Data Processing Agreement

Last updated: 8 August 2026

This Data Processing Agreement "DPA" applies when CloudExpress processes personal data on behalf of a Business Customer as part of our secure file transfer service.


Scope and Roles

CloudExpress acts as a processor for Customer Files, transfer metadata, recipient details, download events, audit records, and related data processed on behalf of Business Customers. The Business Customer remains the controller for personal data contained in Customer Files and transfer instructions.

For account administration, billing, fraud prevention, support, security, and other platform operations, CloudExpress may act as an independent controller as described in our Privacy Policy.


Subprocessors

CloudExpress maintains a current list of material subprocessors, their purposes, and transfer safeguards in the Subprocessor Register.

Customer provides general authorisation for CloudExpress to engage the subprocessors listed in the Subprocessor Register. CloudExpress will provide reasonable advance notice of material additions or replacements and, where applicable, customers may object to a new subprocessor on reasonable data-protection grounds by contacting privacy@cloudexpress.ie. If an objection cannot be resolved, the Customer may terminate the affected services in accordance with their agreement.

We impose data protection obligations on subprocessors that are materially equivalent to those in this DPA, and we remain responsible for subprocessors' performance of those obligations.


Retention, Expiry, and Deletion

Customer Files and transfer data are retained only as long as needed to provide the service and to support user-selected expiry settings.

  • Automatic file expiry: Files are removed from active service once the selected transfer expiry period ends.
  • Customer-controlled deletion of files: Customers may delete Customer Files at any time; deleted Customer Files are removed from active storage promptly in accordance with the configured deletion workflow.
  • Operational, audit, and billing records: Operational records (including logs, audit trails, and billing records) may be retained for a longer period where necessary for security, fraud prevention, accounting, dispute resolution, or to comply with legal obligations.
  • Account deletion: Deleted user accounts are disabled immediately and purged from active service after 30 days.
  • Workspace purge: Deleted non-personal workspaces are purged from active service after 30 days.
  • Backup copies: Deleted data may remain in encrypted backup copies until those backups expire under the applicable backup-retention schedule (for example: full backups 7 days; daily backups 14 days; weekly backups 8 weeks; monthly backups 4 months; yearly backups 2 years). Backup rotation and retention schedules are intended for disaster recovery and business continuity and do not imply that backups are restored to recover individually deleted customer data.

We may retain personal data for longer if required by law, dispute resolution, security investigations, fraud prevention, accounting, or other compliance obligations. Any retained data remains protected by appropriate safeguards.


Article 28 — Processor Obligations

To the extent CloudExpress processes personal data as a processor on behalf of a Customer, the following principles apply:

  • Instructions: CloudExpress will process personal data only on documented instructions from the Customer, unless required to do otherwise by applicable law; where permitted by law we will notify the Customer of such a legal requirement unless prohibited.
  • Subject matter & duration: The subject matter, duration, nature and purpose of processing are set out in the Customer's account and commercial agreement and this DPA.
  • Categories of data subjects & data types: Processing relates to data subjects and personal-data categories that arise from the Customer's use of the Services (for example, senders, recipients, and administrative users).
  • Personnel confidentiality: CloudExpress requires personnel with access to personal data to maintain confidentiality and implements access controls and training appropriate to the processing activities.
  • Technical & organisational measures: CloudExpress implements reasonable technical and organisational measures to protect personal data, including encryption in transit, access controls, logging and monitoring, and vulnerability management as appropriate to the risk.
  • Assistance: CloudExpress will assist Customers, taking into account the nature of the processing and the information available to CloudExpress, with data-subject requests, breach notifications to supervisory authorities, and other reasonable regulatory cooperation.
  • Return or deletion: At the end of the provision of services, CloudExpress will, at the Customer's choice, delete or return personal data in accordance with the agreement, subject to retention for legal obligations and the backup schedule above.
  • Audits & inspections: CloudExpress will make available information necessary to demonstrate compliance and will allow for audits or inspections as agreed in the Customer's contract, subject to reasonable confidentiality restrictions.
  • International transfers: Where processing involves transfers outside the EEA/UK or other applicable jurisdiction, CloudExpress will implement appropriate safeguards such as an adequacy decision, Standard Contractual Clauses, or other lawful mechanisms.
  • Unlawful instructions: CloudExpress will notify the Customer if we believe a Customer instruction infringes applicable data-protection law and will cooperate in seeking a resolution.

Security and Incident Communication

CloudExpress implements technical and organisational measures designed to protect personal data, including encryption in transit, access controls, logging, and monitoring.

We publish service incident and availability information on our Status Page. For urgent incident communication, security reports, or data protection questions, contact security@cloudexpress.ie.

When available, a concise independent penetration-test summary will be published here or made available upon request.