This document describes intended controls and customer expectations so the product can be reviewed coherently. RENANT LIMITED must obtain appropriate legal, tax, regulatory, and provider-contract review before adopting it with an effective date.
Purpose and status of this draft
This draft is prepared for product, security, and legal review by RENANT LIMITED. It describes intended practices for the Renant website, buyer guidance, customer and partner workspaces, infrastructure orchestration, support, and a possible IPv4 leasing service.
Features described elsewhere on the website may still be planning demonstrations. This document does not state that payment processing, provider APIs, automated provisioning, IP leasing, or monitoring is operational.
Who would control the data and what is covered
RENANT LIMITED would determine the purposes and means of the personal data processing described here unless a transaction or separate agreement identifies another party as controller or data user. An upstream infrastructure provider may independently control data it must process for its own account, compliance, network security, or billing obligations.
The intended scope includes visitors, people making inquiries, account users, customer and reseller personnel, affiliates, infrastructure suppliers, IPv4 lessors and lessees, authorized contacts, and people whose details appear in support or abuse reports.
This draft does not cover an upstream provider's independent website or account. Its own notice and contract would apply to processing it controls.
Categories of personal data
- Identity and account
- A sign-in identifier, email address, optional display name, organization, membership, role, and account-security events.
- Inquiry and support
- Name, business contact details, chosen request route, project description, affected service, correspondence, and resolution history.
- Commerce
- Quote, order, invoice, settlement currency, tax and billing details, and payment-provider references. Payment-card data should remain with an approved payment provider.
- Service and technical
- Requested configuration, region, service identifiers, IP assignments, lifecycle actions, usage summaries, operational events, and support diagnostics.
- Supplier and IPv4 diligence
- Legal-entity details, authority evidence, authorized representatives, prefix and ASN records, LOA details, reputation observations, and abuse contacts.
- Website and security
- IP address, device and browser information, timestamps, request and error logs, security signals, and local preferences such as theme, currency display, or an unsaved estimate.
Production forms should identify required and optional fields at the point of collection. RENANT LIMITED should not request identity documents, credentials, private keys, or sensitive content through a general contact form.
How data may be obtained
- Directly from a visitor, customer, partner, supplier, or authorized representative.
- From the identity service used to complete a sign-in.
- From an upstream provider when synchronizing an authorized account, service, price, capacity result, incident, invoice, or lifecycle operation.
- From public or authorized Internet-number sources when validating prefix authority, routing state, RPKI status, RDAP registration, or abuse reputation.
- From security, support, payment, monitoring, and communications suppliers used for an implemented service.
Public availability does not remove the need to use information fairly, accurately, proportionately, and for a defined purpose.
Why data may be used
- Respond to an inquiry and provide a requested comparison or migration discussion.
- Create and secure accounts, verify organization membership, and enforce role-based access.
- Prepare quotes, verify upstream availability, form and administer orders, reconcile provider costs, and maintain billing records.
- Provision, operate, troubleshoot, suspend, migrate, or delete an authorized service.
- Verify IPv4 authority, prepare a draft LOA, coordinate routing, observe reputation and routing changes, and handle abuse reports.
- Protect customers, providers, networks, and RENANT LIMITED from fraud, unauthorized access, malicious activity, and contractual misuse.
- Meet recordkeeping, tax, accounting, regulatory, dispute, and lawful-request obligations.
- Improve navigation and recommendation rules using proportionate and, where practical, aggregated information.
The applicable legal basis may differ by person and jurisdiction. Before launch, each production collection must be mapped to the basis relied upon—such as steps requested before a contract, performance of a contract, consent where required, legitimate interests after balancing, or compliance with a legal obligation.
Recommendations and automated processing
The current server finder uses answers supplied by the visitor and deterministic rules to display planning examples. It does not place an order, determine credit, create infrastructure, or make a legally binding decision.
If fraud, eligibility, identity, or abuse tooling is introduced, RENANT LIMITED should document the signals used, provide appropriate human review and challenge routes, and issue any additional notice required before relying on a decision with significant effect.
