GHOST NODES – PRIVACY POLICY

  1. Overview

Ghost Labs AB provides the Ghost Nodes platform.

This Privacy Policy explains how Ghost Labs collects, uses, and protects personal data in connection with the Ghost Nodes service.

Ghost Labs processes personal data in accordance with the General Data Protection Regulation (GDPR).

Ghost Labs AB is the data controller for personal data described in this policy, except where Ghost Labs acts as processor on behalf of a Customer.

2. Service architecture

Ghost Nodes is a distributed automation platform.

Ghost Labs operates the Ghost Nodes control platform.

Gateways, Agents and monitoring agents run within Customer Infrastructure controlled by the Customer.

Ghost Labs does not host or operate Customer workloads, if not directed to do so by the Customer.

Workflow payload data and application data processed within Customer Infrastructure remain under the Customer’s control.

3. Data we collect

Account Data

We may collect:

  • name
  • email address
  • company name
  • billing details

Service Telemetry

Ghost Nodes Components may transmit operational telemetry including:

  • node identifiers
  • health metrics
  • version information
  • service status data
  • volume data, such as number of messages and aggregate message size

Telemetry does not include workflow payload data or application data processed within Customer Infrastructure.

Website Data

When visiting our website we may collect:

  • IP address
  • browser information
  • usage analytics

Support Data

When a Customer or user contacts Ghost Labs for support, we may process information included in the support request, such as:

  • contact details
  • company information
  • technical issue descriptions
  • relevant troubleshooting information provided by the Customer or user

Customers should not include workflow payload data, application data or other confidential Customer data in support requests unless this has been specifically agreed.

4. How we use data

Personal data may be used to:

  • operate the Ghost Nodes platform
  • manage customer accounts
  • provide support
  • process billing
  • monitor service health
  • detect abuse or violations of the Acceptable Use Policy
  • maintain and improve the security, reliability and functionality of Ghost Nodes

Ghost Labs does not use workflow payload data, application data, prompts, code, logs or AI results processed within Customer Infrastructure for training AI models.

5. Legal basis

Personal data is processed based on:

  • contractual necessity
  • legitimate interests
  • legal obligations

6. Data processed by Customer

Customer may process personal data through automation workflows executed within Customer Infrastructure.

For such data

Customer acts as the data controller.
Ghost Labs acts as the data processor where Ghost Labs processes such data on behalf of the Customer.

Workflow payload data, application data, prompts, code, logs and AI results processed within Customer Infrastructure remain under the Customer’s control.

Where the Customer configures workflows to use external services, including AI services, APIs, SaaS services or cloud services, the Customer controls which data is sent to such services. The processing of such data by the external service is governed by the applicable agreement, configuration and terms for that service.

7. Data retention

Data type

Account data

Service telemetry

Support requests

Billing records

Retention

duration of subscription

up to 90 days

up to 24 months

up to 7 years

Following termination of a subscription, data stored in or made available through the Ghost Nodes control platform may be retained for up to 30 days to allow export by the Customer.

This does not apply to workflow payload data or application data processed within Customer Infrastructure, which remains under the Customer’s control.

8. Data sharing

Ghost Labs does not share workflow payload data or application data processed within Customer Infrastructure with service providers used for Ghost Labs’ own administrative, billing, support, website, analytics or platform management functions.

Where necessary, Ghost Labs may use service providers for its own business and service administration, including website operation, analytics, customer administration, support, billing, accounting, communication, collaboration and platform management.

Such providers may process limited personal data on behalf of Ghost Labs, such as Website Data and support request information.

Service providers process data only on behalf of Ghost Labs and in accordance with applicable data protection requirements.

9. International transfers

Ghost Labs does not transfer workflow payload data or application data processed within Customer Infrastructure outside the EEA.

10. Data security

Ghost Labs implements appropriate technical and organizational measures to protect personal data.

Ghost Nodes is designed to support secure processing of data within Customer Infrastructure, including access control, logging, monitoring and secure communication where applicable.

The Customer is responsible for securing its own infrastructure, networks, runtime environments, identity management, backup, monitoring and incident handling unless otherwise agreed.

11. Data subject rights

Individuals may:

  • access personal data
  • request correction
  • request deletion
  • request portability
  • object to processing

Requests may be sent to: privacy@ghostlabs.se

Where a request concerns personal data processed by a Customer within Customer Infrastructure, Ghost Labs may refer the individual to the relevant Customer.

12. Complaints

Individuals may lodge complaints with the Swedish Authority for Privacy Protection (IMY).

13. Policy Updates

Ghost Labs may update this Privacy Policy periodically.