Purpose
This page explains the public data-processing position for vKloud / Proniit Cloud where personal information is handled through hosting, support, billing, partner enquiries, referral activity, demos, managed services or approved partner activity.
Roles
Where vKloud determines the purpose and means of processing personal information, vKloud acts as the responsible party. Where a service provider or approved partner processes personal information only on instructions, that party may act as an operator.
Processing instructions
- personal information should be processed only for the authorised purpose
- processing should follow written or recorded instructions where applicable
- personal information should not be used for independent marketing, profiling, enrichment, resale, list-building, scraping, retargeting, training datasets, AI model training, credit scoring, background checking, political communication or unrelated commercial activity unless separately authorised and lawful
Categories of personal information
- names and business names
- contact numbers, email addresses and physical addresses
- billing details and account details
- support records and communications
- client requirements and system access records
- user information and technical identifiers
- other information relating to an identifiable person or organisation
Security safeguards
- restricted access
- strong passwords and multi-factor authentication where available
- secure devices and secure storage
- encrypted or access-controlled transmission where practical
- prompt removal of access when no longer required
- protection against unauthorised access, loss, damage, destruction, alteration or disclosure
- incident reporting and evidence collection
Breach notification
Where a partner, operator or service provider becomes aware of actual or suspected unauthorised access, unauthorised disclosure, data loss, leaked credentials, malware infection, suspicious access, unlawful processing or a complaint involving personal information, vKloud should be notified without delay.
Sub-processing and cross-border transfer
Sub-processing and cross-border transfer of personal information should only happen under approved arrangements that maintain appropriate confidentiality, safeguards, return/deletion controls and applicable data-protection requirements.
Data subject requests
Requests, complaints, correction requests, deletion requests, opt-out requests, access requests or objections should be forwarded to vKloud where they relate to vKloud-controlled processing.
Return and deletion
When personal information is no longer required for the authorised purpose, it should be returned, deleted, destroyed, anonymised or stopped from further use as appropriate.