GPUcloud

Privacy Policy

Version of 2026-10-11

This policy explains what personal information GPU Cloud collects, why, how long it keeps it, to whom it discloses it and how to exercise your rights, in accordance with the Quebec Act respecting the protection of personal information in the private sector and PIPEDA.

1. Person in charge of the protection of personal information

Person in charge of the protection of personal information, GPU Cloud — hboivin@hdce.ca

Write to this person for any question, complaint or request for access, correction, portability or deletion. We answer within 30 days.

2. Information collected

Identity and contact details: name, e-mail, company, phone, language, billing address.

Billing: credits, payments, receipts, invoices, taxes, payment tokens and the last four digits of the card. The full number of your card is never kept by GPU Cloud: it is processed only by our payment processor.

Security and technical data: IP address, browser, device cookie, log of sign-ins and sensitive actions, keys (only their fingerprint is kept), AI agent activity.

Use of the service: servers, events and hours billed; support tickets and attachments; log of the e-mails sent; consents given (terms, payments, promotional e-mails).

Purchase journey: first-party sales events (section 14), internal activity log of new customers (section 16) and requests sent with the need form, with or without an account (section 17).

We do not access the content of your servers, except at your request or where the law requires it.

3. Purposes

We use your information to: create and manage your account; provide, bill and support the service; secure your account (two-step verification, new sign-in alerts, trusted devices); send you the required notices (notices before a reload, balance and budget alerts, receipts); prevent fraud and answer payment disputes; meet our legal and tax obligations; measure and improve our purchase journey from internal statistics; send you getting-started tips and availability alerts; answer your quote requests.

We do no advertising profiling, no browser fingerprinting, and we do not sell your information.

4. Consent

We collect your information with your consent, given at sign-up and when accepting this policy, or where the law allows it without consent (performance of the contract, legal obligations, fraud prevention).

E-mails: on your first visit to the console, a separate, optional box that is never pre-checked lets you give your express consent to receive our tips, news and offers by e-mail; if your account already existed, an invitation is offered once in the console’s “Getting started” list. You can give or withdraw this consent at any time in Settings, Privacy, and every e-mail contains an unsubscribe link. We keep the proof of this consent: date, version and fingerprint of the exact text accepted, means used, IP address and browser.

News and offers are only sent with this express consent, which has no time limit. Without it, only the getting-started tips and interest alerts described in section 15 may be sent to you, under the implied consent provided for by Canada’s Anti-Spam Legislation (CASL): during the 6 months following your sign-up or the 2 years following your last purchase (credit top-up or paid order), and never after a refusal.

5. Retention

We keep your information only as long as needed for the purposes above or required by law, according to the retention table below. At the end of that period, it is destroyed or anonymized.

Invoices, payments, receipts, payment consent records: 6 years after the end of the fiscal year (tax obligations).

Audit trail (sign-ins, sensitive actions, AI agent actions): 6 years (evidence in case of dispute or chargeback).

Account profile (name, e-mail, company, phone, billing address): Life of the account; anonymized when the account is deleted (only the mentions required on invoices already issued remain).

Archive of a deleted account (full export of its data): 6 years in a restricted internal location (accounting and legal evidence), then destroyed.

Sign-in devices (device cookie, browser, last IP address): Until the device is removed or the account is deleted; the trust granted lapses after 90 days without use.

E-mails sent (log: recipient, subject, date): 6 years.

Support tickets and attachments: 3 years after the ticket is closed, or until the account is deleted if that happens first.

First-party sales events: 13 months, then deleted automatically; unlinked from the account when it is deleted.

Requests sent with the need form: 24 months, then deleted automatically; deleted earlier on request or when the account is deleted.

Purchase journey activity log and availability alerts: Life of the account; after the account is deleted, linked only to the anonymized identifier of the account.

6. Disclosure to third parties and outside Quebec

We disclose your information only to the subcontractors needed for the service: hosting and computing infrastructure providers, payment processor, e-mail delivery service. They process it only on our behalf, under a written confidentiality and security agreement.

