CloudBaseIndia is committed to GDPR compliance for our EU/UK customers and their end users.
1. Our Role
For your account data, CloudBaseIndia is the Data Controller. For data you store on our servers, CloudBaseIndia is the Data Processor and you are the Data Controller.
2. Lawful Bases
We process personal data under: contractual necessity (service delivery), legitimate interest (security, fraud prevention), legal obligation (tax, KYC), and consent (marketing emails).
3. Your Rights (GDPR Arts. 15-22)
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
4. Security Measures
TLS 1.3 in transit, AES-256 at rest, MFA for staff, ISO 27001 certified, annual SOC 2 Type II audits, 24/7 SOC, breach notification within 72 hours.
5. Sub-Processors
We use vetted sub-processors including Stripe (payments, IE), Cloudflare (CDN, US/EU), SendGrid (transactional email, US), and our datacenter partners. Full list available on request.
6. International Transfers
Transfers outside the EEA rely on Standard Contractual Clauses (2021) and Transfer Impact Assessments.
7. Data Processing Agreement (DPA)
Our DPA is available to all customers — email dpa@cloudbaseindia.com to receive a counter-signed copy.
8. Data Protection Officer
Contact our DPO at dpo@cloudbaseindia.com. EU representative on request.