Every category of data RadiantOS stores, where it lives, and how long it's kept. Tenants elect US or EU at signup; data stays in the chosen region.
| Category | Sub-processor | Regions | Retention |
|---|---|---|---|
Tenant identity Tenant name, billing address, owner email. Vultr Managed PostgreSQL - tenants, profiles, user_tenants. TLS 1.2+ in transit. Managed PostgreSQL encryption at rest. | Vultr | useu | Retained for contract duration + 30 day grace after termination. Account ownership, billing, RBAC. |
End-user identity Names, emails, device identifiers, IPs. Vultr Managed PostgreSQL - profiles, contacts, rmm_agents. TLS 1.2+ in transit. Managed PostgreSQL encryption at rest. | Vultr | useu | Same as tenant identity. Ticket routing, device attribution, MDM enrollment. |
PSA ticket content Ticket subject, body, attachments metadata, time logs. Vultr Managed PostgreSQL - psa_tickets, psa_time_entries; Vultr Archival Object Storage - attachment blobs. TLS 1.2+ in transit. Managed PostgreSQL encryption at rest. Vultr archive object storage server-side encryption. | Vultr | useu | Retained for contract duration + 30 day grace. Configurable per tenant. Support tooling. |
Backup blobs Restic repositories, SaaS backup payloads and export bundles. Vultr Archival Object Storage - regional per-tenant buckets. TLS 1.2+ in transit. Vultr archive object storage server-side encryption. Restic client-side AES-256 where applicable. | Vultr | useu | Per-repo retention policy with legal hold override and configured cleanup windows. Backup, restore, export and disaster recovery. |
Vault secrets Customer passwords, API keys, TOTP secrets and secret metadata. RadiantOS first-party Vault service on Vultr VKE. Secret references live in managed PostgreSQL. Client-side or envelope encryption where supported. Raw secrets are stored only in the vault/KMS tier, not Markdown, logs or analytics. | Vultr | useu | Retained while referenced by at least one active entity, subject to offboarding purge and legal hold. Managed credentials. |
Payment data Card tokens, billing history and invoice metadata. Card PANs never touch RadiantOS servers. Stripe tokenized payment records plus RadiantOS managed billing tables for token references only. Managed by Stripe for payment data. RadiantOS stores only token references and non-card metadata. | Stripe | us | As required by Stripe and billing obligations, typically 7 years. Billing. |
Transactional email Recipient address, subject, HTML body and delivery events. SendGrid in transit. Outbox rows in managed PostgreSQL before handoff. TLS 1.2+ in transit. | SendGrid (Twilio) | us | Email event logs 30 days in SendGrid. Outbox rows 90 days unless customer policy requires longer. Notifications, report delivery and auto-ticket emails. |
Anonymized product analytics Event name, user or tenant pseudonymous identifier, route and product-usage property bag. PostHog Cloud with sensitive fields masked. TLS 1.2+ in transit. | PostHog | useu | PostHog retention per configured project policy. Feature adoption, funnel analysis, onboarding drop-off and product improvement. |
Error telemetry Stack traces, breadcrumbs, spans, scrubbed request metadata and release health. Sentry with PII and secrets scrubbed before ingestion. TLS 1.2+ in transit. | Sentry | us | 90 days unless incident hold requires longer. Bug triage and incident forensics. |
Infrastructure and edge Request headers, IP, TLS metadata and operational logs. No raw application secrets. Cloudflare plus Vultr VKE/application logs. TLS terminated at edge; origin connection TLS 1.3 where supported. | Cloudflare | useu | Cloudflare 30 days, application logs 7 days unless an incident hold applies. Edge routing, DDoS protection, platform observability and security operations. |