Legal

Privacy Policy

How Mycellium Data collects, uses and protects information when you request access, complete onboarding and run your ISP on the platform.

Last updated · July 2026

1. Overview

Mycellium Data is a multi-tenant operations platform for Internet Service Providers — billing, CRM, NOC monitoring and AI-assisted support for fiber, hotspot and community networks. This policy explains what we collect, why we collect it, and the boundaries we enforce around it. It applies to the marketing site, the signup and onboarding flow, and every panel we operate.

2. What we collect

We collect the minimum needed to provision and operate your tenant:

  • Signup data. Company name, contact person, email address, phone number and country — submitted through the access-request form.
  • KYC data. Business registration details, physical address, and ownership or authorised-signatory information collected during onboarding, before provisioning begins.
  • Account credentials. Panel logins with bcrypt-hashed passwords and TOTP two-factor secrets, stored encrypted.
  • Billing records. Invoices, payment references and subscription state for your plan.
  • Operational logs. Provisioning steps, audit events and support correspondence tied to your account.

3. Tenant data isolation

Every ISP on Mycellium Data gets its own dedicated database. Your subscribers, invoices, tickets, network metrics and staff records live in a database that belongs to your tenant alone — never pooled with another ISP's data in shared tables.

Platform-level data (your signup request, KYC record, plan and subscription) lives in the central platform database, separated from every tenant database by design. One tenant's panels cannot read another tenant's rows — the routing and session layers enforce this on every request.

4. How we use information

  • To provision your isolated database, branded panels, DNS and SSL.
  • To verify your business during KYC and keep the platform free of abuse.
  • To invoice you, process payments and manage your subscription.
  • To send service notifications — provisioning status, billing events, security alerts.
  • To operate, secure and improve the platform, including capacity planning and uptime monitoring.

We do not sell your data, and we do not use your subscribers' data for advertising.

5. Cookies and sessions

We use strictly necessary cookies: session cookies that keep you signed in to your panels, and CSRF tokens that protect every form. Platform and tenant sessions use separate cookies and guards — a session on one tenant's panels never authenticates you on another's. We do not use third-party advertising or tracking cookies.

6. Who we share data with

Data is shared only where it is required to run the service: infrastructure and hosting providers that serve your tenant, payment processors that settle your invoices, and email delivery services that carry transactional mail. Each processor is bound to handle data only on our instructions. We disclose data to authorities only where the law compels it.

7. Security

Traffic is encrypted in transit; secrets and credentials are encrypted at rest. Administrative access follows least privilege, master-panel access requires two-factor authentication, and every mutating administrative action is written to an audit log. Tenant databases are isolated per ISP, and nightly backups are retained on a rolling schedule.

8. Retention

We keep your platform account data for as long as your subscription is active, and for a limited period afterwards to meet legal, tax and accounting obligations. Signup requests that are never completed expire and are purged. When your tenant is terminated, your database is retained for a defined grace period — during which you can request an export — and then destroyed.

9. Your rights

You may request access to the personal data we hold about you, correct inaccurate records, request an export of your tenant's data, and ask for deletion where retention is not legally required. For data you hold about your own subscribers inside your tenant, you are the controller — we process it on your behalf.

10. Changes to this policy

If we change this policy we will post the revised version here with a new effective date. Material changes are announced to active tenants by email before they take effect.

11. Contact

Questions about privacy, or a request to exercise your rights — email support@cloudmaster.tech.

Your data, your cloud

One isolated database per ISP. No exceptions.

See how Mycellium Data provisions your sovereign tenant in minutes — database, panels, DNS and SSL included.