HomeCompanyPrivacy Policy

Privacy Policy

What we collect, why we collect it, who sees it, how long we keep it, and the rights you have over it.

Last updated 10 Sep 2026 · 5 min read · This document is part of the Joy Services agreements.

This policy explains how Joy Services ("Joy", "we") handles personal data when you visit our websites, use the console or API, or buy our services. It applies to Joy Services and to Joy-operated services such as 1tbShare; Be Virtual publishes its own policy. Our contact for privacy matters is privacy@joy.services.

1. What we collect

Account and billing data

Name, email address, phone number, username, password (stored only as an Argon2id hash), company name, billing address, tax identifier (for example a GSTIN), country and currency preference. We use this to create and administer your account and to issue compliant invoices.

Payment data

Payments are processed by Razorpay, PayPal, a hosted card checkout and BTCPay. We receive a transaction reference, the amount, the method and, for cards, the last four digits and brand. We never receive or store full card numbers.

Security and usage data

IP addresses, user-agent strings, login history and device fingerprints (for new-device alerts and session binding), API request logs (method, path, status, IP, duration), and actions taken in the console (the audit trail you can see under Account → Security).

Service telemetry

Hypervisor metrics for your servers — CPU, memory, disk and network counters, power state — collected by the regional collector to show live graphs and to detect failures. This telemetry does not include the contents of your disks or memory.

Network data

Flow records (source, destination, ports, byte counts) from NeuroMesh NetFlow for DDoS detection and traffic engineering; these are kept for 30 days. Packet contents are not stored.

Support data

Tickets, emails and attachments you send us, and notes staff add while resolving them.

Website data

Server logs and a small number of first-party cookies: a session cookie when you log in, a currency preference, and a theme preference stored in your browser. We do not use third-party advertising trackers.

  • To provide the service you ordered — performance of a contract.
  • To bill you and keep accounts — contract and legal obligation (tax law).
  • To prevent fraud and abuse and to keep the network secure — legitimate interest and legal obligation.
  • To send transactional email (invoices, renewals, security alerts, ticket replies) — contract.
  • To send product updates — consent, which you can withdraw at any time from Account → Notifications or the link in each email.
  • To comply with law, including lawful requests from authorities in the countries where we operate.

3. Who sees it

Joy staff who need it to do their jobs, under confidentiality obligations and with access logged. Processors who act on our instructions: payment providers (listed above), email delivery providers for transactional mail, and datacenter operators for physical hosting. Authorities where we are legally required to disclose. We do not sell personal data and do not share it with advertisers.

4. Where it is stored

Account, billing and support data is stored on Joy infrastructure in India with encrypted backups in Singapore. Server telemetry is stored in the region of the server. Payment providers process data in their own jurisdictions under their own safeguards.

5. How long we keep it

DataRetention
Invoices, payments and tax records8 years (tax law)
Account profilewhile the account exists, then deleted within 30 days of closure
Login and API logs90 days
Server telemetrylive data 5 minutes; series 15 minutes; daily aggregates 13 months
Flow records30 days
Support tickets3 years after closure
Server disks and snapshotsdeleted within 30 days of termination
1tbShare metadata30 days after link expiry

6. Security

Passwords are hashed with Argon2id; two-factor authentication (TOTP) is available and recommended; sessions are bound to device and network and rotate automatically; server credentials and node secrets are encrypted at rest (XChaCha20-Poly1305); all web traffic uses TLS 1.3 with a strict Content-Security-Policy; staff actions are audited. See the Trust Center for more.

7. Your rights

You can access, correct, export or delete your personal data, object to or restrict certain processing, and withdraw consent for marketing. Most of this is self-service in the console (Account → Profile, Notifications, Security); for everything else open a ticket or email privacy@joy.services. We answer within 30 days. Deleting your account deletes your servers and data; invoices are kept as required by tax law. You may also complain to your local data-protection authority.

8. Cookies

We set a session cookie when you log in (essential), a currency cookie when you change currency (functional) and store a theme preference in your browser's local storage (functional). We do not set analytics or advertising cookies. You can clear these from your browser at any time; the site keeps working.

9. Children

Our services are for people 18 and over. We do not knowingly collect data from children; if you believe a child has created an account, contact us and we will delete it.

10. Changes

We will announce material changes to this policy in the Updates feed and by email 30 days before they take effect. The page shows the date of the last update.