Okustera Logo Okustera
  • Home
  • About Us
  • Why Choose Us
  • Whitepaper
Docs Cloud Console
General Data Protection Regulation (GDPR / DSGVO)

Privacy Policy & Data Protection Notice

Transparent information on the processing of personal data in accordance with Articles 12, 13, and 14 of the EU GDPR.

1. Data Controller & Data Protection Officer

The data controller responsible for the processing of personal data on this website and across our sovereign cloud platform under the General Data Protection Regulation (GDPR) is:

Okustera Cloud
Sovereign Cloud Platform
Jurisdiction: European Union
Platform Lead: Aram Haroyan
Email: [email protected] · [email protected]

Data Protection Officer (DPO)

We have designated an external Data Protection Officer pursuant to Art. 37 GDPR. You can contact our Data Protection Officer directly regarding any privacy inquiries or to exercise your rights:

Data Protection Officer (Datenschutzbeauftragter)
Okustera Cloud
Attn: Data Protection Officer
Direct Email: [email protected]

2. Sovereign Architecture & Zero Third-Country Transfers

Okustera Cloud is architected specifically to solve European data sovereignty concerns resulting from the CJEU Schrems II ruling (Case C-311/18) and the extraterritorial reach of the United States CLOUD Act (18 U.S.C. § 2713):

  • 100% In-Country European Datacenters: All compute nodes (KVM), block storage (Ceph NVMe), object storage (S3-compatible RGW), and network routers (OVN) operate exclusively in certified tier-3/4 datacenters located within the European Economic Area.
  • Zero Third-Country Exposure: We do not transfer personal data or customer workload data to third countries outside the EEA without an adequacy decision. Specifically, zero customer data is transferred to the United States.
  • Independent EU Governance: Okustera Cloud is governed exclusively by European Union law and GDPR, free from foreign holding structures that could be subject to extraterritorial discovery orders.
  • Customer-Managed Keys (CMK): Workload data at rest is protected with AES-256 encryption via OpenStack Barbican KMS. Customers retain the option to hold independent cryptographic master keys, preventing any unauthorized decryption by infrastructure operators.

3. Legal Bases for Processing

We process personal data strictly in accordance with Article 6(1) of the GDPR:

Legal Basis Category of Processing Purpose & Description
Art. 6(1)(a) GDPR
(Consent)
Newsletter, consultation briefs, functional cookies Voluntary opt-in submissions for architectural reviews, webinars, or non-essential browser preferences.
Art. 6(1)(b) GDPR
(Contract)
Console accounts, API provisioning, billing Fulfillment of Master Service Agreements, cloud tenancy configuration, authentication tokens.
Art. 6(1)(c) GDPR
(Legal Obligation)
Invoices, statutory audit logs, tax compliance Retention of commercial transaction records under German HGB (§ 257) and AO (§ 147).
Art. 6(1)(f) GDPR
(Legitimate Interest)
Server access logs, DDoS defense, system integrity Securing infrastructure against unauthorized intrusions, cyberattacks, and maintaining cluster stability.

4. Data Collected on Our Website & Services

A. Server Log Files

When accessing our web endpoints, our web servers (Nginx) automatically record technical access logs necessary to deliver the site and prevent cyber threats:

  • Browser user-agent, operating system, and screen resolution.
  • Referrer URL (previously visited website).
  • Requested URI path and HTTP status code.
  • Date and time of server request.
  • Client IP address (anonymized or retained for a maximum of 7 days strictly for security analysis, DDoS mitigation, and intrusion detection pursuant to Art. 6(1)(f) GDPR).

B. Cookies and Local Storage

Our public marketing website operates without third-party advertising cookies or cross-site tracking scripts. We utilize local browser storage strictly for functional UI preferences:

  • okustera-theme: Stores 'light' or 'dark' UI preference to prevent screen flickering (§ 25 Abs. 2 Nr. 2 TDDDG).
  • okustera-cookie-consent: Stores your cookie consent choices to fulfill audit documentation requirements (Art. 6(1)(c) GDPR).

Detailed information is available in our dedicated Cookie Policy.

C. Architectural Consultations & Contact Inquiries

If you submit a consultation request (e.g. via our Sovereign Architecture Review briefing form), we collect your name, institutional/business email, organization, jurisdiction, and primary architectural priority. This data is processed exclusively to coordinate your requested briefing (Art. 6(1)(b) and Art. 6(1)(a) GDPR) and is never sold or shared with third-party advertisers.

