Infralane Privacy Policy
This Privacy Policy explains how Cranom Technologies Limited, trading as Infralane (“Cranom”, “Infralane”, “we”, “us”, or “our”), collects, uses, stores, shares, and protects personal data when you use the Infralane website, dashboard, APIs, cloud services, developer tools, support channels, surveys, and related services (collectively, the “Services”).
This Policy is intended to be read together with the Infralane Terms of Service.
We process personal data in accordance with applicable Ugandan data-protection law, including the Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021, as applicable.
1. Who is responsible for your personal data?
For personal data that Infralane collects for its own account administration, billing, security, website, support, analytics, and business operations, the responsible organisation is:
Cranom Technologies Limited
Trading as Infralane
Registered in the Republic of Uganda
Registered business address: Kampala, Uganda
Email: info@infralane.cloud
Depending on the processing activity, Cranom Technologies Limited may act as a data collector, data controller, or data processor as those terms are understood under applicable law.
2. Scope of this Policy
This Policy applies to personal data that we process when you:
- visit an Infralane website;
- create or use an Infralane Account;
- authenticate through GitHub or connect a GitHub integration;
- connect public or private repositories;
- build or deploy applications;
- create storage, networking, compute, or other cloud resources;
- use logs, metrics, dashboards, APIs, or other platform features;
- make or attempt a payment;
- contact support;
- subscribe to communications or marketing;
- complete a survey or customer interview; or
- otherwise interact with Infralane.
This Policy does not govern the independent privacy practices of websites, applications, or third-party services that we do not control.
3. Infralane as controller and processor
Because Infralane is a cloud platform, our role differs depending on the data involved.
3.1 When Infralane determines the purpose of processing
We generally act as a data controller for information such as:
- your Infralane Account details;
- contact information;
- authentication and security records;
- billing and transaction records;
- website analytics;
- marketing preferences;
- support communications; and
- information we use to administer, protect, improve, and operate Infralane.
3.2 When a Customer deploys an application on Infralane
A Customer may deploy an application that processes personal data relating to that Customer’s own users, employees, customers, or other individuals.
In that situation, the Customer generally determines why and how the application collects and uses that personal data, and Infralane may process or store the data on the Customer’s behalf as part of providing cloud infrastructure.
For such Customer application data:
- the Customer is responsible for providing appropriate privacy notices and obtaining any required permissions or lawful basis;
- Infralane processes the data to provide, secure, support, and maintain the requested Services; and
- individuals should normally direct application-specific privacy requests to the Customer that operates the application.
Where appropriate, we may enter into a separate data processing agreement with a Customer.
4. Personal data we collect
We collect only the information reasonably relevant to the purposes described in this Policy.
4.1 Account and identity information
When you create or maintain an Account, we may collect:
- name;
- email address;
- phone number;
- password or other authentication information;
- account identifiers;
- organisation or project information that you provide; and
- Account preferences.
4.2 GitHub authentication and repository information
If you use GitHub authentication or connect GitHub to Infralane, we may receive or process information permitted by the GitHub permissions you approve, including:
- GitHub account identity and profile information;
- repository names and identifiers;
- repository metadata;
- branches, commits, and related source-control information;
- access authorisations or tokens required to operate the integration;
- public repository contents;
- private repository contents where you authorise access; and
- source code and files pulled during application builds or deployments.
The permissions requested by Infralane may change as platform features change. Where GitHub requires additional authorisation, GitHub will present the relevant permission request.
4.3 Deployment and infrastructure information
When you use the cloud platform, we may process:
- application and Deployment names;
- project and resource identifiers;
- resource allocations and usage;
- build and deployment status;
- container or image metadata;
- region or data-centre selections;
- configuration metadata;
- network and storage usage;
- logs, metrics, events, and error information; and
- operational data needed to provide and troubleshoot the Services.
4.4 Customer application data
If you choose persistent storage or otherwise submit data through a Deployment, we may store or process Customer application data on your behalf.
The contents and categories of such data depend on what you choose to deploy and store. Infralane does not determine the contents of Customer application databases or files merely because they are hosted through the Services.
4.5 Payment and transaction information
When you purchase Services, we may collect or receive information such as:
- payment amount;
- currency;
- transaction reference;
- payment status;
- billing history;
- phone number or other information needed for the selected mobile-money flow; and
- fraud, verification, or reconciliation information.
Mobile-money payments may be processed using MarzPay or another payment provider made available through Infralane.
