Adal Cloud Adal Cloud Beta
Blog Documentation How To Pricing
Open dashboard ↗
Reliable Webhook Delivery Infrastructure Navigation
Blog → Documentation → How To → Pricing →
Open dashboard ↗
Privacy and data

Adal Cloud Privacy Policy

Read the privacy policy for using Adal Cloud, including data collection, usage, and protection practices.

Last updated on August 30, 2026

Introduction

Adal Cloud is a webhook infrastructure service that enables users to receive, inspect, store, forward, and replay webhook requests. This Privacy Policy explains how Adal collects, uses, stores, and protects personal data when you use our website, dashboard, API, webhook Servers, command-line interface, and related services (the “Service”).

This Policy applies to data you provide directly to Adal, data generated through your use of the Service, and data received through webhook requests sent to your Adal Servers.

Because Adal processes webhook requests on behalf of its users, webhook payloads, headers, query parameters, and other request data may contain personal data or other sensitive information, depending on how you configure and use the Service. You are responsible for ensuring that you have the rights, permissions, and legal basis necessary to send such data to Adal.

By using Adal, you acknowledge that your data will be processed as described in this Privacy Policy.

Definitions

For purposes of this Privacy Policy:

  • “Adal Cloud”, “Adal”, “we”, “us”, or “our” means “ADAL CLOUD” LLP, a limited liability partnership registered in the Republic of Kazakhstan, the provider and operator of the Service.

  • “Service” means the Adal website, dashboard, API, webhook Servers, command-line interface, and any related services provided by Adal.

  • “User”, “you”, or “your” means a person or organization that accesses or uses the Service.

  • “Account Data” means data relating to your Adal account, including your email address, authentication data, account settings, plan information, and related administrative information.

  • “Service Configuration Data” means data you configure in the Service, including Servers, Destination URLs, tokens, delivery settings, storage settings, region settings, and other technical configuration.

  • “Webhook Content” means the content of webhook requests received by Adal on your behalf, including request bodies, payloads, headers, query parameters, path information, and any other data included in those requests.

  • “Request Metadata” means technical information about webhook requests, such as timestamps, HTTP method, request size, source IP address, processing status, delivery status, retry history, and related diagnostic information.

  • “Destination” means a URL or local delivery target configured by you to receive webhook requests forwarded by Adal.

  • “Region” means a geographic or infrastructure location where certain parts of the Service may process or store data.

  • “Personal Data” means any information relating to an identified or identifiable natural person.

  • “Processing” means any operation performed on data, including collection, receipt, storage, access, transmission, forwarding, deletion, and protection.

Who We Are

Adal is operated by “ADAL CLOUD” LLP, a limited liability partnership registered in the Republic of Kazakhstan.

For purposes of applicable data protection laws, “ADAL CLOUD” LLP is the provider and operator of the Service and may act as a data controller when processing Account Data, billing information, security data, communications, and information relating to use of the Service.

When Adal receives, stores, forwards, or replays webhook requests on behalf of a User, “ADAL CLOUD” LLP generally acts as a data processor or service provider. The User determines the content of the webhook requests and the purposes for which such data is processed.

If you have questions about this Privacy Policy or how personal data is processed, contact us at [email protected].

Scope of This Policy

This Privacy Policy applies to the Adal website, dashboard, API, webhook Servers, command-line interface, and related services that link to or reference this Policy.

This Policy covers personal data that we collect directly from you, data generated through your use of the Service, and data received, stored, forwarded, or replayed through webhook requests sent to your Adal Servers.

This Policy does not apply to third-party websites, services, applications, or integrations that are not operated by Adal, even if they send data to Adal or receive data from Adal. Those third-party services are governed by their own privacy policies and terms.

When you configure a Destination, you are responsible for the service, server, application, or local environment that receives forwarded webhook requests from Adal. Adal does not control how data is processed after it has been delivered to a Destination you configure.

If you use Adal on behalf of an organization, customer, or another person, you are responsible for ensuring that you have the authority and legal basis to use the Service and to send data to Adal.

Data We Collect

We collect different categories of data depending on how you use Adal.

Account Data

When you create and use an Adal account, we may collect and process data such as:

  • your email address

  • authentication information

  • account settings

  • language, theme, and interface preferences

  • plan, limits, and usage-related information

  • administrative information relating to your account

We do not store passwords in plaintext. Where password-based authentication is used, passwords are stored only in hashed form.

