GDPR Compliance Policy
Last updated: November 8, 2025
1. Introduction
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. This policy outlines our commitment to GDPR compliance and how we protect your personal data.
2. The purpose of processing personal data
The purpose of processing personal data is mainly to provide products and services and includes information about site promotions, appointments, your identification and the services provided or requested.
In general, the collection of identification data (such as IP or geolocation) is done in order to provide an improved browsing experience and for statistics in order to improve the online presence of the site. This is done by collecting cookies or other specific technical methods and does not always allow the identification of the individual (associating a cookie with a person).
3. Legal Basis for Processing
We process personal data under the following legal bases:
- Consent: You have given clear consent for us to process your personal data for a specific purpose.
- Contract: The processing is necessary for a contract you have with us, or because we have asked you to take specific steps before entering into a contract.
- Legal obligation: The processing is necessary for us to comply with the law.
- Legitimate interests: The processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.
4. Your Rights Under GDPR
Under the GDPR, you have the following rights:
- Right to be informed: You have the right to be provided with clear, transparent and easily understandable information about how we use your personal data and your rights.
- Right of access: You have the right to obtain access to your personal data (if we're processing it), and certain other information (similar to that provided in this privacy policy).
- Right to rectification: You are entitled to have your personal data corrected if it's inaccurate or incomplete.
- Right to erasure: Also known as 'the right to be forgotten', this enables you to request the deletion or removal of your personal data where there's no compelling reason for us to keep using it.
- Right to restrict processing: You have the right to 'block' or suppress further use of your information in certain circumstances.
- Right to data portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
- Right to object: You have the right to object to certain types of processing, including direct marketing.
- Rights related to automated decision making and profiling: We do not use automated decision making or profiling.
5. How to Exercise Your Rights
To exercise any of your rights, please contact us using the details provided in the Contact Us section. We will respond to your request within one month, although we may extend this by a further two months if your request is particularly complex.
6. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact the DPO using the details set out below.
7. Data Breach Notification
In the event of a data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
8. International Data Transfers
We ensure that any transfer of personal data outside the European Economic Area (EEA) is protected by appropriate safeguards, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Binding corporate rules
9. Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes for which we process your personal data, and whether we can achieve those purposes through other means.
10. Complaints
You have the right to make a complaint at any time to the supervisory authority for data protection issues in your country of residence. We would, however, appreciate the chance to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance.
11. Contact Us
If you have any questions about this GDPR policy or our data protection practices, please contact us:
- Email: office@cloud-zones.com
- Phone: +40 773 957 078