Photon Now
PricingDocsContactSign inStart free
All legal documents

Privacy Policy

What personal data we process, why, for how long, who else sees it, and the rights you hold over it.

Version 2026-09-09 · effective 2026-09-09


1Who we are

Photon Now is operated by Alifanov Consulting, established in Norway (“we”, “us”). “Photon Now” below means the service. Our full provider details are on the provider information page.

For questions about this policy, or to exercise any of the rights in section 9, write to privacy@photonnow.com. We have not appointed a Data Protection Officer: our core activities do not involve large-scale, regular and systematic monitoring of individuals, so Article 37 of the GDPR does not require one.

2Two different roles

Photon Now processes two different kinds of data, and our legal role differs between them.

  • Your account with us. Your email address, your sign-in credentials, your organisation membership and our security records about your use of the service. Here we are the controller, and this policy governs it.
  • The data your devices and flows produce. Device names and identifiers, command output, logs, files you publish, tunnel activity — whatever your fleet sends us. Here we are a processor acting on your instructions, under our Data Processing Agreement.

If your personal data reached Photon Now because an organisation using our service put it there, that organisation is the controller — contact them. We will help them respond.

If you use Photon Now purely for personal or household purposes, we still hold what your devices send only to run the service for you, we keep to the DPA’s terms for it, and we treat what it reveals about you as your personal data under this policy.

3What we collect about you, and why

We do not buy data, we do not enrich profiles, and we do not track you across other sites. Everything below is collected because you gave it to us or because operating the service produced it.

WhatWhere it comes fromWhy
Email address (also your sign-in name)Signup, or an invitation from your organisationIdentifying your account, signing you in, sending account email
The organisation name you chose at signupSignupNaming your organisation in the dashboard and on invoices
Password (stored only as a hash)You choose itSigning you in
Two-factor authentication secret and recovery codes (stored hashed)Your authenticator app enrolmentTwo-factor authentication
Session tokensCreated when you sign inKeeping you signed in, and letting you or us revoke a session
Organisation, group, role and permission assignmentsYour organisation administratorDeciding what you may do and see
Security and activity records (what happened, who did it, when, from which IP address)Your use of the serviceSecurity and abuse prevention, and your organisation's audit trail
IP address and request details of any browser or agent that connects to usLoading this site, the dashboard or the APIOperating and securing the service
Billing identifiers, subscription and seat state, and top-up purchase historyStripe, when your organisation subscribes or buys a top-upTaking payment and keeping accounting records
Anything you write to usEmail you send usAnswering you

Payment details never reach us. Card numbers are entered directly into Stripe’s checkout and are held by Stripe. We store the identifiers Stripe gives us and the state of your subscription; Stripe holds your invoices, and we give it your account email so it can send receipts.

You need an email address and a password to have an account. We make no automated decisions about you and we do not profile you.

4Our lawful basis for each purpose

PurposeLawful basis (GDPR Article 6)
Creating and running your account, and delivering the service you asked forPerformance of a contract — Art. 6(1)(b)
Security: two-factor authentication, rate limiting, abuse prevention, the audit trail and our server logsOur legitimate interest in keeping a remote-access platform and its customers safe — Art. 6(1)(f)
Account email: verification, password reset, invitations, purchase confirmations and alert notificationsPerformance of a contract — Art. 6(1)(b)
Taking payment, and keeping accounting recordsContract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c)
Answering your emailContract, or our legitimate interest in responding to you — Art. 6(1)(b)/(f)

Where we rely on a legitimate interest you may object at any time (section 9). We do not send marketing email, and we do not rely on consent for anything.

5Cookies and analytics

Photon Now sets no cookies of its own. When you sign in, your session token is kept in your browser’s local storage, which is strictly necessary for the dashboard to work and needs no consent — which is why there is no cookie banner.

This site carries a live chat from a third-party provider, which sets session cookies when a page loads. They expire when you close your browser and do not follow you to other sites. Nothing that identifies you across visits is stored unless you open the chat and accept the prompt it shows you.

