DRAFT — NOT APPROVED Review copy only. Not effective, not legal advice and not ready for customer reliance or consent.
Rocky Cloud Hub
EN DE

Privacy and data-processing review draft

Rocky Cloud Hub Privacy Information

This working draft maps the intended website, request, checkout and service-processing disclosures. It must be reconciled with the actual architecture, processor list, retention schedule and Swiss legal review before approval.

Status
Not effective — privacy approval pending
Document version
rocky-privacy-2026-08-25

Print using your browser’s print command. The layout is prepared for A4/PDF output.

1. Controller and contact

The intended controller for product enquiries, orders and customer administration is Rocky Consulting GmbH. The verified registered address, privacy contact, commercial-register details and representative must be inserted before this notice is approved.

Until a dedicated approved contact is published, privacy questions should be routed through the Rocky Cloud Hub contact page. This draft must not be used as evidence that a request channel or statutory response process is already finalised.

2. Scope and roles

This notice is intended to cover the Rocky Cloud Hub marketing pages, price calculator, demo and trial requests, B2B checkout, subscription administration and provider-side operations.

For personal data placed in a customer workspace, the customer will generally determine purposes and access while Rocky Consulting GmbH acts in the role agreed with that customer. The final allocation of controller/processor roles and any required data-processing agreement must be approved for each service scope.

3. Data collected

Enquiry and trial data may include company, business contact name, work email, optional telephone number, team size, selected plan/options, notes, language, consent evidence, request reference and technical anti-abuse signals.

Order administration may additionally include billing name and address, tax identifiers, selected recurring plan, billing interval, server-calculated amounts, Stripe customer/session/subscription identifiers, payment state and webhook event references. Rocky Cloud Hub does not intend to receive or store full payment-card numbers; Stripe hosts the payment form.

Service operations may involve authorised-user details, authentication and access logs, support correspondence, configuration, audit events and customer content according to the ordered workspace and customer instructions.

4. Purposes

Data is intended to be used to answer enquiries, prepare trials and quotes, validate B2B authority, calculate and process orders, administer subscriptions, provide and secure the workspace, perform migration/onboarding, deliver support, prevent abuse, maintain auditability and meet applicable accounting or legal obligations.

Contact consent for an enquiry is not newsletter consent. Analytics or advertising use must remain separately consented where required and must not be inferred from a demo, trial or order request.

5. Legal bases — approval required

The intended bases may include steps requested before a B2B contract, performance of an approved contract, compliance with legal obligations, consent where appropriate and proportionate legitimate business or security interests. The exact Swiss Federal Act on Data Protection and, where applicable, GDPR analysis must be completed by qualified counsel.

No legal basis, balancing test or jurisdictional conclusion should be inferred from this draft. The final notice must identify the bases that actually apply to each processing purpose and affected person.

6. Swiss collaboration data and separate payment processing

For Swiss deployments, customer content and core collaboration workloads are intended to be hosted in Swiss data centres. This scoped statement does not mean that every item of personal data in the commercial relationship stays in Switzerland.

Stripe processes checkout, billing and payment information under its own privacy framework and may process data internationally. Stripe determines final tax from the billing address before payment. The final processor disclosure must identify the contracted Stripe entity, transfer mechanism, relevant locations and approved privacy link.

7. Other recipients and subprocessors

Potential recipient categories include approved Swiss infrastructure operators, email delivery, support and monitoring providers, migration specialists, professional advisers, authorities where legally required and customer-selected integrations.

The final notice and, where applicable, data-processing agreement must contain or link to a verified current processor/subprocessor list, describe functions and locations, and explain the notification or objection process for material changes.

8. Cookies, local storage and analytics

Strictly necessary storage may be used for security, session, language, form-state and checkout continuity. Non-essential analytics, attribution or advertising technologies must not load before the required consent is obtained.

The approved cookie inventory must identify each technology, provider, purpose, duration and withdrawal method. Rejecting optional analytics must not prevent a customer from submitting a business enquiry or purchasing an otherwise eligible standard plan.

9. Retention and deletion — schedule incomplete

Enquiry, trial, order, contract, accounting, security, mail-queue and support records require purpose-specific retention periods. Unsuccessful enquiries should not be retained indefinitely, while accounting and contractual records may need longer retention.

Exact durations, deletion/anonymisation triggers, backup handling, litigation holds and customer-workspace return/deletion procedures remain to be approved and inserted. A generic indefinite-retention statement is not acceptable for the final notice.

10. Security and incident handling

Intended controls include access limitation, role separation, encryption in transit, protected credentials, audit logging, anti-abuse controls, backups, operational monitoring and verified payment webhooks. The final notice must reflect controls actually deployed and must not imply a certification or guarantee that has not been verified.

Internal incident assessment, customer notification and legally required authority-notification procedures must be documented separately and aligned with contractual roles.

11. Individual rights and requests

Depending on applicable law and role allocation, individuals may have rights relating to access, correction, deletion, restriction, objection, portability, consent withdrawal and complaint to a competent supervisory authority.

The final notice must provide a verified request channel, identity-verification process, response ownership and explanation of limitations. Withdrawal of optional consent should be as easy as giving it and does not retroactively invalidate earlier lawful processing.

12. Automated decisions, children, changes and effective date

The intended B2B order flow does not rely on solely automated decisions with legal or similarly significant effects. Anti-abuse screening and server-side eligibility checks may route a configuration to manual review. This statement must be verified against production behaviour.

Rocky Cloud Hub is a business service and is not directed to children. The final notice requires an effective date, change-notification process, archived versions and an approved method for communicating material changes to customers.

Draft prepared for internal privacy, security, operational and legal approval. It is not legal advice and must not be presented as an effective privacy notice.
Rocky Cloud Hub Pricing B2B terms draft