Data Processing Boundaries

A privacy policy is more than a promise—it is a verifiable data inventory

This policy explains what data NUMACS processes when you access content, manage orders, use dedicated physical Cloud Mac services, or contact us for support; why it is processed, who can access it, and how to submit a request.

Document status Current version
01 · Scope

What use cases does this policy cover?

This policy applies when you browse content on numacs.com, enter order management from a content page, create or manage a Cloud Mac order, use device services, or contact us through a console ticket or support email.

The content site provides product information, solutions, nodes, help documentation, and legal information. The order management portal handles authentication, device configuration, billing status, and service records. These interfaces serve different functions and therefore require different types of data.

When you use a NUMACS M4 Core or NUMACS M4 Plus dedicated physical machine, the code, dependencies, build artifacts, and project files on the device are customer content. Accounts, orders, device status, and security logs required to operate the platform are service data. They are managed separately by purpose, access conditions, and retention rules.

WEB

Content access

We process basic browser and request information to securely deliver pages, detect abnormal traffic, and improve content usability.

ORDER

Orders and accounts

We process identity, configuration, node, billing-cycle, settlement, and order-linked data to create and fulfill services.

DEVICE

Device services

We process device identifiers, operating status, and necessary event logs to deliver physical nodes and troubleshoot failures.

SUPPORT

Support communications

We process the issue details, redacted logs, and contact information you actively submit to investigate and respond to your request.

02 · Data categories

We process only the data needed for a defined task

Different actions require different fields. Simply browsing the content site does not automatically mean an order is created, and submitting a support request does not authorize us to view device content unrelated to the issue you describe.

Contact information
The name or preferred form of address and email address you provide, plus the language and request topic needed for ongoing communication.
Order-linked information
Account identifier, order number, selected model, rental term, node, add-ons, settlement status, and service start and end records.
Device and browser information
Request time, browser type, device type, network address, session security information, and technical signals used to detect abnormal access.
Support ticket content
Issue description, time of occurrence, reproduction steps, tools used, node, redacted logs, screenshots, and other materials you choose to attach.
Required service logs
Device status changes, authentication results, administrative actions, error codes, resource alerts, and audit events required to deliver the service.
03 · Purposes

Every processing activity serves a specific purpose

We do not use “improving the service” as an unlimited reason to expand data use. Each processing activity must correspond to a specific task involving service delivery, security, support, a contract, or a legal obligation.

A

Provide and fulfill services

Create accounts, confirm orders, assign configurations and nodes, deliver device information, record rental terms, and handle device management requests.

B

Protect accounts and infrastructure

Verify sign-ins, detect abnormal requests, limit automated abuse, audit high-risk administrative actions, and preserve the integrity of service access.

C

Troubleshoot and resolve issues

Use the order number, node, time of occurrence, error information, and necessary logs to reconstruct connection, build, storage, or network issues.

D

Meet contractual and legal obligations

Retain necessary transaction and service records, handle rights requests, and respond to valid legal procedures where required.

The applicable basis depends on the context and may include fulfilling an order you created, taking steps you requested, protecting the legitimate interests of the platform and its users, obtaining necessary consent, and meeting obligations under the laws of the jurisdiction where the platform operator is based.

04 · Billing

Payment information has clear boundaries between the content site, platform, and processors

USD

All billing is in USD

Order amounts, payment status, and billing records are displayed in US dollars (USD).

USDT-TRC20 We record the transaction identifier and settlement status needed to reconcile completed orders.
Visa / Mastercard / Amex Card payments are processed through Stripe; available gateways are determined by the backend response.

The NUMACS content site does not collect payment form data or store complete card numbers, complete security codes, or complete card credentials. The order system retains only information needed to complete orders, reconcile billing, manage risk, and meet legal obligations, such as payment method type, transaction result, amount, currency, and related identifiers.

Payment processors handle necessary data according to their payment-processing responsibilities. We exchange information with them only as needed to complete settlement, process refunds or disputes, reconcile accounts, and prevent abuse.

05 · Customer content

You manage project data on your device; support access requires a specific reason

You are responsible for organizing, authorizing, and backing up source code, build artifacts, dependency caches, media assets, configuration files, keys, and project data stored on your Cloud Mac. NUMACS does not scan project data for content analysis or advertising.

