Legal

Privacy Policy

Plain-language summary first, standard legalese after. Last updated: August 2026.

Short version

1. Who we are

OpenVLAN ("we", "us") operates a Zero Trust networking platform at openvlan.com. This policy explains how we handle personal data when you use our website, control plane, and clients.

2. Data we process

3. Why we process it

To provide the service you asked for: authenticating devices, applying your access policies, routing coordination, and keeping the network operational. Legal bases are contract performance and, where applicable, consent or legitimate interest (security logging, abuse prevention).

4. Retention

Coordination logs are kept for 30 days on free plans and per your plan's retention setting on paid plans. Deleting a tailnet removes device metadata within 30 days; device-held keys are destroyed immediately.

5. Sharing

We share data only with subprocessors needed to run the service (hosting, email, payment processing), under data-processing agreements. We disclose data to authorities only when legally compelled, and publish transparency reports.

6. Your rights

Access, export, correction, deletion, and objection — exercise any of them from the admin console or by emailing privacy@openvlan.com. If you're in the EEA/UK, you also have the right to lodge a complaint with your supervisory authority.

7. International transfers

Servers run in the region you choose; cross-border transfers rely on Standard Contractual Clauses where required.

8. Contact

Data Protection inquiries: privacy@openvlan.com.

This document is an illustrative template for a demo site and is not legal advice.