Privacy Policy
PRIVACY POLICY
PRV Technologies
Last updated: June 22, 2026
Your privacy matters to us. This Privacy Policy explains how PRV Tech, a company registered in the Republic of Korea (Business Registration No. 727-86-02960), operating under the brand name “PRV Technologies” (“PRV Technologies”, “we”, “us” or “our”), collects, uses, shares, stores, and otherwise processes personal information when you use our bare metal dedicated servers, virtual machines, and related cloud infrastructure services (the “Services”), our website at https://prvtechnologies.com, our customer portal and applications, and any related sites or subdomains we operate.
“Personal information” means any information that identifies, relates to, or can reasonably be linked to an identifiable individual. This Privacy Policy should be read together with our Terms of Service and, where it applies to you, our Data Processing Addendum (DPA) and Cookie Policy.
Controller and processor. For personal information that we determine the purposes and means of processing, such as account registration data, billing and payment data, support communications, and data used for security and fraud prevention, we act as the data controller. For personal data contained within the content you store, run, or transmit through the Services (“Customer Content”), you are the controller and we act as your processor; that processing is governed by our DPA rather than by this Privacy Policy. This Privacy Policy describes our processing as a controller.
1. Who This Policy Covers
We process personal information about individuals who are our customers, prospective customers, website visitors, and (where our customer is a business or other organization) the employees, agents, and representatives of that customer. We refer to all such individuals as “you” in this Privacy Policy.
The Services are intended for adults. We do not knowingly collect personal information from anyone under 18 years of age (or the age of majority in your jurisdiction). If you believe a minor has provided us with personal information, please contact us so we can take appropriate steps.
2. Information We Collect
We collect information in two ways: information you provide to us, and information collected automatically when you use the Services.
2.1 Information You Provide
Account and identity data: Your full legal name or legal entity name, email address, phone number, postal/billing address, username, and account credentials.
Billing and payment data: Billing address, the currency of your transactions (Fees are charged in USD), and limited payment-card information. Card details are collected and processed by our PCI-DSS-compliant payment provider; we do not store full card numbers on our own systems.
Identity and fraud-prevention data: Information you submit during verification, and information we use to confirm eligibility, including for sanctions and export-control screening as described in our Terms of Service. This may include government-issued identification documents where strictly necessary to confirm identity and prevent infrastructure abuse. Where we collect identification documents, we use them solely to verify your identity, we store them using encryption while they are needed for that purpose, and we delete them or render them permanently unrecoverable promptly after verification is complete, except where we are required to retain them for a longer period by applicable law. We do not retain identification documents for longer than necessary for the verification purpose, and we do not keep them on file for general fraud-prevention purposes once verification is complete.
Support and communications data: The contents of messages, tickets, and other communications you send us, and records of our correspondence.
Marketing data: Your preferences for receiving communications from us, where you have opted in or where otherwise permitted by law.
2.2 Information Collected Automatically
Log and usage data: Your IP address, browser type and version, operating system, referring pages, the pages and resources you access, timestamps, and diagnostic or error data generated when you use the Services.
Device data: Device type, unique device identifiers, device settings, and (where enabled by you) approximate geo-location derived from your IP address or device.
Service-operational data: Metadata generated as you provision, configure, and use infrastructure resources, such as resource creation and deletion events, bandwidth and usage metrics, and billing-related usage records.
Cookies and similar technologies: Information collected through cookies and similar technologies as described in Section 8.
By itself, some of this information may not identify you, but it may become personal information when combined with other data.
2.3 Phone Numbers and SMS
We collect your phone number when you register, enable two-factor authentication, request security or password-reset verification, or opt in to SMS notifications. We use your phone number for account security, identity verification, and, where you have enabled them, service notifications, sent through our SMS service provider. You can opt out of non-essential messages at any time by replying STOP; essential security and transactional messages may continue where permitted by law. Message and data rates may apply, and message frequency varies.
