VxCloud
Security & Compliance
🌍

GDPR Ready

Data residency, DPAs, and privacy-by-design architecture

GDPR-ready, EU-hosted, documented to the letter

Data Processing Addendum available on request. EU data residency with Frankfurt, Paris, and Stockholm regions. Standard Contractual Clauses for international transfers. Privacy by design in every architecture decision.

EU-hosted
Frankfurt, Paris, Stockholm
DPA
Standard execution
SCCs 2021
For international transfers
Article 32
Security measures mapped

Overview

The EU General Data Protection Regulation (GDPR) is the most comprehensive privacy regulation globally, with extraterritorial reach to any organization processing EU residents' personal data. VxCloud supports GDPR compliance through EU-resident infrastructure, a standard Data Processing Addendum (DPA), Standard Contractual Clauses (SCCs) for international data transfers post-Schrems II, and privacy-by-design architecture aligned with Article 25.

EU data residency is available in Frankfurt (Germany), Paris (France), and Stockholm (Sweden) regions. Customer data, including backups and metadata, remains within the chosen region. For customers with EU-only requirements, personnel access controls restrict administrative access to EU-based staff. Article 32 security-of-processing measures are implemented and documented in our DPA annex.

What's included

Production-grade capabilities, ready to enable in your workspace.

Data Processing Addendum

Standard GDPR-compliant DPA available on execution. Custom DPAs negotiated for Enterprise customers.

EU data residency

Frankfurt, Paris, and Stockholm regions. Customer data, backups, and metadata stay within the chosen region.

Standard Contractual Clauses

2021 EU Commission SCCs for international data transfers, with post-Schrems II supplementary measures documented.

Data subject rights tooling

APIs for access, erasure, rectification, and portability requests. Meet Articles 15-20 programmatically.

Privacy by design

Article 25 privacy-by-design controls: data minimization, purpose limitation, pseudonymization, encryption.

Breach notification

72-hour breach notification commitment aligned with Article 33 supervisory authority timelines.

Business outcomes

Measurable impact teams see when they adopt gdpr ready.

3

EU regions with full residency

Frankfurt, Paris, Stockholm. Data and backups stay in-region; admin access can be EU-personnel-only for strict customers.

72 hr

Breach notification commitment

Our DPA commits to notifying the customer within 72 hours of confirmed breach, supporting your Article 33 timeline.

SCCs 2021

Current Standard Contractual Clauses

Executed under the 2021 European Commission SCCs with Module 2 (controller-to-processor) as the default.

Article 32

Security measures annex

DPA Annex II lists the specific technical and organizational measures protecting personal data — no generic prose.

How customers use it

Real scenarios from VxCloud customers across regulated industries and fast-moving teams.

EU SaaS

German SaaS selling to European enterprises

EU-only residency with personnel controls satisfies the strictest EU customers' vendor due diligence.

Global Enterprise

US enterprise serving EU customers post-Schrems II

SCCs + supplementary measures (encryption, access restrictions) documented in the DPA resolve Schrems II concerns.

AdTech

Advertising platform handling large-scale EU user data

Privacy-by-design tooling supports pseudonymization and data minimization at the architecture level, not retrofit.

Public Sector EU

EU member-state agency subject to national data-sovereignty laws

Regional residency + EU-only staff access + full DPA satisfies national sovereign-cloud requirements in multiple member states.

Frequently asked questions

Still have questions? Our enterprise team answers within one business day.

Our standard DPA is available through your CSM, sales contact, or self-service in the workspace admin panel. Most customers execute the standard version same-day. Custom DPAs with redlines are routed to our privacy team.

Related enterprise capabilities

Ready to move forward with GDPR Ready?

Talk to our enterprise team — we'll scope your requirements, map the right capabilities, and build a rollout plan tailored to your organization.