News
BackCommon Compliance Questions
Security and data protection are key concerns – not only for us at cloudscale, but obviously also for many of our customers. Whether as part of preliminary planning for a future project, for internal documentation, or in response to an audit by end customers, we frequently receive questions regarding compliance. Here, we have summarized some of the most common questions and answers for you at a glance.
Does cloudscale offer a Data Processing Agreement (DPA)?
Yes, cloudscale offers a Data Processing Agreement. (In German, the terms "Bearbeitung" and "Verarbeitung" are derived from the Swiss FADP and the European GDPR, respectively; at cloudscale, we consistently use the term "Verarbeitung".) You can optionally conclude this DPA directly in the cloud control panel under "Contracts", both in the context of your personal user account and for any organization you manage.
In our knowledge base, you can find more information about the DPA; there, you can also download the document if you would like to read it beforehand and do not yet have a user account.
What sub-processors does cloudscale use?
cloudscale currently has no sub-processors – and has no plans to change this. We do not resell third-party services: the server hardware we use is owned by cloudscale and is managed by our own engineers.
Will my data remain in Switzerland? Where exactly?
Yes, cloudscale operates all infrastructure exclusively in data centers in Switzerland. This provision is also set forth in our Terms of Service and is therefore automatically part of the contract when you use our services. On our website, you can find more information about the data centers we use in Lupfig (AG) and Rümlang (ZH).
Our DPA also mentions "transfer to third countries" in connection with sub-processors (of which there are currently none; see above). This is not intended to undermine our commitment to Switzerland as our chosen location, but rather to keep the door open for future services that we may not be able to provide on our own. In any case, we would inform you in a timely manner should this ever become relevant.
Is my data encrypted, and who has the key?
Yes, all content in your volumes (including snapshots) and objects is encrypted "at rest". This means that your data is stored on the SSDs in our storage clusters only in encrypted form.
However, in order to provision your servers and objects as usual, we are necessarily in possession of the keys. Of course, you are free to implement additional encryption using your own key material on your own, for example, using LUKS (for volumes) or SSE-C (for objects).
How is the data returned at the end of the contract?
At cloudscale, you have full ("root") access to your cloud servers and buckets, and you know your data structure best. Before deleting servers or content, you are free to copy your data to your own system or to another new location. Depending on the destination and your personal preference, use the tool of your choice, such as scp, s3cmd, or a transfer feature in your own software.
Who owns cloudscale?
cloudscale.ch Ltd. is registered in Zurich. Its shareholders consist of Swiss individuals (owning 60% of the shares), including our founder and CEO Manuel Schweizer as the majority shareholder, and Cyberlink Ltd. (owning 40%), likewise registered in Zurich. This minimizes the influence of foreign legal systems, such as the U.S. CLOUD Act, as much as possible.
At cloudscale, we like to do things right, and we appreciate it when our customers take data security and privacy seriously, too. We are happy to help if you need answers like the ones above. We are also increasingly compiling these in our knowledge base – so it is best to check there first, and if something is missing, please let us know.
Transparent as always,
Your cloudscale team