Last Updated: January 2026
Cloud-eclipse processes personal data in accordance with the General Data Protection Regulation and the UK Data Protection Act 2018. We maintain procedures ensuring that data handling practices meet current regulatory standards.
We process personal data under the following legal bases:
Under GDPR, individuals whose data we process have specific rights:
You may request confirmation of whether we process your personal data and obtain a copy of that data. We respond to access requests within one month of receipt.
If personal data we hold is inaccurate or incomplete, you have the right to request correction. We update records promptly upon verification of corrected information.
In certain circumstances, you may request deletion of personal data. This right is limited by legal obligations requiring data retention for regulatory compliance, particularly for financial transaction records.
You may request that we limit how we use personal data while disputes about accuracy or processing legitimacy are resolved.
For data you provided to us, you can request a copy in a structured, commonly used format suitable for transfer to another service provider.
You may object to processing based on legitimate interests or for marketing purposes. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
Questions regarding data protection practices or exercising rights should be directed to: [email protected]
We maintain internal procedures ensuring that data protection inquiries receive appropriate attention from qualified personnel.
Personal data is retained only as long as necessary for the purposes for which it was collected or as required by law. Specific retention periods include:
Our primary data processing occurs within the United Kingdom. When technical operations require data transfers outside the UK, we ensure appropriate safeguards are in place through standard contractual clauses or other approved mechanisms.
We implement technical and organizational measures appropriate to the risks presented by processing activities:
Our systems include automated processes for transaction verification and fraud detection. These systems do not make decisions producing legal effects or similarly significant impacts without human oversight. You have the right to request human review of automated decisions affecting you.
In the event of a data breach likely to result in risks to individuals' rights, we notify affected parties and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by GDPR.
When we engage service providers who process personal data on our behalf, we ensure they provide sufficient guarantees of GDPR compliance through contractual commitments and regular assessments.
You have the right to lodge complaints about our data processing practices with the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
United Kingdom
We review and update our data protection practices regularly to ensure ongoing compliance with evolving regulations. Material changes to this policy are communicated to active clients.