Data processing
Data Processing
Last updated: 22 August 2026
This page summarises how Clonext processes personal data on behalf of our clients. When we host and operate a client's application, the client is the data controller and Clonext Cloud Computing S.L. acts as data processor under Article 28 of the GDPR. The binding terms are set out in the Data Processing Agreement (DPA) that forms part of each service agreement; this is a plain-language summary.
Subject matter and duration
We process personal data only to provide the hosted application and related support, for the duration of the service agreement.
Nature and purpose
Hosting, storage, backup, security and operation of the client's isolated instance, strictly on the client's documented instructions.
Types of data and data subjects
Determined by the client through the data they choose to store in their instance (for example their own users, customers or records). Clonext does not decide the purposes of that processing.
Our commitments
- Process personal data only on the client's documented instructions.
- Ensure that people authorised to process the data are bound by confidentiality.
- Apply appropriate technical and organisational security measures (Article 32 GDPR), including encryption, isolated per-client databases, encrypted backups and monitoring.
- Engage sub-processors only under equivalent data-protection obligations, and inform the client of changes.
- Assist the client with data-subject requests and with security, breach-notification and impact-assessment obligations.
- Delete or return personal data at the end of the service, and make available the information needed to demonstrate compliance.
Sub-processors
- Google Cloud — hosting and infrastructure (EU region by default).
Where a sub-processor operates outside the European Economic Area, transfers are covered by appropriate safeguards such as the Standard Contractual Clauses.
Contact
Data-protection queries: info@clonext.com.