Service Configuration Data

When you configure the Service, we may collect and process technical configuration data such as:

  • Server names and settings

  • Destination URLs

  • delivery settings

  • storage settings

  • selected or assigned Regions

  • authentication tokens, access tokens, API keys, or other credentials you provide

  • retry, replay, and delivery behavior settings

You are responsible for ensuring that any credentials, URLs, or configuration values you provide to Adal are valid and appropriate for use with the Service.

Webhook Content

When webhook requests are sent to your Adal Servers, we may receive and process data contained in those requests, including:

  • request bodies and payloads

  • HTTP headers

  • query parameters

  • path information

  • HTTP method

  • content type

  • request size

  • files or other data included in the request, if supported by the Service

Webhook Content is determined by you and by the third-party services, applications, or systems that send requests to your Adal Servers. Adal does not control the content of webhook requests before they are received by the Service.

Depending on your Server settings and Plan, Webhook Content is either persistently stored for later inspection and interaction or held only temporarily in an in-memory delivery buffer.

Request Metadata

We may collect and process technical metadata about webhook requests, including:

  • timestamps

  • source IP address

  • request size

  • Server identifier

  • processing status

  • delivery status

  • retry history

  • replay history

  • error messages

  • diagnostic information relating to request processing and delivery

Request Metadata is used to provide the Service, display request history, support delivery diagnostics, enforce limits, prevent abuse, and maintain reliability.

Delivery Data

When Adal forwards webhook requests to configured Destinations, we may collect and process delivery-related data such as:

  • Destination identifier

  • delivery attempt timestamps

  • delivery status

  • HTTP response status code

  • response time

  • connection errors

  • timeout errors

  • retry attempts

  • delivery logs

  • limited response information, where applicable

This data helps you inspect delivery behavior, debug failed deliveries, and replay requests where supported.

Technical and Security Data

When you access or use the Service, we may collect technical and security-related data such as:

  • IP address

  • browser type and version

  • device and operating system information

  • user agent

  • session information

  • authentication events

  • access logs

  • API usage logs

  • CLI connection logs

  • security events

  • error logs

We use this data to operate, secure, monitor, debug, and improve the Service.

Billing and Payment Data

If you subscribe to a paid Plan or purchase credits, we may process billing-related data such as:

  • selected Plan

  • subscription status

  • usage counters

  • billing email

  • invoice information

  • payment status

  • payment-provider customer or subscription identifiers

Payment card details and other sensitive payment information are processed by our payment provider. Adal does not intentionally store full payment card numbers.

Communications Data

If you contact us, subscribe to updates, or receive service-related messages, we may process communications data such as:

  • your email address

  • message content

  • support requests

  • feedback

  • transactional emails

  • product or service notifications

We use this data to respond to you, provide support, send important service-related information, and communicate about your account or use of the Service.

How We Use Data

We use the data we collect to provide, operate, secure, and improve the Service.

In particular, we may use data for the following purposes:

Providing the Service

We use Account Data, Service Configuration Data, Webhook Content, Request Metadata, Delivery Data, and Technical and Security Data to:

  • create and manage your account

  • authenticate you and maintain your sessions

  • receive webhook requests sent to your Adal Servers

  • store webhook requests in accordance with your Server settings and Plan

  • display request history in the dashboard

  • forward webhook requests to configured Destinations

  • deliver webhook requests through Adal CLI where applicable

  • support replay and retry functionality

  • apply Server configuration, delivery settings, storage settings, and region settings

  • provide API access and CLI connectivity

Request Inspection, Delivery, and Debugging

We use Webhook Content, Request Metadata, and Delivery Data to help you inspect incoming webhook requests, understand delivery behavior, debug delivery failures, and verify that requests were received and processed as expected.

This may include displaying request headers, payloads, query parameters, delivery attempts, response status codes, timing information, error messages, and retry or replay history in the dashboard.

Reliability, Abuse Prevention, and Security

We use Technical and Security Data, Request Metadata, Delivery Data, and usage-related information to:

  • monitor Service availability and performance

  • detect, prevent, and investigate abuse, fraud, spam, excessive traffic, unauthorized access, and security incidents

  • enforce rate limits, usage limits, Plan limits, and other technical restrictions

  • protect the Service, our infrastructure, our users, and third parties

  • maintain logs necessary for security, diagnostics, and incident response

Billing, Plans, and Usage Limits

We use Account Data, Billing and Payment Data, and usage-related information to:

  • manage subscriptions, credits, invoices, and paid Plans

  • calculate usage

  • enforce Plan limits

  • process payments through our payment provider

  • provide billing-related support

  • send billing and subscription-related notices

Support and Communications

We use Account Data, Communications Data, Technical and Security Data, Request Metadata, and other relevant information to:

  • respond to support requests

  • investigate technical issues you report

  • send transactional and service-related messages

  • notify you of important changes to the Service, your account, billing, security, or this Privacy Policy

  • process feedback or inquiries you send to us

Service Improvement

We may use aggregated, statistical, or diagnostic information to understand how the Service is used, improve reliability and user experience, prioritize product development, and troubleshoot performance or usability issues.

