CloudPGP | Keystone Management Group LLC
GDPR and Data Protection Rights
1. Our approach to European data protection
CloudPGP is operated by Keystone Management Group LLC, a company based in the United States. We recognize that individuals in the European Economic Area (EEA) may have rights under Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), when the Regulation applies to our processing activities.
This page explains how to exercise those rights in connection with our public website, https://cloudpgp.com/. It supplements, and should be read alongside, our Privacy Policy and Cookie Policy.
It does not constitute a claim that every processing operation, hosting provider or encryption-service deployment has been independently certified as GDPR compliant.
2. Controller and contact details
For personal data collected and processed in connection with operation of the public CloudPGP website, the controller is:
Keystone Management Group LLC2220 County Road 210, Suite 108
Jacksonville, Florida 32259
United States
To submit a data-protection request, use the contact form at https://cloudpgp.com/contact/ or write to the address above. Do not include passwords, private keys or other confidential security credentials in your request.
If an EU representative is legally required for the relevant processing activities under Article 27 GDPR, the responsible entity must make that representative’s identity and contact details available to individuals and supervisory authorities through an appropriate notice. An American postal address alone is not a substitute for an EU representative where Article 27 applies.
3. Data covered by this notice
Website-related processing may involve information that you submit through forms, business contact and correspondence information, security and request logs, and cookie or privacy-preference records. The purposes, lawful bases, recipients, retention criteria and international-transfer information are described more fully in the Privacy Policy.
The public CloudPGP website is separate from the underlying encryption-service platform. Customer message content, encryption keys and service-account data are subject to the applicable contractual and service-specific privacy arrangements, which may allocate controller and processor responsibilities differently.
4. Your rights under GDPR
Where GDPR applies and the applicable conditions are met, you may exercise the following rights:
Access (Article 15)
Request confirmation of whether we process personal data about you, access to that data, and required information about its processing.
Rectification (Article 16)
Ask us to correct inaccurate information or complete incomplete information.
Erasure (Article 17)
Request deletion of personal data when a legal ground for erasure applies. Certain records may need to be retained for legal obligations or the establishment, exercise or defense of legal claims.
Restriction (Article 18)
Request that we restrict certain processing while a dispute about accuracy, lawfulness or another applicable condition is resolved.
Data portability (Article 20)
Where processing is based on consent or contract and carried out by automated means, request the data you provided in a structured, commonly used and machine-readable format, or request transmission to another controller where technically feasible.
Objection (Article 21)
Object, on grounds relating to your particular situation, to processing based on legitimate interests. You may object at any time to processing for direct marketing if it occurs.
Withdrawal of consent (Article 7)
Withdraw consent at any time, including through Cookie settings for consent-based website technologies. Withdrawal does not affect processing performed lawfully before withdrawal.
Automated decision-making (Article 22)
You have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects. We do not make such decisions using personal data submitted through our public website.
5. Making and receiving a request
Please describe the right you wish to exercise and provide enough information for us to locate the relevant data. We may request proportionate information to verify identity where necessary, but will not require unnecessary personal data.
We respond without undue delay and ordinarily within one month of receiving a valid request. Where permitted by GDPR, we may extend the period by up to two additional months because of complexity or volume, informing you of the extension and reasons within the initial month. Requests are generally free, subject to GDPR rules on manifestly unfounded or excessive requests.
If we cannot comply fully, we will explain the legal basis and available remedies as required.
6. Complaints and supervisory authorities
If you believe your personal data has been processed unlawfully, you may lodge a complaint with a competent data-protection supervisory authority, in particular in the EEA country of your habitual residence, place of work or alleged infringement. You may also seek a judicial remedy where available.
A directory of European data-protection authorities is available from the European Data Protection Board (external link).
7. International data transfers
Keystone is established in the United States, so information submitted through the website may be processed outside the EEA. Where restricted transfers take place, an applicable legal transfer mechanism and appropriate safeguards are required. These may include an adequacy decision covering the particular recipient, European Commission Standard Contractual Clauses, or another lawful mechanism where its conditions are satisfied. Additional technical and organizational measures may be necessary. See the Privacy Policy for additional information.
8. Security, minimization and retention
We aim to collect information proportionate to the purpose of each form, limit access to authorized parties, protect website communications and delete or anonymize information when retention is no longer justified. Retention criteria and the types of information processed are described in the Privacy Policy. We do not invite visitors to send private encryption keys or sensitive customer message content through public website forms.
9. Cookies and consent management
Where consent is required for nonessential cookies or similar tracking, those technologies must remain inactive until you make an affirmative choice. The Website must provide an accessible choice to reject them and a persistent Cookie settings function allowing later changes and withdrawal. Read our Cookie Policy.
10. Updates and contact
We will revise this page when material legal or processing changes make an update necessary. The effective date will be updated accordingly.
Keystone Management Group LLC2220 County Road 210, Suite 108
Jacksonville, Florida 32259
United States
Contact CloudPGP