Payment providers may independently collect information under their own terms and privacy policies.
4.6 Device, network, and usage information
When you access the website or platform, we may automatically collect:
- IP address;
- browser and device information;
- operating system information;
- date and time of requests;
- pages, dashboard areas, or features used;
- session and authentication events;
- API request metadata;
- referring pages;
- diagnostic and performance information; and
- security and audit logs.
4.7 Communications and support
If you contact us, we may collect:
- your name and contact details;
- the contents of your message;
- support tickets;
- attachments you choose to provide;
- records of troubleshooting steps; and
- related correspondence.
Where support requires access to a Deployment or Customer Content, we will use that access only as reasonably necessary to address the request, operate or secure the Services, or comply with law.
4.8 Surveys, customer interviews, and research
If you respond to an Infralane survey, interview, feedback request, or research activity, we may collect the information you choose to provide, such as:
- name and contact details;
- role or company information;
- product needs and pain points;
- feedback;
- opinions;
- usage preferences; and
- consent records.
4.9 Cookies, analytics, and similar technologies
Our websites and dashboard may use cookies, local storage, pixels, analytics tools, or similar technologies to:
- keep you signed in;
- remember preferences;
- protect against fraud and abuse;
- understand how the Services are used;
- measure website and campaign performance;
- diagnose errors;
- improve the Services; and
- support marketing or advertising activities where permitted.
Where consent is required for a category of cookies or tracking, we will request consent through an appropriate mechanism.
5. How we obtain personal data
We may obtain personal data:
- directly from you;
- automatically from your browser, device, or use of the Services;
- from GitHub when you authorise an integration or use GitHub authentication;
- from payment providers when you initiate or complete a transaction;
- from Google services used by us;
- from Cloudflare in connection with website delivery, security, performance, or abuse prevention;
- from an organisation that creates or manages an Account for you;
- from a Customer where you interact with an application hosted through Infralane; or
- from other sources where collection is lawful and relevant to the Services.
6. Why we use personal data
We process personal data for specific purposes connected to operating Infralane, including to:
6.1 Provide the Services
We use information to:
- create and manage Accounts;
- authenticate users;
- connect repositories;
- build source code;
- deploy applications;
- allocate cloud resources;
- provide persistent storage and backups where selected;
- display logs, metrics, and status information;
- process requested actions; and
- provide customer support.
6.2 Process payments and administer billing
We use information to:
- calculate charges;
- initiate or confirm mobile-money payments;
- reconcile payments;
- issue billing records;
- detect payment abuse; and
- manage unpaid balances.
6.3 Secure Infralane
We may process information to:
- authenticate users;
- detect suspicious activity;
- protect Accounts;
- prevent fraud;
- investigate abuse;
- detect malicious traffic;
- respond to vulnerabilities;
- maintain audit records; and
- protect the confidentiality, integrity, and availability of the Services.
6.4 Maintain and improve the platform
We may use usage, diagnostic, performance, feedback, and aggregated information to:
- troubleshoot failures;
- improve reliability;
- understand feature usage;
- plan capacity;
- improve user experience;
- develop new features; and
- measure service performance.
Where reasonably possible for analytical purposes, we may aggregate or de-identify information.
6.5 Communicate with you
We may use your contact information to send:
- security alerts;
- service notices;
- payment or billing information;
- deployment or operational notifications;
- responses to support requests;
- changes to legal terms or policies;
- product updates; and
- marketing communications where permitted.
6.6 Comply with law and enforce our agreements
We may process information to:
- comply with legal and regulatory duties;
- respond to lawful requests;
- establish, exercise, or defend legal claims;
- enforce our Terms of Service;
- investigate violations; and
- protect Infralane, Customers, or third parties.
7. Grounds for processing
Depending on the circumstances and applicable law, we process personal data where:
- you have given consent;
- processing is necessary to provide Services you requested or perform an agreement with you;
- processing is necessary to comply with a legal obligation;
- processing is necessary to protect legitimate security, operational, fraud-prevention, or business interests where permitted by law and not overridden by your applicable rights; or
- another lawful ground permits or requires the processing.
Where processing is based on consent, you may withdraw that consent, subject to applicable law and without affecting processing that was lawful before withdrawal.
Some information is necessary to provide an Account or a requested Service. If you do not provide required Account, authentication, repository-authorisation, billing, or technical information, we may be unable to provide the relevant feature.
