Back to homeLast updated: August 2, 2026

GDPR Compliance

Information for users in the European Economic Area about how we comply with the GDPR.

CruzClaw Cloud is committed to compliance with the General Data Protection Regulation (GDPR) for users located in the European Economic Area (EEA), Switzerland, and the United Kingdom. This page explains how we process personal data under GDPR and the rights available to you.

1. Data Controller

CruzClaw Cloud is the data controller responsible for personal data collected through our website and platform. For service-specific processing carried out by our customers, the customer may be the data controller and CruzClaw acts as a data processor.

2. Legal Basis for Processing

We process personal data under one or more of the following legal bases:

  • Contractual necessity: To provide the Services you signed up for, including account management, billing, and VM provisioning.
  • Consent: For marketing communications, analytics, and non-essential cookies.
  • Legitimate interests: For fraud prevention, security, product improvement, and customer support, provided these interests do not override your rights.
  • Legal obligation: To comply with applicable laws, tax rules, and regulatory requests.

3. Your Data Subject Rights

Under GDPR, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten"): Request deletion of your data, subject to legal and contractual obligations.
  • Right to restrict processing: Ask us to limit how we use your data.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent: Withdraw consent at any time for processing based on consent.

To exercise these rights, contact us at privacy@cruzclaw.app. We will respond within one month, which may be extended by two additional months for complex requests.

4. Data Transfers

CruzClaw operates infrastructure globally. When transferring personal data outside the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms.

5. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee GDPR compliance. You can contact our DPO at dpo@cruzclaw.app.

6. Data Breach Notification

In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.

7. Automated Decision-Making

CruzClaw may use automated processes for fraud detection, abuse prevention, and credit checks. These processes are not used to make decisions that produce legal or similarly significant effects on you without human intervention, except where authorized by law.

8. Cookies and Consent

We request consent for non-essential cookies from users in the EEA. You can manage your consent choices at any time through our cookie banner or by contacting us. See our Cookie Policy for more details.

9. Complaints

If you believe we have not handled your data appropriately, you have the right to lodge a complaint with your local data protection authority. We encourage you to contact us first so we can address your concerns.

10. Changes to This GDPR Notice

We may update this GDPR notice to reflect changes in our practices or legal requirements. We will notify you of material changes by email or by posting a notice on the website.

11. Contact Us

For GDPR-related inquiries, please contact our Data Protection Officer at dpo@cruzclaw.app.