Privacy Policy
Effective: August 28, 2026
AMAYACLOUD INC, a Delaware corporation ("Amaya Cloud," "we," "us," or "our"), provides dedicated bare-metal GPU and cloud infrastructure services to business customers. This Privacy Policy explains what personal information we collect through our website at www.amayacloud.com and in the course of our business relationships, how we use it, and the choices available to you.
This Policy covers information we handle as a business in our own right. It does not govern data our customers place on infrastructure we provide — see "Customer Data" below.
Who we are
Amaya Cloud is a business-to-business infrastructure provider. We do not offer consumer accounts, self-service signup, or a consumer-facing product. Our services are provided to companies under individually negotiated written contracts.
Information we collect
Information you give us directly. If you contact us through our website form or by email, we collect the information you choose to provide — typically your name, business email address, company name, and details about your compute requirements.
Business relationship information. In the course of contracting with and supporting a customer, we collect business-contact details for the individuals who represent that customer, such as names, business email addresses, phone numbers, job titles, and technical contact information. We also collect the corporate, ownership, end-user, and end-use information required by our End-User, End-Use & Export Compliance Certification process, and billing and bank-transfer details necessary to invoice and receive payment.
Website analytics. We use Google Analytics to understand how visitors use our website. Google Signals and advertising personalization features are disabled in our configuration, so this data is not used to build cross-site advertising profiles. Analytics data includes pages viewed, approximate location derived from IP address, browser and device type, and referring source.
Technical and security information. Our systems generate logs relating to infrastructure access, administrative activity, and security monitoring, which may include IP addresses, timestamps, and account or credential identifiers.
Support communications. We support customer engineering teams directly, including through shared Slack channels established with a customer. We collect the communications and technical information exchanged in the course of that support. We do not provide support to, or collect information from, our customers' own end users.
What we do not do
To be specific, because these are common practices we have chosen not to adopt:
- We do not sell personal information, and we do not share it for cross-context behavioral advertising or targeted advertising.
- We do not use advertising pixels, retargeting tags, or session-replay tools on our website.
- We do not operate a customer relationship management platform or marketing-email platform that profiles website visitors.
- We do not process credit or debit card information. Customers pay by bank transfer.
- We do not use customer content to train artificial-intelligence or machine-learning models. This is a contractual commitment in our Master Services Agreement, not only a policy statement.
How we use information
We use personal information to:
- respond to inquiries and provide information about our services;
- negotiate, execute, and administer customer contracts and order forms;
- provision, operate, secure, monitor, and maintain infrastructure services;
- provide technical support to customer engineering teams;
- invoice customers and process payments received by bank transfer;
- conduct export-control, sanctions, and restricted-party screening and related compliance review;
- detect, investigate, and respond to security incidents, abuse, and unlawful activity;
- comply with legal obligations, respond to lawful requests, and establish or defend legal claims; and
- understand website usage in aggregate.
Customer Data
Our customers run their own workloads on infrastructure we provide. Any personal information contained within those workloads ("Customer Data") is controlled by the customer, not by us.
Under our Master Services Agreement, we receive only a limited right to access Customer Data as necessary to provide, secure, maintain, or troubleshoot the infrastructure, or to comply with law. We do not sell Customer Data, train on it, profile it, or analyze it for our own independent purposes. We access customer content only to the minimum extent necessary for hardware diagnostics, infrastructure monitoring, maintenance, security, customer-requested support, or binding legal process. Access is limited to authorized personnel and contractors bound by confidentiality obligations.
If you believe your personal information is held within a customer's workload and you wish to exercise rights over it, please contact that customer directly. We will refer such requests to the relevant customer where appropriate.
Disclosure of information
We disclose personal information only in the following circumstances:
- Infrastructure and data-center providers, including colocation facilities and network providers, as necessary to deliver the services.
- Professional advisers, including legal counsel, accountants, auditors, and insurers, where reasonably necessary.
