GDPR Compliance

cloak.business is fully compliant with the EU General Data Protection Regulation. All data is processed in Germany with comprehensive data protection measures.

GDPR Compliance Features

EU Data Residency

All PII processing and temporary storage happens on servers physically located in Nuremberg, Germany. Data never crosses EU borders — no transfers to the US, UK, or any third country.

DPA Available

Data Processing Agreement available for all Business and Enterprise customers. The DPA covers sub-processors, data categories, retention periods, technical measures, and breach notification obligations.

Data Subject Rights

Full support for data subject rights: access, rectification, erasure, restriction, portability, and right to object. Requests processed within 30 days as required by Article 12 GDPR.

Data Export

Export your account data in JSON format at any time from Account Settings. Includes all presets, entity configurations, and processing history for the last 90 days.

Your Rights Under GDPR

Right to Access: Request a complete copy of all personal data we hold about you
Right to Rectification: Correct inaccurate data
Right to Erasure: Request deletion of your account and all associated personal data
Right to Portability: Receive your data in a machine-readable format (JSON) for transfer to another service
Right to Object: Object to processing based on our legitimate interests
Right to Restrict: Limit how we use your data

Need a Data Processing Agreement?

Enterprise customers can request our standard DPA.