Our Commitment to GDPR
CloudZen recognizes the importance of privacy and data protection in today's digital environment.
We are committed to:
- Processing personal data lawfully, fairly, and transparently
- Collecting personal data only for specified and legitimate purposes
- Limiting personal data collection to what is necessary
- Maintaining accurate and up-to-date information
- Retaining personal data only as long as necessary
- Implementing appropriate technical and organizational safeguards
- Respecting the rights of data subjects
- Maintaining accountability for our processing activities
Privacy and security considerations are incorporated into our business processes, technology solutions, and service delivery practices.
Our Role Under GDPR
Depending on the nature of the processing activity, CloudZen may act as either a:
Data Controller
CloudZen acts as a Data Controller when we determine the purposes and means of processing personal data, including:
- Website visitor information
- Marketing communications
- Event registrations
- Recruitment activities
- Business development activities
- Customer relationship management
Data Processor
CloudZen acts as a Data Processor when we process personal data on behalf of our customers while delivering services such as:
- Product Lifecycle Management (PLM)
- Data Engineering
- Artificial Intelligence and Machine Learning solutions
- AI Advisory services
- Platform Engineering
- Cloud Transformation
- Enterprise Applications
- ERP Integrations
- Digital Product Passport (DPP) solutions
- Managed Services
- Digital Transformation initiatives
When acting as a Data Processor, CloudZen processes personal data only in accordance with documented customer instructions and applicable contractual agreements.
Lawful Basis for Processing
CloudZen processes personal data only where a lawful basis exists under Article 6 GDPR.
Depending on the circumstances, processing may be based on:
Contractual Necessity
Where processing is necessary to perform a contract or take steps before entering into a contract.
Examples include:
- Providing requested services
- Responding to business enquiries
- Managing customer relationships
Legitimate Interests
Where processing is necessary for legitimate business purposes and such interests do not override the rights and freedoms of individuals.
Examples include:
- Website security
- Fraud prevention
- Business development
- Service improvement
- Analytics and reporting
Consent
Where consent is required by law.
Examples include:
- Marketing communications
- Newsletter subscriptions
- Certain categories of cookies
Individuals may withdraw consent at any time.
Legal Obligations
Where processing is necessary to comply with legal or regulatory requirements.
Examples include:
- Tax obligations
- Financial reporting
- Employment law requirements
- Regulatory compliance
Data Subject Rights
CloudZen respects the rights granted to individuals under GDPR.
Subject to applicable law, individuals may exercise the following rights:
Right of Access
Request confirmation of whether personal data is being processed and obtain a copy of that data.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of personal data under certain circumstances.
Right to Restrict Processing
Request limitation of processing activities under specific conditions.
Right to Data Portability
Receive personal data in a structured, commonly used, and machine-readable format.
Right to Object
Object to processing based on legitimate interests or direct marketing activities.
Right to Withdraw Consent
Withdraw previously granted consent at any time.
Right to Lodge a Complaint
Submit a complaint to a competent data protection authority.
Data Security
CloudZen maintains technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction.
Security measures may include:
- Encryption in transit using TLS
- Encryption at rest where appropriate
- Multi-factor authentication
- Role-based access controls
- Security monitoring and logging
- Vulnerability management
- Patch management procedures
- Secure development practices
- Employee confidentiality obligations
- Security awareness training
- Incident response procedures
Security controls are reviewed and updated periodically based on business requirements, risk assessments, and evolving threats.
International Data Transfers
CloudZen may transfer personal data outside the European Economic Area (EEA) where necessary to support business operations, service delivery, customer engagements, or technology services.
Where international transfers occur, CloudZen implements appropriate safeguards, including:
- European Commission Standard Contractual Clauses (SCCs)
- UK International Data Transfer Addendum where applicable
- Transfer Impact Assessments (TIAs)
- Additional technical and organizational measures
These safeguards are designed to ensure an adequate level of protection for personal data transferred internationally.
Data Retention
CloudZen retains personal data only for as long as necessary to:
- Fulfill the purpose for which it was collected
- Meet contractual obligations
- Comply with legal requirements
- Resolve disputes
- Enforce agreements
- Maintain security and business continuity
When retention periods expire, personal data is securely deleted, anonymized, or otherwise disposed of in accordance with applicable laws and internal policies.
Subprocessors and Service Providers
CloudZen works with carefully selected service providers and technology partners that support our business operations.
These providers may include services related to:
- Cloud infrastructure
- Website hosting
- Customer relationship management (CRM)
- Marketing automation
- Analytics
- Customer communications
- Recruitment systems
- Business operations
CloudZen uses Zoho services, including Zoho CRM, Zoho Campaigns, Zoho Marketing Automation, Zoho Forms, Zoho SalesIQ, Zoho Analytics, Zoho Desk, and related services to support customer engagement and business operations.
Where third parties process personal data on our behalf, appropriate contractual safeguards and data processing agreements are implemented.
Privacy by Design and Default
CloudZen applies privacy-by-design and privacy-by-default principles where appropriate.
This includes:
- Limiting data collection to what is necessary
- Restricting access to authorized personnel
- Applying security controls throughout the data lifecycle
- Considering privacy risks during project planning and implementation
- Supporting secure and responsible data handling practices
Data Breach Management
CloudZen maintains procedures for identifying, investigating, managing, and responding to security incidents and personal data breaches.
Where required by applicable law, CloudZen will:
- Notify relevant supervisory authorities
- Inform affected individuals when necessary
- Maintain records of incidents and corrective actions
Exercising Your Rights
To submit a GDPR-related request, please contact:
privacy@cloudzeninnovations.com
Subject Line:
GDPR Data Subject Request
We may request additional information to verify your identity before processing your request.
CloudZen will respond within the timeframes required by applicable data protection laws, typically within one month of receiving a valid request.
Contact Us
If you have questions about GDPR, privacy, or data protection matters, please contact:
CloudZen Innovations GmbH
Hennebergerstrasse 35
90475 Nuremberg
Germany
Email: privacy@cloudzeninnovations.com
Website: https://www.cloudzeninnovations.com