Cloud-eclipse
Home About Services Contact Advertising Content

GDPR Compliance

Last Updated: January 2026

Our Commitment to Data Protection

Cloud-eclipse processes personal data in accordance with the General Data Protection Regulation and the UK Data Protection Act 2018. We maintain procedures ensuring that data handling practices meet current regulatory standards.

Legal Basis for Processing

We process personal data under the following legal bases:

  • Contractual Necessity: Processing required to fulfill service agreements and business relationships
  • Legitimate Interests: Business operations, fraud prevention, and system security
  • Legal Obligation: Compliance with financial regulations and reporting requirements
  • Consent: Where explicitly provided for specific processing activities

Data Subject Rights

Under GDPR, individuals whose data we process have specific rights:

Right to Access

You may request confirmation of whether we process your personal data and obtain a copy of that data. We respond to access requests within one month of receipt.

Right to Rectification

If personal data we hold is inaccurate or incomplete, you have the right to request correction. We update records promptly upon verification of corrected information.

Right to Erasure

In certain circumstances, you may request deletion of personal data. This right is limited by legal obligations requiring data retention for regulatory compliance, particularly for financial transaction records.

Right to Restrict Processing

You may request that we limit how we use personal data while disputes about accuracy or processing legitimacy are resolved.

Right to Data Portability

For data you provided to us, you can request a copy in a structured, commonly used format suitable for transfer to another service provider.

Right to Object

You may object to processing based on legitimate interests or for marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.

Data Protection Officer

Questions regarding data protection practices or exercising rights should be directed to: [email protected]

We maintain internal procedures ensuring that data protection inquiries receive appropriate attention from qualified personnel.

Data Retention

Personal data is retained only as long as necessary for the purposes for which it was collected or as required by law. Specific retention periods include:

  • Transaction records: Seven years from transaction date (regulatory requirement)
  • Business correspondence: Duration of active relationship plus two years
  • Technical logs: Ninety days unless required for security investigations
  • Marketing consents: Until consent is withdrawn

International Data Transfers

Our primary data processing occurs within the United Kingdom. When technical operations require data transfers outside the UK, we ensure appropriate safeguards are in place through standard contractual clauses or other approved mechanisms.

Security Measures

We implement technical and organizational measures appropriate to the risks presented by processing activities:

  • Encryption of data in transit and at rest
  • Access controls limiting data exposure to authorized personnel
  • Regular security assessments and penetration testing
  • Incident response procedures for potential data breaches
  • Staff training on data protection responsibilities

Automated Decision Making

Our systems include automated processes for transaction verification and fraud detection. These systems do not make decisions producing legal effects or similarly significant impacts without human oversight. You have the right to request human review of automated decisions affecting you.

Data Breach Procedures

In the event of a data breach likely to result in risks to individuals' rights, we notify affected parties and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.

Third-Party Processors

When we engage service providers who process personal data on our behalf, we ensure they provide sufficient guarantees of GDPR compliance through contractual commitments and regular assessments.

Supervisory Authority

You have the right to lodge complaints about our data processing practices with the Information Commissioner's Office:

Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom

Policy Updates

We review and update our data protection practices regularly to ensure ongoing compliance with evolving regulations. Material changes to this policy are communicated to active clients.

Cloud-eclipse

Modern payment infrastructure for businesses that value precision, security, and operational efficiency.

Quick Links

  • About Us
  • Services
  • Contact

Legal

  • Privacy Policy
  • GDPR Compliance
  • Cookies Policy
  • Terms of Use

Disclaimer

Services are designed to support business operations and are not a substitute for professional financial advice. Transaction outcomes depend on proper implementation and existing business infrastructure. We recommend consulting with qualified financial advisors for specific business decisions.

© 2026 Cloud-eclipse. All rights reserved. | Contact: [email protected]