Cloud Power Luxembourg SA
Last updated: 6 October 2026

Cloud Power Luxembourg SA (“Cloud Power”, “we”, “us” or “our”) respects your privacy. This policy explains how we collect, use, disclose and protect personal data, and how you can exercise your rights.

It applies to our websites and services located into the cloud-power.eu domain, our enquiries and appointment bookings, and the personal data we process when managing relationships with customers, prospective customers, suppliers and other business contacts.

We process personal data in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”), and applicable Luxembourg data protection and electronic communications legislation.

Who is responsible for your personal data?

For the activities described in this policy, the data controller is:

Cloud Power Luxembourg SA
77, Route d’Arlon
L-8311 Capellen
Luxembourg

Telephone: +352 20 600 820
Privacy contact: info@cloud-power.eu

You may also write to us at the address above, marked “Privacy request”.

Personal data processed on behalf of customers

When providing cloud hosting, managed IT, backup, security monitoring or other services, we may process personal data on behalf of a customer and under that customer’s instructions. In those circumstances, the customer generally acts as the data controller and Cloud Power acts as a data processor.

Such processing is governed by the relevant service agreement and data processing agreement. The customer’s privacy notice explains the purposes and legal bases for that processing.

If your request concerns personal data controlled by one of our customers, please contact that customer directly. If you contact us, we will assist the customer in handling your request in accordance with our obligations.

What personal data do we collect?

Depending on your interaction with us, we process the following categories of personal data:

We collect only the personal data needed for the relevant purpose. Please avoid including sensitive personal information, passwords or confidential customer data in general website enquiries.

If an activity requires special categories of personal data, we will provide any necessary additional information and establish an appropriate legal basis before processing it.

Where does your personal data come from?

We receive personal data:

Where we obtain personal data indirectly, we provide the information required by the GDPR within the applicable timeframe—normally within one month, or earlier if we first contact you or disclose your data before then—unless a lawful exception applies.

Why do we process your personal data?

We use personal data for the purposes below. The legal basis depends on the activity and your relationship with us.

PurposePersonal data involvedLegal basis
Responding to enquiries, arranging appointments and preparing quotationsContact details, correspondence and information about your requestSteps requested before entering into a contract, under Article 6(1)(b), where you are the prospective contracting party. Otherwise, our legitimate interest in responding to enquiries and developing business relationships, under Article 6(1)(f).
Delivering services and administering individual customer contractsContact, contract, account and service informationPerformance of a contract with you, under Article 6(1)(b).
Managing relationships with representatives of corporate customers and suppliersProfessional contact details, correspondence and administrative informationOur legitimate interest in providing services and managing business relationships, under Article 6(1)(f).
Providing support and managing service communicationsContact details, support requests and relevant technical informationPerformance of a contract with you, where applicable; otherwise, our legitimate interest in supporting customers and maintaining services.
Operating and protecting our website and systemsTechnical information, access records and security logsOur legitimate interest in maintaining reliable services, preventing misuse and protecting data and systems, under Article 6(1)(f).
Accounting, invoicing and meeting applicable legal requirementsTransaction, invoice and relevant contact informationCompliance with legal obligations, under Article 6(1)(c), including applicable accounting and tax requirements.
Establishing, exercising or defending legal claimsRelevant correspondence, contractual and transaction recordsOur legitimate interest in protecting our legal rights, under Article 6(1)(f).
Sending optional newsletters or promotional emails, if offeredContact details, preferences and consent recordsYour consent, under Article 6(1)(a), except where the applicable existing-customer exception permits marketing of our own similar services, supported by our legitimate interest.
Using optional analytics, marketing or other non-essential tracking technologies, if enabledOnline identifiers, usage information and preferencesYour consent, under Article 6(1)(a), together with the consent required by electronic communications legislation.

Where we rely on legitimate interests, we assess the necessity of the processing and its impact on your rights and freedoms.

We do not treat visiting our website or accepting this policy as consent to optional processing.

If we intend to use your personal data for a new purpose, we will provide the necessary information before doing so and obtain consent where required.

Do you have to provide personal data?

You can generally browse our website without submitting contact details. Certain technical information is processed to deliver and secure the website.

When you contact us or request a service, we need enough information to respond, identify the relevant organisation and fulfil your request. Required fields are identified on the relevant form. If you do not provide required information, we may be unable to answer your enquiry, arrange an appointment, enter into a contract or provide the requested service.

Where information is required by law or contract, we will explain that requirement when collecting it.

Optional marketing consent and consent to non-essential cookies are voluntary.

Cookies and similar technologies

WordPress and cookies

Our website uses WordPress. Depending on the features you use, WordPress may use cookies for authentication, session management and preferences. Authentication cookies apply to users accessing a login area; they are not necessarily set for ordinary website visitors.

We use strictly necessary cookies without consent only where they are required to transmit communications or provide a service you expressly request. Any non-essential cookies or similar tracking technologies require your prior consent. Their purposes, providers and durations are described in our cookie information.

You can manage cookies through your browser settings. Blocking necessary cookies may prevent certain requested features from working.

For privacy questions or requests, contact info@cloud-power.eu.

You can also manage cookies through your browser. Blocking necessary cookies may affect features you request.

