FluidstackOpen roles

Legal

Data Protection

Last Updated: May 23, 2025

This Data Protection Policy is incorporated into the Terms and Conditions and Terms of Supply between the Fluidstack entity listed in your Order (or FLUIDSTACK LTD, a company incorporated and registered in England with company number 10985545 and registered address at Third Floor, 20 Old Bailey, London, EC4M 7AN, United Kingdom, and headquartered at 780 3rd Avenue, New York, NY 10017, United States) (Fluidstack) and the individual or entity named in the Order with Fluidstack (Customer or Third-Party Provider).

1. Definitions

Defined terms in the Terms and Conditions or Terms of Supply apply to this Policy. In addition, in this Data Protection Addendum the following definitions have the meanings given below:

Applicable Law means applicable laws of the European Union (EU), the European Economic Area (EEA) or any of the EU or EEA's member states from time to time together with applicable laws in the United Kingdom from time to time;

Appropriate Safeguards means such legally enforceable mechanism(s) for transfers of Personal Data as may be permitted under Data Protection Laws from time to time;

Business Contact Information means the names, mailing addresses, email addresses, and phone numbers regarding the other party's employees or consultants including such information regarding the other party's suppliers and customers, used as part of maintaining its business relationships.

Controller, Data Controller and Data Processor have the meanings given to such terms in Data Protection Laws.

Data Protection Laws means (a) in the United Kingdom: (i) the Data Protection Act 2018; and (ii) the GDPR, and/or any corresponding or equivalent national laws or regulations; (b) in member states of the European Union (EU) and/or European Economic Area (EEA): the GDPR and all relevant EU and EEA member state laws or regulations giving effect to or corresponding with any of the GDPR; and (c) any Applicable Laws replacing, amending, extending, re-enacting or consolidating any of the above Data Protection Laws from time to time.

Data Protection Losses means all liabilities, including all: (a) costs (including legal costs), claims, demands, actions, settlements, interest, charges, procedures, expenses, losses and damages (including relating to material or non-material damage); and (b) to the extent permitted by Applicable Law: (i) administrative fines, penalties, sanctions, liabilities or other remedies imposed by a Supervisory Authority; (ii) compensation which is ordered by a Supervisory Authority to be paid to a Data Subject; and (iii) the reasonable costs of compliance with investigations by a Supervisory Authority.

Data Subject has the meaning given to that term in Data Protection Laws.

Data Subject Request a request made by a Data Subject to exercise any rights of Data Subjects under Data Protection Laws.

GDPR the General Data Protection Regulation, Regulation (EU) 2016/679.

International Organisation means an organisation and its subordinate bodies governed by public international law, or any other body which is set up by, or on the basis of, an agreement between two or more countries.

International Recipient (a) any countries outside the United Kingdom and/or the European Economic Area; or (b) any International Organisation(s).

List of Sub-Processors the latest version of the list of Sub-Processors used by Data Processor, as updated and notified to Data Controller by Data Processor from time-to-time, including on its website.

Personal Data has the meaning given to that term in Data Protection Laws.

Personal Data Breach any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Protected Data.

Processing has the meanings given to that term in Data Protection Laws (and related terms such as 'process' have corresponding meanings).

Processing Instructions has the meaning given to that term in paragraph 3.1(a).

Processor has the meaning given to that term in Data Protection Laws.

Protected Data means Personal Data in the Customer Data.

Sub-Processor means another Processor engaged by Data Processor for carrying out processing activities in respect of the Protected Data on behalf of Data Controller.

Supervisory Authority means any local, national or multinational agency, department, official, parliament, public or statutory person or any government or professional body, regulatory or supervisory authority, board or other body responsible for administering Data Protection Laws.

2. Processor and Controller

3. Instructions and details of processing

4. Technical and organisational measures

5. Using staff and other processors

6. Assistance with compliance and Data Subject rights

provided Data Controller will pay Data Processor for all work, time, costs and expenses incurred in connection with providing the assistance in this paragraph 6.2, calculated on a time and materials basis at the Data Processor's standard pricing terms, as notified to Data Controller by Data Processor from time-to-time.

7. International data transfers

8. Information and audit

9. Breach notification

10. Deletion of Protected Data and copies

11. Compensation and claims

12. Data Controller obligations

13. Survival

Appendix 1 - Data processing details

Subject-matter of processing: 

Performance of respective rights and obligations under the Terms and Conditions or Terms of Supply and delivery and receipt of the Services under the Terms and Conditions or Terms of Supply.

Duration of the processing: 

Until the earlier of final termination or final expiry of the Terms and Conditions or Terms of Supply, except as otherwise expressly stated in the Terms and Conditions or Terms of Supply.

Nature and purpose of the processing: 

Processing in accordance with the rights and obligations of the parties under the Terms and Conditions or Terms of Supply; processing as reasonably required to provide the Services; and/or processing as initiated, requested or instructed by Customer in a manner consistent with the Terms and Conditions or Terms of Supply.

Type of Personal Data: 

Includes any types of Protected Data uploaded to the cloud infrastructure.

Categories of Data Subjects: 

Includes any Data Subject about whom Protected Data is uploaded to the cloud infrastructure.

Special categories of Personal Data:

Not applicable.

Individuals can submit a request about their own personal information — including access, correction, and deletion — through our privacy request form.