Data Processing Agreement

Version 1.2, August 2026

This agreement (art. 28 GDPR) applies between the customer (controller) and Cloudpliant (processor) as an annex to the Terms of Service, for all personal data processed in the service on the customer's behalf.

Subject and instructions

Cloudpliant processes the personal data the customer submits or connects (client and UBO names, birth dates, countries, register data, screening results) solely to provide compliance screening, reporting and monitoring, and only on the customer's documented instructions as expressed through the product and its settings.

Confidentiality and security

Personnel authorised to process the data are bound to confidentiality. Cloudpliant implements appropriate technical and organisational measures, including EU-only storage, encryption in transit and at rest, encrypted OAuth token storage (AES-256-GCM), access control and audit logging. Details: see the Security page.

Sub-processors

The customer authorises the sub-processors listed below. Cloudpliant announces changes in advance; the customer may object on reasonable grounds.

  • Hetzner Online GmbH (Germany, EU): application and database hosting, and document storage (ISO 27001-certified data centres)
  • OpenSanctions Datenbanken GmbH (Germany, EU): sanctions and PEP list matching
  • Brevo (France, EU): transactional e-mail (verification, alerts, invitations)
  • Didit Identity Spain, S.L. (Spain, EU; processing in an EU region): digital identity verification through an ID document scan with a facial liveness check. The biometric comparison happens at this sub-processor; Cloudpliant stores only the outcome and the confirmed attributes, never the images. Engaged only if your organisation uses digital identity verification.
  • CM.com (Netherlands, EU): identity confirmation through the client's own bank or itsme (iDIN): name, date of birth and address as confirmed by the bank. Engaged only if your organisation uses digital identity verification.
  • Authologic sp. z o.o. (Poland, EU): identity-verification broker (bank, European eID or ID document). Engaged only if your organisation uses digital identity verification.

Assistance, breaches, audits

Cloudpliant assists the customer with data-subject requests, DPIAs and supervisory enquiries, and notifies the customer of a personal data breach without undue delay after becoming aware of it. The customer may audit compliance once per year at its own cost, upon reasonable notice.

End of the agreement

Upon termination Cloudpliant deletes or returns all personal data, except where retention is configured to satisfy the customer's statutory (Wwft) retention duty, after which deletion is automatic.