GHOST NODES – PRIVACY POLICY
- Overview
Ghost Labs AB provides the Ghost Nodes platform.
This Privacy Policy explains how Ghost Labs collects, uses, and protects personal data in connection with the Ghost Nodes service.
Ghost Labs processes personal data in accordance with the General Data Protection Regulation (GDPR).
Ghost Labs AB is the data controller for personal data described in this policy, except where Ghost Labs acts as processor on behalf of a Customer.
2. Service architecture
Ghost Nodes is a distributed automation platform.
Ghost Labs operates the Ghost Nodes control platform.
Gateways, Agents and monitoring agents run within Customer Infrastructure controlled by the Customer.
Ghost Labs does not host or operate Customer workloads, if not directed to do so by the Customer.
Workflow payload data and application data processed within Customer Infrastructure remain under the Customer’s control.
3. Data we collect
Account Data
We may collect:
- name
- email address
- company name
- billing details
Service Telemetry
Ghost Nodes Components may transmit operational telemetry including:
- node identifiers
- health metrics
- version information
- service status data
- volume data, such as number of messages and aggregate message size
Telemetry does not include workflow payload data or application data processed within Customer Infrastructure.
Website Data
When visiting our website we may collect:
- IP address
- browser information
- usage analytics
Support Data
When a Customer or user contacts Ghost Labs for support, we may process information included in the support request, such as:
- contact details
- company information
- technical issue descriptions
- relevant troubleshooting information provided by the Customer or user
Customers should not include workflow payload data, application data or other confidential Customer data in support requests unless this has been specifically agreed.
4. How we use data
Personal data may be used to:
- operate the Ghost Nodes platform
- manage customer accounts
- provide support
- process billing
- monitor service health
- detect abuse or violations of the Acceptable Use Policy
-
maintain and improve the security, reliability and functionality of Ghost Nodes
Ghost Labs does not use workflow payload data, application data, prompts, code, logs or AI results processed within Customer Infrastructure for training AI models.
5. Legal basis
Personal data is processed based on:
- contractual necessity
- legitimate interests
- legal obligations
6. Data processed by Customer
Customer may process personal data through automation workflows executed within Customer Infrastructure.
For such data
Customer acts as the data controller.
Ghost Labs acts as the data processor where Ghost Labs processes such data on behalf of the Customer.
Workflow payload data, application data, prompts, code, logs and AI results processed within Customer Infrastructure remain under the Customer’s control.
Where the Customer configures workflows to use external services, including AI services, APIs, SaaS services or cloud services, the Customer controls which data is sent to such services. The processing of such data by the external service is governed by the applicable agreement, configuration and terms for that service.
7. Data retention
Data type
Account data
Service telemetry
Support requests
Billing records
Retention
duration of subscription
up to 90 days
up to 24 months
up to 7 years
Following termination of a subscription, data stored in or made available through the Ghost Nodes control platform may be retained for up to 30 days to allow export by the Customer.
This does not apply to workflow payload data or application data processed within Customer Infrastructure, which remains under the Customer’s control.
8. Data sharing
Ghost Labs does not share workflow payload data or application data processed within Customer Infrastructure with service providers used for Ghost Labs’ own administrative, billing, support, website, analytics or platform management functions.
Where necessary, Ghost Labs may use service providers for its own business and service administration, including website operation, analytics, customer administration, support, billing, accounting, communication, collaboration and platform management.
Such providers may process limited personal data on behalf of Ghost Labs, such as Website Data and support request information.
Service providers process data only on behalf of Ghost Labs and in accordance with applicable data protection requirements.
9. International transfers
Ghost Labs does not transfer workflow payload data or application data processed within Customer Infrastructure outside the EEA.
10. Data security
Ghost Labs implements appropriate technical and organizational measures to protect personal data.
Ghost Nodes is designed to support secure processing of data within Customer Infrastructure, including access control, logging, monitoring and secure communication where applicable.
The Customer is responsible for securing its own infrastructure, networks, runtime environments, identity management, backup, monitoring and incident handling unless otherwise agreed.
11. Data subject rights
Individuals may:
- access personal data
- request correction
- request deletion
- request portability
- object to processing
Requests may be sent to: privacy@ghostlabs.se
Where a request concerns personal data processed by a Customer within Customer Infrastructure, Ghost Labs may refer the individual to the relevant Customer.
12. Complaints
Individuals may lodge complaints with the Swedish Authority for Privacy Protection (IMY).
13. Policy Updates
Ghost Labs may update this Privacy Policy periodically.