Informação legal
Política de privacidade
Que dados pessoais tratamos, porquê, e o que nos pode pedir.
Este documento está disponível apenas em inglês. É intencional: é a versão que faz fé, e um texto legal traduzido seria uma segunda redação que ninguém verificou.
Última atualização 3 de set. de 2026
Provibr is a server management platform. This statement explains what personal data we process when you visit our website or use the Provibr panel and agent, why we process it, and what rights you have. We have written it to be readable; nothing in it is meant to hide behind legal phrasing.
1Who we are
Provibr is operated by FullStack Studio, registered in the Netherlands (Chamber of Commerce no. 42097493). We are the controller for the personal data described in this statement, except where section 8 says otherwise.
You can reach us about privacy matters at info@provibr.com.
2What this statement covers
- the marketing website at provibr.com;
- the customer panel at app.provibr.com;
- the Provibr agent, the software you install on your own infrastructure, insofar as it sends data to our platform.
3What we collect and why
Your account
When you create an account we store your name, email address, and password (stored as a salted hash — we cannot read it), plus your language preference if you set one. If you enable two-factor authentication or passkeys, we store the data needed to verify them (a TOTP secret and recovery codes, both encrypted at rest, or the public half of a passkey — never the private key, which stays on your device).
We use this data to authenticate you and operate your account. Legal basis: performance of our contract with you.
Your profile picture in the panel comes from Gravatar, a service of Automattic that links a picture to an email address. To show it, our server sends a one-way hash (SHA-256) of your email address to Gravatar and passes the picture on to you itself. Your browser never contacts Gravatar to display it, so your IP address, the page you were looking at, and any Gravatar cookies you may have are not shared. We do not store the picture in our database; it is held in memory for at most a day so we do not have to ask again. If your address has no Gravatar, the panel shows your initials and nothing at all is requested from a third party. Legal basis: our legitimate interest in a panel where you can tell members apart at a glance — you decide whether an address of yours has a Gravatar at all.
Your organization
An account belongs to an organization (what the panel calls an "account"). We store the organization name, who its members are, their roles and permissions, and pending invitations (the invited email address). Legal basis: performance of contract.
API keys
If you create a key for our public API, we store the name you give it, the first eight characters of the key so you can recognise it in a list, a hash of the key, the permissions you granted it, an optional list of IP addresses it may be used from, and roughly when it was last used. The key itself is shown to you once, at the moment you create it, and is never stored — we cannot read it back. The "last used" moment is written at most once every fifteen minutes: it answers whether a key is still in use without us keeping a record of every request you make. Legal basis: performance of contract.
Billing
Payments are processed by Stripe. We never receive or store your bank account or card details — Stripe handles those. We store what Stripe reports back to us: payment status, amount, method, and reference IDs (including mandate references for recurring payments). We also store your subscription, credit ledger, and the pro forma documents and invoices we generate, which carry your organization name and billing details.
If final invoicing is enabled, we send your billing contact's name and email address and the invoice lines to Moneybird, our invoicing provider, to issue the official invoice.
Legal bases: performance of contract, and our legal obligation to keep financial records.
Support
When you open a support ticket we store the ticket, its messages, and who wrote them, so we can help you and keep a record of what was agreed. Legal basis: performance of contract and our legitimate interest in keeping an accurate support history.
Data about your infrastructure
This is the heart of the product, so we want to be precise about it:
- Your infrastructure credentials never touch our database. API tokens and passwords for your hypervisors and panels are encrypted and stored only on your own agent host. When you submit them, they pass through our platform once, transiently, to reach your agent; our audit records store only the names of the fields you filled in, never their values.
- The agent connects outbound only. We never connect into your network, and you open no inbound ports.
- The agent reports operational data to the panel: basic host facts (hostname, OS and kernel version, CPU count), the inventory it manages (server names, IDs, IP and MAC addresses, resource usage metrics), and structured log records. Log records use fixed event codes with parameters — there is no field a raw system log fits into — and known secret patterns are redacted before records leave your host.
- Console sessions (VNC / terminal) are relayed as an encrypted byte stream. We record session metadata (who, when, how long, how many bytes) for auditing, but never the content — a console is where passwords get typed.
Legal basis: performance of contract.
Audit log
Actions in the panel (creating a server, inviting a member, changing permissions, and so on) are written to an activity log visible to your organization, together with who performed them. This log exists so you can answer "who did what" — we consider that a feature, not a byproduct. Legal basis: performance of contract and our legitimate interest in traceability and abuse prevention.
