Privacy Policy
This Policy explains what personal data Fiberon LLC (the “Company”, the data controller) collects when operating the Fiberon Cloud service, why and for how long it is stored, and what rights users have. The Policy has been prepared in accordance with the Law of the Republic of Azerbaijan “On Personal Data” and takes into account the principles of the EU General Data Protection Regulation (GDPR).
1. What data we collect
- Request data: first and last name, email and, optionally, phone, organisation or subscriber number, intended use, selected plan, preferred language.
- Account data: password hash (the password itself is not stored), cloud username, encrypted two-factor settings, hashes of recovery codes.
- Technical data: IP address and time of registration, consents, sign-ins and important actions; browser information at sign-in.
- Storage information: amount of space used, date of the last cloud sign-in.
- Files you upload to the cloud. We store them but do not analyse or view them (see clause 4.2 of the Terms of Use).
2. Why we process it
- Reviewing requests and providing storage — on the basis of your consent and to perform the Terms.
- Sign-in, password recovery, security notifications — to protect your account.
- Activity log — to investigate security incidents and meet legal requirements.
- Usage statistics — to distribute server space fairly among members.
We do not use the data for advertising and do not sell or pass it to third parties for marketing purposes.
3. Where the data is stored
Portal data and cloud files are stored on servers administered by the Company. Backups are stored encrypted. Connections to the portal and the cloud are protected by HTTPS.
Emails are sent via the Company’s mail server. Portal pages load fonts from Google Fonts, so your browser sends your IP address to Google. When a new password is set, only the first 5 characters of its SHA-1 hash are sent to the Have I Been Pwned service to check it against known breaches; the password itself is never transmitted. If Cloudflare Turnstile bot protection is enabled on a form, Cloudflare receives technical browser data for the check.
4. Retention periods
- Request with an unconfirmed email — up to 7 days.
- Rejected request — up to 30 days after the decision.
- Account and files — while you use the Service; after account deletion, files and data are deleted immediately and from backups within 30 days.
- Security log — 12 months.
5. Your rights
You have the right to: know what data about you is processed; correct inaccurate data; withdraw consent and delete the account (you can do this yourself in the user account); obtain a copy of your files (via the cloud at any time); lodge a complaint with the competent public authority.
Send requests to: info@fiberon.az, +994 50 278 78 11, WhatsApp +994 55 278 78 11. We reply within 30 days.
6. Administrator access
Administrators see request data, account status, storage usage and the activity log. They do not open your files. For especially sensitive data use end-to-end folder encryption: then even the server cannot read the files.
7. Security
Passwords are stored only as strong hashes (Argon2id) and are checked against breach databases using k-anonymity; two-factor secrets are stored encrypted; email links are single-use and time-limited. We notify you by email about sign-ins from new devices. Administrator access is protected by mandatory two-factor authentication. In the event of a data breach posing a risk to users, we will notify them without undue delay.
8. Changes
The current version is always published on this page. We notify users of material changes by email.
9. Data controller
Fiberon LLC, 10 Haji Aliyev street, Quba, AZ 4000, Republic of Azerbaijan. Contact: info@fiberon.az, +994 50 278 78 11, WhatsApp +994 55 278 78 11.