Skip to main content
CedraStack
ServicesPlansAboutContactEmergencyKnowledge BaseFAQRequest Support
/

CedraStack · Legal policies

Privacy Policy

Version 2026-10-07.1 · Effective 2026-10-07 · Updated 2026-10-07

1. Scope and responsibilities2. Identity, company and inquiry information3. Billing and service records4. Security and account data5. Purposes and use6. Providers and international processing7. Cookies, browser storage and verification8. Email and optional tracking9. Security and confidentiality10. Retention, requests and deletion11. Updates

1. Scope and responsibilities

CedraStack, based in Lebanon and serving clients worldwide, uses portal and inquiry data to administer accounts, deliver support and manage its business. For those purposes it determines how the information is used. When supporting a client’s systems under documented instructions, it may act as that client’s processor; the DPA and service order describe that separate relationship. Privacy requests: hello@cedrastack.com.

2. Identity, company and inquiry information

We collect names, email addresses, phone numbers, language preferences, company names, country/city, company size, contact preferences and inquiry descriptions. Lead requests also include urgency and service interests. Contact form contents are sent by transactional email; lead requests are stored for follow-up and may be linked to a later company account. Please submit only information necessary for your request.

3. Billing and service records

We process subscription and commitment details, invoices, payment references and proofs, tickets/messages/attachments, bookings, work dates and durations, infrastructure assets, onboarding checklists, uploaded documents, maintenance and monthly reports. Authorized administrators may keep internal operational notes and tasks. Client portal visibility is limited by company membership and role; internal notes are not client-facing reports.

4. Security and account data

Passwords are hashed. MFA authenticator seeds are encrypted; recovery codes and session/reset tokens are hashed in storage. Sessions and security history can contain IP addresses, browser User-Agent, timestamps and security actions. We also process roles, verification status, policy acceptance receipts, audit logs and deletion requests. These records support access control, abuse prevention, incident investigation and accountability. Do not submit third-party passwords or special-category personal data unless expressly necessary and agreed through an appropriate channel.

5. Purposes and use

Information is used for account administration, agreed support, billing, maintenance, service reports, transactional communications, security and financial/legal recordkeeping. Lead acknowledgement allows us to review and answer the inquiry; it is not marketing consent. We do not sell portal information. Any separate marketing programme would require its own notice and applicable permission rather than reusing contract acceptance.

6. Providers and international processing

Cloudflare provides application hosting, D1 database storage, R2 file storage and Turnstile verification. Brevo delivers transactional emails, which contain recipient details and relevant account or service information. Provider infrastructure may process data in multiple countries outside your own. Payment services shown in checkout or invoices, including Whish where applicable, may receive payment information under their own terms. See Subprocessors. No Payoneer or card integration is implied. Applicable transfer arrangements must be assessed for the relationship; this policy is not a claim of GDPR compliance or certification.

7. Cookies, browser storage and verification

cedrastack_session is an authentication cookie with a seven-day maximum lifetime, HttpOnly and SameSite=Lax; Secure is applied over HTTPS. The cedrastack-language localStorage entry remembers EN/FR preference. Protected forms load Cloudflare Turnstile, which processes browser/challenge information; the server sends the verification token and IP when available. The application currently contains no advertising or marketing analytics. No marketing cookie banner is added for functionality that is not present. Provider security behavior may vary with its configuration.

8. Email and optional tracking

We send verification/reset links, security alerts, support, billing, invitation and service messages through Brevo. The application requests no optional pixel tracking for all recipients. Brevo account settings must also enable the provider’s per-contact tracking controls; provider-level delivery logs and security processing remain. Do not assume email is a secure channel for credentials.

9. Security and confidentiality

We use role/company access controls, restricted file delivery, password hashing, MFA protections, session management and bounded operational logging. Access is limited to people and providers needed for the service. These measures reduce risk but do not make any system completely secure. Notify support@cedrastack.com promptly if you suspect unauthorized access.

10. Retention, requests and deletion

See Retention for category-specific periods and manual review limits. Eligible account deletion has a 30-day reversible grace period, followed by administrator cleanup; shared company accounts need assistance. Service content and private files are removed, with durable retry queues for storage failures. Financial and minimized audit/legal records may remain; provider email copies and backups have separate processes. Request access, correction, deletion or export at hello@cedrastack.com; we verify identity and authority and assess applicable obligations. Some requests require manual work; there is no universal self-service export.

11. Updates

The version and effective date identify this notice. Historical snapshots remain available in Legal/Policies. Material updates can trigger a portal acknowledgement. A privacy acknowledgement confirms receipt of the notice; it is not blanket consent for unrelated processing. Contact hello@cedrastack.com with questions.

SHA-256: fe57572613afdc8c52375e7e4c504e2057b9b819997d03b398eecd0537c08929

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
CedraStack
CedraStack

Remote IT & Cloud Support for Modern Businesses.

Beirut, Lebanon

Services

Microsoft 365Servers & VirtualizationNetworking & SecurityCloud & Infrastructure

Support

Support PlansEmergency SupportClient Portal

Contact

FAQRequest IT Supporthello@cedrastack.comsupport@cedrastack.com

Monday–Friday
08:00–18:00 Beirut

Legal

Client Terms of ServicePrivacy PolicySupport Policy and Response TargetsData Processing AgreementProviders and SubprocessorsData Retention Policy
© 2026 CedraStack. All rights reserved.