Data Processing Addendum

Last updated 28 July 2026

This addendum applies where C10UD LLC (“Processor”) processes personal data on behalf of a customer (“Controller”) in providing the Services, and where that processing is subject to the GDPR, the UK GDPR, or similar data protection law. It forms part of, and is governed by, our Terms of Service. Terms not defined here have the meaning given in the GDPR.

1. Roles and scope

The Controller determines the purposes and means of processing the personal data it puts on the Services. C10UD acts as Processor and processes that data only to provide the Services.

Each party complies with the data protection law applicable to it. The Controller is responsible for having a lawful basis for the personal data it submits and for the accuracy and legality of that data.

2. Processor obligations

  • Process personal data only on the Controller’s documented instructions, which include the Terms of Service, this addendum, and use of the Services’ features. If law requires processing beyond those instructions, we will tell the Controller first unless the law forbids it.
  • Tell the Controller if, in our opinion, an instruction infringes applicable data protection law.
  • Ensure that people authorised to process the data are bound by confidentiality obligations.
  • Implement and maintain the technical and organisational measures described in Annex II.
  • Not sell, retain or use personal data for any purpose other than providing the Services.

3. Sub-processors

The Controller gives general authorisation for C10UD to engage sub-processors. Our current sub-processors are listed on the Sub-processors page, which is kept up to date.

We will give at least 30 days’ notice before adding or replacing a sub-processor, by email to account holders who have subscribed to notifications on that page. The Controller may object on reasonable data protection grounds within that period; if we cannot offer an alternative, the Controller may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees.

We impose data protection obligations on each sub-processor that are no less protective than those in this addendum, and remain liable for their performance.

4. Assistance to the Controller

  • Data subject requests — we will promptly forward any request we receive that relates to the Controller’s data, and provide reasonable assistance, using the Services’ features where possible, for the Controller to respond within the legal deadline.
  • Personal data breaches — we will notify the Controller without undue delay after becoming aware of a personal data breach affecting its data, with the information available to us, and update as the investigation progresses, so the Controller can meet its own 72-hour notification duty.
  • Impact assessments — we will provide reasonable assistance with data protection impact assessments and prior consultations, taking into account the nature of the processing and the information available to us.

5. Deletion and return

On termination or expiry, the Controller may export its data for 30 days. After that we delete the personal data, including from backups in the ordinary backup rotation, unless law requires us to keep it — in which case we keep it only for as long as required and continue to protect it under this addendum. On written request we will confirm deletion.

6. Audits and information

We will make available the information reasonably necessary to demonstrate compliance with this addendum, and allow for and contribute to audits by the Controller or an independent auditor it mandates.

Audits are limited to once every 12 months (unless a regulator requires more, or following a personal data breach), require at least 30 days’ written notice, must be conducted during business hours without unreasonably disrupting our operations, are subject to confidentiality, and are at the Controller’s expense. We may satisfy an audit request by providing existing reports and documentation where these reasonably address the request.

7. International transfers

Personal data is processed in Google Cloud and AWS regions across the Americas, EMEA and Asia-Pacific. Where the Controller transfers personal data subject to the GDPR or UK GDPR to us, the European Commission’s Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated into this addendum by reference and are completed as follows: the Controller is the data exporter and C10UD the data importer; the optional docking clause applies; under Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in section 3; under Clause 17, the governing law is that of Ireland; under Clause 18(b), the forum is the courts of Ireland; Annexes I and II are as set out below.

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies, with C10UD as importer. For transfers from Switzerland, references to the GDPR are read as references to the Swiss FADP and the competent authority is the FDPIC.

8. Liability and precedence

Each party’s liability under this addendum is subject to the limitations of liability in the Terms of Service. In case of conflict, this addendum prevails over the Terms of Service for matters of personal data processing, and the Standard Contractual Clauses prevail over this addendum.

Annex I — Description of processing

  • Subject matter — provision of the hosting, compute and platform Services described in the Terms of Service.
  • Duration — the term of the customer’s subscription, plus the deletion period in section 5.
  • Nature and purpose — hosting, storing, transmitting, backing up, securing and otherwise processing personal data as necessary to run the Controller’s workloads and to provide support.
  • Types of personal data — determined by the Controller. Typically the account data of the Controller’s own users, and any personal data contained in the Controller’s applications, databases, files and logs.
  • Categories of data subjects — determined by the Controller. Typically the Controller’s customers, employees, contractors and end users.
  • Special category data — the Services are not designed for special category data; the Controller must not submit it without a separate written agreement.
  • Frequency — continuous, for the duration of the subscription.
  • Competent supervisory authority — that of the Controller’s establishment or, where the Controller is not established in the EEA, of its EU representative.

Annex II — Technical and organisational measures

  • Encryption of data in transit over public networks, and encryption of secrets and credentials at rest.
  • Isolation between customer workloads, using container or hardware-level virtualisation boundaries.
  • Role-based access control for staff, least privilege by default, and logging of administrative access.
  • Credential delivery at runtime rather than embedding secrets in build artefacts or configuration files.
  • Regular patching of host systems, monitoring of platform health, and alerting on anomalous activity.
  • Backups of platform state, with restoration procedures tested periodically.
  • Confidentiality obligations for all personnel with access to customer environments.
  • A documented incident response process covering detection, containment, notification and remediation.

Questions about this document? Email legal@c10ud.net.