Privacy statement

Last updated: 3 September 2026

Who we are

Dorelli Cloud (dorelli.cloud) builds, hosts and maintains websites and apps for customers. Dorelli Cloud is a product of Dorelli Hosting, handelsnaam van Uitgeverij Doreleijers. For privacy questions, contact [email protected].

What data we process

When you submit a request: your name, email address and message. As a customer: your login details (email and an encrypted password), your support tickets and the technical statistics of your website (availability, response time, visitor counts). If you publish a trial site, the “Trial sites” section below applies as well. We never collect more than necessary.

Trial sites

If you publish a site on a dorelli.cloud subdomain — through the upload form, a template, the command line or our GitHub Action — we process your email address and the files you supply. The email address is needed to send you the management link and to warn you before the trial period ends; it is used for nothing else. Your IP address is held briefly in memory only, to cap how many sites may be published per hour — it is not stored. The management key is stored hashed, so we cannot read it ourselves.

Screening of trial sites

Before a trial site becomes reachable for the first time, we have the text of its pages checked automatically for abuse (phishing, fraud, illegal content). We put those sites under our own domain, so we want to know what goes on them. Only the visible text — roughly 12,000 characters at most — is sent to Anthropic for that check (see “Sub-processors”); images, code and file names are not. No human is involved unless a site is blocked. So do not put other people’s personal data in a site you publish with us.

Apps and databases

If your application runs in a container with us (App and usage-based plans), we process what your app stores in its database and storage on your behalf: you are the controller, we are the processor (see the data processing agreement). That data lives in Microsoft data centers within the EU (Amsterdam region for containers and storage, Dublin region for databases). On first start we have the start page of your app screened automatically for abuse, in the same way as trial sites: only the visible text goes to Anthropic. Secrets you enter in your portal (for example API keys) are stored with Microsoft and not shown again; technically we can retrieve them, and we do so only at your request or to resolve an incident. To bill usage we record per day how much compute, memory, requests, traffic and storage your building blocks used; those are quantities, not content.

Contact forms on customer sites

If a site we host has a contact form, those messages travel through us to the owner of that site. We do not keep the content: we forward it and it is then gone from our systems. What we do record briefly is that something was sent (which site, a hashed form of the IP address, the time), solely to block spam; that is deleted automatically after two days. For those messages the site owner is the controller and we are the processor.

What we use it for

Solely to handle your request, publish, host and monitor your website, provide support and invoice you. We do not sell or share data for marketing and we send no newsletters unless you ask for them.

Cookies

Dorelli Cloud uses functional cookies only: one for your language preference and one for your portal login session. Forms are protected by Cloudflare Turnstile, which blocks bots without tracking you and without puzzles. No tracking, no ad cookies, no cookie wall needed.

Where your data lives

Websites, databases and backups run in data centers within the European Union (Amsterdam and Dublin regions). One exception: the text of a trial site is sent to Anthropic for the abuse check, which processes outside the EU. Anthropic does not use that text to train models and deletes it within 30 days — longer only if a text is flagged as abuse. It is, moreover, text you intended to publish on a public website. Customer data — accounts, tickets, statistics, invoices — does not leave the EU.

Sub-processors

We work with a small number of GDPR-compliant suppliers: Microsoft (EU data centers for hosting and storage), Cloudflare (security, CDN, bot protection and email), Mollie (payments, Netherlands) and Anthropic (the automated abuse check on trial sites only, United States, under the European Commission’s standard contractual clauses). Data processing agreements are in place with each of them.

Retention

Requests that do not lead to a customer relationship are deleted within 6 months. A trial site stays online for 14 days; the files are then deleted, and the registration (email address, subdomain name) within 6 months after that. The contact-form spam log is kept for 2 days. Customer data is kept for the duration of the service; after cancellation we delete your account and site within 30 days (invoices are kept for 7 years due to tax law). App databases and storage are kept for 30 days after deletion (an own database server 7 days); usage records are kept for 7 years with the invoice they belong to. Monitoring data is automatically deleted after 90 days.

Your rights

You have the right to access, correct, delete and transfer your data, and to object to processing. Email [email protected] and we will handle your request within 30 days. If you want a trial site removed sooner than after 14 days, one email is enough. You can always lodge a complaint with the Dutch Data Protection Authority.

Security

All connections are encrypted (HTTPS/TLS), passwords and keys are stored hashed, systems are monitored 24/7 and daily backups run. On trial sites we serve static files only — never third-party code — and they carry noindex for as long as they are trials. Access to customer data is limited to what is strictly necessary.