GDPR & Privacy Policy

How OptiCloud protects your data and respects your rights

Introduction

OptiCloud, operated by Solutia s.r.o., is committed to protecting the privacy and personal data of our users in full compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Czech data protection legislation.

This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have regarding your data. OptiCloud is designed with privacy-by-design and privacy-by-default principles at its core.

Data Controller

Company: Solutia s.r.o.

EU Registration: CZ.01.01.02/01/24_054/0004809

Address: Czech Republic, EU

Data Protection Contact: privacy@solutia.cz

What Data We Collect

OptiCloud collects and processes the following categories of personal data:

Identity & Account Data

Name, email address, role, department — provided during account creation via Keycloak SSO. Used for authentication and RBAC.

Cloud Cost & Resource Data

Billing data, resource metadata, and usage metrics from connected cloud providers (OCI, Azure, AWS, GCP). This data may contain project names and cost center identifiers.

Application Usage Data

Actions performed within OptiCloud: service requests submitted, approvals, provisioning events. Recorded in the audit trail for compliance.

Technical & Log Data

IP addresses, browser type, session tokens, API request logs. Collected automatically for security monitoring and performance optimization.

Purpose of Data Processing

  • Providing multi-cloud cost management, billing aggregation, and resource provisioning services
  • Authenticating users and enforcing role-based access control (10 RBAC roles)
  • Maintaining a complete audit trail for ISO/IEC 27001 compliance and regulatory requirements
  • Generating cost reports, dashboards, and budget alerts for authorized users
  • Monitoring system performance, security, and ensuring 99.9% SLA availability

Legal Basis for Processing

Contract Performance (Art. 6(1)(b))

Processing necessary to provide the OptiCloud service as contracted with your organization.

Legitimate Interest (Art. 6(1)(f))

Security monitoring, fraud prevention, and system performance optimization.

Legal Obligation (Art. 6(1)(c))

Maintaining audit trails and financial records as required by law.

Consent (Art. 6(1)(a))

Where applicable, for optional analytics and communication preferences.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:

7 years

Audit trail & compliance logs

3 years

Cost & billing records

90 days

Technical logs & sessions

Security Measures

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Authentication via Keycloak SSO with 2FA (TOTP) for privileged roles (SuperAdmin, CloudAdmin, SecurityOfficer)
  • Role-based access control with 10 configurable roles — users only see data relevant to their role
  • All infrastructure hosted within the European Union (EU-hosted data centers)
  • Regular security assessments, penetration testing, and vulnerability scanning
  • ISO/IEC 27001 aligned security controls and incident response procedures

Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR. To exercise any of these rights, contact privacy@solutia.cz:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request deletion of your data ('right to be forgotten'), subject to legal retention requirements.

Right to Restrict Processing (Art. 18)

Request limitation of data processing in certain circumstances.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interest.

Right to Lodge a Complaint (Art. 77)

File a complaint with your national data protection authority.

International Data Transfers

OptiCloud infrastructure is hosted entirely within the European Union. When connecting to external cloud providers (OCI, Azure, AWS, GCP), only billing metadata and resource identifiers are transmitted via encrypted API calls. No personal user data is transferred outside the EU. Where cloud provider APIs involve non-EU endpoints, appropriate safeguards (Standard Contractual Clauses) are in place.

Contact & Complaints

If you have questions about this privacy policy or wish to exercise your data protection rights, please contact us:

Email: privacy@solutia.cz

Supervisory Authority: Office for Personal Data Protection of the Czech Republic (ÚOOÚ)

Last updated: March 2026