3. How We Use Personal Information
We use personal information for the following purposes:
To create and administer your Account and provide the Services;
To process orders, billing, and payments, and to manage your Account Balance and subscriptions;
To communicate with you, including sending invoices, service and security notices, and responding to your requests;
To provide customer support and to investigate and resolve issues, including billing disputes and chargebacks;
To maintain the security, integrity, and availability of the Services, and to detect, prevent, and investigate fraud, abuse, and violations of our Terms or Acceptable Use Policy, including the automated detection of related or duplicate accounts described in our Terms;
To comply with legal obligations, including tax, accounting, sanctions, and export-control requirements, and to respond to lawful requests from authorities;
To operate, improve, and develop the Services and our website, including through analytics and performance and error monitoring provided by third-party services (Google Analytics 4, PostHog, and Sentry), and to measure and support advertising — which may include sharing certain information with third-party advertising platforms (Google advertising services) — as further described in Section 8 and our Cookie Policy. Where required by law, analytics and advertising activities that rely on non-essential cookies or similar technologies are carried out only with your consent;
To send marketing communications where you have consented or where otherwise permitted by law (you can opt out at any time); To deliver, measure, and improve advertising, including interest-based or cross-context advertising where you have consented or where otherwise permitted by law, and to share online identifiers and usage information with advertising platforms (Google advertising services) for these purposes, subject to your choices and applicable opt-out rights; and
To establish, exercise, or defend legal claims, and to enforce our agreements.
4. Legal Bases for Processing
Where data protection law requires a legal basis (for example, the Republic of Korea Personal Information Protection Act (PIPA), the EU/UK GDPR, or comparable laws), we rely on one or more of the following:
Performance of a contract: To provide the Services you have ordered, to deploy the necessary cloud infrastructure, and to administer your Account.
Legitimate interests: To secure and improve the Services, prevent fraud and abuse, and conduct limited marketing, balanced against your rights and interests.
Consent: For certain marketing and SMS notifications, and for analytics, performance-monitoring, advertising, and other non-essential cookies and similar technologies (and the related sharing of information with analytics and advertising providers) where consent is required by law. You may withdraw your consent at any time, without affecting processing already carried out, through our cookie preference center or as otherwise described in Section 8 and our Cookie Policy.
Legal obligation: To comply with tax, accounting, sanctions/export-control, and other statutory requirements.
The Services are intended only for adults, as described in Section 1, and are not directed to children. We do not knowingly rely on the consent of anyone below the age of 18 (or the age of majority or digital-consent age in their jurisdiction). If we become aware that we have collected personal information from such a person without appropriate authority, we will take reasonable steps to delete it.
5. How We Share Personal Information
We share personal information as described below. Depending on your location, some of our analytics and advertising activities may be considered a "sale" or "sharing" of personal information under applicable law; you can exercise your choices as described in Section 10 and our Cookie Policy, and we honor the Global Privacy Control (GPC) signal.
Service providers (processors): Vendors who process personal information on our behalf and under contract, such as global cloud and data-center infrastructure providers (including Supabase), content-delivery and security providers (including Cloudflare), payment processors, fraud-prevention and identity-verification services, SMS and email providers, customer-support tooling, and analytics and performance- and error-monitoring providers (including Google Analytics 4, PostHog, and Sentry).
Advertising platforms: Third-party advertising platforms (including Google advertising services) with which we share certain online identifiers and usage information, where you have consented or where otherwise permitted by law, to measure and support advertising, including advertising tailored to your interests across other sites and services. These platforms may process that information under their own privacy policies and, in some cases, for their own purposes.
Professional advisors and authorities: Legal, accounting, and similar advisors, and courts, regulators, or law-enforcement bodies where required by law or to establish, exercise, or defend legal rights.
Payment and card networks: Where necessary to process payments or to respond to and contest chargebacks.
Corporate transactions: An acquirer or successor in connection with a merger, acquisition, reorganization, financing, or sale of assets, subject to this Privacy Policy.
Categories of providers we rely on include global infrastructure and hosting providers, content-delivery and security providers, payment processors, fraud-prevention and verification services, communications (email/SMS) providers, customer-support platforms, analytics and performance- and error-monitoring providers, and advertising platforms. A current list naming the sub-processors that process Customer Content on your behalf is available to customers on written request to our Privacy Department, as described in our DPA. The specific third-party analytics and advertising providers used on our website, and the choices available to you, are identified in our Cookie Policy.
6. International Transfers (Cross-Border Data Transfers)
PRV Technologies is based in the Republic of Korea. To deliver our high-performance cloud infrastructure, we partner with top-tier third-party service providers and cloud infrastructure operators whose data centers and processing facilities are located outside of South Korea. As of the date of this Policy, the personal information we process as a controller is transferred to and processed in the United States, where our current infrastructure and certain operational, analytics, monitoring, and advertising vendors (including Google, PostHog, Sentry, Cloudflare, and Supabase) are located or process data. Some of these third-party providers may also process data in other countries in accordance with their own arrangements.
