Data Processing Agreement (DPA)

Last updated: 2026-07-12

1. Scope

This Data Processing Agreement (DPA) governs the processing of personal data by CloudForge Team on behalf of the customer, in accordance with Art. 28 GDPR.

2. Subject Matter

CloudForge Team processes personal data solely to provide the CloudForge Sentinel service as described in the Master Service Agreement (MSA) and these Terms of Service.

3. Duration

Processing begins on the effective date of the MSA and continues until the termination of the MSA plus the deletion period defined in Section 7.

4. Nature and Purpose

The processing includes: collection, storage, analysis, and visualization of infrastructure metadata, container inventory data, vulnerability findings, and AI system governance data submitted by the customer via the CloudForge Agent or web interface.

5. Categories of Data

Customer-uploaded data may include: hostname, IP address, container images, software versions, vulnerability metadata, AI system configuration. No special categories of personal data (Art. 9 GDPR) are intentionally processed.

6. Data Subject Categories

Data subjects are typically employees or contractors of the customer (operators of the monitored infrastructure). No data of natural persons outside the customer's organization is intentionally processed.

7. Deletion Periods

Findings data: retained for the duration of the subscription + 30 days, then automatically deleted. Audit logs: retained for 365 days, then automatically deleted. Account data: deleted within 30 days of account termination upon written request.

8. Sub-Processors

CloudForge Team engages the following sub-processors: - Hetzner Online GmbH (Infrastructure hosting, Germany/EU) - Object storage provider (configurable, EU region by default) A current list of sub-processors is published at https://cloudforge.team/legal/dpa and updated at least 30 days before any change.

9. Technical and Organizational Measures (TOMs)

- Encryption in transit (TLS 1.3) and at rest (AES-256) - Role-based access control (RBAC) with mandatory MFA for admin roles - Database credentials rotated every 90 days - Audit logging of all admin actions - Daily encrypted backups with 30-day retention - Annual penetration testing - Incident response plan with 72-hour notification

10. Data Subject Rights

CloudForge Team supports the customer in fulfilling data subject requests (Art. 15-22 GDPR). Requests should be directed to privacy@cloudforge.team and will be processed within 30 days.

11. International Data Transfers

All customer data is processed within the European Union by default. Any transfer to third countries requires Standard Contractual Clauses (SCC) per Art. 46 GDPR and customer approval.

12. Liability and Termination

Upon termination of the MSA, all customer data will be deleted within 30 days unless legal retention obligations require otherwise. A deletion certificate can be provided on request.

CloudForge Team — Cloud, Container and AI under control