Where practicable, we use aggregated or de-identified data for analytics and product improvement. We do not use Webhook Content to train AI models.

Legal Compliance and Enforcement

We may use data where necessary to:

  • comply with applicable laws, regulations, legal obligations, and lawful requests

  • retain records required for tax, accounting, security, or compliance purposes

  • enforce our Terms of Service

  • protect our rights, users, infrastructure, and third parties

  • resolve disputes or investigate violations

Legal Bases for Processing

Where the GDPR or similar data protection laws apply, we process personal data only where we have a legal basis to do so.

Depending on the category of data and the purpose of processing, we rely on the following legal bases.

Performance of a Contract

We process personal data where necessary to provide the Service to you, manage your account, receive and process webhook requests, forward requests to configured Destinations, provide request history, support retries and replays, provide API and CLI access, enforce Plan limits, and perform other actions you request.

This includes processing Account Data, Service Configuration Data, Webhook Content, Request Metadata, Delivery Data, Technical and Security Data, and Billing and Payment Data where necessary to provide the Service.

Legitimate Interests

We may process personal data where necessary for our legitimate interests, provided those interests are not overridden by your rights and interests.

Our legitimate interests include:

  • operating, maintaining, and improving the Service

  • monitoring reliability and performance

  • debugging errors and delivery failures

  • preventing abuse, spam, fraud, unauthorized access, and security incidents

  • protecting the Service, our infrastructure, our users, and third parties

  • enforcing technical limits and preventing misuse

  • maintaining diagnostic, security, and audit logs

  • communicating with you about important service-related matters

Legal Obligations

We may process and retain certain data where necessary to comply with legal, tax, accounting, regulatory, or compliance obligations.

This may include billing records, invoices, payment status information, security records, and records required to respond to lawful requests or protect our legal rights.

Consent

Where required by law, we may process personal data based on your consent.

This may apply, for example, to optional marketing communications, non-essential cookies, or other optional features that require consent.

You may withdraw your consent at any time where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Processing Webhook Content on Your Behalf

When Adal receives, stores, forwards, or replays Webhook Content on behalf of a User, the User determines the content of the webhook requests and the purposes for which such data is processed.

In those circumstances, Adal generally processes Webhook Content as a data processor or service provider on behalf of the User. The User is responsible for ensuring that there is an appropriate legal basis for sending Webhook Content to Adal and for configuring the Service in a manner that complies with applicable law.

Adal does not determine what personal data is included in webhook requests sent to your Servers.

Webhook Content and User Responsibility

Adal is designed to receive, inspect, store, forward, retry, and replay webhook requests on behalf of its Users.

Webhook Content is determined by you and by the third-party services, applications, systems, or users that send requests to your Adal Servers. Adal does not control the content of webhook requests before they are received by the Service.

Webhook Content may include personal data, confidential information, authentication data, business data, or other sensitive information, depending on how you configure and use the Service.

You are responsible for:

  • deciding which systems are permitted to send webhook requests to your Adal Servers

  • ensuring that you have the rights, permissions, and legal basis necessary to send Webhook Content to Adal

  • configuring Servers, storage settings, Regions, Destinations, and delivery settings appropriately

  • avoiding unnecessary collection or transmission of personal data or sensitive information

  • ensuring that Webhook Content does not violate applicable law, third-party rights, or contractual obligations

  • protecting Server URLs, tokens, credentials, and other access details

  • deleting Webhook Content when it is no longer needed, where such deletion is available through the Service

You should not send highly sensitive data to Adal unless it is necessary for your use case and you have taken appropriate legal, technical, and organizational measures.

Adal may process Webhook Content only as necessary to provide the Service, including receiving requests, storing them in accordance with your settings and Plan, displaying them in the dashboard, forwarding them to configured Destinations, supporting retries and replays, debugging delivery issues, enforcing limits, preventing abuse, and maintaining security.

Adal does not use Webhook Content for advertising and does not sell Webhook Content to third parties.

Adal does not use Webhook Content to train AI models.

When you configure a Destination, Adal forwards Webhook Content to that Destination in accordance with your settings. You are responsible for the Destination and for any processing of Webhook Content that occurs after delivery to that Destination.

If Webhook Content contains personal data relating to your customers, users, employees, or other third parties, you are responsible for providing any required notices, obtaining any required consents, and ensuring that your use of Adal complies with applicable data protection laws.

