24RACKS CLOUD S.L.
Data Processing Terms
Framework for personal data hosted on a Customer’s behalf.
Purpose and roles
Where 24racks hosts or processes personal data on the Customer’s behalf, the Customer is controller and 24racks is processor. The object, duration, nature and purpose are limited to providing the ordered Service and documented controller instructions.
Data, instructions and confidentiality
Data types and data-subject categories depend on Customer content. 24racks processes it only on lawful documented instructions unless law requires otherwise. It binds authorised people to confidentiality and applies appropriate security measures.
Assistance, subprocessors and end of service
24racks reasonably assists with data-subject rights, security, breaches, impact assessments and prior consultation, and will notify known breaches in its scope without undue delay. At the end of the Service, data is returned or erased as instructed unless retention is legally required. Subprocessors and international transfers require Article 28 GDPR safeguards and applicable mechanisms.
Audits must be agreed so they do not compromise security, confidentiality or other customers’ continuity. LEGAL_REVIEW_REQUIRED: this item must be validated and, where appropriate, completed by legal counsel before final publication. The audit process, notice, costs and confirmed subprocessors need agreement.