8. GitHub integration and source code
GitHub is central to some Infralane deployment workflows.
If you authorise Infralane to access a repository, including a private repository, we may pull and process its source code and related information when needed to perform a build, deployment, redeployment, troubleshooting action, or other feature you request.
Source code may pass through or be temporarily stored by build, caching, logging, or deployment systems to the extent technically necessary to provide the Services.
We do not claim ownership of source code merely because it is processed by Infralane.
You can revoke or modify GitHub permissions through available GitHub and Infralane controls. Revoking access may disable builds, deployments, or other integration features that depend on that access.
9. Cookies, analytics, marketing, and advertising
We may use analytics and similar technologies to understand how people find and use Infralane.
We may also use marketing or advertising tools to measure campaigns, understand interest in Infralane, or communicate relevant information about our Services, where permitted by law.
You may have controls available through:
- our cookie or consent interface;
- your browser;
- your device;
- unsubscribe links in marketing messages; or
- settings provided by the relevant third-party platform.
Essential technologies required for authentication, security, fraud prevention, or core site functionality may not be optional because the Services may not function properly without them.
10. When we share personal data
We do not sell your personal data.
We may disclose personal data in the following circumstances.
10.1 Service providers and subprocessors
We may use third parties to provide parts of the Services, including:
- GitHub — authentication, source-code integration, and repository access that you authorise;
- Cloudflare — network delivery, performance, DNS, security, and abuse protection where enabled;
- Google — analytics, authentication, productivity, infrastructure, or other services that we configure from time to time;
- MarzPay — mobile-money and payment processing;
- infrastructure and data-centre providers used to provide compute, storage, networking, and related cloud capacity; and
- other technical, security, communications, support, or business service providers reasonably necessary to operate Infralane.
We may change service providers as our infrastructure and product evolve.
Service providers receive only the information reasonably necessary for the services they perform and are expected to handle information subject to applicable contractual and legal obligations.
10.2 At your direction
We may disclose data when you request or authorise us to do so, including when you enable a third-party integration.
10.3 Legal and safety reasons
We may disclose information where reasonably necessary to:
- comply with applicable law;
- comply with a valid court order, regulatory request, or other binding legal process;
- investigate fraud, abuse, or a security incident;
- protect the rights, safety, property, or security of Infralane, our Customers, or others; or
- establish, exercise, or defend legal claims.
10.4 Corporate transactions
If Cranom Technologies Limited is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, information may be disclosed to relevant advisers, counterparties, or successors subject to appropriate confidentiality and legal safeguards.
11. Infrastructure providers and data-centre locations
Infralane uses third-party infrastructure and data-centre capacity and may add, remove, or replace providers as the platform expands.
We do not necessarily publish the identity of every underlying infrastructure provider.
Where your chosen Deployment region or technical configuration causes data to be processed in a particular location, we may process Customer Content and related operational data in that location as necessary to provide the Services.
We take reasonable steps to select providers and arrangements that support the security and lawful processing of data.
12. International and cross-border processing
Because cloud, security, analytics, repository, and payment services may operate across multiple countries, personal data may be processed or stored outside Uganda.
Where Cranom Technologies Limited, as a Uganda-based data controller or processor, processes or stores personal data outside Uganda, we will take steps required by applicable law, which may include ensuring that the destination provides adequate or equivalent protection, using appropriate contractual and organisational safeguards, and obtaining consent where required.
The location of Customer application data may also depend on the data-centre region selected by the Customer.
13. How long we retain personal data
We do not keep personal data longer than reasonably necessary for the purpose for which it was collected, except where a longer period is required or permitted by law.