Storage, Retention and Deletion

Adal stores and retains data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, enforce our agreements, maintain security, and support operational reliability.

Retention periods may depend on the type of data, your Plan, your Server settings, your storage settings, the selected or assigned Region, and applicable legal or technical requirements.

Webhook Storage Settings

Depending on your Server configuration, Plan, and available features, Adal supports two storage modes for accepted webhook requests.

Persistent storage means that Adal stores Request data and delivery records in the regional database and stores the Request body in regional Cloudflare R2 object storage. While the Request remains within its retention period, it may be available in the dashboard and API for inspection, delivery history, manual retry, Replay, and other supported interactions.

Transient delivery means that Adal does not persist the accepted Request or its delivery state to the regional database or Cloudflare R2. The Request is held temporarily in Redis memory only for the delivery workflow. Each Destination has an independent Delivery: work for that Destination ends when a Delivery succeeds or its configured attempts are exhausted. If one Destination succeeds while another still has a pending attempt or retry, the Request remains in memory for the unfinished Destination.

In transient delivery mode, Adal permanently deletes the complete Request and its temporary delivery state when all associated Destinations have reached a final outcome, or earlier when the Request's temporary retention deadline expires. If the deadline expires first, remaining pending Deliveries and retries stop. After deletion, the Request cannot be inspected, manually retried, replayed, restored, or otherwise used through the Service.

Transient Request data is not included in Adal backups. Adal may still keep limited account-level usage, security, abuse-prevention, or billing records that do not contain the Request URI, headers, body, source IP address, Destination configuration, or Delivery history, as described elsewhere in this Policy.

Webhook Content Retention

Persistently stored Webhook Content is retained in accordance with your Server settings, Plan limits, and applicable retention period. Transient Request data follows the shorter lifecycle described above and may be deleted as soon as delivery work finishes, even if its temporary retention deadline has not yet been reached.

The retention period included in your Plan is the minimum period for which a persistently stored Request is retained. Adal does not delete the Request at the exact second that period ends. The Request remains stored until the first midnight UTC after the full retention period has elapsed and is deleted by that scheduled cleanup.

Where the Service allows you to delete webhook requests, request history, Server data, or stored payloads, deletion will remove that data from active systems within a reasonable period, unless retention is required for legal, security, abuse-prevention, billing, backup, or operational reasons.

Deleting a Server overrides the normal retention period for its active data. It immediately stops the Server from accepting new webhook requests and starts deletion of the Server's Destinations, accepted Requests, Webhook Content, Request Metadata, Delivery Data, replay data, and related Server configuration from active systems. This process is normally completed promptly but may take several seconds when a Server has a large number of Requests. The data is not kept in active systems until its previously scheduled retention date.

Persistently stored Webhook Content deleted from active systems may remain in backups or disaster-recovery systems until the affected backup expires. Backups are created daily and retained for seven days. Transient Request data is not written to those backups or to ordinary application logs.

Request Metadata and Delivery Data

For persistently stored Requests, Adal may retain Request Metadata and Delivery Data for the applicable Request retention period to provide request history, delivery diagnostics, Replay and retry functionality, abuse prevention, security monitoring, usage calculation, billing support, and operational reliability.

This may include timestamps, Server identifiers, delivery status, retry history, replay history, response status codes, error messages, and diagnostic information. In transient delivery mode, the Request-specific metadata and Delivery state remain only in the temporary in-memory workflow and are deleted with the Request. Limited account-level usage, security, abuse-prevention, or billing records may remain, but they do not contain the Request content or Delivery history described above.

Account and Configuration Data

We retain Account Data and Service Configuration Data for as long as your account remains active or as needed to provide the Service.

If you request account deletion, the account is scheduled for deletion seven days after the request. Account Data and Service Configuration Data are then deleted or deactivated, except where we need to retain certain data for legal, tax, accounting, security, fraud-prevention, dispute-resolution, or compliance purposes. Copies contained in backups may remain until the applicable seven-day backup retention period expires.

Billing and Legal Records

Billing records, invoices, payment status information, tax records, and related administrative records currently do not have a fixed automatic deletion schedule. They may be retained after account deletion and, in all cases, for at least the minimum period required by applicable law.

This data may be retained even after account deletion where necessary to comply with legal, tax, accounting, or regulatory obligations.

Support Communications

Support requests and related communications currently do not have a fixed automatic deletion schedule. You should not include webhook payloads, Destination credentials, access tokens, signing secrets, or other unnecessary sensitive information in a support request.