When you use our Services, your personal information is transferred to, stored, and processed in these overseas locations. These transfers are strictly necessary for the performance of our contract with you and to fulfill the core service obligations outlined in our Terms of Service.
Entities and Locations: Global infrastructure hosting providers, payment gateway operators, and operational support vendors. A current list naming the sub-processors that process personal information, and our current data-center locations, is available to customers on written request to our Privacy Department, as described in our DPA. We may add locations in other regions as we expand the Services, and we will update that information accordingly.
Items Transferred: Account data, IP address, log/usage metadata, billing details, and Customer Content (the processing of Customer Content is further described in, and governed by, our DPA).
Purpose and Timing: Transferred via electronic networks in real-time as you provision, utilize, or pay for the Services.
Retention Period: Personal information transferred abroad is retained and protected by our partners for the duration of your account life or as required by applicable statutory financial, tax, and cyber-security retention laws.
Where transfers are subject to the EU or UK GDPR, we ensure that our global partners enter into the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or rely on another lawful transfer mechanism for the relevant transfer. Where personal information is transferred to third-party analytics, monitoring, content-delivery, or advertising providers in countries outside the EEA or UK, those transfers rely on the providers’ own lawful transfer mechanisms, such as the EU-US Data Privacy Framework (for example, Google’s certification under that framework), the Standard Contractual Clauses, or the UK International Data Transfer Addendum, as applicable. Onward transfers from the Republic of Korea to other countries are carried out in accordance with the cross-border-transfer requirements of PIPA, including obtaining your consent where required. You may request a general overview of our data flows by contacting our Privacy Department.
7. How Long We Keep Personal Information and Destruction Procedures
We keep personal information only for as long as necessary for the purposes described in this Privacy Policy, including providing the Services, and for legitimate business, legal, tax, accounting, and dispute-resolution purposes.
Retention Period: As a general matter, account-related personal information is retained for the life of your Account. After your Account is terminated, our handling of Customer Content is governed by our Terms of Service and DPA, and we may retain specific transactional records for up to five (5) years, or for such other period as is required by applicable law, including any communications-data retention obligations that apply to us under the laws of the Republic of Korea.
Identification documents: Where you provide government-issued identification documents for verification, we keep them only for as long as needed to complete and confirm verification, and we delete them or render them permanently unrecoverable promptly afterward, unless a longer retention period is required by applicable law. While retained, such documents are stored using encryption and are accessible only to personnel who need them to carry out or confirm that verification. We do not retain the identification documents themselves for general fraud-prevention purposes after verification is complete; any ongoing fraud-prevention and security activity relies on other data described in this Policy, such as log, usage, and device data, and not on continued retention of your identification documents.
Destruction Procedures and Methods: When personal information becomes unnecessary because the retention period has expired or the purpose of processing has been achieved, we destroy it without delay. Personal information stored in electronic file formats is permanently deleted using technical methods that render the data completely unrecoverable, untraceable, and irreversible. Any physical documents or printouts containing personal information are securely shredded or incinerated.
8. Cookies and Similar Technologies
We use cookies and similar technologies to operate and secure our website and, with your consent where required by law, for analytics, performance and error monitoring, and advertising. Strictly necessary cookies — including those that keep you signed in, maintain your session, and support security and content delivery — do not require consent. Non-essential cookies, including third-party analytics, performance-monitoring, and advertising cookies (provided by Google Analytics 4, PostHog, Sentry, and Google advertising services), are blocked until you consent, and you can accept, decline, or withdraw your consent at any time through our cookie preference center. Some information collected through advertising cookies is shared with third-party advertising platforms, which, depending on your location, may be treated as a "sale" or "sharing" of personal information; you can exercise the related opt-out rights as described in Section 10. We recognize and honor the Global Privacy Control (GPC) signal. For full details, including the providers we use, see our Cookie Policy.
9. Security
We use technical, administrative, and organizational measures designed to protect personal information against loss, misuse, and unauthorized access, disclosure, or alteration. Depending on the system and the sensitivity of the data, these measures include encryption of data in transit and, where appropriate, at rest; access controls and the principle of least privilege; support for multi-factor authentication; and logging and monitoring of our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for the security of systems and software you operate on the Services, as described in our Terms of Service.
