Privacy Policy

Last updated: June 17, 2025

Your Privacy Matters: This Privacy Policy explains how CloudExplain collects, uses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and German data protection laws.

1. Controller and Contact Information

Data Controller: CloudExplain
Address: Lothringerstraße 7, 81667 Munich
Email: info@cloudexplain.eu
Data Protection Officer: info@cloudexplain.eu

2. Data We Collect

2.1 Personal Data

We collect the following categories of personal data:

Data Category Examples Legal Basis
Account Information Name, email address, profile picture Contract performance (Art. 6(1)(b) GDPR)
Authentication Data OAuth tokens, login credentials Contract performance (Art. 6(1)(b) GDPR)
Usage Data IP address, browser type, access times Legitimate interests (Art. 6(1)(f) GDPR)
Model Data Uploaded models, datasets, analysis results Contract performance (Art. 6(1)(b) GDPR)
Communication Data Support tickets, feedback, correspondence Contract performance (Art. 6(1)(b) GDPR)

2.2 Automatically Collected Data

We automatically collect certain information when you use our service:

3. How We Use Your Data

3.1 Primary Purposes

We process your personal data for the following purposes:

3.2 Analytics and Improvement

With your consent or based on legitimate interests, we may use data for:

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

5. Data Sharing and Disclosure

5.1 Third-Party Service Providers

We may share your data with trusted third-party service providers who assist us in operating our service:

5.2 Data Processing Agreements

All third-party processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance and appropriate data protection measures.

5.3 Legal Disclosure

We may disclose your data when required by law or to protect our rights, property, or safety, or that of our users or others.

6. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:

7. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

8. Data Security

8.1 Technical Measures

We implement robust security measures to protect your data:

8.2 Organizational Measures

9. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

9.1 Right to Information and Access (Art. 15)

You have the right to know what personal data we process about you and to request a copy of your data.

9.2 Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete personal data.

9.3 Right to Erasure (Art. 17)

You can request deletion of your personal data under certain circumstances, including:

9.4 Right to Restrict Processing (Art. 18)

You can request restriction of processing in certain situations, such as when disputing the accuracy of data.

9.5 Right to Data Portability (Art. 20)

You can request to receive your personal data in a structured, commonly used format and transmit it to another controller.

9.6 Right to Object (Art. 21)

You can object to processing based on legitimate interests or for direct marketing purposes.

9.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of past processing.

9.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority, particularly in your country of residence, workplace, or where the alleged infringement occurred.

10. Cookies and Tracking Technologies

10.1 Current Cookie Usage

We currently only use essential cookies necessary for the basic functioning of our service. These include:

Cookie Type Purpose Duration Status
Essential Cookies Authentication, security, core functionality Session/1 year Currently Used
Preference Cookies User settings, language preferences 1 year Not currently implemented
Analytics Cookies Usage statistics, performance monitoring 2 years Not currently implemented

10.2 Cookie Management

Currently, we only use essential cookies that are necessary for the service to function properly. These cannot be disabled as they are required for authentication and security. Should we implement optional cookies in the future, you will be able to manage your preferences through a cookie banner or your browser settings.

11. Children's Privacy

CloudExplain is not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we discover that we have collected such data, we will delete it promptly.

12. Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

13. Automated Decision Making

We may use automated decision-making for:

You have the right to request human intervention, express your point of view, and contest automated decisions that significantly affect you.

14. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices or applicable laws. We will:

15. Contact Us

For any questions about this Privacy Policy or to exercise your rights, please contact us:

Privacy Team: info@cloudexplain.eu
Data Protection Officer: info@cloudexplain.eu
Address: Lothringerstraße 7, 81667 Munich
Phone: +49 172 951 8758

16. Supervisory Authority

If you have concerns about how we handle your personal data, you can contact the relevant supervisory authority:

German Federal Commissioner for Data Protection and Freedom of Information
Graurheindorfer Str. 153
53117 Bonn, Germany
Phone: +49 228 997799-0
Email: poststelle@bfdi.bund.de

Effective Date: This Privacy Policy is effective as of June 17, 2025, and applies to all personal data processing activities from this date forward.