Security & Privacy

GDPR and Data Protection

Learn how Felicloud protects your data in compliance with the General Data Protection Regulation (GDPR) and European privacy laws.

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union regulation that protects the personal data and privacy of EU citizens. It applies to all companies that handle EU residents' data, regardless of where the company is located.

Felicloud is 100% GDPR Compliant

As a European company with servers exclusively in the EU, we're subject to and fully comply with GDPR and other European data protection laws.

Your Data Rights Under GDPR

Right to Access

You can request a copy of all personal data we hold about you.

Right to Rectification

You can correct inaccurate personal data we hold about you.

Right to Erasure

You can request deletion of your personal data ("right to be forgotten").

Right to Portability

You can export your data in a machine-readable format.

Right to Object

You can object to certain types of data processing.

Right to Restriction

You can request limited processing of your personal data.

How We Protect Your Data

  • EU-Only Data Storage: All servers are located in the European Union. Your data never leaves the EU.
  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Optional end-to-end encryption available.
  • Minimal Data Collection: We only collect data necessary to provide the service. We don't sell or share your data with third parties for advertising.
  • Access Controls: Strict internal policies limit who can access customer data.
  • Regular Audits: We conduct regular security audits and assessments.
  • Data Processing Agreements: We have DPAs with all subprocessors who handle your data.

Data We Collect

Account Information

  • • Email address (required for account)
  • • Password (stored encrypted)
  • • Account settings and preferences

Usage Data

  • • Storage usage statistics
  • • Login history and IP addresses
  • • Device information for connected apps

Your Files

  • • Files you upload to your storage
  • • File metadata (names, sizes, dates)
  • • Sharing settings for your files
Good to knowYour files are your property. We don't access, analyze, or use them except as needed to provide the service (e.g., generating thumbnails).

Exercising Your Rights

Here's how to exercise your GDPR rights:

Download Your Data

Go to Settings → Privacy → Download your data. You'll receive a file containing your personal information and all your stored files.

Delete Your Account

Go to Settings → Account → Delete account. This immediately and permanently deletes your account and all associated data.

Contact Our DPO

For any privacy-related requests, contact our Data Protection Officer at[email protected]

Data Retention

Retention Periods

Active account dataAs long as account is active
Deleted files (trash)30 days
Inactive free accounts12 months before deletion
After account deletionPermanently deleted immediately
Billing recordsAs required by law (usually 7 years)

Third-Party Services

We use limited third-party services, all GDPR-compliant:

  • Payment Processing: Stripe (PCI DSS compliant)
  • Email Delivery: EU-based email service
  • Analytics: Self-hosted Matomo (no data sharing)
Good to knowWe never sell your data. Third-party services only process data necessary for their specific function.

Contact Information

For privacy-related questions or requests:

We respond to GDPR requests within 30 days as required by law.

Still Need Help?

Our support team is available to assist you with any questions or issues you may have.