GDPR compliance for your self-hosted business apps

You stay the controller. Pilae acts as your processor under art. 28, signs the agreement, keeps your data in the EU or Switzerland, and helps you answer every data subject request.

Talk to our teamRequest the security pack

Law
Regulation (EU) 2016/679, the GDPR
Pilae role
Processor under art. 28, on your documented instructions
Hosting
Any of 12 Pilae Cloud regions, six in Switzerland and the EU, or your premises
Contact
privacy@pilae.com

What Pilae delivers as your GDPR processor

The GDPR makes you answerable for the personal data your apps hold. Art. 28 lets you use a processor only if it gives sufficient guarantees. These are the guarantees your contract contains.

An art. 28 data processing agreement

Subject matter, duration, purposes, categories of data and data subjects, and every clause art. 28(3) requires. Signed at onboarding, before any data moves.

Data in the EU or Switzerland

Choose a region in Switzerland or the EU, such as Zurich, Frankfurt or Gravelines, or your own premises, per app. Data, backups and logs stay in that region.

Security of processing under art. 32

Apps answer only on a private mesh behind one hardened gate on port 443. Encrypted disks and backups, named access, every action logged.

Breach notice under art. 33

A personal data breach affecting your apps is reported to you without undue delay, with the facts you need to notify your supervisory authority within 72 hours.

Data subject requests

Access, rectification, erasure, portability and restriction: we find a person's data across your apps, export it in open formats or delete it, on your instruction.

Sub-processors under your control

Every sub-processor is disclosed to you in the DPA with its role and location. Changes are notified in advance, and you can object.

Pilae as your processor under art. 28 of the GDPR

When Pilae operates your apps, we process personal data on your behalf. The GDPR calls your organisation the controller and Pilae the processor. Art. 28 says you may only use a processor that gives sufficient guarantees, bound by a written agreement that lists what it may do with the data.

Our data processing agreement is that agreement. It names the apps, the data, the purposes, the location and every sub-processor. It also covers the Swiss revised FADP, so an organisation with users in the EU and Switzerland signs one document. See the Swiss nLPD page for the Swiss side.

EU data residency, or Switzerland under an adequacy decision

You choose where each app runs. Pilae Cloud offers dedicated machines in 12 regions, six of them in Switzerland and the EU: Zurich, Frankfurt, Falkenstein, Gravelines, Amsterdam and Helsinki. They are hosted in ISO 27001-certified datacentres. Your data, backups and logs stay in the region you choose, with backups on a second site in the same jurisdiction. Data residency explains how the region is written into your contract.

Your own premises are also an option. The European Commission has recognised Switzerland as adequate since 2000 and confirmed it in January 2024, so data processed in Zurich needs no extra transfer tool. The six worldwide regions, London, Ashburn, Hillsboro, Singapore, Tokyo and Sydney, are there for teams that need them. If you place personal data in one of them, the transfer rules of chapter V apply: London benefits from an adequacy decision, and for the others the DPA attaches the standard contractual clauses. Where a sub-processor sits outside the EU and outside an adequate country, the DPA also attaches the standard contractual clauses adopted by the Commission in 2021.

Security of processing and breach notice

Art. 32 asks for security appropriate to the risk. Your apps answer only on a private network, run on hardened machines and are backed up daily, encrypted and offsite. Every change is planned, approved and recorded by the Pilae Agent, and every login and action lands in the audit log. The security page lists each control.

If a breach affects your data, we tell you without undue delay, with what happened, which data and people it touched, and what we have done. You then have what you need to notify your supervisory authority within the 72 hours art. 33 allows.

Data subject requests across every app

A person who asks for their data expects one answer, not one per system. Because your apps run on machines we operate, we can search the whole estate for a person’s records. We then export, correct or delete them on your instruction and record the result. Nextcloud, Keycloak and Open WebUI each export in open formats.

For a proposal covering your estate, see pricing or talk to us.

How we set up your GDPR file at onboarding

  1. Map the processing

    We list each app, the personal data it holds, the data subjects concerned and who uses it.

  2. Choose the location

    An EU country, Switzerland or your premises, per app. The choice is written into your contract.

  3. Sign the DPA

    Our standard agreement under art. 28, with the sub-processor list and the security annex, signed before migration starts.

  4. Hand over the records

    You receive the facts your art. 30 record and any impact assessment need: data categories, locations, recipients, retention and security measures.

What your contract includes

Processor agreement
Our standard DPA under art. 28 of the GDPR and art. 9 of the Swiss revised FADP, signed at onboarding.
Data location
Named per app in the contract. We do not move it without your written agreement.
Transfers
Standard contractual clauses for any sub-processor outside the EU and outside a country with an adequacy decision.
Breach notice
Without undue delay after we become aware of a breach affecting your data.
Assistance
Help with data subject requests, impact assessments and prior consultations, as art. 28(3) requires.
End of contract
Your data returned in open formats, then deleted from machines and backups, with written confirmation.

The apps behind it

Questions

Is Pilae GDPR certified?

No. Pilae does not hold a GDPR certification under art. 42. It meets its processor obligations through a signed art. 28 agreement, security measures built to ISO 27001 controls, and the notification and assistance commitments in the DPA.

Can a Swiss company process personal data for an EU organisation?

Yes. The European Commission recognises Switzerland as providing an adequate level of protection, and confirmed that decision in its January 2024 review. Personal data can flow from the EU to a processor in Switzerland without extra transfer tools. If you prefer, your data stays in an EU region such as Frankfurt, Falkenstein, Gravelines, Amsterdam or Helsinki.

Does my data stay inside the EU?

If you choose it, yes. Pilae Cloud has five EU regions, Frankfurt, Falkenstein, Gravelines, Amsterdam and Helsinki, plus Zurich. Your data, backups and logs stay in the region you choose, backups go to a second site in the same jurisdiction, and the region is named in your contract.

Who handles data subject requests?

You decide how to answer them, as the controller. Pilae finds the data across the apps we operate for you, then exports, corrects or deletes it on your instruction, and records what was done.

Which sub-processors could see personal data?

Your application data stays on dedicated machines in an ISO 27001-certified datacentre in the region you choose, or on your own servers. Supporting services are disclosed to you in the signed DPA with their role and location, and optional AI features are used only if you enable them.

Do you sign our own DPA?

Every plan includes our standard DPA. On Enterprise plans we review your own template and sign it where it matches how the service runs.

Related

Bring your GDPR questions to an engineer.

Thirty minutes with your data protection officer and one of our engineers: where each app will live, who the sub-processors are, and what the DPA says.