Cloud Power Luxembourg SA
Last updated: 6 October 2026
Cloud Power Luxembourg SA (“Cloud Power”, “we”, “us” or “our”) respects your privacy. This policy explains how we collect, use, disclose and protect personal data, and how you can exercise your rights.
It applies to our websites and services located into the cloud-power.eu domain, our enquiries and appointment bookings, and the personal data we process when managing relationships with customers, prospective customers, suppliers and other business contacts.
We process personal data in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), and applicable Luxembourg data protection and electronic communications legislation.
Who is responsible for your personal data?
For the activities described in this policy, the data controller is:
Cloud Power Luxembourg SA
77, Route d’Arlon
L-8311 Capellen
Luxembourg
Telephone: +352 20 600 820
Privacy contact: info@cloud-power.eu
You may also write to us at the address above, marked “Privacy request”.
Personal data processed on behalf of customers
When providing cloud hosting, managed IT, backup, security monitoring or other services, we may process personal data on behalf of a customer and under that customer’s instructions. In those circumstances, the customer generally acts as the data controller and Cloud Power acts as a data processor.
Such processing is governed by the relevant service agreement and data processing agreement. The customer’s privacy notice explains the purposes and legal bases for that processing.
If your request concerns personal data controlled by one of our customers, please contact that customer directly. If you contact us, we will assist the customer in handling your request in accordance with our obligations.
What personal data do we collect?
Depending on your interaction with us, we process the following categories of personal data:
- Identity and business contact details: your name, business email address, telephone number, employer, job title and business address.
- Enquiries and communications: information provided through contact forms, appointment bookings, emails, telephone conversations and other correspondence.
- Customer and supplier information: contact persons, quotations, orders, contracts, invoices, payment information and related administrative records.
- Account and support information: where applicable, account identifiers, access permissions, support requests and information needed to investigate and resolve technical issues.
- Technical and security information: IP addresses, timestamps, browser and device information, requested pages, authentication events, error records and security logs.
- Preferences and consent records: communication preferences, cookie choices, and records of consent or withdrawal.
- Website usage information: where enabled and legally permitted, information about how visitors navigate and interact with our website.
We collect only the personal data needed for the relevant purpose. Please avoid including sensitive personal information, passwords or confidential customer data in general website enquiries.
If an activity requires special categories of personal data, we will provide any necessary additional information and establish an appropriate legal basis before processing it.
Where does your personal data come from?
We receive personal data:
- directly from you when you contact us, book an appointment, use our services or communicate with us;
- automatically through the operation of our website and systems;
- from your employer or another organisation when you act as its representative or authorised contact; and
Where we obtain personal data indirectly, we provide the information required by the GDPR within the applicable timeframe—normally within one month, or earlier if we first contact you or disclose your data before then—unless a lawful exception applies.
Why do we process your personal data?
We use personal data for the purposes below. The legal basis depends on the activity and your relationship with us.
| Purpose | Personal data involved | Legal basis |
|---|---|---|
| Responding to enquiries, arranging appointments and preparing quotations | Contact details, correspondence and information about your request | Steps requested before entering into a contract, under Article 6(1)(b), where you are the prospective contracting party. Otherwise, our legitimate interest in responding to enquiries and developing business relationships, under Article 6(1)(f). |
| Delivering services and administering individual customer contracts | Contact, contract, account and service information | Performance of a contract with you, under Article 6(1)(b). |
| Managing relationships with representatives of corporate customers and suppliers | Professional contact details, correspondence and administrative information | Our legitimate interest in providing services and managing business relationships, under Article 6(1)(f). |
| Providing support and managing service communications | Contact details, support requests and relevant technical information | Performance of a contract with you, where applicable; otherwise, our legitimate interest in supporting customers and maintaining services. |
| Operating and protecting our website and systems | Technical information, access records and security logs | Our legitimate interest in maintaining reliable services, preventing misuse and protecting data and systems, under Article 6(1)(f). |
| Accounting, invoicing and meeting applicable legal requirements | Transaction, invoice and relevant contact information | Compliance with legal obligations, under Article 6(1)(c), including applicable accounting and tax requirements. |
| Establishing, exercising or defending legal claims | Relevant correspondence, contractual and transaction records | Our legitimate interest in protecting our legal rights, under Article 6(1)(f). |
| Sending optional newsletters or promotional emails, if offered | Contact details, preferences and consent records | Your consent, under Article 6(1)(a), except where the applicable existing-customer exception permits marketing of our own similar services, supported by our legitimate interest. |
| Using optional analytics, marketing or other non-essential tracking technologies, if enabled | Online identifiers, usage information and preferences | Your consent, under Article 6(1)(a), together with the consent required by electronic communications legislation. |
Where we rely on legitimate interests, we assess the necessity of the processing and its impact on your rights and freedoms.
