Data processing addendum
Read this agreement carefully—it outlines important legal rights and remedies available to you.
Last revised: 5-7-2025
This Data Processing Addendum (“Addendum”) forms part of the Terms of Service and Privacy Policy between Cloudoora and the customer (“Customer,” “you,” or “your”) to reflect the parties’ agreement with respect to the processing of personal data in compliance with applicable data protection laws.
1. Definitions
For the purpose of this Addendum:
- Personal Data means any information relating to an identified or identifiable natural person.
- Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- Controller means the entity that determines the purposes and means of Processing.
- Processor means the entity that Processes Personal Data on behalf of the Controller.
- Sub-Processor means a third-party processor engaged by Cloudoora to assist in processing activities.
- Applicable Data Protection Laws means GDPR, CCPA, and any other relevant privacy regulations.
2. Scope and Application
This Addendum applies when Cloudoora Processes Personal Data on behalf of the Customer while providing services such as domain registration, hosting, or cloud infrastructure.
Cloudoora acts as a Data Processor, and the Customer acts as the Data Controller.
3. Roles and Responsibilities
Customer Responsibilities:
- Ensure that Personal Data is collected and processed in accordance with all applicable laws.
- Obtain necessary consents and provide required notices to data subjects.
Cloudoora Responsibilities:
- Process Personal Data only on documented instructions from the Customer.
- Maintain appropriate technical and organizational measures to protect Personal Data.
- Ensure personnel authorized to process data are subject to confidentiality obligations.
4. Purpose and Duration of Processing
Purpose: Data will be processed solely to deliver Cloudoora services (e.g., hosting, support, billing).
Duration: Personal Data will be retained for the term of the customer’s use of Cloudoora services unless required by law or agreement.
5. Sub-Processing
Cloudoora may engage Sub-Processors to fulfill its contractual obligations, including:
- Domain registries
- Payment gateways
- CDN or cloud infrastructure providers
Cloudoora ensures that Sub-Processors are bound by written agreements requiring compliance with data protection standards equivalent to this Addendum.
A current list of Sub-Processors can be provided upon request.
6. International Data Transfers
Cloudoora may transfer and process Personal Data outside of the Customer’s jurisdiction. When doing so:
- We ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent legal mechanisms.
- Transfers will only occur if necessary to provide services or as required by law.
7. Security Measures
Cloudoora implements industry-standard technical and organizational security measures including:
- Data encryption at rest and in transit
- Network and access controls
- Vulnerability monitoring and regular audits
Upon request, Cloudoora will provide further details of its security practices.
8. Data Subject Rights
Cloudoora will assist the Customer in fulfilling its obligations to respond to data subjects’ requests, including:
- Access, rectification, and deletion requests
- Objections to processing
- Requests for data portability
Such assistance will be limited to the extent that Cloudoora has access to the relevant data.
9. Data Breach Notification
Cloudoora will notify the Customer without undue delay upon becoming aware of a Personal Data Breach, including:
- A description of the nature and scope of the breach
- Mitigation steps taken or planned
- The contact point for further communication
10. Data Retention and Deletion
At the end of the service relationship:
- Cloudoora will delete or return all Personal Data unless retention is required by law.
- Deletion will be done in a secure and verifiable manner.
11. Audit and Compliance
- Cloudoora will make available all information necessary to demonstrate compliance with this Addendum.
- Allow for reasonable audits by the Customer or a mutually agreed third-party auditor, subject to confidentiality and security constraints.
12. Conflict and Precedence
In the event of any conflict between this Addendum and any other agreement, the terms of this Addendum shall prevail concerning data protection and privacy obligations.
13. Contact and Notices
Data Protection Officer
Email: privacy@cloudoora.com