Our approach follows the CNPD’s guidance on cookies and similar technologies.

Marketing communications

Where we send promotional communications, we obtain your consent unless a specific legal exception applies.

Where permitted, we may use contact details obtained from an existing customer relationship to promote our own similar products or services, provided we offered a clear, free opportunity to object when collecting the details and in each subsequent message.

You can unsubscribe using the link in a marketing email or contact us using the details in Section 1.

You may object to direct marketing at any time. We will stop using your personal data for that purpose, including any related profiling.

We may retain minimal information on a suppression list to ensure that we respect your choice.

Necessary service, security and contractual communications are separate from optional marketing. This distinction reflects the CNPD’s guidance on customer communications.

Who receives your personal data?

Access is limited to people and organisations that need the information for the purposes described in this policy.

Depending on the activity, recipients include:

Providers acting as our processors must process personal data under our instructions and appropriate contractual obligations, including confidentiality and security requirements.

Some recipients, such as public authorities or certain professional advisers, act as independent controllers for their own processing.

International transfers

Personal data is processed in Gravelines. Certain providers or their authorised personnel may process or access data outside the European Economic Area (“EEA”).

Where a destination or recipient is covered by an applicable European Commission adequacy decision, we rely on that decision.

Otherwise, we use appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, and assess whether additional measures are necessary to protect the data.

You can contact us to obtain information about the relevant safeguards and a copy of applicable contractual safeguards, subject to necessary redactions.

These arrangements must meet the requirements described in the CNPD’s international transfer guidance.

How long do we retain personal data?

We retain personal data only for as long as necessary for its purpose, including applicable legal requirements.

Data categoryRetention period or criteria
Enquiries and appointment records that do not result in a contract30 days after the enquiry is resolved or the last substantive interaction.
Customer, supplier and contractual recordsFor the relationship’s duration, followed by the applicable statutory retention period or relevant legal claims period.
Accounting records and supporting documentsGenerally ten years where Luxembourg accounting requirements apply, calculated according to the applicable statutory rules.
Support records730 days after closure, unless specified records are needed for a continuing contractual obligation or legal claim.
Website and security logs60 days, with relevant extracts retained longer where necessary to investigate an identified incident or legal claim.
Marketing recordsUntil consent is withdrawn, an objection is received or 120 days, whichever applies first.
Consent and suppression recordsLimited records retained for the period necessary to demonstrate compliance and respect your choices.
Cookies and related analytics dataThe durations stated in our cookie information. Cookie expiry and retention of associated server-side data may differ.
Backup copiesRemoved through our documented backup rotation within 360 days, subject to justified legal holds.

Luxembourg’s general accounting retention requirements are described on Guichet.lu.

Where a dispute, investigation or legal preservation obligation requires longer retention, we limit retention to the relevant information and restrict its use accordingly.

When retention is no longer justified, we delete the data or irreversibly anonymise it.

For data processed on behalf of customers, retention, return and deletion follow the customer’s instructions and the applicable data processing agreement.

How do we protect personal data?

We apply technical and organisational measures appropriate to the risks of processing.

Access is limited according to responsibilities and operational need. We review safeguards as our systems, services and risks evolve.

Where a personal data breach occurs, we assess it and notify the competent authority and affected individuals where required by law.

Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights:

To exercise your rights, contact us using Section 1. Please describe your request and the relevant interaction with Cloud Power.

If we have reasonable doubts about your identity, we may request only the additional information necessary to verify it.

We respond without undue delay and normally within one month of receiving your request. Where necessary because of its complexity or the number of requests, we may extend that period by up to two further months. We will explain any extension within the first month.

Requests are normally free. Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse it, as permitted by the GDPR. If we cannot fulfil a request, we will explain why and inform you of your complaint and judicial remedy options.

These rights and response requirements are set out in Chapter III of the GDPR.

Automated decision-making and profiling

We do not use personal data covered by this policy to make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

Any optional profiling for marketing or analytics must be described in the relevant disclosure before it begins.

Children’s personal data

Our website and business services are intended for professional users and are not directed at children.

If you believe a child has provided personal data through our website, please contact us so that we can assess the situation and take appropriate action.

Third-party websites and services

Our website may contain links to third-party websites or services. Those organisations are responsible for their own processing, as described in their privacy notices.

Where a third-party service is embedded within our website, the applicable data collection, recipient and consent information is provided through our privacy and cookie disclosures.

Complaints

You may contact us about a privacy concern using the details in Section 1.

You also have the right to lodge a complaint with a competent supervisory authority, particularly in the EEA country where you habitually reside, work or where the alleged infringement occurred. You do not have to contact us first to exercise that right.

In Luxembourg, the supervisory authority is:

Commission nationale pour la protection des données (CNPD)
Service des réclamations
15, Boulevard du Jazz
L-4370 Belvaux
Luxembourg

Complaint information and the online form are available on the CNPD website.

Changes to this policy

We may update this policy to reflect changes in our processing activities or legal requirements. The current version will remain accessible on our website, with its update date shown above.

Where required, we will notify you of material changes and obtain fresh consent before starting processing that requires it. Updating this policy does not itself constitute your consent.