When requesting technical support, first provide the order number, node, time of occurrence, reproduction steps, and redacted error information. Only when these materials are insufficient to locate the issue and you explicitly request further assistance will we assess whether additional temporary diagnostic steps are needed.

What you are responsible for

  • Manage device access credentials and SSH keys
  • Control permissions for repositories, certificates, and project files
  • Continuously back up code, assets, and build artifacts
  • Remove sensitive fields before submitting logs
  • Export and verify necessary data before the rental term ends

What the platform handles

  • Maintain necessary links between orders and devices
  • Record device status and administrative action results
  • Troubleshoot issues within the scope of the ticket
  • Limit support-material access to relevant personnel
  • Apply the relevant retention rules after processing is complete
06 · Sharing

Sharing occurs only through links necessary to deliver the service

We do not sell personal data. Data may be processed by service providers responsible for infrastructure operations, identity and security, payment processing, customer support, or responding to valid legal requirements, only as necessary for those responsibilities.

When selecting processors, we consider and restrict their task scope, access permissions, security capabilities, confidentiality obligations, and deletion arrangements. Participants may process data only for agreed purposes and may not use it for independent marketing unrelated to NUMACS services.

Because device nodes, support collaboration, and payment processing may take place in different regions, data may be processed across borders. Such processing is limited to what is needed to fulfill orders, operate infrastructure, maintain security, or provide support, with contractual, access, and technical controls applied under applicable rules.

01

Request received

Browsing, orders, or support requests generate the data needed to complete the task.

02

Minimal distribution

Data flows only to the relevant identity, security, payment, device, or support function.

03

Access control

Access is limited by responsibility, and necessary high-risk administrative actions are logged.

04

End-of-life processing

Data is deleted or de-identified after the task is complete and the necessary retention period has elapsed.

07 · Lifecycle

Retention depends on purpose, not a one-size-fits-all period

We set retention periods based on order fulfillment, support handling, account security, dispute resolution, financial records, and compliance obligations. We consider data volume, sensitivity, risks from unauthorized use, whether the purpose has been completed, and whether a lower-data alternative exists.

Account and order records
Retained for as long as necessary to provide services, process settlement, maintain billing records, and fulfill applicable obligations.
Support materials
Retained as long as needed to resolve the request, verify the outcome, and address related follow-up issues; attachments no longer needed enter the deletion process.
Security and audit logs
Retained for the period needed to investigate abnormal activity, protect accounts, and verify administrative actions.
Customer content on devices
Users should manage and back up this content during the rental term and complete migration and verification before the service ends.

After the retention purpose is complete, data is deleted, aggregated, or de-identified. If deletion must be paused for a valid legal requirement, security investigation, or dispute, retention measures apply only to the relevant scope.

08 · Rights requests

You can request access to, correction of, or deletion of your data

Where permitted by applicable rules, you may request access, correction, deletion, restriction of processing, a copy of your data, or object to specific processing. Some requests may be reasonably limited by order fulfillment, security records, legal obligations, or the rights of others.

To prevent data from being disclosed to the wrong person, we verify account-linked information based on the request type. Where possible, provide your login email, relevant order number, data scope, and requested action. Do not include passwords, private keys, or complete payment credentials in your first email.

1

Describe the request scope

Specify the account, order, ticket, or other data you want us to review.

2

Complete identity verification

Confirm through necessary account-linked information that the requester is the data subject.

3

Process and respond

We will complete the search, correction, export, restriction, or deletion and explain the outcome.

Submit a privacy request

Email support@numacs.com, or sign in to the console to submit a ticket. Use the same email for business inquiries, security reports, and compliance-material requests.

Disputes related to this policy, data processing, or rights requests are governed by the laws of the jurisdiction where the platform operator is based and handled by courts with jurisdiction in that jurisdiction.

For service usage rules, order responsibilities, and acceptable use requirements, see the Terms of Service.

Clarify the request before submitting materials

The more complete your account email, order number, data scope, and requested action, the clearer the verification and processing path. Redact every attachment before submitting it.