Data Processing Agreement
PT Wastu Peladen Nusantara, operating as Cloudnan
Last updated: April 22, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between PT Wastu Peladen Nusantara ("Processor", "we", "us") and the customer ("Controller", "you") who uses the Cloudnan platform. It governs the processing of personal data that the Controller submits to the Service in the course of using Cloudnan, and fulfils the requirements of Article 28 of the General Data Protection Regulation (GDPR).
1. Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person that the Controller submits to the Service.
- "Processing" — any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
- "GDPR" — the General Data Protection Regulation (EU) 2016/679 and, where applicable, the UK GDPR.
- "Sub-processor" — any third party engaged by the Processor to carry out Processing on behalf of the Controller.
2. Scope and Purpose of Processing
The Processor shall process Personal Data only:
- on documented instructions from the Controller (including as set out in the Terms of Service),
- to the extent necessary to provide and operate the Cloudnan Service, and
- in compliance with applicable data protection law.
The subject-matter, duration, nature, and purpose of the processing, the type of personal data, and the categories of data subjects are described in Annex 1 at the end of this DPA.
3. Processor Obligations
The Processor shall:
- Process Personal Data only on the documented instructions of the Controller.
- Ensure that persons authorised to process Personal Data have committed to confidentiality.
- Implement appropriate technical and organisational security measures (Article 32 GDPR).
- Respect the conditions for engaging Sub-processors set out in Section 5.
- Assist the Controller in fulfilling its obligations to respond to data subject requests.
- Assist the Controller in ensuring compliance with Articles 32–36 GDPR (security, breach notification, DPIA).
- Delete or return all Personal Data at the end of service provision, at the Controller's choice.
- Provide all information necessary to demonstrate compliance and allow for audits.
4. Security Measures
The Processor maintains the following technical and organisational measures:
- Encryption of data in transit (TLS 1.2+) and at rest
- Access controls and role-based permissions
- Regular security assessments and vulnerability scanning
- Incident response and breach notification procedures
- Logical isolation of customer data
5. Sub-processors
The Controller provides general written authorisation for the use of Sub-processors. The Processor shall inform the Controller of any intended changes to Sub-processors (additions or replacements) with at least 14 days' notice, giving the Controller the opportunity to object. Current Sub-processors are listed in our GDPR page.
The Processor shall impose equivalent data protection obligations on all Sub-processors by written contract.
6. International Transfers
Where Personal Data is transferred from the EEA or UK to a third country (including to Indonesia where our infrastructure is based), such transfers are made under the Standard Contractual Clauses (Module Two: Controller to Processor) adopted by the European Commission in Decision 2021/914, which are incorporated into this DPA by reference.
7. Data Breach Notification
The Processor shall notify the Controller without undue delay — and in any event within 72 hours of becoming aware — of a Personal Data breach affecting the Controller's data. The notification shall include the information required under Article 33(3) GDPR to the extent available.
8. Requesting This DPA
Business customers who require a countersigned DPA for their GDPR compliance records may request one by emailing [email protected] with the subject "DPA Request". We will provide a signed copy within 10 business days.
Annex 1 — Details of Processing
Subject-matter
Provision of the Cloudnan server fleet management platform.
Duration
For the term of the subscription agreement plus any retention period required by law.
Nature and purpose
Storage, transmission, and display of server metrics, command outputs, and user account data for the purpose of operating the Service.
Types of Personal Data
Name, email, IP addresses, server hostnames, system metrics, command logs, and any other data the Controller chooses to transmit via the Service.
Categories of data subjects
Employees or contractors of the Controller who use the Cloudnan dashboard or whose servers are managed through the platform.
