The short version
- Our role
- We control account, website, billing, security, and support data. We process Customer Data for the operator that placed it in ISPAgents.
- Managed hosting
- UISP and UniFi controller data remains scoped to the customer account and is used to operate, secure, back up, and support that deployment.
- Payments
- Stripe hosts payment entry and the billing portal. ISPAgents does not receive the full card number entered on those pages.
- Advertising
- We do not sell personal information or share it for cross-context behavioral advertising.
01Scope and our data protection roles
This Privacy Policy applies to ispagents.com, ISPAgents customer accounts and workspaces, managed UISP and UniFi hosting, support, billing, and related services (the Services). ISPAgents means the service provider identified on the applicable order, invoice, or Stripe receipt. You may request the provider's legal name and postal address at legal@ispagents.com before placing a paid order.
We handle personal information in two different roles:
- Controller or business. We decide why and how to process account, website, sales, billing, product usage, security, and support information needed to run ISPAgents.
- Processor or service provider. A customer decides why and how to process subscriber, device, network, field-service, and controller information placed in the Services (Customer Data). We process it on that customer's instructions to provide the Services.
This policy does not replace a customer's own privacy notice to its subscribers, employees, or contractors. It also does not govern third-party websites or services that a customer chooses to connect.
02Information we process
The data involved depends on the Services a customer enables.
| Category | Examples | Primary purpose |
|---|---|---|
| Business and account | Name, work email, company, role, team membership | Create the account, authorize users, and communicate |
| Authentication and security | Magic-link and session records, IP address, browser or user agent, policy acceptance, permissions, and audit events | Sign users in, prevent abuse, and preserve accountability |
| Billing | Stripe customer and subscription IDs, plan, metered quantity, invoice and payment status, billing identity, and tax details | Quote, charge, invoice, reconcile, and manage subscriptions |
| Subscriber and service operations | Subscriber contact and service address, plan, balance, invoice, support, RADIUS identity and sessions, and service status | Operate the customer's ISP workflow on its instructions |
| Devices and network telemetry | Device identifiers, MAC and IP addresses, serial numbers, RouterOS or CPE configuration, TR-069 or USP parameters, SNMP, syslog, IPFIX, diagnostics, and availability | Inventory, monitor, diagnose, configure, and collect telemetry |
| Managed controllers | Requested hostname and capacity, owner and support email, controller accounts, device and topology data, configuration, logs, backups, and lifecycle events | Provision and operate managed UISP or UniFi instances |
| Support and field work | Support messages, tickets, call notes, job location, photos, signatures, cash collection records, and inventory movements | Resolve support requests and perform customer-directed work |
Customers choose what to connect and configure. They should not place special category data, government identifiers, payment card security codes, or other data that is unnecessary for the Services into free-text fields or logs.
03Where information comes from
We receive information:
- directly from account owners, authorized users, and sales contacts;
- from systems a customer connects, including RADIUS, MikroTik, TR-069, TR-369 USP, SNMP, syslog, billing, messaging, UISP, and UniFi;
- automatically from browsers, applications, APIs, hosting infrastructure, and security controls when the Services are used; and
- from service providers such as Stripe when they report checkout, subscription, invoice, or payment events.
04How and why we use information
We process controller data for the following purposes and legal bases:
- Contract. To create and administer accounts, provision workspaces and controllers, collect telemetry, deliver support, meter usage, and bill for the Services.
- Legitimate interests. To secure the Services, investigate abuse, maintain audit trails, diagnose reliability, improve product workflows, and communicate relevant service information. We balance these interests against the rights of affected individuals.
- Legal obligations. To maintain tax and accounting records, respond to lawful process, enforce rights, and meet applicable security or incident-reporting duties.
- Consent. Where law requires consent for an optional communication or technology. Consent can be withdrawn without affecting earlier lawful processing.
Customer Data is processed under the customer's documented instructions, the applicable data processing agreement, and the customer's chosen product configuration.
05Customer Data and subscriber requests
The customer is responsible for its Customer Data, including providing legally required notices, establishing a lawful basis, configuring retention, and responding to its subscribers and personnel. ISPAgents does not determine why an operator bills, suspends, monitors, or manages a subscriber or device.
A subscriber or customer employee seeking access, correction, deletion, or another right concerning Customer Data should contact the relevant operator first. We will assist that operator as required by the data processing agreement and applicable law. We may redirect a request when we cannot identify the responsible customer without exposing another tenant's information.
06Managed UISP and UniFi hosting
A managed deployment creates provisioning, DNS, billing, health, backup, and support records. UISP deployments use a customer-scoped host unless an order says otherwise. UniFi controllers use customer-scoped application, database, network, and storage boundaries on managed hosting capacity.
