Overview
This Privacy Policy explains how Lagster (“Lagster,” “we,” “us”), a limited liability company organized in Delaware, United States, collects, uses, and protects personal information when you use our website, client software, and network-optimization services (together, the “Service”).
We operate under the principle of data minimization: we collect the smallest set of information that lets the network work and your account function — and nothing else. We are the “data controller” for the information described below.
What We Collect
How We Use It
We use the information in section 02 only to:
Operate the routing network and choose the fastest path for your session.
Run your account: authentication, licensing, subscription billing.
Investigate abuse, fraud, and security incidents.
Respond to your support requests.
Improve performance in aggregate (e.g. which PoPs need more capacity).
Comply with legal obligations (tax, accounting, lawful requests).
We do not use your data to train advertising models, profile you across the web, or sell it to anyone.
Legal Basis (GDPR / UK GDPR)
If you are in the EEA, UK, or Switzerland, we process your personal data under the following legal bases:
Contract — to deliver the Service you purchased (account, billing, network routing).
Legitimate interests — protecting the network from abuse, preventing fraud, improving performance, aggregate analytics.
Legal obligation — tax, accounting, and responding to lawful requests.
Consent — marketing communications (where applicable). You can withdraw consent at any time.
Retention
When data is no longer needed, we delete it or de-identify it so it can no longer be linked to you.
Security
TLS 1.3 in transit for all website and client traffic.
AES-256 at rest for account and billing data.
Bcrypt/Argon2-hashed passwords — we never see your plaintext.
Role-based access control, audit logs, and least-privilege access for staff.
Regular dependency scanning, code review, and vulnerability monitoring. We respond to reports at legal@lagster.cloud.
No system is perfectly secure. If we experience a breach that affects your data, we will notify you and relevant authorities as required by applicable law.
International Transfers
Lagster is based in Delaware, United States, and our routing network operates globally. Your personal data may be processed in the United States and other countries where our service providers operate.
When we transfer data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. You can request a copy of the safeguards in place by emailing legal@lagster.cloud.
Your Rights
Depending on where you live, you have the following rights in relation to your personal data:
Access — request a copy of what we hold.
Correction — fix inaccurate or incomplete data.
Deletion — ask us to erase your data, subject to legal retention.
Portability — receive your data in a machine-readable format.
Restriction / Objection — limit or object to certain processing.
Opt out of sale / sharing (California & similar jurisdictions) — we do not sell or share personal data for cross-context behavioural advertising, but you can still submit the request on the record.
Withdraw consent where processing is based on consent.
Lodge a complaint with your local data-protection authority.
To exercise any of these rights, email legal@lagster.cloud from your account email. We respond within 30 days.
Children
Lagster is not directed at children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal data, email legal@lagster.cloud and we will delete it.
Changes To This Policy
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, for material changes, give advance notice via email or an in-product banner.
Contact
Data protection questions, access requests, and formal notices go to: