QuixiCloud GDPR & DPDPA Compliance Policy
Last Updated: July 10, 2026
Effective Date: May 1, 2026
1. Introduction
QuixiCloud Data Storage Private Limited ("QuixiCloud," "we," "us," or "our") is fundamentally committed to protecting your privacy. This policy outlines our compliance with applicable global privacy frameworks, specifically focusing on the European Union General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act (DPDPA). This document complements our Privacy Policy by detailing your legal rights and our specific obligations under these laws.
2. Scope
This Compliance Policy applies to all personal data collected and processed through:
- The QuixiCloud Web Platform
- QuixiCloud Android and Windows applications
- QuixiCloud WebDAV services and APIs
- Customer support and billing interactions
3. Roles and Responsibilities
To understand how your data is treated under the GDPR and DPDPA, it is important to clarify QuixiCloud's role depending on the context of the data being processed:
- QuixiCloud as a Data Controller / Data Fiduciary: When we collect your account information, billing details, support communications, and platform usage metadata to manage your account and administer the service, QuixiCloud acts as the Data Controller (GDPR) or Data Fiduciary (DPDPA).
- QuixiCloud as a Data Processor: When you upload and store your files on our servers, you are the Data Controller. QuixiCloud acts solely as the Data Processor. We process those files strictly on your behalf and only to provide the requested storage services.
4. Lawful Basis for Processing
When acting as a Data Controller, we process personal data based on one or more of the following lawful grounds:
- Performance of a Contract: Processing is necessary to provide the QuixiCloud service and fulfill our obligations under the Terms and Conditions (e.g., creating your account, processing payments).
- Compliance with Legal Obligations: Retaining certain billing or transaction records for tax and accounting purposes.
- Legitimate Interests: Monitoring system performance, preventing fraud, and ensuring network security.
- Consent: Where required by law, we will obtain your explicit consent before processing data for specific purposes (e.g., marketing communications). You may withdraw this consent at any time.
5. Categories of Personal Data Processed
As detailed in our Privacy Policy, we strictly minimize the data we collect. The categories of personal data processed may include:
- Account information (Name, Email)
- Contact and billing details
- Device and connection information
- Authentication logs (IP addresses, timestamps)
- Support requests and correspondence
- Usage metadata (Quotas, file sizes, directory structures)
Note: Customer file content is handled according to our secure storage and encryption architecture. Because of our encryption protocols, QuixiCloud generally cannot access or read the contents of the files you store as a Data Processor.
6. Data Subject Rights
Under the GDPR and DPDPA, you possess significant rights regarding your personal data. You have the right to:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Correction / Rectification: Request that we correct inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): Request the deletion of your account and personal data, subject to certain legal or operational retention requirements.
- Right to Restrict Processing: Request that we suspend the processing of your data in specific scenarios.
- Right to Object: Object to our processing of your data based on legitimate interests.
- Right to Data Portability: Request a copy of your data in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent: Withdraw consent for processing where consent was the lawful basis.
To exercise any of these rights, please contact our Privacy Officer (details in Section 12).
7. Cross-Border Data Transfers
QuixiCloud operates a global infrastructure. To provide our service, your personal data and encrypted files may be processed or stored in multiple regions, including India, Singapore, Europe, and the United States. We implement appropriate legal and technical safeguards for all international data transfers as required by applicable privacy laws.
8. Data Retention
We retain personal data only for as long as is strictly necessary to fulfill the purposes outlined in this policy:
- Active account data is retained while your subscription is valid.
- The storage lifecycle and specific file deletion processes (including the 7-day grace period and 30-day disaster recovery retention) are thoroughly detailed in our Terms & Conditions and Privacy Policy.
- Certain financial and transactional records may be retained for longer periods to comply with mandatory tax or legal obligations.
9. Security Measures
In accordance with GDPR Article 32 and corresponding DPDPA requirements, QuixiCloud implements robust technical and organizational measures to ensure a level of security appropriate to the risk. These include:
- Client-side encryption and secure streaming encryption
- TLS encryption for data in transit
- Strict logical access controls and Multi-Factor Authentication (MFA)
- Continuous monitoring and incident response capabilities
For extensive details, please review our Security Policy.
10. Data Breach Notification
In the highly unlikely event of a personal data breach that poses a risk to your rights and freedoms, QuixiCloud will respond in strict accordance with legal requirements. We will notify affected users and the competent data protection authorities or regulatory bodies without undue delay, outlining the nature of the breach, potential consequences, and the mitigation measures we have taken.
11. Subprocessors
To deliver a globally scalable service, QuixiCloud may engage carefully selected third-party service providers (such as payment processors or physical infrastructure providers). These Subprocessors are contractually bound to protect your personal data in accordance with our strict privacy standards and all applicable legal obligations.
12. Contact Information & Complaints
If you wish to exercise your data subject rights, have questions about this policy, or wish to submit a complaint regarding our data practices, please contact our Data Protection Officer (DPO):
Privacy Officer / DPO: privacy@quixicloud.com
If you are a resident of the European Economic Area (EEA) and feel that we have not addressed your concerns, you have the right to lodge a complaint with your local supervisory authority. Residents of India may approach the Data Protection Board of India under the DPDPA.