Kupe Cloud Privacy Policy
Version: v1.0.0 Last updated: April 20, 2026
1. Introduction
This Privacy Policy explains how Kupe Cloud collects, uses, stores, and shares personal data when you use our website, signup flow, managed Kubernetes platform, and related services.
Kupe Cloud is owned and operated by Core Solutions LTD. In this policy, “Kupe Cloud”, “Kupe”, “we”, “us”, and “our” refer to Core Solutions LTD, except where the context makes clear that we are referring to the Kupe Cloud service or brand.
This policy applies to:
- visitors to our website;
- people who sign up for an account or request information from us;
- users invited into a Kupe tenant;
- customer administrators and team members; and
- people who receive service, product, or marketing communications from us.
2. Who We Are
The controller for the personal data described in this policy is:
Core Solutions LTD
Registered in: England and Wales
Company number: 11659922
VAT number: 310885805
Registered office: 3rd Floor 86-90 Paul Street, London, United Kingdom, EC2A 4NE
Core Solutions LTD operates the Kupe Cloud service and decides how and why personal data is used for website, signup, account, identity, billing, support, security, analytics, and marketing purposes.
Where we handle customer-controlled service data on behalf of a customer, we generally act as a processor and the relevant customer acts as the controller.
For privacy questions, rights requests, or complaints, contact privacy@coresolutions.ltd. Privacy and legal contacts use the coresolutions.ltd domain because Core Solutions LTD is the legal entity behind the Kupe Cloud service. Operational and product contacts use @kupe.cloud.
If you want to withdraw marketing consent or opt out of product updates, you can also use the unsubscribe link in the email or contact privacy@coresolutions.ltd.
3. Personal Data We Collect
Depending on how you interact with Kupe Cloud, we may collect the following categories of personal data.
A. Website and signup data
When you sign up through our site, we currently collect:
- first name and last name;
- work email address;
- company name;
- tenant identifier generated from your company or signup data;
- invitation code, where invitation-only access is enabled; and
- your marketing preference if you opt in to updates.
B. Identity and account data
To provision and manage access, we create and maintain account records such as:
- email address;
- username;
- display name;
- account verification state;
- account status;
- tenant membership; and
- role information such as
adminorreadonly.
The website signup form does not collect your password directly. If you set or reset a password for Kupe Cloud access, authentication credentials and related password-hash data are processed within our managed Authentik identity service, which we host and manage as part of the Kupe Cloud platform.
C. Tenant administration and service data
When a tenant is created or managed, we may process:
- tenant display name;
- tenant contact email;
- tenant billing email;
- plan and promotional credit balance;
- Paddle customer and subscription identifiers;
- member email addresses;
- member roles;
- invitation status;
- billing cycle and subscription status; and
- current usage, invoice, and credit application records connected to the tenant.
D. Communications and support data
We may collect:
- contact form or email enquiry content;
- support requests and onboarding conversations;
- message history with administrators and users; and
- records of account, operational, or commercial communications.
E. Security and operational data
To operate and protect the service, we may process:
- IP address data used for rate limiting and abuse prevention;
- request, delivery, and error logs;
- token validation and account verification events;
- invitation, membership, and access-control events; and
- service diagnostics needed for troubleshooting, monitoring, and reliability.
Our current signup service keeps IP-based rate-limit visitor entries in memory for a short period, currently around five minutes, to mitigate abuse.
F. Billing and commercial data
We use Paddle as our merchant of record for billing. Depending on the integration and transaction flow, Kupe Cloud may receive limited billing and subscription data such as:
- billing contact name or email;
- billing address, country, or tax-related information;
- subscription and invoice identifiers;
- transaction and payment status; and
- plan, credits, invoice totals, tax amounts, and related audit records.
We do not store full payment card details ourselves when Paddle handles checkout and payment processing.
G. Browser, analytics, and preference data
Our website stores a theme preference in browser local storage so we can remember your light or dark mode choice.
We also use Cloudflare Web Analytics to understand website performance and high-level usage. Based on Cloudflare’s current product documentation, Cloudflare Web Analytics does not use cookies or local storage for analytics collection.
H. Personal data we receive from others
If you were invited into a Kupe Cloud tenant, we received your email address, name, and intended role from the tenant administrator who invited you. You can ask us at any time who invited you and ask to be removed from the tenant.
4. How We Use Personal Data
We use personal data to:
- create and verify accounts;
- provision tenants and manage tenant membership;
- send verification, invitation, welcome, service, billing, and support emails;
- operate identity, authentication, and account recovery flows;
- administer subscriptions, credits, invoices, and account status;
- respond to enquiries, onboarding requests, and support issues;
- monitor, secure, and improve the reliability of the service;
- detect and prevent abuse, fraud, and misuse;
- understand website performance and service usage; and
- send product updates, guides, and marketing communications where permitted.
5. Our Lawful Bases
We rely on the following lawful bases under UK GDPR, depending on the purpose of the processing:
- Account creation, email verification, tenant provisioning, tenant membership, and service delivery: performance of a contract or steps taken at your request before entering into a contract.
- Authentication, account recovery, service security, fraud prevention, abuse prevention, rate limiting, logging, troubleshooting, and service monitoring: legitimate interests.
- Billing, invoicing, accounting, tax handling, and maintaining required business records: performance of a contract and legal obligation.
- Customer support, onboarding assistance, and business enquiries: performance of a contract, steps taken before entering into a contract, and legitimate interests.
- Cloudflare Web Analytics and service-performance measurement: legitimate interests.