Some of these subcontractors may process information outside Quebec, elsewhere in Canada or in the United States. Before any disclosure outside Quebec, we carry out a privacy impact assessment and ensure, by contract, that the information will receive adequate protection.

We may also disclose information where the law requires it (court order, tax authority) or to the payment processor in case of payment dispute.

7. Cookies and local storage

We only use strictly necessary cookies: the sign-in session cookie and the gpc_device device cookie (signed random value, not readable by scripts, one-year lifetime), used only to recognize a browser already used for your account and a device you declared trusted. No advertising or tracking cookie is used.

No cookie is used for statistics. The site keeps in your browser’s storage: gpc_aid, a random identifier replaced every day, sent with the sales events (section 14); gpc_attr, the source of the first page of your visit (UTM parameters and name of the site that referred you), erased when the tab is closed. No event is sent when your browser sends the Global Privacy Control (GPC) or Do Not Track (DNT) signal. You can erase this data at any time with the site data in your browser.

8. Your rights

Access and portability: “Download my data” in the console (Settings → Privacy) provides your information in a structured, commonly used format. Correction: edit your profile in the console or write to us.

Deletion: “Delete my account” in the console, after a 7-day withdrawal period; the information the law requires us to keep is anonymized rather than deleted. Withdrawal of consent: you may withdraw a consent at any time, subject to legal and contractual obligations. You may also request that the dissemination of information cease or that it be de-indexed where the law provides for it.

If you are not satisfied with our answer, you may file a complaint with the Commission d’accès à l’information du Québec or the Office of the Privacy Commissioner of Canada.

9. Security

We protect your information with reasonable measures: encrypted communications, mandatory two-step verification, restricted and logged administrative access, key fingerprints instead of the keys themselves, tamper-evident audit logs, backups and access control on archives.

10. Confidentiality incidents

We keep a register of confidentiality incidents. When an incident presents a risk of serious injury, we promptly notify the Commission d’accès à l’information and the persons concerned, and take measures to reduce the risk.

11. Automated decisions

Some decisions are made automatically: hibernation of hourly servers when the balance runs out or a budget limit is reached, refusal of spending beyond a limit, blocking of a sensitive action on a device that is not trusted. On request, we tell you the information and criteria that led to the decision, and you may submit your observations to a member of our team.

12. Minors

The Platform is intended for adults and businesses. We do not knowingly collect information about persons under 18.

13. E-mails

Transactional e-mails (receipts, notices before a reload, balance, budget and security alerts, invoices) are always sent. News and offers are only sent with your express consent (section 4). Getting-started tips and availability alerts follow the rules of section 15. All these e-mails contain an unsubscribe link (CASL).

14. First-party sales events

To measure and improve our purchase journey, we record ourselves, in our own database, short sales events: viewing the pricing or a GPU page, a stock-out shown, an availability alert request, sign-up, card saved, first deployment and credit top-up. Each event contains only its name, its date, a few short codes (product, model, kind, origin) and, where applicable, the source, medium and campaign (UTM parameters) of the first page of your visit, and the name of the site that referred you (never the full address of the page).

What is not collected: no IP address and no user agent is kept with these events, no cookie is used, no third-party script or tracker is loaded and these events are disclosed to no third party. When your browser sends the GPC or DNT signal, no browsing event is sent.

Browsing events are associated only with the random identifier of the day (gpc_aid), never with your account, even when you are signed in: they cannot link your visits from one day to the next. Only the events recorded by our servers during an action of your account (sign-up, card saved, first deployment, top-up, availability alert request) are linked to your account; at your sign-up, the source of your visit and the identifier of the day may be attached to it.

These events are used only to produce internal statistics, viewed by the platform administrators. They are deleted automatically 13 months after they are recorded. When your account is deleted, those linked to it are unlinked and only count in the totals.

15. Getting-started tips and availability alerts

After your sign-up, we may send you getting-started tips: a welcome e-mail then, as long as you have not launched any server, follow-ups about 1, 3 and 7 days after the sign-up, and a single reminder when a quote prepared in the console was not followed by an order after 24 hours, only if the machine is available at that time.

