Introduction to GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It establishes strict requirements for how organizations collect, process, store, and protect personal data of individuals in the European Union. At Felicloud, GDPR compliance is not just a legal obligation—it's a fundamental part of our commitment to protecting your privacy and respecting your rights.
1. Legal Basis for Data Processing
Under GDPR, we must have a lawful basis for processing your personal data. We process your data under the following legal grounds:
Contractual Necessity:
Processing your data is necessary to perform our contract with you (providing cloud storage services)
Legitimate Interests:
We have legitimate interests in ensuring security, preventing fraud, and improving our services
Legal Obligation:
We process certain data to comply with legal and regulatory requirements (e.g., tax laws, anti-money laundering)
Consent:
For optional features like marketing communications, we obtain your explicit consent
2. Data Minimization Principles
GDPR requires that we collect only the minimum amount of personal data necessary. In accordance with this principle:
- We collect only essential information needed to provide our services
- We do not build advertising profiles from your files; analytics and advertising measurement cookies are only used with your consent
- We do not share your data with third parties for marketing purposes
- We automatically delete unnecessary data when it is no longer needed
Our philosophy is simple: less data collected means less risk to your privacy.
3. Your GDPR Rights Explained
GDPR grants you comprehensive rights over your personal data. Here's what each right means in practice:
Right of Access (Article 15)
You can request a complete copy of all personal data we hold about you, including information about how we use it, who we share it with, and how long we keep it. We will provide this information in a clear, structured format within 30 days.
Right to Rectification (Article 16)
If any of your personal data is inaccurate or incomplete, you have the right to have it corrected. You can update most information directly in your account settings, or contact us for assistance.
Right to Erasure / 'Right to be Forgotten' (Article 17)
You can request deletion of your personal data. We will delete your account and all associated data within 30 days, except where we have a legal obligation to retain certain information (e.g., billing records for tax purposes).
Right to Data Portability (Article 20)
You can request your data in a commonly used, machine-readable format (such as JSON or CSV) so you can transfer it to another service provider. This includes your account information and file metadata.
Right to Object (Article 21)
You can object to certain types of data processing, particularly processing based on legitimate interests. For example, you can opt out of marketing communications at any time.
Right to Restrict Processing (Article 18)
In certain circumstances, you can request that we limit how we process your data while we investigate a concern or dispute you have raised.
To exercise any of these rights, please contact our Data Protection Officer at [email protected]. We take all rights requests seriously and will respond promptly.
4. EU Data Residency
One of our core commitments is that the files and account data stored with Felicloud remain within the European Union. This provides you with the strongest data protection available worldwide.
Our servers are located in Portugal, on infrastructure we own and operate:
- Primary infrastructure: Portugal (our own infrastructure)
- Redundant storage: within the same EU infrastructure (Felicloud does not keep separate backup copies of your files)
Your data is stored in Portugal on infrastructure we own and operate. As an EU company, we are subject to EU law (GDPR), not US jurisdiction.
5. Security Measures and Data Protection by Design
GDPR requires that we implement appropriate technical and organizational measures to protect your data. We employ multiple layers of security:
- Encryption of stored files on our servers (AES-256), with optional end-to-end encryption for the folders you choose
- Encrypted transmission of all data using the TLS protocol
- Regular security reviews and updates of our systems
- Strict access controls - only authorised personnel can access our systems
- Employee training on data protection and confidentiality
- Incident response plan to address any potential data breaches within 72 hours as required by GDPR
6. Data Processing Agreements
When we use third-party service providers (known as 'data processors' under GDPR), we ensure they meet strict requirements:
- All providers are located in the EU or have adequate data protection mechanisms
- We have formal Data Processing Agreements (DPAs) in place with all processors
- Processors are contractually required to implement appropriate security measures and only process data according to our instructions
We carefully vet all service providers to ensure they maintain GDPR compliance and uphold the same high standards for data protection that we do.
7. International Data Transfers
The files and account data stored in Felicloud are not transferred outside the European Union. Where optional third-party cookies that you have accepted (such as the Meta or Reddit advertising pixels) involve processing outside the EU, the following safeguards apply:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions confirming the recipient country provides adequate data protection
For the data stored in your account, we avoid international transfers altogether by keeping all our infrastructure within the EU.
8. Supervisory Authority and Complaints
You have the right to lodge a complaint with a data protection supervisory authority if you believe we have violated your GDPR rights. The supervisory authority in your country is responsible for handling such complaints.
You can find your local data protection authority at: European Data Protection Board - Members List
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance and handle data protection matters. You can contact our DPO directly with any questions or concerns:
Email: [email protected]
10. Transparency and Accountability
GDPR requires organizations to demonstrate compliance through documentation and transparency. We maintain:
- Records of all data processing activities
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- Regular internal audits of data protection practices
- This public GDPR compliance statement outlining our commitments and practices
Questions About GDPR?
We're committed to transparency and helping you understand your data protection rights. If you have any questions about GDPR, our compliance practices, or how we protect your data, please don't hesitate to reach out.
Contact: [email protected]
We will respond to all inquiries within 48 hours and handle rights requests within the GDPR-mandated 30-day timeframe.