Processors, upstream providers, and disclosure
Data should be disclosed only to the extent needed for the stated purpose. Possible recipients include:
- The selected upstream infrastructure, reseller-channel, network, or IP announcement provider.
- Identity, hosting, storage, support, communications, monitoring, security, document-signing, and payment suppliers actually configured for the service.
- A customer's authorized reseller or administrator where account ownership and permissions require it.
- Professional advisers, auditors, insurers, banks, and prospective transaction parties subject to appropriate duties.
- Authorities or other parties where disclosure is legally required or reasonably necessary to protect rights, safety, services, or networks.
Provider names and roles should be disclosed before they receive customer data where required. Contracts and proportionate diligence should address confidentiality, security, deletion, incident handling, and use of subprocessors.
International processing and transfers
RENANT LIMITED is registered in Hong Kong and intends to coordinate services supplied in multiple countries. Personal data may therefore be processed outside the person's country when an account, provider region, support path, or supplier requires it.
Before launch into a market, RENANT LIMITED should identify relevant transfer restrictions and implement the contract, assessment, consent, localization, or other safeguard required for the specific transfer. This draft does not claim that one transfer mechanism is valid everywhere.
Retention and deletion
Personal data should be kept only for the shortest period reasonably needed for the collection purpose, security, dispute handling, accounting, provider reconciliation, and applicable legal obligations. Different records require different schedules.
| Record group | Retention trigger | Draft approach |
|---|---|---|
| Unconverted inquiries | Request closure or withdrawal | Delete or minimize after the response and a defined follow-up window. |
| Accounts and services | Account or service closure | Keep operational records while active, then retain only what contracts, disputes, security, and law require. |
| Quotes and finance | Quote expiry or transaction completion | Apply documented commercial, tax, accounting, and chargeback schedules. |
| Security and audit events | Event creation | Use a risk-based period that permits investigation without indefinite collection. |
| IPv4 diligence and LOAs | Application rejection or lease end | Retain authority and abuse evidence for the active relationship and a justified post-return period. |
Production schedules, deletion jobs, backup treatment, legal holds, and processor deletion obligations must be approved before this notice becomes effective. Data under a justified legal hold may be isolated from ordinary use until the hold ends.
Choices and privacy requests
Depending on applicable law, a person may be able to ask whether RENANT LIMITED holds their personal data and request access, correction, deletion, restriction, objection, portability, consent withdrawal, or review of certain automated outcomes. These rights are not identical in every jurisdiction and may be limited by identity verification, another person's rights, security, privilege, or retention duties.
Use the website contact directory to make a privacy request and clearly label it as such. RENANT LIMITED should verify the requester proportionately, record the request, respond within the legally applicable period, and explain any lawful refusal. A person may also have a right to complain to the authority applicable to them.
Browser-stored theme, currency, and planning preferences can generally be cleared through browser controls. Clearing them does not delete server records tied to an account or submitted request.
Security and incident handling
The intended controls include access limited by role, protected administrative routes, secret separation, encryption in transit, audit trails, idempotent operations, provider-access review, and secure deletion processes. Controls must be tested against the implemented system.
No Internet service can promise absolute security. If a personal-data incident occurs, RENANT LIMITED should contain it, preserve relevant evidence, assess risk, coordinate affected processors and providers, and notify people or authorities where required.
Children, changes, and company details
The intended business infrastructure services are not directed to children. Age eligibility and any required guardian process must be confirmed for each launch market rather than inferred from this draft.
Material changes should be described clearly and, where appropriate, notified before they apply. An archived copy and effective date should be retained for each adopted version.
RENANT LIMITED
3906, 39/F, THE CENTER, 99
QUEEN'S ROAD, CENTRAL
HONG KONG
Raise a policy question before relying on this draft.
Use the contact page and identify the policy and section involved. Do not submit passwords, private keys, payment-card data, identity documents, or confidential network credentials through a general inquiry form.
Open the contact directory