These e-mails rely on your express consent (section 4) or, failing that, on the implied consent provided for by CASL: without express consent, they are only sent during the 6 months following your sign-up or the 2 years following your last purchase. They stop as soon as you launch a first server or refuse promotional e-mails. At most one of these e-mails is sent per 20-hour period, and at most five in total. None is sent to an account that is disabled, deleted or subject to a deletion request.

Each e-mail states the sender’s name and postal address and the reason it was sent, and contains an unsubscribe link that works in one click, without signing in. That click records your refusal, even if you had never given express consent, and ends the getting-started tips and promotional e-mails; notices about your account (receipts, invoices, security) are still sent. These e-mails contain no tracking pixel or tracking link.

Availability alerts. When you click “Notify me” for an unavailable machine, we send you a single e-mail when it becomes available again; the request remains valid for 90 days and a new click renews it. This alert, which you asked for, is sent even without consent to promotional e-mails. We may also infer your interest in a machine from your activity in the console during the last 30 days (quote, refused order or deployment, viewing a product or the configurator). These interest alerts are promotional: they are only sent with your express consent or, failing that, within the implied consent described above, and never after a refusal. Each alert contains the unsubscribe link.

16. Follow-up of new customers

To help new customers get started and address their difficulties, we keep an internal activity log of the journey to a first server: quotes prepared, orders or deployments refused (for example for lack of availability or credit), payment failures and interest in a product. This log contains only codes (type, product, reason), never free text, secrets or card data.

From this log and the status of your account, the platform administrators receive internal follow-up notices (new sign-up, customer stuck at a step), at most one per customer and per type of notice. The log and these notices are used only for support and sales and are accessible only to the platform administrators.

This log is kept for the life of the account; after the account is deleted, it is linked only to the anonymized identifier of the account, without name or e-mail.

17. Business requests (need form)

The need form (Business page, machines offered on request or out of stock) can be filled in without an account. We collect: your e-mail and, if you provide them, your name, company and phone; the description of your need (GPU model, quantity, duration, start date, sector, data sovereignty requirement, message); where on the site the request comes from; the source, medium and campaign (UTM parameters) and the name of the site that referred you, where applicable; your language; your account, if you were signed in. No IP address is kept.

Your consent to be contacted about this request is required to send it. Your information is used only to answer your request and prepare a quote for you: sending it does not add you to any mailing list and is not consent to promotional e-mails. An acknowledgement is sent to you in your language, at most one per address and per day; the internal notice sent to our team does not contain your contact details.

Requests are accessible only to the platform administrators. They are deleted automatically 24 months after they are sent, or earlier on simple request to the person in charge of the protection of personal information (section 1). When an account is deleted, the requests sent from that account or with its e-mail address are deleted.

18. Changes and contact

Any new version of this policy is shown at your next console visit and must be accepted to keep using it. The date of the version in force appears at the top of the page.

Questions: hboivin@hdce.ca.

Retention policy

InformationRetention
Invoices, payments, receipts, payment consent records6 years after the end of the fiscal year (tax obligations)
Audit trail (sign-ins, sensitive actions, AI agent actions)6 years (evidence in case of dispute or chargeback)
Account profile (name, e-mail, company, phone, billing address)Life of the account; anonymized when the account is deleted (only the mentions required on invoices already issued remain)
Archive of a deleted account (full export of its data)6 years in a restricted internal location (accounting and legal evidence), then destroyed
Sign-in devices (device cookie, browser, last IP address)Until the device is removed or the account is deleted; the trust granted lapses after 90 days without use
E-mails sent (log: recipient, subject, date)6 years
Support tickets and attachments3 years after the ticket is closed, or until the account is deleted if that happens first
First-party sales events13 months, then deleted automatically; unlinked from the account when it is deleted
Requests sent with the need form24 months, then deleted automatically; deleted earlier on request or when the account is deleted
Purchase journey activity log and availability alertsLife of the account; after the account is deleted, linked only to the anonymized identifier of the account