Our commitment to transparency. Last updated: March 15, 2026.
CloudSync Solutions AG ("CloudSync," "we," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our website, desktop agent, and API (collectively, the "Services").
Account data: Email address, name, organization name, and billing information when you create an account or subscribe to a paid plan.
File metadata: File names, sizes, modification timestamps, and folder structure. This metadata is necessary to provide sync functionality.
File content: Your files are encrypted on your device using AES-256-GCM before being transmitted to our servers. We store only the encrypted ciphertext. Due to our zero-knowledge architecture, we cannot access or read your file content.
Usage data: Sync agent version, operating system, device type, IP address, and aggregate usage statistics (storage used, files synced). We do not track individual file access patterns.
Cookies: Essential cookies for authentication and session management. Optional analytics cookies (see Cookie Policy).
We use your data exclusively to provide, maintain, and improve the Services. Specifically: to authenticate your identity, sync your files across devices, process payments, send transactional emails (account verification, billing receipts, security alerts), and monitor service health.
We do not sell, rent, or share your personal data with third parties for advertising purposes. We do not use your data for profiling or automated decision-making.
Your encrypted files are stored on infrastructure hosted in Switzerland and the European Union. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Our infrastructure is SOC 2 Type II audited and ISO 27001 certified.
We retain your data for as long as your account is active. Upon account deletion, all data (including encrypted file content and metadata) is permanently erased within 30 days.
Under the General Data Protection Regulation, you have the right to: access your personal data, rectify inaccurate data, request erasure ("right to be forgotten"), restrict processing, data portability, and object to processing. To exercise these rights, contact privacy@cloudsync.io.
Data Protection Officer: privacy@cloudsync.io
CloudSync Solutions AG, Bahnhofstrasse 21, 8001 Zurich, Switzerland.
By using CloudSync Services, you agree to these Terms of Service. If you are using the Services on behalf of an organization, you agree to these terms on behalf of that organization.
CloudSync provides file synchronization, backup, and sharing services through desktop agents, a web interface, and a REST API. The desktop agent runs as a background service, periodically synchronizing designated folders with CloudSync's encrypted storage infrastructure.
You are responsible for maintaining the confidentiality of your account credentials and encryption keys. CloudSync cannot recover your encryption keys if lost — this is a fundamental property of our zero-knowledge design. We strongly recommend enabling two-factor authentication and maintaining a secure backup of your recovery key.
You agree not to use the Services to store or distribute malware, infringing content, or illegal material. We reserve the right to suspend accounts that violate these terms. Due to our zero-knowledge encryption, we cannot proactively scan file content; enforcement relies on reports and account-level signals.
We target 99.9% uptime for Free and Pro plans, 99.95% for Business, and 99.99% for Enterprise (with SLA). Scheduled maintenance windows are communicated 72 hours in advance via email and the status page. The desktop agent is designed to gracefully handle connectivity interruptions, queuing changes locally until the connection is restored.
These Terms are governed by the laws of Switzerland. Any disputes shall be resolved in the courts of the Canton of Zurich.
For Business and Enterprise customers processing personal data under GDPR, we offer a pre-signed Data Processing Agreement that covers: lawful basis for processing, sub-processor disclosures, data breach notification procedures (within 72 hours), cross-border transfer mechanisms (Standard Contractual Clauses), and technical/organizational security measures.
Our current sub-processors: Hetzner (infrastructure, DE/FI), Stripe (payments, US/EU), Postmark (transactional email, US), Sentry (error monitoring, EU). A full list with processing purposes is available upon request.
To request a signed DPA, email legal@cloudsync.io with your organization name and CloudSync account email.