Preventing abuse of the free trial
The trial runs for fourteen days without payment details, which makes it worth abusing: the same person signs up again every couple of weeks and enrols the same machine under a new account. To recognise that pattern we compare a small number of characteristics between trial accounts created in the last thirty days:
- a salted, one-way hash of the machine identity of the host your agent runs on. We never receive the identity itself, and the stored hash identifies nothing outside Provibr;
- the email address and domain name you registered with, reduced to the mailbox behind them (plus addressing and Google dots removed);
- the host name your agent reports for itself;
- the IP address of the session you registered from, which we read from your sign-in session rather than storing a second copy.
We keep only the outcome of that comparison: a score, the reasons behind it, and the identifiers of the other accounts a characteristic points at. The characteristics themselves are not copied into it.
Legal basis: our legitimate interest in preventing abuse of the free trial (Article 6(1)(f) GDPR; recital 47 names fraud prevention as such an interest). There is no automated decision with legal or similarly significant effect: nothing is refused, shortened, suspended or emailed on this outcome. It is shown to an administrator, who reads it and weighs it, because reused hosts and customers who moved between providers do exist. You can object to this processing at any time at info@provibr.com.
Website visits
Our servers and Cloudflare, which sits in front of our websites, process technical request data (IP address, requested page, browser type) to deliver the site and protect it against attacks. We keep short-lived server logs for troubleshooting and security. Legal basis: legitimate interest in operating and securing the service.
We also use Google Analytics to understand how the website is used: which pages are visited, roughly where visitors come from, and what kind of device and browser they use. It is configured privacy-friendly: IP addresses are truncated, the data is not shared with Google for advertising purposes, and we do not use it to identify individual visitors. Analytics only runs after you accept it via the cookie notice. Legal basis: consent.
We also use Ahrefs Analytics for the same kind of aggregate statistics. It is cookieless by design: it stores nothing on your device, sets no identifier, and builds no visitor profile, which is why it runs without asking for consent and does not appear in the cookie table. Legal basis: legitimate interest in understanding how the website is used.
When you use the chat assistant on our website, your message and the recent conversation are sent to Anthropic, our AI provider, so it can generate a reply. The assistant only answers questions about Provibr, from our own documentation. We do not store the conversation on our servers — it lives in your browser and is sent per request — and we ask you never to paste a password, key, or personal data into it. Legal basis: legitimate interest in helping visitors understand the product, and acting on your request when you choose to use the assistant.
4What we do not do
- No advertising trackers. We use Google Analytics (only with your consent) and the cookieless Ahrefs Analytics for aggregate visitor statistics (see section 3) — but we load no advertising or cross-site tracking scripts, ever.
- We do not sell personal data, and we do not share it with anyone except the processors named in this statement.
- We do not read your infrastructure. The agent reports the operational data described above and nothing else; it does not inspect the workloads running on your machines.
- Embedded video loads only on request. The tutorials page shows thumbnails we host ourselves; nothing reaches YouTube or Google until you click play on a video, and the player we then load runs on
youtube-nocookie.com.
5Cookies
We use the following cookies:
| Cookie | Purpose | Type |
|---|---|---|
better-auth.session_token | Keeps you signed in to the panel | Strictly necessary |
provibr-locale | Remembers your language choice | Preference |
provibr-consent | Remembers whether you accepted or declined analytics cookies, when you chose, and which version of this notice you saw | Strictly necessary |
_ga, _ga_* | Google Analytics: distinguishes visitors for aggregate site statistics | Analytics (consent) |
better-auth.two_factor | Carries your sign-in between the password step and the two-factor step | Strictly necessary |
better-auth.better-auth-passkey | Holds the one-time challenge while your passkey is verified | Strictly necessary |
plic_*, plic_code_*, pv_code_* | Hand a newly created agent its licence file and activation code, once | Strictly necessary |
In the panel the session cookie carries a __Secure- prefix (__Secure-better-auth.session_token), because the panel is served over https.
The session, language, and consent cookies are needed for the site to work and require no consent. The Google Analytics cookies are set only after you accept them via the cookie notice; if you decline, the site works exactly the same. Without a language cookie we read your browser's Accept-Language header to pick a language; that header is not stored.
6Who we share data with (processors)
| Party | Role | What they receive |
|---|---|---|
| Stripe Payments Europe, Ltd. (IE) | Payment processing | Payment details you enter on their checkout; your language preference |
| Moneybird B.V. (NL) | Invoicing | Billing contact name and email, invoice lines |
| Cloudflare, Inc. (US) | CDN and security proxy for our websites | Technical request data (IP address, requested URLs) |
| Google Ireland Ltd. (IE) | Website analytics (Google Analytics) | Truncated IP address, pages visited, device and browser information — only with your consent |
| Ahrefs Pte. Ltd. (SG) | Website analytics (Ahrefs Analytics, cookieless) | Technical request data (IP address, page visited, referrer, browser type) — no cookies or device identifiers |
| Anthropic PBC (US) | AI provider for the website chat assistant | The chat messages you send to the assistant |
| Automattic, Inc. (US) | Profile pictures in the panel (Gravatar) | A one-way hash of your email address |
| Google Ireland Ltd. (IE) | Video playback for the tutorials page (YouTube, privacy-enhanced mode) | IP address, device and browser information — only after you click play on a tutorial |
Hosting is done in-house: Provibr runs on FullStack Studio's own servers, located in the Netherlands. We do not use a third-party hosting provider for platform data.
