GDPR Compliance
How 25cent.cloud complies with GDPR and protects data privacy.
Overview
25cent.cloud is fully compliant with the General Data Protection Regulation (GDPR). This page explains how we respect your rights and protect your data.
Who We Are
- Data Controller: 25cent.cloud, Inc., San Francisco, CA
- Data Protection Officer: dpo@25cent.cloud
- Headquarters: San Francisco, California (EU representative upon request)
Legal Basis for Processing
We process personal data under these legal bases:
- Contract Performance: Account creation, file storage/sharing
- Legitimate Interest: Security, fraud prevention, service improvement
- Legal Obligation: Legal requests from authorities
- Consent: Marketing communications (you can opt out)
Your Rights Under GDPR
Right to Access
You can request a copy of your personal data. Email: privacy@25cent.cloud
Right to Rectification
Correct inaccurate data. Update your profile anytime in Account Settings.
Right to Erasure ("Right to Be Forgotten")
Request deletion of your data (subject to legal obligations). We delete within 30 days of account closure.
Right to Restrict Processing
Request we limit use of your data. Email: privacy@25cent.cloud
Right to Data Portability
Get your data in a standard format. Export from Account Settings or email us.
Right to Object
Object to processing (marketing, profiling, etc.). We honor objections.
Rights Related to Automated Decision-Making
We don't make decisions based solely on automated processing.
Data Protection Principles
Lawfulness, Fairness, Transparency
We process data lawfully and transparently. See Privacy Policy for details.
Purpose Limitation
We use data only for stated purposes (service delivery, security, improvement).
Data Minimization
We collect minimum necessary data. Don't require excessive permissions.
Accuracy
We keep data accurate. You can correct information anytime.
Storage Limitation
We don't keep data longer than necessary. Files auto-delete on expiration. Account data deleted 30 days after account closure.
Integrity and Confidentiality
AES-256 encryption, access controls, regular security audits protect your data.
Data Transfers
Data is stored in the United States on AWS servers. We use Standard Contractual Clauses to ensure adequate protection.
Sub-processors
We use these data processors:
- AWS: Cloud infrastructure
- Stripe: Payment processing
- SendGrid: Email delivery
All have Data Processing Agreements meeting GDPR requirements.
Data Breach Notification
If a breach affects your data, we'll notify you within 72 hours (or sooner if required) with:
- Nature of the breach
- Data affected
- Likely impact
- Measures taken
- Contact information for details
Data Subject Requests
How to Submit
Email: privacy@25cent.cloud
Include: your name, account email, request type, and details.
Timeline
We respond within 30 days (extendable to 60 days for complex requests).
Verification
We may request ID verification to confirm your identity.
Privacy by Design
Data protection is built into our systems:
- Encryption by default
- Minimal data collection
- Automatic expiration
- Access controls and logging
- Security audits regularly
Children's Data
GDPR offers special protection for children under 16. 25cent.cloud is not intended for children. If you're under 16, get parental consent or don't use the Service.
Cookies & Tracking
See Cookie Policy for details. We use minimal cookies (session, analytics) and you can control them.
Marketing Communications
We only send marketing if you opt in. Unsubscribe anytime with the link in emails.
Profiling & Automated Decisions
We don't profile users for targeting or make decisions based solely on automated processing.
GDPR Compliance Training
Our team receives regular GDPR training to ensure compliance.
Data Protection Officer
Our DPO oversees data protection compliance. Contact: dpo@25cent.cloud
Regulatory Requests
We comply with lawful government requests but:
- Only respond to valid legal process (warrant, court order)
- Notify users when possible
- Request narrowest scope possible
- Maintain detailed records
Changes to This Policy
We update this policy as needed. Material changes notified via email.
EU Representative
For EU users, designate an EU representative upon request.
Contact
- Privacy Questions: privacy@25cent.cloud
- Data Subject Requests: privacy@25cent.cloud
- Data Protection Officer: dpo@25cent.cloud
- General Contact: Contact Us