5. Cloud Platform Workloads & Data Processor Role (Art. 28 GDPR)

When enterprise customers utilize the Okustera Cloud Platform (e.g., deploying Virtual Machines, Kubernetes clusters, DBaaS instances, or AI inference endpoints):

  • Customer is Data Controller: The customer remains the sole data controller for all personal data stored, processed, or transmitted through their tenant cloud resources.
  • Okustera is Data Processor: Okustera processes customer workload data strictly on documented customer instructions pursuant to Art. 28 GDPR. We execute a comprehensive Data Processing Agreement (DPA / Auftragsverarbeitungsvertrag - AVV) including technical and organizational measures (TOMs).
  • Zero Access to Plaintext Content: Okustera operators have no access to customer virtual disks or memory without explicit, time-bounded customer authorization for emergency operational support.

6. Data Retention & Deletion

We retain personal data only for as long as necessary to achieve the respective processing purposes or as mandated by statutory retention periods:

  • Web Server Access Logs: Retained for 7 days, after which they are deleted or permanently anonymized.
  • Consultation Inquiries: Deleted after 90 days if no contractual relationship or commercial negotiation ensues.
  • Tenant Cloud Data: Deleted immediately upon customer instance termination or within 30 days of account cancellation pursuant to contract terms.
  • Accounting & Invoicing Records: Retained for 6 to 10 years pursuant to German commercial and tax statutory requirements (§ 257 HGB, § 147 AO).

7. Your Statutory Rights as a Data Subject

Under Chapter III of the GDPR, you possess the following enforceable rights regarding your personal data:

Right of Access (Art. 15 GDPR)
You have the right to obtain confirmation and full information regarding whether and which personal data we process concerning you.
Right to Rectification (Art. 16 GDPR)
You have the right to demand the immediate correction of inaccurate or incomplete personal data.
Right to Erasure / Forgotten (Art. 17 GDPR)
You have the right to request the deletion of your personal data where statutory prerequisites are satisfied.
Right to Restriction (Art. 18 GDPR)
You have the right to request restriction of processing while accuracy or legitimacy is being verified.
Right to Data Portability (Art. 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Object (Art. 21 GDPR)
You have the right to object at any time to processing based on legitimate interest (Art. 6(1)(f) GDPR).
How to exercise your rights: To exercise any of these statutory rights, please send an informal email to our Data Protection Officer at [email protected] or write to our postal address. We will respond within one month in accordance with Art. 12(3) GDPR.

8. Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement.

Our lead supervisory authority is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59-61, 10555 Berlin, Germany
Website: https://www.datenschutz-berlin.de

9. Technical and Organizational Security Measures (Art. 32 GDPR)

We implement state-of-the-art technical and organizational measures (TOMs) to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:

  • Encryption in Transit: TLS 1.3 with strict modern cipher suites, HSTS preloading, and automated certificate lifecycle.
  • Encryption at Rest: LUKS volume encryption, Ceph NVMe dm-crypt, and Barbican KMS hardware security module integration.
  • Network Segmentation: OVN Geneve encapsulation, microsegmentation, and zero cross-tenant packet leakage.
  • Access Governance: Role-based access control (RBAC), multi-factor authentication (MFA), and audit logging.
  • Continuous Vulnerability Management: Automated patch deployment, pre-commit secret scanning, and automated SAST verification.
Okustera Logo Okustera

The Sovereign Cloud Operating System. Pure open standards, upstream Kubernetes, OVN VPCs, and Ceph NVMe storage engineered under European jurisdiction.

Region: RegionOne · Host: ns570036 · EU Sovereign
100% IN-COUNTRY 0€ EGRESS TAX
Platform
  • Architecture
  • Cloud Catalog
  • AI Model Foundry
  • Why Choose Us
  • About Okustera
Sovereignty & Trust
  • Sovereignty Whitepaper
  • Compliance Matrix
  • AWS vs Sovereign
  • ZTNA Console
Developers
  • Documentation
  • CLI Simulator
  • LLMs Context
  • Full LLMs Spec
  • Cloud Console
Legal & Compliance
  • Terms of Service (MSA)
  • Privacy Policy (GDPR)
  • Cookie Policy
  • Impressum (Legal Notice)
  • Cookie Settings

Sovereign Jurisdiction: Okustera Cloud is governed strictly under European Union jurisdiction with 100% in-country infrastructure and zero US CLOUD Act exposure.

VMware, AWS, DeepSeek, Proxmox, and other third-party trademarks are the property of their respective owners. Okustera is not affiliated with or endorsed by these entities.

© Okustera Cloud. All rights reserved. Sovereign Cloud Infrastructure.
Terms Privacy Cookies Impressum Sitemap
Privacy & Cookie Preferences 100% EU HOSTED

We use strictly necessary local storage to ensure website functionality and remember your theme choice. We do not use third-party advertising cookies or cross-site trackers. Learn more in our Cookie Policy and Privacy Policy.