CloudWrkz

Privacy Policy

Last updated: December 5, 2025

Compliant with GDPR (EU) and BDSG (Germany)

At CloudWrkz, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our services, website, and applications (collectively, the "Service"). This policy is designed to comply with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the German Federal Data Protection Act (Bundesdatenschutzgesetz - BDSG).

By using our Service, you consent to the data practices described in this Privacy Policy. If you do not agree with the practices described in this policy, please do not use our Service.

1. Data Controller

The data controller responsible for processing your personal data is:

CloudWrkz

Address: [Your Company Address, Germany]

Email: privacy@cloudwrkz.com

Data Protection Officer: dpo@cloudwrkz.com

2. Types of Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Data You Provide to Us

  • Account Information: Name, email address, password (hashed), and any other information you provide when creating an account
  • Profile Information: Additional information you choose to provide in your user profile
  • Communication Data: Information you provide when contacting us, including support requests, feedback, or inquiries
  • Payment Information: Billing address, payment method details (processed securely through third-party payment processors)

2.2 Data Collected Automatically

  • Usage Data: Information about how you access and use our Service, including pages visited, time spent, and features used
  • Device Information: IP address, browser type and version, device type, operating system, and unique device identifiers
  • Log Data: Server logs, including access times, error logs, and system events
  • Location Data: General location information derived from your IP address (country/region level)

2.3 Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Service and store certain information. For detailed information about our use of cookies, please see Section 9 below.

3. Legal Basis and Purpose of Processing

We process your personal data based on the following legal bases under GDPR Article 6:

3.1 Consent (Article 6(1)(a) GDPR)

We process your personal data when you have given clear consent for specific purposes, such as:

  • Marketing communications and newsletters
  • Non-essential cookies and tracking technologies
  • Optional profile information

You have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

3.2 Contract Performance (Article 6(1)(b) GDPR)

We process your personal data to perform our contract with you, including:

  • Creating and managing your account
  • Providing and maintaining our Service
  • Processing payments and transactions
  • Providing customer support

3.3 Legal Obligation (Article 6(1)(c) GDPR)

We process your personal data to comply with legal obligations, such as:

  • Tax and accounting requirements
  • Data retention obligations
  • Compliance with court orders or legal requests

3.4 Legitimate Interests (Article 6(1)(f) GDPR)

We process your personal data based on our legitimate interests, including:

  • Improving and optimizing our Service
  • Preventing fraud and ensuring security
  • Analyzing usage patterns and trends
  • Business administration and operations

We always balance our legitimate interests against your rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 7.5).

4. Data Sharing and Disclosure

We may share your personal data with the following categories of recipients:

4.1 Service Providers

We engage third-party service providers to perform functions on our behalf, such as:

  • Cloud hosting and infrastructure providers
  • Payment processing services
  • Email service providers
  • Analytics and monitoring services
  • Customer support platforms

These service providers are contractually bound to process your data only for specified purposes and in accordance with our instructions and applicable data protection laws.

4.2 Legal Requirements

We may disclose your personal data if required by law or in response to valid requests by public authorities, including:

  • Court orders or subpoenas
  • Government investigations
  • Regulatory compliance requirements

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections.

5. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs): Approved by the European Commission
  • Adequacy Decisions: Transfers to countries with adequate data protection laws
  • Binding Corporate Rules: For transfers within corporate groups

You have the right to obtain a copy of the safeguards we use for international transfers by contacting us at the address provided in Section 1.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention periods are as follows:

  • Account Data: Retained for the duration of your account and for 3 years after account deletion for legal and accounting purposes
  • Transaction Data: Retained for 7 years as required by German tax and commercial law
  • Marketing Data: Retained until you withdraw consent or unsubscribe
  • Log Data: Retained for 12 months for security and troubleshooting purposes
  • Support Communications: Retained for 3 years after the resolution of your inquiry

After the retention period expires, we will securely delete or anonymize your personal data in accordance with applicable laws.

7. Your Rights Under GDPR

As a data subject, you have the following rights regarding your personal data:

7.1 Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether we process your personal data and, if so, to access that data and receive a copy of it, along with information about the processing.

7.2 Right to Rectification (Article 16 GDPR)

You have the right to request correction of inaccurate or incomplete personal data.

7.3 Right to Erasure ("Right to be Forgotten") (Article 17 GDPR)

You have the right to request deletion of your personal data when:

  • The data is no longer necessary for the original purpose
  • You withdraw consent and there is no other legal basis
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

7.4 Right to Restrict Processing (Article 18 GDPR)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or object to processing.

7.5 Right to Object (Article 21 GDPR)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

7.6 Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

7.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.

7.8 Exercising Your Rights

To exercise any of these rights, please contact us at:

Email: privacy@cloudwrkz.com

Subject Line: "GDPR Data Subject Request"

We will respond to your request within one month (or two months for complex requests) in accordance with GDPR requirements. We may request verification of your identity before processing your request.

8. Automated Decision-Making and Profiling

We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, unless:

  • It is necessary for entering into or performing a contract
  • It is authorized by EU or Member State law
  • You have given explicit consent

If we implement automated decision-making in the future, we will inform you and provide you with the right to human intervention, to express your point of view, and to contest the decision.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and store information about your preferences and activity on our Service.

9.1 Types of Cookies We Use

  • Essential Cookies: Required for the Service to function properly (e.g., authentication, security)
  • Functional Cookies: Enhance functionality and personalization (e.g., language preferences)
  • Analytics Cookies: Help us understand how visitors use our Service
  • Marketing Cookies: Used to deliver relevant advertisements (only with your consent)

9.2 Managing Cookies

You can control and manage cookies through your browser settings. However, disabling certain cookies may affect the functionality of our Service. You can also manage your cookie preferences through our cookie consent banner.

For more information about our use of cookies, please see our Cookie Policy (if applicable) or contact us at privacy@cloudwrkz.com.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Regular backups and disaster recovery procedures
  • Secure coding practices and vulnerability management

Despite our efforts, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.

11. Children's Privacy

Our Service is not intended for individuals under the age of 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal data from children without parental consent.

If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information. If you believe we have collected information from a child, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated policy on this page with a new "Last updated" date
  • Sending an email notification to registered users (for significant changes)
  • Displaying a prominent notice on our Service

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.

13. Right to Lodge a Complaint

If you believe that our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

In Germany, the relevant supervisory authority is:

Die Bundesbeauftragte für den Datenschutz und die Informationsfreiheit

Website: www.bfdi.bund.de

Email: poststelle@bfdi.bund.de

However, we encourage you to contact us first at privacy@cloudwrkz.com so we can address your concerns directly.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Data Controller: CloudWrkz

Email: privacy@cloudwrkz.com

Data Protection Officer: dpo@cloudwrkz.com

Address: [Your Company Address, Germany]

By using CloudWrkz, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal data as described herein, in accordance with GDPR and German data protection laws.