Skip to main content

Privacy Policy

Last updated: January 15, 2026

Privacy Policy

Document owner: Chief Privacy Officer (CPO) Version: 3.0 Effective date: January 1, 2026 Last updated: January 15, 2026 Classification: Public — Trust Center Review cadence: Quarterly, and upon material changes to data processing activities or applicable law Company: Acme Cloud, Inc. Address: 1200 Market Street, Suite 400, San Francisco, CA 94103, USA Primary contacts: trust@acmecloud.com | security@acmecloud.com | privacy@acmecloud.com


Definitions

TermDefinition
CCPACalifornia Consumer Privacy Act, as amended by the CPRA
ControllerEntity determining purposes and means of personal data processing
CPRACalifornia Privacy Rights Act, amending the CCPA
Data SubjectIndividual whose personal data is processed
DPAData Processing Agreement governing processor activities
DSRData Subject Request, a request to exercise privacy rights
DPIAData Protection Impact Assessment
EEAEuropean Economic Area (EU member states plus Iceland, Liechtenstein, Norway)
GDPRGeneral Data Protection Regulation (EU) 2016/679
LGPDLei Geral de Proteção de Dados (Brazil General Data Protection Law)
PDPAPersonal Data Protection Act (Singapore, Thailand)
Personal DataInformation relating to an identified or identifiable natural person
PIPLPersonal Information Protection Law (China)
ProcessorEntity processing personal data on behalf of a Controller
SCCsStandard Contractual Clauses for international data transfers
Sensitive Personal DataSpecial categories including health, biometric, racial origin, religious beliefs
SubprocessorThird party engaged by a Processor to process Personal Data
UK GDPRUnited Kingdom General Data Protection Regulation

Scope and Applicability

1.1 Organizational Scope

This Privacy Policy applies to Acme Cloud, Inc. ("Acme Cloud," "we," "us," or "our"), a company incorporated in Delaware, USA, with principal offices at 1200 Market Street, Suite 400, San Francisco, CA 94103, USA. This policy governs the collection, use, storage, disclosure, and protection of Personal Data by Acme Cloud across all business operations, products, services, and corporate activities.

1.2 Service Scope

This Privacy Policy covers Personal Data processing activities related to:

Service CategoryScope DescriptionPrimary Data Subjects
Acme Cloud SaaS PlatformCloud-based compliance management softwareCustomer end users, customer employees
Customer SupportHelp desk, technical support, professional servicesCustomer administrators, end users
Sales and MarketingLead generation, communications, eventsProspects, website visitors, event attendees
Corporate Websiteacmecloud.com and subdomainsWebsite visitors, job applicants
EmploymentHR operations, benefits administrationEmployees, contractors, candidates
Vendor ManagementProcurement, partner relationshipsVendor contacts, partners

1.3 Geographic Applicability

This Privacy Policy is designed to comply with privacy regulations across jurisdictions where Acme Cloud operates or processes Personal Data:

JurisdictionApplicable LawSupervisory AuthorityLocal Representative
European UnionGDPRLead: Irish Data Protection CommissionAcme Cloud EU Ltd., Dublin, Ireland
United KingdomUK GDPR, Data Protection Act 2018Information Commissioner's OfficeAcme Cloud UK Ltd., London
United States (California)CCPA/CPRACalifornia Privacy Protection AgencyN/A (domestic)
United States (Other states)State privacy laws (Virginia, Colorado, etc.)State AG officesN/A (domestic)
BrazilLGPDANPDAcme Cloud Brasil Ltda., São Paulo
CanadaPIPEDA, provincial lawsOffice of the Privacy CommissionerAcme Cloud Canada Inc., Toronto
AustraliaPrivacy Act 1988OAICAcme Cloud Australia Pty Ltd., Sydney
SingaporePDPAPDPCAcme Cloud Singapore Pte. Ltd.

