Plain-language summary first, standard legalese after. Last updated: August 2026.
OpenVLAN ("we", "us") operates a Zero Trust networking platform at openvlan.com. This policy explains how we handle personal data when you use our website, control plane, and clients.
To provide the service you asked for: authenticating devices, applying your access policies, routing coordination, and keeping the network operational. Legal bases are contract performance and, where applicable, consent or legitimate interest (security logging, abuse prevention).
Coordination logs are kept for 30 days on free plans and per your plan's retention setting on paid plans. Deleting a tailnet removes device metadata within 30 days; device-held keys are destroyed immediately.
We share data only with subprocessors needed to run the service (hosting, email, payment processing), under data-processing agreements. We disclose data to authorities only when legally compelled, and publish transparency reports.
Access, export, correction, deletion, and objection — exercise any of them from the admin console or by emailing privacy@openvlan.com. If you're in the EEA/UK, you also have the right to lodge a complaint with your supervisory authority.
Servers run in the region you choose; cross-border transfers rely on Standard Contractual Clauses where required.
Data Protection inquiries: privacy@openvlan.com.
This document is an illustrative template for a demo site and is not legal advice.