Logs and Security Records

Technical logs, access logs, authentication logs, API logs, CLI connection logs, and security event logs are retained for seven days to maintain security, investigate incidents, debug issues, prevent misuse, and protect the Service, users, infrastructure, and third parties.

Adal does not maintain a separate long-term abuse log. Current error and abuse-prevention state held temporarily in Redis expires within 24 hours.

Where practicable, logs are limited to the information necessary for operational, diagnostic, and security purposes.

Backups

Persistently stored data deleted from active systems may remain in encrypted or access-controlled backups until the affected backup expires. Backups are created daily and retained for seven days. Transient Request data is not written to backups.

Backups are used for disaster recovery, business continuity, and security purposes. Backup data is not used for ordinary production access unless it is restored as part of a recovery process.

User-Controlled Deletion

Where the Service provides deletion controls, you may delete Servers, Destinations, stored webhook requests, request history, or other data through the dashboard, API, or other supported interfaces.

Deleting a Server immediately disables its ingest URL and starts deletion of its associated data from active systems. The deletion may take several seconds for a Server with a large number of Requests, but previously accepted Requests are not retained until their original scheduled deletion dates. The ingest URL remains permanently reserved and is not assigned to another user.

Some limited security, abuse-prevention, billing, legal, or backup records may be retained where necessary as described in this Policy. Deleting a Destination without deleting its Server prevents future deliveries to that Destination but does not delete the Server's Requests.

Data Minimization

Adal seeks to limit stored data to what is necessary for the configured Service behavior.

You can reduce the amount of Webhook Content stored by selecting transient delivery where available, limiting sensitive data sent to Adal, choosing an appropriate retention period for persistent storage, and deleting data that is no longer needed.

Regional Data Storage

Adal may allow you to select, or may assign, a Region for certain parts of the Service, including the storage and processing of webhook request data.

Where regional storage is available and enabled, Adal seeks to store Webhook Content and related request data in the selected or assigned Region in accordance with your Server settings, Plan, and available infrastructure.

Regional storage may apply to data such as:

  • Webhook Content

  • Request Metadata

  • Delivery Data

  • Server-specific request history

  • stored payloads, where payload storage is enabled

Some data may be processed or stored outside the selected or assigned Region where necessary to provide, secure, operate, or support the Service. This may include Account Data, authentication data, billing data, usage data, support communications, system logs, security records, monitoring data, email delivery data, payment-provider data, and data processed by third-party service providers.

Adal does not guarantee that all categories of data will remain exclusively within a selected Region unless expressly stated in a separate written agreement or specific Service documentation.

When you configure Servers, storage settings, Destinations, and Regions, you are responsible for selecting the configuration appropriate for your legal, security, and compliance requirements.

If a Destination is located outside the selected or assigned Region, webhook requests may be transmitted to that Destination in accordance with your configuration. Adal does not control the location, infrastructure, or data-processing practices of Destinations you configure.

Regional storage settings do not prevent data from being transmitted outside a Region where such transmission is required by your configuration, including delivery to Destinations, use of Adal CLI, API access, support requests, or other actions you initiate.

Sharing with Third Parties

Adal does not sell personal data, Account Data, or Webhook Content to third parties.

We may share data with third parties only where necessary to provide, operate, secure, support, or improve the Service, comply with legal obligations, process payments, or protect our rights, users, infrastructure, and third parties.

Service Providers

We may share data with trusted service providers that help us operate the Service. These providers may process data on our behalf and only for the purposes described in this Privacy Policy or in accordance with our instructions.

Such service providers may include:

  • hosting and infrastructure providers

  • database, storage, and backup providers

  • email delivery providers

  • payment and billing providers

  • authentication and security providers

  • monitoring, logging, and error-tracking providers

  • analytics providers, if used

  • customer support and communication tools

  • content delivery, DDoS protection, or network security providers

The categories of data shared depend on the provider and the purpose of processing. For example, a payment provider may process billing and payment-related data, while a hosting provider may process data stored or transmitted through the Service.

Payment Providers

If you purchase a paid Plan, subscription, or credits, payment and billing data may be processed by our payment provider.

Adal does not intentionally store full payment card numbers. Payment card details and other sensitive payment information are processed by the payment provider under its own terms and privacy policy.

Destinations Configured by You

When you configure a Destination, Adal forwards webhook requests to that Destination in accordance with your settings.

A Destination may be a third-party service, your own server, your application, your local environment, or another server you control. You are responsible for the Destination and for any processing of data that occurs after Adal delivers data to that Destination.

Adal does not control the privacy, security, infrastructure, or data-processing practices of Destinations you configure.

