Privacy Policy & Data Protection Notice
Transparent information on the processing of personal data in accordance with Articles 12, 13, and 14 of the EU GDPR.
1. Data Controller & Data Protection Officer
The data controller responsible for the processing of personal data on this website and across our sovereign cloud platform under the General Data Protection Regulation (GDPR) is:
Sovereign Cloud Platform
Jurisdiction: European Union
Platform Lead: Aram Haroyan
Email: [email protected] · [email protected]
Data Protection Officer (DPO)
We have designated an external Data Protection Officer pursuant to Art. 37 GDPR. You can contact our Data Protection Officer directly regarding any privacy inquiries or to exercise your rights:
Okustera Cloud
Attn: Data Protection Officer
Direct Email: [email protected]
2. Sovereign Architecture & Zero Third-Country Transfers
Okustera Cloud is architected specifically to solve European data sovereignty concerns resulting from the CJEU Schrems II ruling (Case C-311/18) and the extraterritorial reach of the United States CLOUD Act (18 U.S.C. § 2713):
- 100% In-Country European Datacenters: All compute nodes (KVM), block storage (Ceph NVMe), object storage (S3-compatible RGW), and network routers (OVN) operate exclusively in certified tier-3/4 datacenters located within the European Economic Area.
- Zero Third-Country Exposure: We do not transfer personal data or customer workload data to third countries outside the EEA without an adequacy decision. Specifically, zero customer data is transferred to the United States.
- Independent EU Governance: Okustera Cloud is governed exclusively by European Union law and GDPR, free from foreign holding structures that could be subject to extraterritorial discovery orders.
- Customer-Managed Keys (CMK): Workload data at rest is protected with AES-256 encryption via OpenStack Barbican KMS. Customers retain the option to hold independent cryptographic master keys, preventing any unauthorized decryption by infrastructure operators.
3. Legal Bases for Processing
We process personal data strictly in accordance with Article 6(1) of the GDPR:
| Legal Basis | Category of Processing | Purpose & Description |
|---|---|---|
| Art. 6(1)(a) GDPR (Consent) |
Newsletter, consultation briefs, functional cookies | Voluntary opt-in submissions for architectural reviews, webinars, or non-essential browser preferences. |
| Art. 6(1)(b) GDPR (Contract) |
Console accounts, API provisioning, billing | Fulfillment of Master Service Agreements, cloud tenancy configuration, authentication tokens. |
| Art. 6(1)(c) GDPR (Legal Obligation) |
Invoices, statutory audit logs, tax compliance | Retention of commercial transaction records under German HGB (§ 257) and AO (§ 147). |
| Art. 6(1)(f) GDPR (Legitimate Interest) |
Server access logs, DDoS defense, system integrity | Securing infrastructure against unauthorized intrusions, cyberattacks, and maintaining cluster stability. |
4. Data Collected on Our Website & Services
A. Server Log Files
When accessing our web endpoints, our web servers (Nginx) automatically record technical access logs necessary to deliver the site and prevent cyber threats:
- Browser user-agent, operating system, and screen resolution.
- Referrer URL (previously visited website).
- Requested URI path and HTTP status code.
- Date and time of server request.
- Client IP address (anonymized or retained for a maximum of 7 days strictly for security analysis, DDoS mitigation, and intrusion detection pursuant to Art. 6(1)(f) GDPR).
B. Cookies and Local Storage
Our public marketing website operates without third-party advertising cookies or cross-site tracking scripts. We utilize local browser storage strictly for functional UI preferences:
okustera-theme: Stores 'light' or 'dark' UI preference to prevent screen flickering (§ 25 Abs. 2 Nr. 2 TDDDG).okustera-cookie-consent: Stores your cookie consent choices to fulfill audit documentation requirements (Art. 6(1)(c) GDPR).
Detailed information is available in our dedicated Cookie Policy.
C. Architectural Consultations & Contact Inquiries
If you submit a consultation request (e.g. via our Sovereign Architecture Review briefing form), we collect your name, institutional/business email, organization, jurisdiction, and primary architectural priority. This data is processed exclusively to coordinate your requested briefing (Art. 6(1)(b) and Art. 6(1)(a) GDPR) and is never sold or shared with third-party advertisers.
5. Cloud Platform Workloads & Data Processor Role (Art. 28 GDPR)
When enterprise customers utilize the Okustera Cloud Platform (e.g., deploying Virtual Machines, Kubernetes clusters, DBaaS instances, or AI inference endpoints):
- Customer is Data Controller: The customer remains the sole data controller for all personal data stored, processed, or transmitted through their tenant cloud resources.
- Okustera is Data Processor: Okustera processes customer workload data strictly on documented customer instructions pursuant to Art. 28 GDPR. We execute a comprehensive Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag - AVV) including technical and organizational measures (TOMs).
- Zero Access to Plaintext Content: Okustera operators have no access to customer virtual disks or memory without explicit, time-bounded customer authorization for emergency operational support.
6. Data Retention & Deletion
We retain personal data only for as long as necessary to achieve the respective processing purposes or as mandated by statutory retention periods:
- Web Server Access Logs: Retained for 7 days, after which they are deleted or permanently anonymized.
- Consultation Inquiries: Deleted after 90 days if no contractual relationship or commercial negotiation ensues.
- Tenant Cloud Data: Deleted immediately upon customer instance termination or within 30 days of account cancellation pursuant to contract terms.
- Accounting & Invoicing Records: Retained for 6 to 10 years pursuant to German commercial and tax statutory requirements (§ 257 HGB, § 147 AO).
7. Your Statutory Rights as a Data Subject
Under Chapter III of the GDPR, you possess the following enforceable rights regarding your personal data:
8. Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.
Our lead supervisory authority is:
Alt-Moabit 59-61, 10555 Berlin, Germany
Website: https://www.datenschutz-berlin.de
9. Technical and Organizational Security Measures (Art. 32 GDPR)
We implement state-of-the-art technical and organizational measures (TOMs) to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:
- Encryption in Transit: TLS 1.3 with strict modern cipher suites, HSTS preloading, and automated certificate lifecycle.
- Encryption at Rest: LUKS volume encryption, Ceph NVMe dm-crypt, and Barbican KMS hardware security module integration.
- Network Segmentation: OVN Geneve encapsulation, microsegmentation, and zero cross-tenant packet leakage.
- Access Governance: Role-based access control (RBAC), multi-factor authentication (MFA), and audit logging.
- Continuous Vulnerability Management: Automated patch deployment, pre-commit secret scanning, and automated SAST verification.