This policy explains how Joy Services ("Joy", "we") handles personal data when you visit our websites, use the console or API, or buy our services. It applies to Joy Services and to Joy-operated services such as 1tbShare; Be Virtual publishes its own policy. Our contact for privacy matters is privacy@joy.services.
1. What we collect
Account and billing data
Name, email address, phone number, username, password (stored only as an Argon2id hash), company name, billing address, tax identifier (for example a GSTIN), country and currency preference. We use this to create and administer your account and to issue compliant invoices.
Payment data
Payments are processed by Razorpay, PayPal, a hosted card checkout and BTCPay. We receive a transaction reference, the amount, the method and, for cards, the last four digits and brand. We never receive or store full card numbers.
Security and usage data
IP addresses, user-agent strings, login history and device fingerprints (for new-device alerts and session binding), API request logs (method, path, status, IP, duration), and actions taken in the console (the audit trail you can see under Account → Security).
Service telemetry
Hypervisor metrics for your servers — CPU, memory, disk and network counters, power state — collected by the regional collector to show live graphs and to detect failures. This telemetry does not include the contents of your disks or memory.
Network data
Flow records (source, destination, ports, byte counts) from NeuroMesh NetFlow for DDoS detection and traffic engineering; these are kept for 30 days. Packet contents are not stored.
Support data
Tickets, emails and attachments you send us, and notes staff add while resolving them.
Website data
Server logs and a small number of first-party cookies: a session cookie when you log in, a currency preference, and a theme preference stored in your browser. We do not use third-party advertising trackers.
2. Why we use it (legal bases)
- To provide the service you ordered — performance of a contract.
- To bill you and keep accounts — contract and legal obligation (tax law).
- To prevent fraud and abuse and to keep the network secure — legitimate interest and legal obligation.
- To send transactional email (invoices, renewals, security alerts, ticket replies) — contract.
- To send product updates — consent, which you can withdraw at any time from Account → Notifications or the link in each email.
- To comply with law, including lawful requests from authorities in the countries where we operate.
3. Who sees it
Joy staff who need it to do their jobs, under confidentiality obligations and with access logged. Processors who act on our instructions: payment providers (listed above), email delivery providers for transactional mail, and datacenter operators for physical hosting. Authorities where we are legally required to disclose. We do not sell personal data and do not share it with advertisers.
4. Where it is stored
Account, billing and support data is stored on Joy infrastructure in India with encrypted backups in Singapore. Server telemetry is stored in the region of the server. Payment providers process data in their own jurisdictions under their own safeguards.
5. How long we keep it
| Data | Retention |
|---|---|
| Invoices, payments and tax records | 8 years (tax law) |
| Account profile | while the account exists, then deleted within 30 days of closure |
| Login and API logs | 90 days |
| Server telemetry | live data 5 minutes; series 15 minutes; daily aggregates 13 months |
| Flow records | 30 days |
| Support tickets | 3 years after closure |
| Server disks and snapshots | deleted within 30 days of termination |
| 1tbShare metadata | 30 days after link expiry |
6. Security
Passwords are hashed with Argon2id; two-factor authentication (TOTP) is available and recommended; sessions are bound to device and network and rotate automatically; server credentials and node secrets are encrypted at rest (XChaCha20-Poly1305); all web traffic uses TLS 1.3 with a strict Content-Security-Policy; staff actions are audited. See the Trust Center for more.
7. Your rights
You can access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent for marketing. Most of this is self-service in the console (Account → Profile, Notifications, Security); for everything else open a ticket or email privacy@joy.services. We answer within 30 days. Deleting your account deletes your servers and data; invoices are kept as required by tax law. You may also complain to your local data-protection authority.
8. Cookies
We set a session cookie when you log in (essential), a currency cookie when you change currency (functional) and store a theme preference in your browser's local storage (functional). We do not set analytics or advertising cookies. You can clear these from your browser at any time; the site keeps working.
9. Children
Our services are for people 18 and over. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.
10. Changes
We will announce material changes to this policy in the Updates feed and by email 30 days before they take effect. The page shows the date of the last update.