Third-Party Integrations

You may configure third-party services, applications, or systems to send webhook requests to your Adal Servers or to receive webhook requests from Adal.

Your use of such third-party integrations is governed by the terms and privacy policies of those third parties. Adal is not responsible for how third-party integrations collect, use, transmit, store, or protect data before sending it to Adal or after receiving it from Adal.

Legal Requirements and Protection

We may disclose data where we believe disclosure is necessary to:

  • comply with applicable laws, regulations, legal process, or lawful requests

  • respond to court orders, subpoenas, or government requests

  • enforce our Terms of Service or other agreements

  • investigate, prevent, or address fraud, abuse, security incidents, or technical issues

  • protect the rights, property, safety, infrastructure, or security of Adal, our users, or third parties

Where legally permitted and reasonably practicable, we may notify affected users of legal requests for their data.

Business Transfers

If Adal is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, data may be transferred as part of that transaction.

In such cases, we will take reasonable steps to ensure that personal data remains protected and is processed in accordance with this Privacy Policy or a policy that affords materially similar protections.

Aggregated or De-Identified Data

We may share aggregated, anonymized, or de-identified information that does not identify you or any individual.

Such information may be used for analytics, reporting, product improvement, service statistics, or public communication about the Service.

International Data Transfers

Adal may process and store data in countries other than the country where you are located.

Depending on your location, Server settings, selected or assigned Region, Service configuration, and the third-party service providers we use, your data may be transferred to, stored in, or processed in countries outside your country, the European Economic Area, the United Kingdom, or Switzerland.

Where regional storage is available and enabled, Adal seeks to store Webhook Content and related request data in the selected or assigned Region, as described in the “Regional Data Storage” section. However, certain categories of data may still be processed outside that Region where necessary to provide, operate, secure, support, or improve the Service.

This may include Account Data, authentication data, billing data, usage data, support communications, technical logs, monitoring data, email delivery data, payment-provider data, security records, and data processed by third-party service providers.

Where we transfer personal data internationally, we take steps designed to protect that data in accordance with applicable data protection laws. Those steps may include relying on:

  • adequacy decisions adopted by competent authorities

  • Standard Contractual Clauses or similar contractual safeguards

  • data processing agreements with service providers

  • technical and organizational security measures

  • transfer risk assessments, where required

  • other lawful transfer mechanisms available under applicable law

If you are located in the European Economic Area, the United Kingdom, or Switzerland, and your personal data is transferred to a country that has not been recognized as providing an adequate level of protection, we will use appropriate safeguards where required by applicable law.

International transfers may also occur when you configure a Destination outside your selected or assigned Region, when you use Adal CLI from another country or region, when you access the dashboard or API from another location, or when you instruct Adal to transmit data to a third-party service.

You are responsible for ensuring that your configuration of Servers, Destinations, CLI connections, Regions, and third-party integrations complies with the data-transfer requirements applicable to your use case.

Adal does not control the location, infrastructure, or data-processing practices of Destinations you configure.

Security

Adal implements reasonable technical and organizational measures designed to protect data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.

These measures may include:

  • encryption in transit using TLS

  • access controls for accounts, the dashboard, the API, and internal systems

  • authentication and authorization mechanisms

  • hashed password storage, where password-based authentication is used

  • token-based access for API, CLI, Servers, or other Service features

  • infrastructure monitoring and logging

  • security and abuse-prevention controls

  • backup and disaster-recovery procedures

  • restricted access to production systems

  • internal access based on operational need

  • separation of user accounts, Servers, and request data at the application level

  • regular review of security-relevant events and errors

Adal uses security measures appropriate to the nature of the Service and the data being processed. However, no method of transmission over the Internet, no method of electronic storage, and no online service can be guaranteed to be completely secure.

You are responsible for keeping your account credentials, API keys, Server URLs, CLI tokens, Destination credentials, and other access details secure. You should not share those credentials with unauthorized persons or expose them in public repositories, client-side code, logs, screenshots, or other public locations.

You are also responsible for configuring your Servers, storage settings, Regions, Destinations, and access controls in a manner appropriate for your security and compliance requirements.

If you believe that your account, Server URL, API key, token, Destination, or any other access detail has been compromised, you should rotate or revoke the affected credentials where possible and contact us promptly.

Adal may suspend, restrict, or disable access to the Service, an account, Server, token, Destination, or other feature where we reasonably believe it is necessary to protect the Service, our users, infrastructure, third parties, or data.

Cookies

Adal may use cookies and similar technologies to provide, secure, and improve the Service.

Cookies are small text files stored on your device by your browser. Similar technologies may include local storage, session storage, tokens, or other browser-based storage mechanisms.

