Effective Date: January 1, 2026 · Form DPA-ENT-v4 · Compliance: GDPR, CCPA/CPRA, SOC 2
Corporate Data Confidentiality: MyCloudVault Workspaces operates strictly as a business service provider. Customer files, spreadsheets, presentations, and team documents are encrypted both in transit (TLS 1.3) and at rest (AES-256). MyCloudVault does not inspect, sell, sample, or monetize customer files under any circumstances.
1. Scope & Commercial Purpose
This Privacy Statement and Data Processing Addendum (“DPA”) applies to corporate entities and business subscribers (“Customer” or “Tenant”) utilizing MyCloudVault Workspaces. MyCloudVault is a business-to-business (B2B) platform and does not offer consumer services or individual personal subscriptions.
2. Data Ownership and Tenant Isolation
All uploaded company files, team folders, metadata, and employee access records remain the exclusive property of the subscribing organization:
Logical Tenant Isolation: Each company workspace is segregated into a dedicated tenant namespace keyed by an organizational UUID (/workspace/{tenant_uuid}).
No Machine Learning Training: Customer documents and uploaded files are strictly excluded from AI model training or analytics.
Employee Data Access: Only authenticated personnel authorized by the Customer’s corporate IT administrator can access shared team folders.
3. GDPR Article 28 Processor Commitments
Under Regulation (EU) 2016/679 (GDPR), MyCloudVault acts exclusively as a Data Processor on behalf of the Customer (the Data Controller).
Processing is performed solely to provide file hosting, sync, and workspace collaboration as instructed by Customer.
Customer administrators retain full capability to export, delete, or modify user workspaces and files at any time.
Data residency options allow organizations to restrict file storage to designated regional cloud availability zones (e.g. EU or US).
4. Inquiries & Privacy Office
Enterprise security officers, IT directors, and legal teams can direct compliance inquiries to: