Last updated: 2026-07-12
This Data Processing Agreement (DPA) governs the processing of personal data by CloudForge Team on behalf of the customer, in accordance with Art. 28 GDPR.
CloudForge Team processes personal data solely to provide the CloudForge Sentinel service as described in the Master Service Agreement (MSA) and these Terms of Service.
Processing begins on the effective date of the MSA and continues until the termination of the MSA plus the deletion period defined in Section 7.
The processing includes: collection, storage, analysis, and visualization of infrastructure metadata, container inventory data, vulnerability findings, and AI system governance data submitted by the customer via the CloudForge Agent or web interface.
Customer-uploaded data may include: hostname, IP address, container images, software versions, vulnerability metadata, AI system configuration. No special categories of personal data (Art. 9 GDPR) are intentionally processed.
Data subjects are typically employees or contractors of the customer (operators of the monitored infrastructure). No data of natural persons outside the customer's organization is intentionally processed.
Findings data: retained for the duration of the subscription + 30 days, then automatically deleted. Audit logs: retained for 365 days, then automatically deleted. Account data: deleted within 30 days of account termination upon written request.
CloudForge Team engages the following sub-processors: - Hetzner Online GmbH (Infrastructure hosting, Germany/EU) - Object storage provider (configurable, EU region by default) A current list of sub-processors is published at https://cloudforge.team/legal/dpa and updated at least 30 days before any change.
- Encryption in transit (TLS 1.3) and at rest (AES-256) - Role-based access control (RBAC) with mandatory MFA for admin roles - Database credentials rotated every 90 days - Audit logging of all admin actions - Daily encrypted backups with 30-day retention - Annual penetration testing - Incident response plan with 72-hour notification
CloudForge Team supports the customer in fulfilling data subject requests (Art. 15-22 GDPR). Requests should be directed to privacy@cloudforge.team and will be processed within 30 days.
All customer data is processed within the European Union by default. Any transfer to third countries requires Standard Contractual Clauses (SCC) per Art. 46 GDPR and customer approval.
Upon termination of the MSA, all customer data will be deleted within 30 days unless legal retention obligations require otherwise. A deletion certificate can be provided on request.