodes are activated against your licence. There is no live monitoring of your nodes.
Certificates
A certificate request carries a public key and the names and addresses the certificate will cover. When you or your nodes ask for a certificate, the private key is created on the node or in your browser and is never sent to us. If you ask Cenvero staff to issue a certificate for you by hand instead, its key is created on our server, handed to you once and not kept. Your account’s own certificate authority is created and held by us, with its signing key stored encrypted, so that it can sign your nodes’ certificates.
The developer programme
If you apply to build plugins: your application (a display name, your organisation and why you want to take part). If you take the identity check: your legal name, country, contact email, a registration number if you give one, and any document you upload. Identity-check documents are stored privately and used only to verify you. We also keep your signing certificates (they hold public keys only), your store’s details, and the plugins you publish. Your publisher name and your plugins’ names, descriptions and versions are shown publicly on the marketplace.
Enquiries
When you use the contact form: your name, email address, company (if you give one), the product you ask about, your message, and the page you sent it from.
Security and audit records
A record of changes made to accounts, licences, orders, nodes and the marketplace: what was done, when, by which account and from which IP address. Our web server and application logs record requests, including IP addresses. While you are signed in, the server keeps your session, which can include your IP address and the kind of browser you use.
4. Why we use it
- To provide what you signed up for and bought: your account, orders, licences, nodes, certificates and the developer programme.
- Because the law requires it: invoices and other billing records.
- For our legitimate interests: keeping the service secure and stopping abuse (logs, audit records, limits on how often forms can be sent), and answering your enquiries.
We do not sell your data, and we do not use it for advertising.
5. Who else handles it
- Hosting. Our server is in Nuremberg, Germany, in the EU.
- Cloudflare. All traffic to this site passes through Cloudflare, which provides its content delivery, its encrypted connections and its protection against attacks. Cloudflare therefore processes your IP address and your requests. It runs a worldwide network, so a request may be handled at one of its locations outside the EU. If a form asks you to show you are human, Cloudflare runs that check too.
- Our content domain. The logo and site icons load from cdn.cenvero.com, Cenvero’s own content domain.
- No font or styling service. The site’s fonts and styling code are served from our own server, so opening a page contacts no one else for them.
- Email. When we email you (to confirm your address, about your orders, licences, nodes and renewals, or to answer you), the message goes through an email delivery provider, which handles your email address and the message.
- No payment processor. Payments are made manually, following the instructions shown at checkout, and verified by Cenvero.
We share personal data with no one else, except where the law requires us to disclose it.
6. Cookies
The site sets only the cookies it needs to work:
| Cookie | What it does | How long it lasts |
|---|---|---|
Session (its name ends in -session) | Keeps you signed in, and carries a form’s messages from one page to the next. | 120 minutes after your last visit to a page |
XSRF-TOKEN | Protects your forms from being sent by another website. | 120 minutes |
The sign-in page has no “keep me signed in” option, so no long-lived sign-in cookie is set. Cloudflare may set its own strictly necessary security cookies, for example to tell people from automated traffic. There are no analytics, advertising or tracking cookies, and nothing else is stored in your browser. That is why the site shows no cookie banner: strictly necessary cookies need no consent.
7. How long we keep it
- Web server and application logs: 14 days.
- Your account, licences and nodes: while your account exists.
- Billing records (orders, invoices, payment references, wallet history): while your account exists, and after that for as long as the law requires us to keep them.
- Payment proofs: kept with their order. A proof you replace after a rejected payment is deleted.
- Identity-check documents: while they are needed for the check and for the verified status that follows it. We delete them when you ask us to.
- Enquiries: kept so we can follow up on them. Ask us and we delete yours.
- Security and audit records: as long as they are needed to keep the service secure and to account for the changes they record.
- Your session: it ends 120 minutes after your last visit to a page, or when you sign out.
8. Your rights
The service is run from the EU, so you have the rights that data-protection law (the GDPR) gives you. You can ask us to:
- show you the personal data we hold about you (access);
- correct it;
- delete it;
- export it, in a format another service can read;
- stop or limit using it, where we rely on our legitimate interests (objection).
You can change your name, company, email address and password yourself, under Settings in your account. For everything else, ask through the contact form. Some records we must keep, such as invoices, and some we need for as long as you use a licence.
You can also complain to a data-protection supervisory authority, for example the one in the country where you live or work.
9. How we protect it
- Every connection to this site is encrypted (TLS).
- Passwords are stored only as one-way hashes.
- Payment proofs and identity-check documents are stored privately, never at a public address.
- Cenvero staff see only what their role needs: billing staff see billing, for example.
10. Changes to this notice
When this notice changes, the date at the top changes with it. We announce significant changes on this site or by email before they apply.
11. Contact
Questions about this notice or your data go through the contact form. How the service itself may be used is set out in the terms of service.