Legal
Privacy Notice
How Cloudlayer handles account, document, form, signature, payment, support, and website data, including choices and privacy rights.
This notice explains how Cloudlayer handles personal data when people visit cloudlayer.io, create or use an account, contact us, or interact with documents, forms, signing requests, and other workflows that a Cloudlayer customer operates. “Personal data” includes information that identifies or can reasonably be linked to a person.
Cloudlayer can have different legal roles depending on the data and the activity:
- Cloudlayer acts as a controller when it decides why and how to handle account administration, billing, security, support, service analytics, and its own website and communications.
- Cloudlayer acts as a processor or service provider when a customer submits content or operates a form, document, signature, delivery, storage, or integration workflow and determines the purpose of that processing. The customer is responsible for its instructions, notices, permissions, and legal basis.
The Data Processing Addendum governs processing for a customer when Cloudlayer acts on that customer’s behalf.
Who is responsible
“Cloudlayer,” “we,” and “us” mean the operator of cloudlayer.io and the Cloudlayer service identified in the applicable order, checkout record, or account.
Privacy questions and requests may be sent to privacy@cloudlayer.io. Service and account questions may be sent to support@cloudlayer.io.
Data we handle
The data involved depends on how the service is used.
| Category | Examples | Typical source |
|---|---|---|
| Account and organization data | Name, email address, authentication identifier, organization, workspace, membership, role, settings, and account status | The account holder, an inviting organization, or the authentication provider |
| Customer content | HTML, CSS, templates, uploaded files, assets, form definitions, variables, contacts, documents, images, videos, signing envelopes, and instructions | The customer or a customer-authorized integration |
| Respondent and signer data | Form answers, names, contact details, signatures, initials, consent records, routing information, authentication evidence, and event history | The respondent, signer, customer, or customer-authorized integration |
| Generated and captured material | Rendered files, webpage captures, extracted content, document metadata, job status, and output references | A customer request and the resulting Cloudlayer workflow |
| AI feature data | Prompts, selected source material, instructions, generated suggestions, output, and feedback when an AI feature is used | The customer and the applicable model service |
| Billing and commercial data | Plan, usage, billing contact, subscription, invoice, transaction, tax, and payment status | The customer and Stripe; payment-card entry is handled in Stripe-hosted controls |
| Device, usage, and security data | IP address, browser and device attributes, request time, route, identifiers, security signals, logs, audit events, and feature activity | The browser, device, Cloudlayer systems, and infrastructure providers |
| Support and communications data | Messages, attachments, chat content, preferences, and information needed to investigate a request | The person contacting us and the relevant account systems |
| Integration data | Authorization metadata, destination configuration, webhook events, delivery details, and external object references | The customer and the customer-selected integration |
We may receive data directly, from a customer or organization, from service providers listed in the Subprocessor List, or from a customer-directed system. We do not use a person’s contacts or customer content to infer unrelated personal profiles.
Why we use personal data
When Cloudlayer acts as controller, it uses personal data for the purposes and legal grounds below. The exact legal ground can vary by jurisdiction.
| Purpose | Typical legal ground |
|---|---|
| Provide accounts, contracted service, billing, support, and requested communications | Perform a contract or take requested pre-contract steps |
| Authenticate users; prevent fraud, abuse, and unauthorized access; protect service integrity | Legitimate interests in security and service protection; legal obligation where applicable |
| Operate, debug, maintain, and improve service reliability and usability | Legitimate interests in operating and improving the service, balanced against individual rights |
| Keep records, respond to legal process, enforce terms, and resolve disputes | Legal obligation and legitimate interests in establishing, exercising, or defending rights |
| Send product or commercial communications | Consent where required, or legitimate interests where permitted; every message includes applicable choices |
| Load optional analytics or support technology | Consent where required; optional categories remain off until selected |
When Cloudlayer acts as processor, the customer’s instructions and legal basis control. We process the data to provide, secure, support, and maintain the configured workflow; comply with documented lawful instructions; and meet legal obligations that apply to us.
Documents, forms, signatures, and captures
Customers decide what they collect, generate, capture, send, store, and sign. A customer must have the rights and permissions needed for source webpages, authentication credentials, cookies, files, personal data, form questions, recipients, and delivery destinations. Supplying a URL or technical access does not by itself establish a lawful right to capture or reuse material.
Cloudlayer processes customer content to execute the requested workflow. Customer documents, uploads, submissions, and signatures are not used for unrelated advertising. Cloudlayer does not place them in a public training or test corpus without the customer’s explicit permission.
AI features send only the content selected for that feature to the identified model service. Customers should not submit data to an AI feature unless they have authority to do so and have assessed whether the feature is appropriate. The AI Additional Terms describe responsibility for prompts and output.
Sharing and recipients
We disclose personal data only as needed for the purposes in this notice:
- to infrastructure, authentication, payment, email, analytics, support, AI, and other providers that help deliver the service;
- to a customer-directed storage provider, webhook, integration, recipient, respondent, or signer when the customer configures that flow;
- within an organization or workspace according to membership, role, sharing, and audit controls;
- to professional advisers, auditors, insurers, and authorities when reasonably necessary and legally permitted;
- in connection with a financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and notice requirements; or
- with the person’s direction or consent.