Essential Cookies

We may use essential cookies and similar technologies that are necessary for the Service to function properly.

These may be used to:

  • keep you signed in

  • maintain your session

  • authenticate requests

  • protect against unauthorized access

  • remember security-related state

  • prevent abuse

  • support dashboard and API functionality

Essential cookies are required for the Service to operate and cannot be disabled through the Service without affecting core functionality.

Preference Cookies

Where applicable, we may use cookies or browser storage to remember your preferences, such as:

  • language preferences

  • theme or appearance settings

  • dashboard interface preferences

  • other non-sensitive settings

These technologies help provide a consistent user experience.

Analytics Cookies

Adal does not currently use advertising cookies.

If we use analytics cookies or similar analytics technologies, we will use them to understand how the Service is used, monitor performance, improve usability, and prioritize product improvements.

Where required by law, we will request your consent before using non-essential analytics cookies.

Advertising Cookies

Adal does not use cookies to sell personal data or Webhook Content.

Adal does not use Webhook Content for advertising purposes.

Adal does not use advertising cookies unless clearly disclosed and, where required by law, based on your consent.

Managing Cookies

You can control or delete cookies through your browser settings. Most browsers allow you to block cookies, delete existing cookies, or receive a warning before cookies are stored.

If you block or delete essential cookies, some parts of the Service may not work correctly, including login, dashboard access, session management, API access, or security features.

Your Rights

Depending on your location and applicable data protection laws, you may have certain rights in relation to your personal data.

These rights may include:

Right of Access

You may request confirmation of whether we process personal data about you and request access to that personal data.

Where applicable, you may also request information about the purposes of processing, categories of personal data processed, categories of recipients, retention periods, and other information required by applicable law.

Right to Rectification

You may request that we correct inaccurate or incomplete personal data about you.

You may also be able to update certain Account Data directly through the dashboard or account settings.

Right to Erasure

You may request that we delete personal data about you where applicable law gives you that right.

This right may be subject to limitations. For example, we may need to retain certain data for legal, tax, accounting, billing, security, fraud-prevention, dispute-resolution, backup, or compliance purposes.

Right to Restriction of Processing

You may request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of the data or assess an objection to processing.

Right to Data Portability

Where applicable, you may request a copy of personal data that you provided to us in a structured, commonly used, and machine-readable format.

Where technically feasible and required by law, you may also request that we transmit such data to another controller.

Right to Object

You may object to certain processing of your personal data where we rely on legitimate interests as the legal basis for processing.

You may also object to processing for direct marketing purposes, if such processing is used.

Right to Withdraw Consent

Where we process personal data based on your consent, you may withdraw that consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

Right to Lodge a Complaint

If you believe that we process your personal data in violation of applicable data protection laws, you may have the right to lodge a complaint with a competent data protection authority.

We encourage you to contact us first so that we can attempt to resolve your concern.

Requests Related to Webhook Content

Webhook Content may contain personal data relating to your customers, users, employees, or other third parties.

Where Adal processes Webhook Content on behalf of a User, the User is generally responsible for handling data subject requests relating to that Webhook Content.

If we receive a request from an individual relating to Webhook Content controlled by one of our Users, we may direct that individual to the relevant User or assist the User in responding to the request, where required by applicable law and technically feasible.

How to Exercise Your Rights

You may exercise your rights by contacting us at: [email protected]

We may need to verify your identity before responding to your request. We may also ask for additional information if necessary to locate the relevant data or process your request.

We will respond to requests within the time required by applicable law.

In some cases, we may decline or limit a request where permitted by law — for example, if the request is manifestly unfounded or excessive, if we cannot verify your identity, if we are required to retain the data, or if fulfilling the request would adversely affect the rights and freedoms of others.

Account Deletion and Data Export

You may request deletion of your Adal account or export of certain data associated with your account, where supported by the Service and required by applicable law.

Account Deletion

If you request account deletion, Adal schedules the account for deletion seven days after the request, subject to applicable legal, security, billing, backup, and operational requirements.

Account deletion may include deletion or deactivation of:

  • your Account Data

  • Servers created under your account

  • Destinations configured by you

  • API keys, CLI tokens, and other access credentials

  • stored webhook requests and request history

  • stored Webhook Content, where applicable

  • Service Configuration Data associated with your account

After account deletion, you may lose access to the dashboard, API, CLI connections, Servers, request history, stored payloads, delivery history, replay functionality, billing information, and other Service features.

Data That May Be Retained

Some data may be retained after account deletion where necessary or permitted by law.

