UK GDPR compliance

Privacy policy

Cloud VGP treats the protection of personal data belonging to its customers, prospects and visitors as a priority. This policy explains transparently how your data is collected, used, protected and how long it is retained.

Last updated: 13 July 2026 — Version 2.0 — Hosting in the UK and the European Union

1. Introduction

Cloud VGP publishes the SaaS platform “Contrôle Réglementaire”, dedicated to managing statutory inspection and the regulatory compliance of work equipment. In the course of its activities, Cloud VGP collects and processes personal data in accordance with the UK GDPR, the Data Protection Act 2018 and Regulation (EU) 2016/679.

This policy applies to processing carried out through cloud-vgp.net, including downloads of the Corporate Book.

2. Data controller

Controller
Cloud VGP
Address
STATION F, 5 Parvis Alan Turing, 75013 Paris — France
Company number / VAT
923 025 274 00013 — FR53 923 025 274
Responsible officer & data contact
Michael Halabi
Contact
cloud.vgp@gmail.com

3. Data we collect

We only collect data that is strictly necessary for the purposes described below (data minimisation). No special category data within the meaning of Article 9 of the UK GDPR is collected.

  • Identification: first name, surname, business email, telephone, company — legitimate interests or performance of a contract, retained for the relationship + 3 years.
  • Account & sign-in: username, hashed password, connection logs — performance of a contract, retained for the life of the account + 12 months.
  • Operational data: assets, inspection reports, schedules, field photographs — performance of a contract, retained for the contract term and associated legal obligations (up to 10 years).
  • Billing: address, VAT number, invoicing history — legal obligation, retained for 10 years.
  • Browsing: pages viewed, duration, device, anonymised IP — consent, 13 months maximum.
  • Support & contact: messages and email exchanges — legitimate interests, 3 years after the last contact.

4. Purposes & lawful bases

  • Creating, managing and securing your user account — performance of a contract.
  • Delivering the service: asset management, report generation, scheduling — performance of a contract.
  • Invoicing, accounting and tax obligations — legal obligation.
  • Customer support and responding to your enquiries — legitimate interests.
  • Service improvement and anonymised usage statistics — legitimate interests.
  • Targeted B2B marketing — legitimate interests, with a right to object.
  • Audience measurement and non-essential cookies — consent.

5. Recipients & processors

Your data is accessible to authorised Cloud VGP teams (sales, support, engineering) on a strict need-to-know basis. To deliver the service we rely on a limited number of processors, all contractually bound to data protection obligations.

  • Amazon Web Services EMEA — application and database hosting (United Kingdom and European Union).
  • Google Analytics 4 and Google Tag Manager (Google Ireland Ltd) — anonymised audience measurement (Ireland / United States, standard contractual clauses and the UK international data transfer addendum).
  • Stripe Payments Europe Ltd — payment processing (Ireland, standard contractual clauses).
  • Calendly LLC — booking of product demonstrations (United States, standard contractual clauses).
  • Resend, Inc. — transactional email delivery (United States, standard contractual clauses).

6. International transfers

Operational data is hosted exclusively within the United Kingdom and the European Union. Certain ancillary tools may transfer data to the United States; such transfers are covered by standard contractual clauses together with the UK international data transfer addendum and, where applicable, the Data Privacy Framework.

7. Retention

Retention periods are set out in section 3. At the end of those periods, data is permanently deleted or securely archived where a legal obligation requires it, in particular for accounting records.

8. Security

  • TLS 1.3 encryption for all communications.
  • Encryption at rest (AES-256) across all databases.
  • Hashed passwords (bcrypt / argon2) and multi-factor authentication available.
  • Strict role-based access control and row-level security.
  • Daily automated backups retained for 30 days, hosted in the UK and the EU.
  • Continuous logging and monitoring of sensitive access.
  • Regular security testing and prompt patching.

9. Your rights

Under the UK GDPR you have the right of access, rectification, erasure, restriction, data portability and the right to object, as well as the right not to be subject to solely automated decision-making.

To exercise your rights, write to cloud.vgp@gmail.com. We will respond within one month at the latest.

10. Cookies & trackers

cloud-vgp.net uses only cookies strictly necessary for its operation, together with audience-measurement cookies subject to your consent. You may withdraw consent at any time through your browser settings.

11. Children

The website and the platform are intended for business users only. We do not knowingly collect data relating to anyone under the age of 16.

12. Changes to this policy

This policy may be updated to reflect legal, technical or organisational developments. The date of the latest update appears at the top of this page.

13. Contact & complaints

For any question relating to your personal data: cloud.vgp@gmail.com.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — ico.org.uk.

See also : Legal notice