PhotonMark VPN LogoPhotonMark VPN

Privacy Policy

Last updated: May 11, 2026.

1. Services Covered

This policy covers PhotonMark Cloud and current or future PhotonMark hosted services, including dedicated VPN, OpenClaw hosting, Hermes automation, PhotonMark Veo, private storage, managed IT engagements, support, billing, account portals, and related infrastructure.

PhotonMark Ltd. is based in New Zealand. We aim to handle personal information consistently with the New Zealand Privacy Act 2020, including the Information Privacy Principles, and with other privacy, consumer, communications, and data-protection laws that apply to a specific service, customer location, provider, or transaction.

2. Information We Collect

Account and billing

Email address, authentication data, account status, Stripe payment status, invoices, purchased plans, credits, and support messages.

Service operation

Provisioning metadata, selected protocol, assigned resources, usage totals needed to enforce allowances, job status, configuration/profile history, and operational logs.

Security and abuse prevention

Source IP addresses, request metadata, login events, rate limits, reputation checks, abuse indicators, and infrastructure health signals.

Uploaded or generated content

Files, prompts, reference images, generated videos, automation inputs, or storage objects only where a service requires them to perform the requested work.

3. How We Use Information

We use information to operate services, verify accounts, process payments, provision infrastructure, enforce plan limits, provide support, secure our systems, prevent abuse, troubleshoot failures, and comply with lawful obligations.

Payments are processed by Stripe. PhotonMark does not store full card numbers, CVV, or card expiry data.

4. VPN-Specific Logs

PhotonMark VPN does not log the content of your traffic or the websites you visit through the VPN. We do log source IP addresses used when clients connect to our WireGuard or Hysteria2 servers, protocol-specific usage totals needed for plan enforcement, and assigned public IPv4 reputation data used to detect abuse and protect service quality.

5. AI, Automation, and Storage Content

For OpenClaw, Hermes, Veo, Drive, and custom automation services, content you submit may be processed by infrastructure or third-party providers required to deliver the service. We use that content to perform the requested work, provide downloads or history, troubleshoot failures, and maintain account records.

6. Retention

Operational records are retained only as long as reasonably needed for service operation, billing, auditability, troubleshooting, abuse prevention, security, backups, and legal obligations. Generated files, uploads, and service logs may have service-specific retention windows.

7. Sharing

We do not sell customer personal information. We may share necessary data with infrastructure providers, payment processors, email providers, cloud APIs, support tools, and professional advisers where required to provide or protect the services.

Some providers may be located outside New Zealand. Where cross-border disclosure rules apply, we consider whether the recipient is subject to comparable privacy safeguards, whether the disclosure is necessary to deliver the requested service, or whether another lawful basis applies.

8. Security

We use practical administrative, technical, and operational safeguards appropriate to small hosted services, including access controls, account verification, infrastructure monitoring, backups where configured, abuse controls, and limited provider access. No internet service can be guaranteed perfectly secure.

9. International and Provider Requirements

Some services rely on international platforms, model providers, payment processors, hosting companies, email systems, domain providers, or customer-selected integrations. Your use of those services may also be subject to their privacy notices, acceptable-use rules, regional restrictions, and lawful request processes.

10. Legal Requests and Jurisdiction

PhotonMark Ltd. is a New Zealand company. We respond to valid legal requests and lawful orders as required by applicable law. If legally permitted, we may notify affected customers before disclosure.

11. Access, Correction, and Deletion

You may request access, correction, or deletion of account data by contacting [email protected] from your account email. We may retain minimal records where required by law, billing, security, fraud prevention, abuse investigation, or backup integrity.

12. Contact

For privacy-related inquiries, email [email protected].