Our general retention approach is:
| Data category | General retention approach |
|---|---|
| Account and profile information | While the Account is active and normally for up to 90 days after termination, unless longer retention is required by law or necessary for a legal claim. |
| Customer application data on persistent storage | While the relevant storage or Account is active and, where retained after termination, normally for no more than 90 days, subject to deletion settings, technical limitations, legal requirements, and backup rotation. |
| Opt-in backups | For the period associated with the enabled backup feature and, after termination, subject to normal backup rotation and the 90-day post-termination retention approach where technically applicable. |
| GitHub authorisations and integration data | While the integration is connected or needed to provide the requested feature, followed by reasonable technical cleanup and any limited security or audit retention required by law. |
| Build and deployment copies of source code | For as long as reasonably necessary to perform builds, deployments, caching, troubleshooting, security, or related platform operations, and not as an independent claim of ownership over the source code. |
| Payment and transaction records | For as long as reasonably necessary for payment reconciliation, accounting, taxation, fraud prevention, legal compliance, and dispute handling. |
| Security, audit, diagnostic, and operational logs | For as long as reasonably necessary for security, troubleshooting, reliability, abuse prevention, and legal compliance; where linked to a closed Account, they are normally deleted or de-identified within the 90-day post-termination period unless a longer period is justified or required. |
| Support communications | For as long as reasonably necessary to resolve the request, maintain service history, improve support, or establish and defend legal claims. |
| Marketing information | Until you opt out, consent is withdrawn where applicable, or the information is no longer needed for the relevant lawful marketing purpose. |
| Survey and research information | For as long as reasonably necessary for the stated research, customer-development, product-improvement, or business purpose, after which it may be deleted or de-identified. |
Deletion from live systems may not immediately remove residual copies from backups or disaster-recovery systems. Such copies remain protected and are removed through normal rotation unless retention is required by law.
We may de-identify information instead of deleting it where permitted by law and where the information can no longer reasonably identify an individual.
14. Security
We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Measures may include, as appropriate to the relevant system:
- access controls;
- authentication controls;
- network and infrastructure security measures;
- logging and monitoring;
- least-privilege access practices;
- secure development and operational procedures;
- incident-response processes;
- backups where the relevant feature is enabled; and
- controls applied by our service providers.
No Internet or cloud service can guarantee absolute security.
You are also responsible for protecting your Account credentials, source-code credentials, application secrets, application configuration, and access granted to your own users.
15. Data breaches and security incidents
If we become aware of unauthorised access to or acquisition of personal data for which notification is required by applicable law, we will take reasonable steps to:
- investigate and contain the incident;
- mitigate reasonably foreseeable harm;
- preserve information needed for investigation;
- notify the appropriate authority where required; and
- notify affected individuals or Customers where required by law.
Where Infralane processes Customer application data on behalf of a Customer, we may notify the relevant Customer so that the Customer can meet its own legal obligations.
16. Your privacy rights
Subject to applicable law, you may have rights concerning personal data that Infralane controls, including the right to:
- ask whether we hold personal data about you;
- request access to personal data we hold about you;
- request a description of that data;
- request information about third parties or categories of third parties that have had access to your data where applicable;
- request correction of inaccurate, incomplete, misleading, irrelevant, excessive, out-of-date, or unlawfully obtained personal data;
- request deletion or destruction of data that we no longer have authority to retain;
- withdraw consent where processing is based on consent;
- object to or prevent certain direct-marketing processing where applicable;
- exercise applicable rights concerning significant decisions based solely on automated processing; and
- lodge a complaint with the competent data-protection authority.
We may need to verify your identity before fulfilling a request.
Some rights are subject to lawful exceptions. For example, we may need to retain certain information for legal obligations, fraud prevention, security, transaction records, or legal claims.
17. How to exercise your rights
To submit a privacy request, email:
Please include enough information for us to identify your Account and understand the request. Do not send passwords, private keys, or unnecessary sensitive information in your request.
We may ask for reasonable proof of identity before disclosing, correcting, or deleting personal data.
If your request concerns data collected by an application operated by an Infralane Customer, you should generally contact that Customer first. We will assist Customers with valid data-subject requests where required by applicable law and our agreement with the Customer.
You may also have the right to complain to Uganda’s Personal Data Protection Office (PDPO).
18. Users under 16
Infralane is not intended for people under 16 years of age, and we do not knowingly invite people under 16 to create Accounts.
If we learn that a person under 16 has provided personal data in connection with an Account contrary to our eligibility rules, we may take reasonable steps to restrict the Account and delete the information, subject to applicable legal obligations.
Users aged 16 or 17 may use the Services only to the extent permitted by applicable law and the Infralane Terms of Service.
19. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to Infralane features;
- new service providers;
- new data-processing activities;
- changes in law or regulatory guidance; or
- improvements to how we explain our privacy practices.
If a change is material, we will provide reasonable notice through the website, dashboard, email, or another appropriate channel where required or reasonably practicable.
The effective date at the top of this Policy identifies the current version.
20. Contact us
Questions, complaints, or requests concerning privacy or personal data may be sent to:
Cranom Technologies Limited
Trading as Infralane
Registered in the Republic of Uganda
Registered business address: Kampala, Uganda
Email: info@infralane.cloud