Data Processing Agreement

Version 0.1, July 2026

This agreement (art. 28 GDPR) applies between the customer (controller) and Cloudpliant (processor) as an annex to the Terms of Service, for all personal data processed in the service on the customer's behalf.

Subject and instructions

Cloudpliant processes the personal data the customer submits or connects (client and UBO names, birth dates, countries, register data, screening results) solely to provide compliance screening, reporting and monitoring, and only on the customer's documented instructions as expressed through the product and its settings.

Confidentiality and security

Personnel authorised to process the data are bound to confidentiality. Cloudpliant implements appropriate technical and organisational measures, including EU-only storage, encryption in transit and at rest, encrypted OAuth token storage (AES-256-GCM), access control and audit logging. Details: see the Security page.

Sub-processors

The customer authorises the sub-processors listed below. Cloudpliant announces changes in advance; the customer may object on reasonable grounds.

  • Google Cloud (EU region): application hosting and storage
  • PostgreSQL database hosting (EU region)
  • OpenSanctions Datenbanken GmbH (Germany): sanctions and PEP matching
  • Brevo (France): transactional e-mail

Assistance, breaches, audits

Cloudpliant assists the customer with data-subject requests, DPIAs and supervisory enquiries, and notifies the customer of a personal data breach without undue delay after becoming aware of it. The customer may audit compliance once per year at its own cost, upon reasonable notice.

End of the agreement

Upon termination Cloudpliant deletes or returns all personal data, except where retention is configured to satisfy the customer's statutory (Wwft) retention duty, after which deletion is automatic.