We do not treat visiting our website or accepting this policy as consent to optional processing.
If we intend to use your personal data for a new purpose, we will provide the necessary information before doing so and obtain consent where required.
Do you have to provide personal data?
You can generally browse our website without submitting contact details. Certain technical information is processed to deliver and secure the website.
When you contact us or request a service, we need enough information to respond, identify the relevant organisation and fulfil your request. Required fields are identified on the relevant form. If you do not provide required information, we may be unable to answer your enquiry, arrange an appointment, enter into a contract or provide the requested service.
Where information is required by law or contract, we will explain that requirement when collecting it.
Optional marketing consent and consent to non-essential cookies are voluntary.
Cookies and similar technologies
WordPress and cookies
Our website uses WordPress. Depending on the features you use, WordPress may use cookies for authentication, session management and preferences. Authentication cookies apply to users accessing a login area; they are not necessarily set for ordinary website visitors.
We use strictly necessary cookies without consent only where they are required to transmit communications or provide a service you expressly request. Any non-essential cookies or similar tracking technologies require your prior consent. Their purposes, providers and durations are described in our cookie information.
You can manage cookies through your browser settings. Blocking necessary cookies may prevent certain requested features from working.
For privacy questions or requests, contact info@cloud-power.eu.
You can also manage cookies through your browser. Blocking necessary cookies may affect features you request.
Our approach follows the CNPD’s guidance on cookies and similar technologies.
Marketing communications
Where we send promotional communications, we obtain your consent unless a specific legal exception applies.
Where permitted, we may use contact details obtained from an existing customer relationship to promote our own similar products or services, provided we offered a clear, free opportunity to object when collecting the details and in each subsequent message.
You can unsubscribe using the link in a marketing email or contact us using the details in Section 1.
You may object to direct marketing at any time. We will stop using your personal data for that purpose, including any related profiling.
We may retain minimal information on a suppression list to ensure that we respect your choice.
Necessary service, security and contractual communications are separate from optional marketing. This distinction reflects the CNPD’s guidance on customer communications.
Who receives your personal data?
Access is limited to people and organisations that need the information for the purposes described in this policy.
Depending on the activity, recipients include:
- authorised Cloud Power personnel;
- accountants, auditors, legal advisers, insurers and other professional advisers where necessary;
- public authorities, regulators or courts where disclosure is legally required or necessary to protect legal rights; and
- advisers and prospective successors where necessary for a business transaction, subject to appropriate confidentiality and data protection safeguards.
Providers acting as our processors must process personal data under our instructions and appropriate contractual obligations, including confidentiality and security requirements.
Some recipients, such as public authorities or certain professional advisers, act as independent controllers for their own processing.
International transfers
Personal data is processed in Gravelines. Certain providers or their authorised personnel may process or access data outside the European Economic Area (“EEA”).
Where a destination or recipient is covered by an applicable European Commission adequacy decision, we rely on that decision.
Otherwise, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and assess whether additional measures are necessary to protect the data.
You can contact us to obtain information about the relevant safeguards and a copy of applicable contractual safeguards, subject to necessary redactions.
These arrangements must meet the requirements described in the CNPD’s international transfer guidance.
How long do we retain personal data?
