Privacy Policy
What personal data we process, why, for how long, who else sees it, and the rights you hold over it.
Version 2026-09-09 · effective
1Who we are
Photon Now is operated by Alifanov Consulting, established in Norway (“we”, “us”). “Photon Now” below means the service. Our full provider details are on the provider information page.
For questions about this policy, or to exercise any of the rights in section 9, write to privacy@photonnow.com. We have not appointed a Data Protection Officer: our core activities do not involve large-scale, regular and systematic monitoring of individuals, so Article 37 of the GDPR does not require one.
2Two different roles
Photon Now processes two different kinds of data, and our legal role differs between them.
- Your account with us. Your email address, your sign-in credentials, your organisation membership and our security records about your use of the service. Here we are the controller, and this policy governs it.
- The data your devices and flows produce. Device names and identifiers, command output, logs, files you publish, tunnel activity — whatever your fleet sends us. Here we are a processor acting on your instructions, under our Data Processing Agreement.
If your personal data reached Photon Now because an organisation using our service put it there, that organisation is the controller — contact them. We will help them respond.
If you use Photon Now purely for personal or household purposes, we still hold what your devices send only to run the service for you, we keep to the DPA’s terms for it, and we treat what it reveals about you as your personal data under this policy.
3What we collect about you, and why
We do not buy data, we do not enrich profiles, and we do not track you across other sites. Everything below is collected because you gave it to us or because operating the service produced it.
| What | Where it comes from | Why |
|---|---|---|
| Email address (also your sign-in name) | Signup, or an invitation from your organisation | Identifying your account, signing you in, sending account email |
| The organisation name you chose at signup | Signup | Naming your organisation in the dashboard and on invoices |
| Password (stored only as a hash) | You choose it | Signing you in |
| Two-factor authentication secret and recovery codes (stored hashed) | Your authenticator app enrolment | Two-factor authentication |
| Session tokens | Created when you sign in | Keeping you signed in, and letting you or us revoke a session |
| Organisation, group, role and permission assignments | Your organisation administrator | Deciding what you may do and see |
| Security and activity records (what happened, who did it, when, from which IP address) | Your use of the service | Security and abuse prevention, and your organisation's audit trail |
| IP address and request details of any browser or agent that connects to us | Loading this site, the dashboard or the API | Operating and securing the service |
| Billing identifiers, subscription and seat state, and top-up purchase history | Stripe, when your organisation subscribes or buys a top-up | Taking payment and keeping accounting records |
| Anything you write to us | Email you send us | Answering you |
Payment details never reach us. Card numbers are entered directly into Stripe’s checkout and are held by Stripe. We store the identifiers Stripe gives us and the state of your subscription; Stripe holds your invoices, and we give it your account email so it can send receipts.
You need an email address and a password to have an account. We make no automated decisions about you and we do not profile you.
4Our lawful basis for each purpose
| Purpose | Lawful basis (GDPR Article 6) |
|---|---|
| Creating and running your account, and delivering the service you asked for | Performance of a contract — Art. 6(1)(b) |
| Security: two-factor authentication, rate limiting, abuse prevention, the audit trail and our server logs | Our legitimate interest in keeping a remote-access platform and its customers safe — Art. 6(1)(f) |
| Account email: verification, password reset, invitations, purchase confirmations and alert notifications | Performance of a contract — Art. 6(1)(b) |
| Taking payment, and keeping accounting records | Contract — Art. 6(1)(b) — and legal obligation — Art. 6(1)(c) |
| Answering your email | Contract, or our legitimate interest in responding to you — Art. 6(1)(b)/(f) |
Where we rely on a legitimate interest you may object at any time (section 9). We do not send marketing email, and we do not rely on consent for anything.
5Cookies and analytics
Photon Now sets no cookies of its own. When you sign in, your session token is kept in your browser’s local storage, which is strictly necessary for the dashboard to work and needs no consent — which is why there is no cookie banner.