This may include:

  • billing records

  • invoices

  • payment status information

  • tax and accounting records

  • security logs

  • abuse-prevention records

  • legal and compliance records

  • records necessary to resolve disputes or enforce our agreements

  • data stored in daily backups until the applicable seven-day backup retention period expires

We will not retain deleted account data longer than necessary for the purposes described in this Privacy Policy.

Server and Request Deletion

Where the Service provides deletion controls, you may delete Servers, Destinations, individual webhook requests, request history, or stored payloads without deleting your entire account.

Deleting a Server immediately disables its webhook URL and stops future processing of requests sent to that Server. It also starts deletion of the Server's Destinations, accepted Requests, stored Webhook Content, Request Metadata, Delivery Data, replay data, and related configuration from active systems. Deletion is normally completed promptly but may take several seconds when the Server has a large number of Requests. Previously accepted Requests are not retained until their scheduled retention dates after the Server is deleted.

The deleted Server's ingest URL remains permanently reserved and is not assigned to another user.

Deleting a webhook request or stored payload may remove it from active systems within a reasonable period, subject to the backup, logging, security, legal, and operational limitations described in this Privacy Policy.

Data Export

Where supported by the Service or required by applicable law, you may request an export of certain data associated with your account.

Exportable data may include:

  • Account Data

  • Service Configuration Data

  • Server settings

  • Destination settings

  • request history

  • Request Metadata

  • Delivery Data

  • stored Webhook Content, where available and permitted

  • billing or usage-related information

The scope and format of exported data may depend on the type of data, your Plan, technical feasibility, security requirements, and applicable law.

Webhook Content Controlled by Users

If Webhook Content contains personal data relating to your customers, users, employees, or other third parties, you are responsible for determining whether such data should be exported, deleted, retained, or otherwise processed.

Where Adal processes Webhook Content on your behalf, we may assist you with deletion or export requests where required by applicable law and technically feasible.

Requesting Deletion or Export

You may request account deletion or data export by using the available dashboard controls or API functionality, or by contacting us at: [email protected]

We may need to verify your identity before processing deletion or export requests. We may also need additional information to locate the relevant account, Server, request, or data.

We will process deletion and export requests within the time required by applicable law.

Children’s Privacy

Adal is not intended for use by children.

You must be at least 18 years of age, or the age of legal majority in your jurisdiction, to create an Adal account and use the Service.

We do not knowingly collect personal data directly from children. If we become aware that we have collected personal data directly from a child without appropriate authorization, we will take reasonable steps to delete that data.

Because Adal processes webhook requests on behalf of Users, Webhook Content may contain personal data submitted by third-party systems, applications, or services. Users are responsible for ensuring that any Webhook Content sent to Adal complies with applicable laws relating to children’s data and privacy.

If you believe that a child has provided personal data to Adal directly, or that Webhook Content processed through Adal contains children’s personal data in violation of applicable law, please contact us at: [email protected]

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the Service, legal requirements, technical infrastructure, data-processing practices, or other operational reasons.

When we update this Privacy Policy, we will revise the “Last updated” date at the top of the Policy.

If we make material changes that significantly affect your privacy rights or how we process personal data, we will take reasonable steps to notify you. Notice may be provided through the Service, a dashboard notification, email, or another appropriate method.

Unless otherwise stated, changes to this Privacy Policy become effective when posted.

Your continued use of the Service after the updated Privacy Policy becomes effective constitutes acknowledgment of the updated Policy.

If you do not agree with the updated Privacy Policy, you should stop using the Service and may request deletion of your account as described in this Policy.

Contact

If you have questions about this Privacy Policy, how Adal processes personal data, or how to exercise your privacy rights, contact us at: [email protected]

You may also contact us to request access, correction, deletion, restriction, export, or other actions relating to your personal data, where applicable under data protection laws.

If your request relates to Webhook Content, please include sufficient information to help us identify the relevant account, Server, request, or time period. For security reasons, we may ask you to verify your identity and authority before disclosing, deleting, exporting, or modifying any data.

If you use Adal on behalf of an organization, we may direct certain privacy or data-protection requests to the account owner, administrator, or other authorized representative of that organization.

For legal and privacy matters, please contact:

“ADAL CLOUD” LLP BIN: 260640039277 Republic of Kazakhstan [email protected]

Adal Cloud Adal Cloud

Reliable webhook delivery infrastructure.

Product

  • Blog
  • Documentation
  • How To
  • Pricing

Company

  • About
  • Status
  • Changelog
  • Contact

Legal

  • Security
  • Privacy Policy
  • Terms of Service
© 2026 “ADAL CLOUD” LLP. All rights reserved.