Where a processor is established outside the EEA or moves data there (Cloudflare, Google, Ahrefs, Anthropic, Automattic), transfers are covered by an adequacy decision (EU–US Data Privacy Framework) and/or Standard Contractual Clauses.
7How long we keep data
- Account and organization data: for as long as your account exists, then deleted within a reasonable period after closure.
- Trial abuse signals: removed by the nightly sweep as soon as the trial ends or the account starts paying, so they never outlive the trial they describe. The machine identity hash stays on the agent record for as long as that agent exists, and the registration IP is not stored separately: it disappears with the sign-in session it belongs to, seven days after that session was last used.
- API keys: for as long as your account exists. Revoking a key does not remove it: the row stays in your list as history, so you can still see that it existed, what it was allowed to do, and when it was last used.
- API idempotency records: 24 hours. A short-lived technical copy of the answer we gave to a repeatable API request, so a client whose connection dropped can safely retry it.
- Invoices and payment records: 7 years, as required by Dutch tax law.
- Server performance metrics: detailed data for a few hours; five-minute aggregates for up to 90 days so long-range graphs keep working. Agent and link metrics: aggregated data for up to 90 days.
- Agent log records: about 7 days.
- Webhook deliveries: 90 days. We keep what we sent, the response status, how long it took, and the IP address we connected to, so a delivery that failed can still be explained afterwards.
- Script console output: 30 days. What your automation and flow scripts print while they run.
- Flow run history: 12 months. Which script template and version we rendered for which server, and the non-secret values we filled in — never the rendered result, and never a secret.
- Daily usage counts: 13 months. One row per account per day recording how many servers it had. Your invoices are kept separately for 7 years, as above.
- Analytics data: up to 14 months, after which Google Analytics deletes it automatically.
- Chat assistant conversations: not stored on our servers. Your messages travel to Anthropic per request to generate a reply; Anthropic may keep them for a limited period for its own trust-and-safety purposes, per its policy, and then deletes them.
- Audit events and support tickets: for the life of your account, because they document what happened and what was agreed.
- Database backups: rotated automatically after 14 days.
8When we act as a processor
The infrastructure data your organization manages through Provibr — server inventories, IP address plans, hostnames, the content of scripts you write — is your data. To the extent it contains personal data (for example, a hostname or IP plan that identifies one of your own customers), you are the controller and we process it only on your instructions, as your processor. The terms of that processing are set out in our Data Processing Agreement, which forms part of the Terms of Service and applies automatically — no signature required.
9Security
Security is the product's design constraint, not an add-on:
- All traffic between panel, platform, and agent is encrypted in transit on every leg of the route — including between our CDN and our own servers (TLS 1.2 or newer; agents authenticate with mutual TLS and pinned certificates).
- The agent connects outbound only; your network stays closed.
- Your infrastructure credentials are stored encrypted on your own host only, with a key bound to that machine.
- Payment provider API keys and script secrets stored on our platform are encrypted at rest (AES-256-GCM).
- Access within our platform follows least privilege: members see only what their role and permissions allow, and organizations are strictly isolated from one another.
- When our support staff need to look into your account, they do so by temporarily acting as one of your members, with exactly that member's permissions and never more, and every such session is recorded and shown to you in your own activity log. Anything that could cause lasting harm, such as deleting or reinstalling a server or changing credentials, stays blocked until you generate a one-time code and give it to us; that consent is yours to give and to revoke at any time. Our staff can never see or set your password, and never read your two-factor recovery codes.
- Databases are backed up daily.
No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the Dutch Data Protection Authority as the GDPR requires.
10Your rights
Under the GDPR you can ask us to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it (where we are not legally required to keep it — invoices, for example, must stay for 7 years);
- restrict or object to processing based on our legitimate interests;
- receive your data in a portable format.
Email info@provibr.com and we will respond within one month. You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
11Children
Provibr is a business service and is not directed at children. We do not knowingly process data of anyone under 16.
12Changes to this statement
If we change this statement in a way that matters, we will announce it in the panel before the change takes effect. The date at the top always tells you when it was last revised.
13Contact
- FullStack Studio
- Chamber of Commerce: 42097493
- Email: info@provibr.com
O aviso volta a aparecer e pode escolher de novo.
Comece com um host e um agente
Crie uma conta, instale o agente com um único comando e ligue o seu primeiro host Proxmox. O período experimental dura 14 dias e não pede quaisquer dados de pagamento.