Data Processing Agreement
Version 0.1, July 2026
This agreement (art. 28 GDPR) applies between the customer (controller) and Cloudpliant (processor) as an annex to the Terms of Service, for all personal data processed in the service on the customer's behalf.
Subject and instructions
Cloudpliant processes the personal data the customer submits or connects (client and UBO names, birth dates, countries, register data, screening results) solely to provide compliance screening, reporting and monitoring, and only on the customer's documented instructions as expressed through the product and its settings.
Confidentiality and security
Personnel authorised to process the data are bound to confidentiality. Cloudpliant implements appropriate technical and organisational measures, including EU-only storage, encryption in transit and at rest, encrypted OAuth token storage (AES-256-GCM), access control and audit logging. Details: see the Security page.
Sub-processors
The customer authorises the sub-processors listed below. Cloudpliant announces changes in advance; the customer may object on reasonable grounds.
- Google Cloud (EU region): application hosting and storage
- PostgreSQL database hosting (EU region)
- OpenSanctions Datenbanken GmbH (Germany): sanctions and PEP matching
- Brevo (France): transactional e-mail
Assistance, breaches, audits
Cloudpliant assists the customer with data-subject requests, DPIAs and supervisory enquiries, and notifies the customer of a personal data breach without undue delay after becoming aware of it. The customer may audit compliance once per year at its own cost, upon reasonable notice.
End of the agreement
Upon termination Cloudpliant deletes or returns all personal data, except where retention is configured to satisfy the customer's statutory (Wwft) retention duty, after which deletion is automatic.