We retain personal data only for as long as necessary for its purpose, including applicable legal requirements.
| Data category | Retention period or criteria |
|---|---|
| Enquiries and appointment records that do not result in a contract | 30 days after the enquiry is resolved or the last substantive interaction. |
| Customer, supplier and contractual records | For the relationship’s duration, followed by the applicable statutory retention period or relevant legal claims period. |
| Accounting records and supporting documents | Generally ten years where Luxembourg accounting requirements apply, calculated according to the applicable statutory rules. |
| Support records | 730 days after closure, unless specified records are needed for a continuing contractual obligation or legal claim. |
| Website and security logs | 60 days, with relevant extracts retained longer where necessary to investigate an identified incident or legal claim. |
| Marketing records | Until consent is withdrawn, an objection is received or 120 days, whichever applies first. |
| Consent and suppression records | Limited records retained for the period necessary to demonstrate compliance and respect your choices. |
| Cookies and related analytics data | The durations stated in our cookie information. Cookie expiry and retention of associated server-side data may differ. |
| Backup copies | Removed through our documented backup rotation within 360 days, subject to justified legal holds. |
Luxembourg’s general accounting retention requirements are described on Guichet.lu.
Where a dispute, investigation or legal preservation obligation requires longer retention, we limit retention to the relevant information and restrict its use accordingly.
When retention is no longer justified, we delete the data or irreversibly anonymise it.
For data processed on behalf of customers, retention, return and deletion follow the customer’s instructions and the applicable data processing agreement.
How do we protect personal data?
We apply technical and organisational measures appropriate to the risks of processing.
Access is limited according to responsibilities and operational need. We review safeguards as our systems, services and risks evolve.
Where a personal data breach occurs, we assess it and notify the competent authority and affected individuals where required by law.
Your rights
Subject to the conditions and exceptions in the GDPR, you have the following rights:
- Access: obtain confirmation of whether we process your personal data and receive a copy and relevant information.
- Rectification: have inaccurate data corrected and incomplete data completed.
- Erasure: request deletion where a legal ground for erasure applies.
- Restriction: request limits on processing in the circumstances specified by the GDPR.
- Portability: receive data you provided in a structured, commonly used, machine-readable format, and request its transmission to another controller where processing is automated and based on consent or a contract.
- Objection: object, on grounds relating to your particular situation, to processing based on legitimate interests. We will stop unless we demonstrate compelling overriding grounds or the processing is necessary for legal claims.
- Objection to marketing: object to direct marketing at any time, without needing to give a reason.
- Withdrawal of consent: withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Protection concerning automated decisions: exercise applicable rights relating to decisions based solely on automated processing that have legal or similarly significant effects.
To exercise your rights, contact us using Section 1. Please describe your request and the relevant interaction with Cloud Power.
If we have reasonable doubts about your identity, we may request only the additional information necessary to verify it.
We respond without undue delay and normally within one month of receiving your request. Where necessary because of its complexity or the number of requests, we may extend that period by up to two further months. We will explain any extension within the first month.
Requests are normally free. Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse it, as permitted by the GDPR. If we cannot fulfil a request, we will explain why and inform you of your complaint and judicial remedy options.
These rights and response requirements are set out in Chapter III of the GDPR.
Automated decision-making and profiling
We do not use personal data covered by this policy to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.
Any optional profiling for marketing or analytics must be described in the relevant disclosure before it begins.
Children’s personal data
Our website and business services are intended for professional users and are not directed at children.
If you believe a child has provided personal data through our website, please contact us so that we can assess the situation and take appropriate action.
Third-party websites and services
Our website may contain links to third-party websites or services. Those organisations are responsible for their own processing, as described in their privacy notices.
Where a third-party service is embedded within our website, the applicable data collection, recipient and consent information is provided through our privacy and cookie disclosures.
Complaints
You may contact us about a privacy concern using the details in Section 1.
You also have the right to lodge a complaint with a competent supervisory authority, particularly in the EEA country where you habitually reside, work or where the alleged infringement occurred. You do not have to contact us first to exercise that right.
In Luxembourg, the supervisory authority is:
Commission nationale pour la protection des données (CNPD)
Service des réclamations
15, Boulevard du Jazz
L-4370 Belvaux
Luxembourg
Complaint information and the online form are available on the CNPD website.
Changes to this policy
We may update this policy to reflect changes in our processing activities or legal requirements. The current version will remain accessible on our website, with its update date shown above.
Where required, we will notify you of material changes and obtain fresh consent before starting processing that requires it. Updating this policy does not itself constitute your consent.
