1. Information we collect
1ProNAS may process account email addresses, display names, company details, tenant roles, session records, IP and user-agent hashes, subscription status, support enquiries, connector identities, NAS model and operating-system details, storage-capacity readings, authorised share names, file metadata required for approved analysis, audit records and service logs.
Payment-card details are entered directly into Stripe and are not stored by 1ProNAS. Mailtrap processes transactional email delivery information. The platform must not request NAS passwords, full payment-card details, OTP codes or private API keys through support forms.
2. Why information is used
- Authenticate users and protect sessions.
- Create and administer client and integrator workspaces.
- Operate NAS health, capacity, alerting and approved file-lifecycle workflows.
- Process subscriptions and reconcile verified billing events.
- Deliver OTP, alert and support emails.
- Investigate abuse, incidents, service faults and tenant-isolation concerns.
- Meet legal, accounting and security obligations.
3. Client-controlled NAS information
Each client determines which NAS devices and shares are authorised. The first connector deployment is read-only. SMB, NFS and NAS administration ports must remain private. Sensitive file contents should not be uploaded to support forms. File metadata and analysis results remain tenant-scoped and must not be exposed to another client or integrator without authorised delegation.
4. Sharing and processors
Information is shared only with service providers required to operate the platform, authorised Axon personnel, an approved integrator acting for the client, or authorities where legally required. Current planned processors are listed on the Subprocessors page. Client payment methods are not visible to integrator staff.
5. Security and retention
1ProNAS uses encrypted transport, hashed OTPs, HttpOnly session cookies, tenant-scoped credentials, audit records, restricted infrastructure access and backup controls. Retention periods depend on record type and are described in the Retention and Deletion policy.
6. Requests and contact
Verified users may request access, correction, export or deletion where applicable. Some records may be retained for security, billing, dispute or legal requirements. Submit requests through the secure contact form and do not include authentication secrets.