- Hardware manufacturers and upstream suppliers, and lenders, lessors, or financing parties, where reasonably necessary for compliance, warranty, or vendor-protection purposes. This is disclosed to and agreed by customers in our End-User, End-Use & Export Compliance Certification.
- Government and law-enforcement authorities, where required by applicable law or valid legal process. Where legally permitted and reasonably practicable, we will notify the affected customer before disclosing Customer Data and will reasonably cooperate with efforts to seek protection.
- In connection with a corporate transaction, such as a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections.
We do not disclose personal information to advertising networks or data brokers.
Cookies and similar technologies
Our website uses a limited set of cookies and similar technologies:
- Strictly necessary technologies that support basic site operation and security.
- Google Analytics cookies (
_gaand related), used to measure website usage. As noted above, Google Signals and advertising features are disabled.
We do not use advertising, retargeting, or cross-site tracking cookies.
Most browsers allow you to block or delete cookies through their settings. Blocking analytics cookies will not affect your ability to use our website. If you are visiting from a jurisdiction that requires prior consent for non-essential cookies, and we begin serving visitors in that jurisdiction at scale, we will implement a consent mechanism at that time.
Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of your personal information, and to appeal a decision we make about such a request.
To make a request, email sales@amayacloud.com with the subject line "Privacy Request." Please include your name, the email address you used to interact with us, your state or country of residence, and the right you wish to exercise. We may need to ask for additional information to verify your identity, proportionate to the sensitivity of the request.
We do not sell or share personal information for targeted advertising, so opt-out rights relating to those activities do not apply to our practices. Where required by applicable law, we honor qualifying browser-based universal opt-out signals, including Global Privacy Control.
We will not discriminate against you for exercising any privacy right.
Retention
We retain personal information for as long as reasonably necessary for the purposes described above.
- Inquiry and business-contact information is retained for the duration of the business relationship and a reasonable period afterward.
- Contract, billing, and tax records are retained as required by applicable legal, accounting, and tax obligations.
- Export-control and compliance records, including End-User Certifications and screening records, are retained for at least five years after the relevant use of the services, consistent with our contractual and regulatory obligations.
- Security and access logs are retained according to our internal security schedule.
- Customer Data is handled under the terms of the applicable Master Services Agreement. Following expiration or termination of an order form and the applicable data-export period, we sanitize customer storage media under NIST Special Publication 800-88 guidance or a materially equivalent standard, or physically destroy the media where sanitization is not technically feasible. Copies may persist in routine, immutable disaster-recovery media until overwritten in the ordinary course, subject to continuing confidentiality and security obligations and no active use.
Security
We maintain administrative, physical, and technical safeguards for the infrastructure we manage, including restricted facility access, management-network controls, monitoring, and administrative-access controls. Security responsibilities are allocated between us and our customers in our Master Services Agreement: we are responsible for physical data-center security, hardware lifecycle management, managed network perimeter controls, availability monitoring, and hardware diagnostics; customers are responsible for application and operating-system security, user access, encryption, keys, and backups.
We maintain an incident response program. Under our Service Level Agreement, we notify affected customers of a security incident without undue delay and no later than 72 hours after we become aware of it.
No security measure can guarantee absolute security.
International visitors and transfers
Our services are operated from the United States and our infrastructure is located in the United States. If you contact us or do business with us from outside the United States, your information will be processed in the United States.
We currently market and provide services to business customers in the United States. Our services are subject to U.S. export-control and sanctions requirements, and access from or by certain persons, entities, or destinations is restricted or prohibited — see our Export Control and Sanctions Notice.
Children
Our services are business services intended for organizations. They are not directed to children, and we do not knowingly collect personal information from anyone under 18. Individuals interacting with us must be at least 18 years old and authorized to act on behalf of the organization they represent.
Changes to this Policy
We may update this Policy from time to time. We will revise the effective date above and, where required by law, provide additional notice.
Contact us
AMAYACLOUD INC, a Delaware corporation.
501 Silverside Road, Suite 102
Wilmington, New Castle County
Delaware 19809
United States
Email: sales@amayacloud.com
Web: www.amayacloud.com
← Back to site