Legal

Our commitment to transparency. Last updated: March 15, 2026.

Privacy Policy Terms of Service Data Processing Agreement Cookie Policy

Privacy Policy

CloudSync Solutions AG ("CloudSync," "we," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your personal data when you use our website, desktop agent, and API (collectively, the "Services").

1. Data We Collect

Account data: Email address, name, organization name, and billing information when you create an account or subscribe to a paid plan.

File metadata: File names, sizes, modification timestamps, and folder structure. This metadata is necessary to provide sync functionality.

File content: Your files are encrypted on your device using AES-256-GCM before being transmitted to our servers. We store only the encrypted ciphertext. Due to our zero-knowledge architecture, we cannot access or read your file content.

Usage data: Sync agent version, operating system, device type, IP address, and aggregate usage statistics (storage used, files synced). We do not track individual file access patterns.

Cookies: Essential cookies for authentication and session management. Optional analytics cookies (see Cookie Policy).

2. How We Use Your Data

We use your data exclusively to provide, maintain, and improve the Services. Specifically: to authenticate your identity, sync your files across devices, process payments, send transactional emails (account verification, billing receipts, security alerts), and monitor service health.

We do not sell, rent, or share your personal data with third parties for advertising purposes. We do not use your data for profiling or automated decision-making.

3. Data Storage & Security

Your encrypted files are stored on infrastructure hosted in Switzerland and the European Union. All data is encrypted at rest (AES-256) and in transit (TLS 1.3). Our infrastructure is SOC 2 Type II audited and ISO 27001 certified.

We retain your data for as long as your account is active. Upon account deletion, all data (including encrypted file content and metadata) is permanently erased within 30 days.

4. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the right to: access your personal data, rectify inaccurate data, request erasure ("right to be forgotten"), restrict processing, data portability, and object to processing. To exercise these rights, contact privacy@cloudsync.io.

5. Contact

Data Protection Officer: privacy@cloudsync.io
CloudSync Solutions AG, Bahnhofstrasse 21, 8001 Zurich, Switzerland.

Terms of Service

By using CloudSync Services, you agree to these Terms of Service. If you are using the Services on behalf of an organization, you agree to these terms on behalf of that organization.

1. Service Description

CloudSync provides file synchronization, backup, and sharing services through desktop agents, a web interface, and a REST API. The desktop agent runs as a background service, periodically synchronizing designated folders with CloudSync's encrypted storage infrastructure.

2. Account Responsibilities

You are responsible for maintaining the confidentiality of your account credentials and encryption keys. CloudSync cannot recover your encryption keys if lost — this is a fundamental property of our zero-knowledge design. We strongly recommend enabling two-factor authentication and maintaining a secure backup of your recovery key.

3. Acceptable Use

You agree not to use the Services to store or distribute malware, infringing content, or illegal material. We reserve the right to suspend accounts that violate these terms. Due to our zero-knowledge encryption, we cannot proactively scan file content; enforcement relies on reports and account-level signals.

4. Service Availability

We target 99.9% uptime for Free and Pro plans, 99.95% for Business, and 99.99% for Enterprise (with SLA). Scheduled maintenance windows are communicated 72 hours in advance via email and the status page. The desktop agent is designed to gracefully handle connectivity interruptions, queuing changes locally until the connection is restored.

5. Governing Law

These Terms are governed by the laws of Switzerland. Any disputes shall be resolved in the courts of the Canton of Zurich.

Data Processing Agreement

For Business and Enterprise customers processing personal data under GDPR, we offer a pre-signed Data Processing Agreement that covers: lawful basis for processing, sub-processor disclosures, data breach notification procedures (within 72 hours), cross-border transfer mechanisms (Standard Contractual Clauses), and technical/organizational security measures.

Our current sub-processors: Hetzner (infrastructure, DE/FI), Stripe (payments, US/EU), Postmark (transactional email, US), Sentry (error monitoring, EU). A full list with processing purposes is available upon request.

To request a signed DPA, email legal@cloudsync.io with your organization name and CloudSync account email.

Cookie Policy

We use cookies to provide core functionality and, with your consent, to understand how our website is used.

CookieTypePurposeDuration
cs_sessionEssentialAuthentication sessionSession
cs_csrfEssentialCSRF protectionSession
cs_cookiesEssentialCookie consent preference1 year
_cs_analyticsAnalyticsAnonymous usage statistics (self-hosted Plausible)1 year

We use self-hosted Plausible Analytics, which does not use cookies by default and does not track individuals across sites. The analytics cookie is only set if you explicitly accept analytics cookies. You can change your preference at any time using the cookie banner or by emailing privacy@cloudsync.io.