RRansomBackup
HomeTermsSecurityIT
UPDATED 2 SEPTEMBER 2026

Privacy and cookies

The service is designed not to receive the repository password and to retain only information needed to deliver and secure the service.

1. Controller and contact

The controller is the operator of the RansomBackup service. Contact help@ransombackup.com for information and data-subject requests.

2. Data processed

  • email, language, account identifier and technical device name;
  • client status, backup result and time, storage use, quota and plan;
  • minimal snapshot catalogue: identifier, time and path count, not content;
  • restore requests and authorization events;
  • IP address, user agent, timestamps and technical security logs;
  • support messages and administration data required for paid plans.
We do not receive the Restic password. Files, names and metadata are encrypted on the device. The server stores encrypted blocks and cannot read them without the customer’s password.

3. Purposes and legal bases

Data is used to activate accounts, provide backup and restore, display statistics, enforce quota and inactivity rules, send operational notices, provide support, prevent abuse and meet legal duties. Legal bases are performance of the requested service, legitimate interests in security and fraud prevention, and legal obligations; consent is used where required.

4. Retention

Account metadata and repository follow the Terms: after 60 days without qualifying activity a FREE account is disabled, held in quarantine for 7 days and permanently deleted. Security logs and support requests are retained as needed for security, diagnostics and legal claims; administrative records follow statutory periods.

5. Recipients and infrastructure

Necessary hosting, connectivity and email providers may process data under their applicable role. Personal data is not sold or used for behavioural advertising.

6. Rights

You may request access, rectification, erasure, restriction, objection and portability where applicable by emailing help@ransombackup.com. You may lodge a complaint with the Italian data protection authority. Once an encrypted repository is deleted, it cannot be recovered.

7. Cookies and public website

The public site uses no profiling, advertising or third-party analytics cookies and embeds no social resources. Normal HTTP server logs may be processed for delivery and security. If non-technical tracking is introduced, the notice and consent controls will be updated first.

8. Security and changes

HTTPS, token separation and access controls are used. No system is risk-free: never email a password or token. Material notice changes are communicated by site, application or email where appropriate.

Home · Terms · Security · Support