Data charter

Last updated: 19 August 2026

1. Company commitment

The Company undertakes to respect the principles of article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability.

2. Data protection by design and by default

In accordance with article 25 GDPR, data protection is built in from the design stage and guaranteed by default. Each major change to a service or system undergoes a prior review.

3. Records of processing activities

The Company maintains records in accordance with article 30 GDPR, listing all processing operations carried out under its responsibility and as processor.

4. Roles

4.1. Controller for data collected directly (prospects, clients, suppliers, candidates, website visitors, employees).

4.2. Processor within the meaning of article 28 GDPR for Client data hosted, backed up or administered under the Services.

5. Technical measures

6. Organisational measures

7. DPO

The Company has appointed a DPO in accordance with articles 37 to 39 GDPR. Contact: info@drjcloud.com.

8. Breach notification

The Company documents every breach and the measures taken.

9. DPIA

In accordance with article 35 GDPR, the Company conducts a prior impact assessment for any processing likely to result in a high risk. It is reviewed at each substantial change, and at least every 3 years.

10. International transfers

12. Cooperation with regulators

The Company cooperates actively with supervisory authorities and responds to their requests within the time limits they set.

13. Periodic review

The charter is reviewed annually by Management, under the supervision of the DPO. Any substantial change is communicated by appropriate means.