devops-simulator
legal — privacy policy

Privacy Policy

Last updated: 30 May 2026

This Privacy Policy explains how devops-simulator ("we", "us") collects, uses, and protects your personal data when you request access to and use the service at sim.metisops.com. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.

1. Who we are (Data Controller)

The controller responsible for your personal data is MetisOps Limited PA, 28th Oktovriou 18, Vrilissia 15235, Greece, operating devops-simulator. For any privacy question or to exercise your rights, contact us at admin@metisops.com.

2. What data we collect

We collect only what we need to run an access-controlled training service:

  • Identity & request details — your email address, name, and the free-text reason you provide when requesting access.
  • Authentication data — one-time sign-in (magic link) verification tokens and server-side session records.
  • Access credentials — SSH public keys you add (and their fingerprints), and CLI API tokens (which we store only as a salted hash, never in plaintext).
  • Usage records — scenario attempt results submitted by the bin/sim CLI: scenario ID, pass/fail exit code, duration, hints used, and optional technical metadata the CLI may send (e.g. OS or kubectl context).
  • Technical/log data — IP address and basic request metadata processed transiently by our reverse proxy and host for security, abuse prevention, and service delivery.

We do not intentionally collect special-category data, and we ask that you not include it in your access-request reason.

3. Why we process it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Create and manage your account; grant repository and CLI accessPerformance of a contract / steps at your request (Art. 6(1)(b))
Review access requests, secure the platform, prevent abuseOur legitimate interests (Art. 6(1)(f))
Authenticate you via magic link and maintain your sessionPerformance of a contract (Art. 6(1)(b))
Record scenario progress to show your dashboardPerformance of a contract / legitimate interests
Comply with legal obligations where applicableLegal obligation (Art. 6(1)(c))

4. Cookies

We use only strictly-necessary cookies (authentication and security). We do not use analytics, advertising, or third-party tracking cookies. See our Cookie Policy for the full list.

5. Who we share data with

We do not sell your personal data. We share it only with processors that help us run the service, under appropriate data-processing terms:

  • DigitalOcean — cloud hosting/infrastructure for the application and database.
  • Cloudflare — DNS, TLS certificates, and network security.
  • Email delivery provider — a transactional email provider (to be appointed before email delivery is enabled), used solely to deliver sign-in links. Not in use at this time.

We may also disclose data where required by law or to protect our rights and the security of the service.

6. International transfers

Our application and database are hosted within the European Economic Area, in Frankfurt, Germany (DigitalOcean). Where a processor (such as Cloudflare) may process data outside the EEA, we rely on an adequacy decision or on Standard Contractual Clauses, with supplementary measures where needed, to safeguard your data.

7. How long we keep it

  • Account and access data: while your account is active.
  • Sign-in/verification tokens: short-lived (links expire after 7 days); consumed or expired tokens are removed.
  • Server logs: retained for a limited period for security, then rotated.
  • On account deletion, we delete or anonymise your personal data unless we must retain certain records to meet a legal obligation.

8. Your rights

Under the GDPR you have the right to:

  • access a copy of your personal data;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with your local data-protection supervisory authority.

To exercise any of these, email admin@metisops.com. We will respond within the time limits set by the GDPR (normally one month).

9. Security

We protect your data with encryption in transit (TLS), hashing of API tokens, role- and status-based access controls, and least-privilege access to systems. No method of transmission or storage is perfectly secure, but we work to protect your data and review our measures regularly.

10. Children

The service is intended for professional/educational use by adults and is not directed at children under 16. We do not knowingly collect data from children.

11. Changes to this policy

We may update this policy from time to time. We will revise the "last updated" date above and, for material changes, take reasonable steps to notify you.

12. Contact

MetisOps Limited PA, 28th Oktovriou 18, Vrilissia 15235, Greece — admin@metisops.com.