Cloudlayer does not sell personal data for money. Cloudlayer does not use personal data for cross-context behavioral advertising. If a future practice is treated as a “sale,” “sharing,” or targeted advertising under applicable law, Cloudlayer will provide the required notice and choice before enabling it.
Our maintained provider and destination disclosures are in the Subprocessor List.
International transfers
Cloudlayer and its providers may process data in the United States and other countries identified in the Subprocessor List. Where transfer law requires a safeguard, Cloudlayer uses an approved transfer mechanism, such as the European Commission Standard Contractual Clauses and, for restricted UK transfers, the applicable UK Addendum or International Data Transfer Agreement. Customers remain responsible for choosing customer-directed destinations and regions.
Cloudlayer does not promise that all data remains in one country or region unless an order expressly identifies a verified regional service and its scope.
Retention and deletion
We keep data only for as long as needed for the purpose described, the customer’s configured retention and deletion choices, contract performance, security, dispute resolution, and legal obligations.
- Account, organization, billing, and audit records follow the account lifecycle and applicable legal recordkeeping periods.
- Customer content and generated output follow the selected storage mode, workspace policy, deletion controls, trash or recovery period, and contract.
- Temporary job payloads and transient processing artifacts are removed on the service’s operational schedule after the job and recovery window no longer require them.
- Support and security records are retained for the period reasonably needed to resolve the matter and protect the service.
- Consent records are retained long enough to honor and demonstrate the person’s choice.
Deletion may be delayed for backups, fraud prevention, legal holds, billing records, or other legal obligations. During such a delay, use is restricted to the reason for retention. Aggregated or de-identified information may be retained when it cannot reasonably identify a person.
Security
Cloudlayer uses administrative, technical, and organizational measures designed for the nature and risk of the data. These include access controls, tenant scoping, encryption in transit and at rest where the service stores data, secret management, logging and audit controls, secure development, vulnerability management, backups, incident response, and provider review. See Security for the maintained security posture.
No service can guarantee absolute security. Customers must configure access, roles, sharing, retention, integrations, and source credentials appropriately for their use.
Cloudlayer has not enabled the service for protected health information or electronic protected health information. Do not submit PHI or ePHI unless Cloudlayer has expressly enabled an eligible service scope and executed the required agreement with the customer.
Privacy choices and rights
Depending on location and context, a person may have rights to:
- know whether and how personal data is processed;
- access or receive a copy of personal data;
- correct inaccurate personal data;
- delete personal data;
- object to or restrict certain processing;
- receive portable data in an available structured format;
- withdraw consent without affecting earlier lawful processing;
- opt out of a sale, sharing, targeted advertising, or qualifying profiling where applicable;
- appeal a denied request where applicable; and
- complain to a data protection or consumer protection authority.
Use in-product controls where available or email privacy@cloudlayer.io. Describe the account or interaction and the right you wish to exercise. We may verify identity and authority, request only the additional information reasonably needed, and use an authorized-agent process where law permits. We will not discriminate against a person for exercising a privacy right.
If Cloudlayer holds the data only for a customer, we may direct the person to that customer and help the customer respond under the DPA. Some requests may be limited by another person’s rights, legal privilege, security, fraud prevention, or recordkeeping law. We will explain an applicable denial and appeal route.
Automated decisions
Cloudlayer provides automation and AI-assisted tools, but does not use account or website data to make a solely automated decision that produces legal or similarly significant effects about an individual. Customers are responsible for any decisions they make using forms, documents, signatures, captures, generated content, or AI output and for providing legally required review or appeal.
Children
The service is for business users who can enter a binding contract and is not directed to children. A customer may not use Cloudlayer to collect children’s personal data unless the customer has a lawful basis, gives required notices, obtains required consent, and has written authorization from Cloudlayer for that use. Cloudlayer does not knowingly open accounts for children under 13.
Cookies and browser storage
Cloudlayer uses necessary browser storage for security, sign-in, service delivery, saved preferences, and privacy choices. Optional analytics and support tools are controlled by consent where required. The Cookie and Similar Technologies Notice identifies categories, purposes, providers, and controls.
The first privacy layer offers equally prominent one-click “Accept all” and “Reject all” actions plus “Choose options.” Continuing to browse, scrolling, or closing a page is not consent. You can reopen your choices through Settings in the app or Privacy choices in the site footer and reject every optional category there.
Changes to this notice
We may update this notice when processing, law, or the service changes. We will post the revised version and its effective date. If a change materially affects a consent-based purpose, category, or provider, Cloudlayer will request a new choice rather than treating continued browsing as consent. Contractual notice requirements remain governed by the applicable agreement.
How can you contact Cloudlayer or complain?
Email privacy@cloudlayer.io or write to Cloudlayer, 2769 Jefferson Davis Highway, Suite 111-1054, Stafford, Virginia 22554, United States.
People in the EEA or UK may also complain to the supervisory authority for their habitual residence, place of work, or the alleged infringement. People in jurisdictions with an attorney-general or privacy-agency complaint process may use that process as provided by law.