Privacy Policy

Version 1.2, August 2026

Cloudpliant provides compliance-screening software for organisations subject to the Dutch anti-money-laundering act (Wwft). This policy explains what personal data we process, in which role, and what your rights are.

Two roles

For visitors of this website and holders of a Cloudpliant account we are the data controller: we decide how account data (name, e-mail, login data) is used.

For the persons our customers screen (their clients and beneficial owners) we are a data processor: the customer, the Wwft-obliged institution, is the controller and instructs us via the product. Their legal basis is typically the legal obligation of art. 6(1)(c) GDPR arising from the Wwft. Requests about this data should be addressed to the institution that screened you; we assist them under our data processing agreement.

What we process

  • Account data: name, e-mail address, password hash, OAuth identities you connect (Google, Exact Online, HubSpot).
  • Screening data (as processor): names, dates of birth, country, business-register (KvK) data, insolvency-register results, curatele and bewind register results (the measure, its dates and the appointed representative, never the ground it was imposed on), sanctions/PEP match results and the reports built from them.
  • Identity-verification data (as processor, only if your organisation uses digital identity verification): the attributes the chosen method confirms, such as name, date of birth, address or document number, and the verification result. Never the document images or biometric data itself.
  • Technical data: server logs (IP address, timestamp) kept briefly for security and abuse prevention, and visit statistics for this website (pages read, buttons clicked, browser and country), measured on our own servers without a cookie or a profile.

Where and how long

All production data is stored within the European Union. Account data is kept while your account exists. Screening data is retained according to the retention period configured by the responsible institution (default 5 years, the Wwft minimum in art. 33) and deleted automatically afterwards.

Sub-processors

  • Hetzner Online GmbH (Germany, EU): application and database hosting, and document storage (ISO 27001-certified data centres)
  • OpenSanctions Datenbanken GmbH (Germany, EU): sanctions and PEP list matching
  • Brevo (France, EU): transactional e-mail (verification, alerts, invitations)
  • Didit Identity Spain, S.L. (Spain, EU; processing in an EU region): digital identity verification through an ID document scan with a facial liveness check. The biometric comparison happens at this sub-processor; Cloudpliant stores only the outcome and the confirmed attributes, never the images. Engaged only if your organisation uses digital identity verification.
  • CM.com (Netherlands, EU): identity confirmation through the client's own bank or itsme (iDIN): name, date of birth and address as confirmed by the bank. Engaged only if your organisation uses digital identity verification.
  • Authologic sp. z o.o. (Poland, EU): identity-verification broker (bank, European eID or ID document). Engaged only if your organisation uses digital identity verification.

Cookies

The application places one strictly necessary cookie, the login session, plus a few small interface preferences your browser remembers. The marketing site places nothing on your device at all, and our visit statistics run on our own servers without cookies, which is why you see no cookie banner. The cookie statement has the details.

Your rights

You can access, correct or delete your account data at any time via Settings or by contacting privacy@cloudpliant.com. Note that transparency rights of screened persons can be restricted where the Wwft prohibits tipping off (art. 23 GDPR). You can lodge a complaint with the Autoriteit Persoonsgegevens.