GDPR
The EU General Data Protection Regulation ("GDPR") came into force across the European Union on 25th May 2018 and brought with it significant changes to data protection law. It requires any data processors and data controls to use the highest-possible privacy settings by default, so that the data is not available publicly without explicit, informed consent, and cannot be used to identify a subject without additional information stored separately.
We have taken all necessary measures to ensure that our products and services fully comply with GDPR. We will try to write in plain language because we want to communicate clearly with you. This document may therefore lack some of the precision of a formally prepared statement drafted by legal professionals, but it still represents our good faith effort to protect the personal data information of our customers.
Our product, CubeBackup, is a backup tool which helps Google Workspace and Microsoft 365 organizations back up their business data to self-hosted storage. We do not store any Google Workspace and Microsoft 365 data for our customers. By using CubeBackup, you are already standing on very solid ground.
CubeBackup GDPR Compliance Statement
Definitions
- "CubeBackup" means our business name, CubeBackup Inc.
- "Products" means the software distributed by CubeBackup.
- "Service" means the website https://www.cubebackup.com.
- "Customers" means the Google Workspace and Microsoft 365 organizations who uses our Products to backup their Google Workspace and Microsoft 365 data.
- "Personal data" means any personal data of Customers.
Our commitment
CubeBackup is committed to the compliance of GDPR. CubeBackup can specifically confirm the following:
No Google Workspace or Microsoft 365 data for any Google or Microsoft account of our Customers, including Google Drive files, Shared drives files, Gmail messages, Google Contacts, Google Calendar data, Google Sites files, OneDrive or SharePoint site data, Outlook Mail, Outlook Calendar or Outlook People data, is collected or stored by CubeBackup.
CubeBackup confirms that no personal data pertaining to a specific Google Workspace and Microsoft 365 account for any Customer is collected or stored by CubeBackup, except for the data listed in "Personal Data collected by CubeBackup".
No configuration settings, metadata, private key files or log files for our Products are collected or stored by CubeBackup, unless specifically provided by our Customers for technical support purposes.
CubeBackup does not share Customer information with any third parties.
Personal Data collected by CubeBackup
CubeBackup holds itself to high standards in handling and processing personal information. The small amount of data we collect at your consent is necessary to provide our products and services. Here is the data we collect and store:
Purchasing information
Name
Email address
Google Workspace or Microsoft 365 domain
Number of users
Purchase dateCookies
Cookies are used to facilitate and improve your experience on our website and products.
CubeBackup only collects the above data when Customers or representative of Customers purchase our Products or visit our website. CubeBackup does not collect any Personal data when Customers are using our Products.
To better understand how our approach to privacy ensures that we conform to the GDPR, please see our Privacy Policy and Cookie Policy.
Data Security
CubeBackup and our Products employ appropriate security measures to protect personal data against unauthorized access and accidental disclosure. The security measures cover:
SSL encryption for any Google and Microsoft API requests All data transferred between the Customer's private storage and Google Cloud / Microsoft Azure Cloud, is HTTPS/SSL encrypted.
AES encryption for backup data By default, all backup data is AES encrypted on the Customer's private storage. The private key for the AES encryption is also generated and stored on the Customer's private storage.
Google OAuth login Google domain-wide OAuth for authentication and authorization is used by our Product, so no password is required for Google APIs requests.
More information can be found at CubeBackup Security.
Personal Data Breach
CubeBackup shall notify Customers without undue delay on CubeBackup becoming aware of a personal data breach, and provide sufficient information to each Customer. CubeBackup must inform the applicable supervisory authorities as required by law and regulation.
Cookie policy
We use Cookies to facilitate and improve your experience of our Site and we have carefully chosen these Cookies and have taken steps to ensure that your privacy and personal data is protected and respected at all times.
To better understand how cookies are used, please see our Cookie Policy.
Contact CubeBackup Support
If you have any questions about our GDPR compliance, please contact our support team via [email protected]