- Optional product updates and marketing emails: consent.
Our legitimate interests include operating a secure managed Kubernetes service, preventing fraud and abuse, maintaining service continuity, understanding service and website performance, administering customer and prospect relationships, and defending legal claims where necessary.
6. Marketing
If you opt in, we send you platform updates, product news, and best-practice guides by email.
You can withdraw consent at any time by using the unsubscribe link in the email or by contacting privacy@coresolutions.ltd.
Right to object: You have the right to object at any time to the use of your personal data for direct marketing.
7. Who We Share Personal Data With
We may share personal data with:
- identity and access providers used to authenticate users and manage tenant access;
- infrastructure, hosting, networking, and Kubernetes-related providers used to run Kupe Cloud;
- Cloudflare, including Cloudflare Web Analytics, related website or network services, and offsite backup storage of platform-managed data;
- email delivery providers that send verification, invitation, welcome, support, or operational emails on our behalf;
- Paddle, which handles checkout, payment processing, tax, invoicing, and related billing operations as merchant of record;
- professional advisers such as lawyers, accountants, auditors, and insurers; and
- regulators, courts, law enforcement, or other third parties where disclosure is required by law or reasonably necessary to protect rights, users, or the service.
A current list of named subprocessors is available at /subprocessors and on request to privacy@coresolutions.ltd.
8. International Transfers
Some of our providers may process personal data outside the UK.
Where we make a restricted transfer, we use an appropriate transfer mechanism required by applicable law, such as an adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful safeguard.
If you would like more information about the safeguards used for a particular transfer, contact privacy@coresolutions.ltd.
9. Retention
We keep personal data only for as long as necessary for the purpose for which it was collected and for related security, legal, accounting, and compliance reasons.
Our current default retention approach is:
- website enquiries and lead communications: up to 24 months after the last meaningful contact unless a longer period is needed for an ongoing customer relationship or dispute;
- signup attempts, verification records, invitation records, and operational audit events: up to 12 months;
- security, request, and troubleshooting logs: up to 12 months;
- active account, identity, and tenant administration records: for the life of the account or tenant relationship and generally up to 12 months after closure, unless longer retention is required;
- billing, invoice, tax, subscription, and statutory business records: up to 6 years where required for accounting, tax, or legal record-keeping;
- marketing preferences: for as long as you remain opted in;
- marketing suppression records: retained on an ongoing basis after you unsubscribe so we can continue to honour your opt-out, as permitted under the Privacy and Electronic Communications Regulations.
We may retain data for longer where necessary to establish, exercise, or defend legal claims, or where the law requires a longer retention period.
10. Security
We apply technical and organisational measures designed to protect personal data, including role-based access controls, encryption in transit, service monitoring, identity management, abuse controls, and measures to reduce the risk of unauthorised access.
No service can be completely secure, but we work to detect, respond to, and remediate incidents promptly.
11. Controller and Processor Roles
Core Solutions LTD acts as a controller for personal data used to run the website, create accounts, manage commercial relationships, send service communications, handle support, secure the service, operate analytics, and manage marketing preferences.
Core Solutions LTD generally acts as a processor for customer-controlled personal data that customers place into or manage through Kupe Cloud, where the customer determines the purposes and means of the processing.
Customers are responsible for ensuring that they have a lawful basis for customer data they upload to the platform or submit through tenant administration flows, such as inviting team members into a tenant.
12. When Personal Data Is Required
Some personal data is required so we can provide the service.
If you do not provide required signup, account, identity, or billing information, we may be unable to:
- create or verify your account;
- provision or manage your tenant;
- invite users into your tenant;
- provide support or respond properly to your enquiry; or
- provide or bill for the service.
Marketing consent is optional and is not required to create an account.
13. Your Rights
Depending on applicable law, you may have rights to:
- access your personal data;
- correct inaccurate or incomplete data;
- delete personal data in certain circumstances;
- restrict processing;
- object to processing;
- request portability of data you provided to us; and
- withdraw consent where processing is based on consent.
To exercise your rights, contact privacy@coresolutions.ltd.
We respond to verified rights requests within one month of receipt. We may extend this by up to two further months for complex or numerous requests, and we will tell you within the first month if we need to do so. We may also ask for information to verify your identity before responding.
You also have the right to complain to the UK Information Commissioner’s Office (“ICO”). Information about the ICO is available at ico.org.uk.
14. Automated Decision-Making
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects on individuals. Our abuse-prevention and rate-limiting controls are technical safeguards and do not make decisions that affect your legal rights.
15. Children
Kupe Cloud is intended for business use. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, contact privacy@coresolutions.ltd and we will delete it.
16. Cookies, Analytics, and Similar Technologies
When you select a light or dark theme on our site, we store that preference in your browser’s local storage so we can apply it on your next visit. Storage of this preference is treated as strictly necessary to provide the theme service you have explicitly requested by selecting a theme, and so does not require consent under the Privacy and Electronic Communications Regulations.
We use Cloudflare Web Analytics for website analytics. Based on Cloudflare’s current product documentation, it does not use cookies or local storage for analytics collection.
We may also use cookies or similar technologies that are strictly necessary for security, session handling, or service delivery.
If we introduce non-essential cookies, advertising technologies, or analytics tools that require consent under applicable law, we will provide appropriate notice and consent controls before using them.
17. Changes to This Policy
We may update this policy from time to time. When we do, we will post the updated version here and update the “Last updated” date.
18. Contact
For privacy questions, rights requests, or transfer-safeguard requests, contact privacy@coresolutions.ltd.