CloudGenie

Legal

Data Processing Addendum

Last updated: 2026-07-15

This Data Processing Addendum ("DPA") forms part of the agreement between CloudGenie Ltd (Durham, United Kingdom — the "Processor") and the Customer (the "Controller") under the Terms of Service, and applies to the extent CloudGenie processes personal data contained in Customer Data on the Customer's behalf.

1. Subject matter and duration

Processing is performed to provide the CloudGenie Service for the duration of the agreement, plus the post-termination export window described in the Terms.

2. Nature and purpose of processing

Hosting, storage, analysis and display of data retrieved from the Customer's connected cloud accounts and data submitted by the Customer's users, for cloud cost management, resource discovery, compliance reporting and related features.

3. Categories of data and data subjects

Data subjects: the Customer's authorised users; individuals whose personal data appears incidentally in cloud resource metadata (e.g. resource names, tags, log entries).
Categories: business contact details of users (name, email, role); technical identifiers (IP addresses, session identifiers); incidental personal data contained in Customer cloud metadata. No special-category data is intended to be processed; the Customer agrees not to submit it.

4. Controller and processor obligations

The Customer warrants it has a lawful basis for the processing it instructs. CloudGenie will: (a) process personal data only on documented instructions from the Customer, including with regard to international transfers; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures described in Annex 1; (d) assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations under Articles 32–36 UK/EU GDPR; (e) delete or return personal data at the end of the engagement; and (f) make available information necessary to demonstrate compliance and allow for audits as described in Section 8.

5. Sub-processors

The Customer provides general authorisation for the sub-processors listed at /legal/subprocessors. CloudGenie will give at least 30 days' notice of intended additions or replacements (via that page and, for enterprise customers, by email), during which the Customer may object on reasonable data-protection grounds. CloudGenie remains liable for its sub-processors' performance.

6. International transfers

Where processing involves a transfer of UK or EEA personal data to a third country without an adequacy decision, the parties incorporate the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses (Module 2: controller → processor), as applicable, which are deemed executed by acceptance of these Terms.

7. Personal data breach

CloudGenie will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably required for the Customer to meet its own notification obligations.

8. Audit

Upon reasonable written notice (no more than once per 12 months unless required by a supervisory authority), CloudGenie will make available documentation evidencing its security programme and, where that is insufficient, permit an audit under confidentiality at the Customer's cost during normal business hours without disrupting operations.

Annex 1 — Technical and organisational measures

Contact

Signed DPA copies and enterprise variations: legal@cloudgenie.co