Privacy and data processing.
Handling data responsibly is our whole reason for being. This page explains how Secloud processes personal data on your behalf as your processor under GDPR, the security we apply, who we work with and how transfers are handled.
1. Roles and definitions
Under this agreement you are the controller and Secloud is the processor. "Agreement Personal Data" means any personal data, including special categories, processed in connection with the services. "DP Laws" means the applicable data protection laws, including the GDPR (EU 2016/679), the ePrivacy Directive and any national laws that supplement or replace them. The terms controller, processor, personal data, processing and data subject carry the meanings given to them under GDPR.
2. Data protection obligations
Secloud processes Agreement Personal Data on your behalf in order to provide the services. Both parties commit to observe the requirements of DP Laws and to give each other reasonable assistance, information and cooperation to meet their respective obligations. Secloud gathers personal data from you to deliver the services, manage the relationship (including invoicing and support) and, using de-identified data only, to improve its products. Secloud does not externally publish or disclose anything derived from your data that would identify a data subject or your organisation without your consent.
3. Controller obligations
As controller, you confirm that all personal data collected or provided for processing was obtained in compliance with DP Laws, and that all instructions you give in respect of the data are lawful.
4. Processor obligations
4.1 Acting on your instructions
Secloud processes Agreement Personal Data only in line with your instructions as set out in this agreement, unless required by law to act otherwise, in which case we will tell you where we are legally permitted to. If we believe an instruction would breach DP Laws, we may decline to carry it out without being in breach of this agreement.
4.2 Confidentiality of personnel
Secloud ensures that any personnel, agents or contractors who process the data are bound by appropriate confidentiality obligations.
5. Security measures
Secloud implements technical and organisational measures appropriate to the risk, including, as relevant:
- Pseudonymisation and encryption of personal data.
- Measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems.
- The ability to restore access to the data in a timely way after a physical or technical incident.
- A process for regularly testing, assessing and evaluating the effectiveness of these measures.
6. Breaches and assistance
Taking into account the nature of the processing and the information available to us, Secloud provides reasonable assistance with your obligations under DP Laws, including responding to data subject requests, carrying out data protection impact assessments, and returning or deleting data at the end of the term. Secloud notifies you without undue delay after becoming aware of a personal data breach, and provides the details you reasonably need to meet your notification obligations, including the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or recommended.
On written request, Secloud makes available the information reasonably necessary to demonstrate compliance and allows for audits, on at least five days' notice, no more than once per calendar year, during normal business hours and subject to confidentiality. In the event of a breach, an audit may be carried out on five business days' notice.
7. Sub-processors
You give Secloud general authorisation to engage sub-processors, provided each is bound by data protection obligations substantially the same as those in this agreement. Secloud remains fully liable for its sub-processors and will notify you of any intended addition or replacement so you have the opportunity to object. The current sub-processors are:
- DigitalOcean LLC — application and database hosting, Amsterdam, Netherlands.
- Cloudflare, Inc. — CDN, DDoS protection, DNS and edge compute, global network.
- LINK Mobility ASA — SMS delivery, EEA and non-EEA depending on destination.
- Laravel Forge — server provisioning and management, USA.
- Envoyer — zero-downtime deployments, USA.
- GitHub — source hosting and CI/CD, USA.
- Nightwatch — error monitoring and logging.
8. International transfers
Secloud may transfer Agreement Personal Data outside the EEA and the UK, including via authorised sub-processors, provided the transfer is made in compliance with DP Laws. Where required, this is done using the EU Standard Contractual Clauses or another approved transfer mechanism. As controller, you authorise Secloud to enter into the Standard Contractual Clauses on your behalf where necessary.
9. Term, deletion and survival
This agreement is in effect from 1 May 2023 and remains valid until the service agreement ends or the DPA is terminated or replaced. You may terminate it with immediate effect. Secloud may terminate on three months' written notice. On expiry, Secloud will, at your choice and within three months, delete or return all Agreement Personal Data and delete existing copies, except where legally required to retain them, in which case we keep them confidential and stop actively processing them.
Appendix: details of the processing
Subject matter and duration
Personal data is processed to provide the services, for the duration of the service agreement and this DPA.
Nature and purpose
Collection of personal data from you and your current and prospective employees or other relevant data subjects, for the purpose of providing the services.
Types of personal data
- Personal details such as title, name, email, address, employee ID and job position.
- Demographic details such as age, tenure, work status, place of work, organisational unit, work history and education.
- Technical information such as public IP address, time and date of access, browser activity and settings, device data and log-in ID data.
Categories of data subjects
Former, current and prospective employees of the controller, along with self-employed, contract, temporary and voluntary personnel, agents, representatives and independent contractors working for the controller.
Questions about how we handle data? Email or call +47 33 45 54 00.
See the security behind the platform
We are glad to share our security measures, sub-processor list and certifications, and to sign a data processing agreement that fits your organisation. Book a call to get started.