Any usage analytics we run is cookieless and privacy-preserving: no advertising, no session replay and no tracking across other sites. If a third party provides it, we name them in section 6.

Profile pictures come from Gravatar (Automattic Inc., United States), which receives a one-way hash of your email address; if you have no Gravatar, the dashboard shows your initials.

6Who else processes your data

The providers that process your fleet’s data on our behalf are listed on the sub-processors page, which is the authoritative list. Each is a processor under contract with us, except Stripe, which is an independent controller for the payment itself.

A few other recipients handle only our own data about you: the hosts that serve this site and the dashboard to your browser (GitLab and Cloudflare, United States, whose access logs see your network address and the pages you open); Google (Google Workspace), which hosts our contact mailboxes and may process the email you send us in the United States; a live-chat provider in the United States, which receives your network address when a page loads and whatever you type into the chat; and Automattic, for the Gravatar request described in section 5.

We do not sell personal data and we do not share it for advertising. We disclose data to a public authority only where we are legally obliged to, and we will tell you unless we are forbidden from doing so.

7Where your data is

Our servers and our database are hosted by OVHcloud in the EU, and that is where your account data and your fleet’s data live. Data leaves the EEA only through the providers named on the sub-processors page and in section 6.

Each transfer to the United States relies on the European Commission’s Standard Contractual Clauses, incorporated in that provider’s data processing terms. We do not currently rely on the EU–US Data Privacy Framework. Write to privacy@photonnow.com for a copy of the clauses we rely on.

8How long we keep things

DataKept for
Your account and its credentials (or an invitation sent to you, until it is accepted or revoked)As long as the account exists, then deleted within 30 days of closure (sooner on request) and purged from backups within a further 14 days
Security-relevant activity records (sign-ins, permission changes, destructive actions, terminal and tunnel sessions, payments)365 days
Routine activity records90 days
Automated flow run history and step resultsUp to 90 days, and only the most recent 100 runs per organisation
Alerts90 days after the last occurrence
Notification delivery records30 days
Our server logsAt most 14 days
Email you send usUntil the matter is closed and for up to twelve months afterwards; longer only if it is part of a dispute or a record we must keep
Invoices and the accounting records behind themFive years after the end of the financial year, as Norwegian bookkeeping law requires

Records with a horizon above are deleted automatically when it passes. Files you publish and your device records are kept until you delete them; the DPA governs what happens to them when your account ends.

9Your rights

Under the GDPR you may ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict a particular use of it, object to any processing we base on our legitimate interests (section 4), and ask for it in a portable form. Write to privacy@photonnow.com from the address on your account and we will answer within one month. There is no self-service export or delete in the dashboard yet; a person handles each request.

We cannot delete a record we are legally required to keep, such as an invoice. And if your account belongs to somebody else’s organisation, deleting your account does not delete that organisation’s own data about your activity in it — ask them.

If you think we have handled your data badly, please tell us first — but you are entitled to complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or to the supervisory authority where you live or work, and you do not have to come to us first.

10How we protect it

Passwords are stored only as hashes, two-factor authentication is available on every account, and every connection to our servers is encrypted in transit. Destructive actions require you to re-authenticate when you request them, and they are written to the audit trail. We describe our security measures in more detail on request, and to business customers in the DPA. If you have found a security problem, our disclosure policy tells you how to report it and what protection you have when you do.

If a breach affects you, we will tell you. We notify Datatilsynet within 72 hours where the law requires it, every affected customer without undue delay, and affected individuals directly where the risk to them is high.

11Children

Photon Now is a tool for managing computers and is not directed at children. We do not knowingly create accounts for anyone under 16.

12Changes to this policy

The version and effective date at the top of this page change whenever the text does. For a change that materially affects you we will email the address on your account before it takes effect. Superseded versions are available on request from hello@photonnow.com.

Photon Now.·Built in Drammen, Norway 🇳🇴
PricingDocsSecurityContactSign in
© 2026 Alifanov Consulting
TermsPrivacyProvider informationLegal