10. Your Privacy Rights
Subject to applicable law and to verification of your identity, you may have the right to access the personal information we hold about you; to correct inaccurate or incomplete information; to request deletion or suspension of processing; to object to certain processing; to data portability; and to withdraw consent where processing is based on consent. You will not be discriminated against for exercising these rights. To make a request, contact our Chief Privacy Officer using the details in Section 13. We will respond within the timeframes required by applicable law. If you have concerns we cannot resolve, you may also lodge a complaint with your local data protection authority. Where applicable law gives you the right to opt out of the "sale" or "sharing" of your personal information, or of targeted or cross-context behavioral advertising, you may exercise it through our cookie preference center, by using a recognized opt-out signal such as the Global Privacy Control (GPC), which we honor, or by contacting us using the details in Section 13.
10.1 EU/UK GDPR
If you are in the European Economic Area or the United Kingdom, you have the rights described above under the EU GDPR and UK GDPR, including the rights to access, rectification, erasure, restriction, objection, and portability, and the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner’s Office). We process such personal information as a controller for the purposes set out above, and rely on the legal bases in Section 4. International transfers are protected as described in Section 6. Where we rely on your consent for analytics, advertising, or other non-essential cookies and similar technologies, you may withdraw that consent at any time through our cookie preference center, without affecting the lawfulness of processing carried out before withdrawal.
10.2 California (CCPA/CPRA)
If you are a California resident, you have the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes for collection, and the categories of third parties to whom it is disclosed; to request deletion or correction; to opt out of the "sale" or "sharing" of your personal information; and to be free from discrimination for exercising your rights. In the past 12 months we have collected identifiers, customer records, commercial information, internet/network activity, and geolocation data, as described in Section 2, for the business purposes described in Section 3. We use third-party analytics and advertising cookies and similar technologies on our website (provided by Google Analytics 4, PostHog, Sentry, and Google advertising services) and share online identifiers and internet/network activity with analytics and advertising providers; depending on the activity, this may constitute a "sale" or "sharing" of personal information, and sharing for cross-context behavioral advertising, as those terms are defined under California law. You can opt out of this sale/sharing through our cookie preference center, by using the Global Privacy Control (GPC) signal, which we recognize and honor, or by contacting us using the details in Section 13. We do not knowingly sell or share the personal information of consumers we know to be under 16 years of age. The categories of personal information we have "sold" or "shared" (as defined under California law) in the past 12 months are online identifiers and internet/network activity information, disclosed to analytics and advertising providers. We do not sell or share the other categories of personal information described in this Policy.
10.3 Republic of Korea (PIPA)
As a Korean legal entity, we fully comply with the Personal Information Protection Act (PIPA). You may exercise your rights to access, correct, delete, or suspend the processing of your data through your legal representative or an authorized agent. You may also file a dispute or complaint with the Personal Information Protection Commission (PIPC) or the Personal Information Dispute Mediation Committee. Where we use cookies or similar technologies that are not strictly necessary, including for analytics and advertising, we obtain your consent as required under PIPA and provide the ability to withdraw consent through our cookie preference center.
11. Marketing Communications
Where permitted, we may send you information about the Services and related offerings. You can opt out of marketing at any time using the unsubscribe link in our emails or by contacting us. You cannot opt out of essential, non-promotional messages about your Account, such as billing, security, and changes to the Terms or Services, while you maintain an Account.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the “Last updated” date above and, where appropriate or required by law, provide additional notice (for example, by email or through the customer portal). Your continued use of the Services after the changes take effect constitutes acceptance of the updated Privacy Policy, except where additional consent is required by law.
13. Contact Us & Chief Privacy Officer
For questions, requests, or complaints regarding this Privacy Policy, your personal information, or to exercise your privacy rights, please contact our designated Chief Privacy Officer (CPO):
Company Name: PRV Tech (operating as “PRV Technologies”)
Business Registration No.: 727-86-02960
Address: Suite 3-704, 495 Parang-ro, Seo-gu, Incheon 22770, Republic of Korea
Chief Privacy Officer (CPO): Joon Young Park
Privacy & Legal Department Email: privacy@prvtechnologies.com
General Inquiries: contact@prvtechnologies.com
Website: https://prvtechnologies.com