When configured, the ISPAgents workspace can pull selected controller data through a read-only API connection to create a unified customer timeline. Hosting controllers are not authorized to initiate access into the production workspace. A customer may separately configure controller integrations that communicate with Ubiquiti or another third party; that third party's privacy terms then also apply.
07Payments through Stripe
Stripe hosts checkout and the customer billing portal. Stripe may collect a billing name, address, tax ID, payment method, and transaction information. We receive the details needed to administer the account, such as Stripe identifiers, payment method type and limited display details, invoice totals, and payment status. We do not receive the full card number or card security code entered on a Stripe-hosted page.
Stripe acts as our processor for some payment activity and as an independent controller for activities it determines, including fraud prevention and legal compliance. See the Stripe Privacy Policy.
08AI-assisted features
If a customer enables an AI-assisted feature, the prompt and the selected records needed for that task may be sent to a documented AI service provider. We limit that context to the feature being used and treat the provider as a subprocessor where it handles Customer Data.
We do not use one customer's Customer Data to train models for other customers. AI output is advisory and may be inaccurate. Authorized users remain responsible for reviewing proposed actions before applying them to a network, subscriber, bill, or controller.
09Support and administrative access
Authorized ISPAgents personnel may access an account or managed controller when needed to respond to a customer request, investigate a security or reliability event, recover the service, or meet a legal obligation. Access is limited by role and operational need. Sensitive support access may require a reason or approval and is recorded in audit logs.
Customers can provide owner and support contact emails during managed hosting provisioning. These addresses are used to establish controller access and communicate operational events.
11Locations and international transfers
ISPAgents currently uses primary cloud infrastructure in the United States, including the Chicago region. Service providers may process data in other countries where they operate. This means information can be transferred outside the country where it was collected.
Where required, we use a valid transfer mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK addendum, or another legally recognized safeguard. Customers may request information about the applicable safeguard at privacy@ispagents.com.
12Retention and deletion
We keep information only as long as reasonably necessary for the purpose described above. The period depends on account status, customer configuration, security and audit needs, backup cycles, legal requirements, and unresolved disputes or payments.
- Account and workspace data is generally kept while the account is active and through a limited closure and recovery process.
- Customer-generated export download files expire after 24 hours. The source records are governed by their ordinary retention settings.
- Controller data is removed from active systems after confirmed decommissioning, subject to backup rotation and records that must be kept for security, billing, or legal reasons.
- Billing and transaction records may be retained for tax, accounting, dispute, chargeback, and fraud-prevention periods required by law or financial providers.
Deletion from backups occurs as those backups are overwritten or expire. We isolate retained records from ordinary product use when deletion is not yet technically or legally possible.
13Security
We use administrative, technical, and physical safeguards designed for the sensitivity of the information, including tenant and hosting isolation, encryption in transit, role-based access, secret management, audit logging, backups, monitoring, and approval controls for sensitive operations. No internet service can guarantee absolute security.
Customers are responsible for choosing authorized users, reviewing roles, securing connected systems, and promptly removing access that is no longer needed. Report a suspected vulnerability or incident to security@ispagents.com. More detail is available on our Security page.
14Your privacy rights
Depending on location and applicable law, an individual may have rights to know or access personal information, correct it, delete it, restrict or object to processing, receive portable data, withdraw consent, and appeal a denied request. Individuals may also complain to their local data protection authority.
Send a request concerning ISPAgents controller data to privacy@ispagents.com. Include enough information to identify the relevant account and request. We may verify identity and authority, including for an authorized agent, and will use verification data only for that purpose. We will respond within the period required by applicable law. These rights may be limited by exemptions, legal retention duties, security, and the rights of others.
15United States state privacy notice
During the preceding 12 months, we may have collected the categories described in Section 2: identifiers and business contact data, account and commercial records, internet or network activity, approximate or customer-directed field location, professional information, support communications, and inferences needed for security or service operation. We use and disclose those categories for the business purposes described in Sections 4 and 10.
We do not sell personal information, share it for cross-context behavioral advertising, or offer a financial incentive for personal information. We use sensitive information, such as account credentials, precise field location when a customer enables it, and limited payment information, only to provide and secure requested Services. We do not discriminate against an individual for exercising an applicable privacy right.
17Business use and children
The Services are designed for businesses and their authorized personnel, not for personal, family, or household use by children. We do not knowingly collect personal information directly from children. Customer Data may concern an operator's subscribers, including household members; the operator is responsible for the legal basis and notices for that information.
18Changes and contact
We may update this policy when the Services, providers, or law change. We will post the revised version and effective date here. We will provide additional notice before a material change when required by law.
Privacy requests: privacy@ispagents.com
Legal and provider identity: legal@ispagents.com
Security reports: security@ispagents.com