This site carries a live chat from a third-party provider, which sets session cookies when a page loads. They expire when you close your browser and do not follow you to other sites. Nothing that identifies you across visits is stored unless you open the chat and accept the prompt it shows you.
Any usage analytics we run is cookieless and privacy-preserving: no advertising, no session replay and no tracking across other sites. If a third party provides it, we name them in section 6.
Profile pictures come from Gravatar (Automattic Inc., United States), which receives a one-way hash of your email address; if you have no Gravatar, the dashboard shows your initials.
6Who else processes your data
The providers that process your fleet’s data on our behalf are listed on the sub-processors page, which is the authoritative list. Each is a processor under contract with us, except Stripe, which is an independent controller for the payment itself.
A few other recipients handle only our own data about you: the hosts that serve this site and the dashboard to your browser (GitLab and Cloudflare, United States, whose access logs see your network address and the pages you open); Google (Google Workspace), which hosts our contact mailboxes and may process the email you send us in the United States; a live-chat provider in the United States, which receives your network address when a page loads and whatever you type into the chat; and Automattic, for the Gravatar request described in section 5.
We do not sell personal data and we do not share it for advertising. We disclose data to a public authority only where we are legally obliged to, and we will tell you unless we are forbidden from doing so.
7Where your data is
Our servers and our database are hosted by OVHcloud in the EU, and that is where your account data and your fleet’s data live. Data leaves the EEA only through the providers named on the sub-processors page and in section 6.
Each transfer to the United States relies on the European Commission’s Standard Contractual Clauses, incorporated in that provider’s data processing terms. We do not currently rely on the EU–US Data Privacy Framework. Write to privacy@photonnow.com for a copy of the clauses we rely on.
8How long we keep things
| Data | Kept for |
|---|---|
| Your account and its credentials (or an invitation sent to you, until it is accepted or revoked) | As long as the account exists, then deleted within 30 days of closure (sooner on request) and purged from backups within a further 14 days |
| Security-relevant activity records (sign-ins, permission changes, destructive actions, terminal and tunnel sessions, payments) | 365 days |
| Routine activity records | 90 days |
| Automated flow run history and step results | Up to 90 days, and only the most recent 100 runs per organisation |
| Alerts | 90 days after the last occurrence |
| Notification delivery records | 30 days |
| Our server logs | At most 14 days |
| Email you send us | Until the matter is closed and for up to twelve months afterwards; longer only if it is part of a dispute or a record we must keep |
| Invoices and the accounting records behind them | Five years after the end of the financial year, as Norwegian bookkeeping law requires |
Records with a horizon above are deleted automatically when it passes. Files you publish and your device records are kept until you delete them; the DPA governs what happens to them when your account ends.
9Your rights
Under the GDPR you may ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict a particular use of it, object to any processing we base on our legitimate interests (section 4), and ask for it in a portable form. Write to privacy@photonnow.com from the address on your account and we will answer within one month. There is no self-service export or delete in the dashboard yet; a person handles each request.
We cannot delete a record we are legally required to keep, such as an invoice. And if your account belongs to somebody else’s organisation, deleting your account does not delete that organisation’s own data about your activity in it — ask them.
If you think we have handled your data badly, please tell us first — but you are entitled to complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or to the supervisory authority where you live or work, and you do not have to come to us first.
10How we protect it
Passwords are stored only as hashes, two-factor authentication is available on every account, and every connection to our servers is encrypted in transit. Destructive actions require you to re-authenticate when you request them, and they are written to the audit trail. We describe our security measures in more detail on request, and to business customers in the DPA. If you have found a security problem, our disclosure policy tells you how to report it and what protection you have when you do.
If a breach affects you, we will tell you. We notify Datatilsynet within 72 hours where the law requires it, every affected customer without undue delay, and affected individuals directly where the risk to them is high.
11Children
Photon Now is a tool for managing computers and is not directed at children. We do not knowingly create accounts for anyone under 16.
12Changes to this policy
The version and effective date at the top of this page change whenever the text does. For a change that materially affects you we will email the address on your account before it takes effect. Superseded versions are available on request from hello@photonnow.com.