1.4 Data Subject Categories

CategoryRelationshipExample Data Collected
CustomersBusiness relationshipAccount information, usage data, billing
End UsersUse customer's Acme Cloud instanceAuthentication, activity logs
ProspectsMarketing engagementContact information, interaction history
Website VisitorsBrowse our websitesDevice information, analytics
Job ApplicantsApply for employmentResume, application materials
EmployeesEmployment relationshipHR data, payroll, benefits
VendorsBusiness relationshipContact information, payment details

Data Controller and Processor Roles

2.1 Role Determination Matrix

Processing ActivityAcme Cloud RoleCustomer RoleLegal Basis
Customer account managementControllerN/AContract performance
Platform usage by end usersProcessorControllerDPA terms
Customer support interactionsJoint ControllerJoint ControllerLegitimate interest
Marketing to customersControllerN/AConsent or legitimate interest
Analytics on platform usageController (aggregated)Controller (individual)Legitimate interest
Billing and paymentControllerN/AContract performance
Security monitoringProcessor/ControllerControllerLegal obligation, legitimate interest

2.2 Controller Responsibilities

When acting as a Data Controller, Acme Cloud:

1.1. Determines purposes and means of processing Personal Data 1.2. Establishes lawful basis for each processing activity 1.3. Provides privacy notices to Data Subjects 1.4. Responds to Data Subject rights requests 1.5. Conducts Data Protection Impact Assessments where required 1.6. Maintains records of processing activities 1.7. Implements appropriate technical and organizational security measures 1.8. Reports personal data breaches to supervisory authorities and affected individuals 1.9. Ensures lawful international data transfers

2.3 Processor Responsibilities

When acting as a Data Processor on behalf of Customers, Acme Cloud:

2.1. Processes Personal Data only on documented Customer instructions 2.2. Ensures persons authorized to process Personal Data are bound by confidentiality 2.3. Implements technical and organizational security measures per the DPA 2.4. Engages Subprocessors only with Customer authorization 2.5. Assists Customer in responding to Data Subject requests 2.6. Assists Customer with security, breach notification, and DPIAs 2.7. Deletes or returns Personal Data upon service termination 2.8. Makes available information demonstrating compliance 2.9. Permits and contributes to audits conducted by Customer or auditors


Personal Data Collection

3.1 Categories of Personal Data Collected

Data CategorySpecific Data ElementsCollection SourceRetention Default
Identity DataName, username, employee IDRegistration, SSOAccount lifetime + 30 days
Contact DataEmail, phone, mailing addressRegistration, CRMAccount lifetime + 30 days
Account DataLogin credentials, MFA devicesRegistrationAccount lifetime
Professional DataJob title, company, departmentRegistration, enrichmentAccount lifetime
Transaction DataSubscription, payments, invoicesPayment processor7 years (legal)
Technical DataIP address, device ID, browserAutomatic collection90 days (logs)
Usage DataFeatures used, actions taken, session dataPlatform analytics2 years (aggregated indefinite)
Profile DataPreferences, settings, configurationsUser inputAccount lifetime
Communication DataSupport tickets, emails, chatSupport interactions3 years
Marketing DataPreferences, campaign interactionsMarketing systemsUntil opt-out + 30 days

3.2 Collection Methods

MethodData CategoriesNotice ProvidedOpt-Out Available
Account registrationIdentity, Contact, AccountRegistration formN/A (required)
Website formsContact, Professional, MarketingForm disclosureYes
Cookies and trackingTechnical, UsageCookie bannerYes (non-essential)
Customer uploadsCustomer-determinedDPA termsPer customer policy
Third-party integrationsTechnical, UsageIntegration setupYes
Support interactionsCommunicationSupport termsN/A
Email campaignsMarketing, TechnicalUnsubscribe linkYes
Events and webinarsContact, ProfessionalRegistration formYes

3.3 Data Minimization Practices

Acme Cloud collects only Personal Data necessary for specified purposes:

PrincipleImplementationVerification
Purpose limitationData fields mapped to specific purposesAnnual privacy review
Collection minimizationOptional fields clearly markedForm design review
Storage limitationRetention schedules enforcedAutomated deletion
Access minimizationRole-based access controlsQuarterly access review
AccuracyCorrection mechanisms providedUser self-service

Lawful Basis for Processing

4.1 Legal Basis by Processing Activity

Processing ActivityPrimary Legal BasisAlternative BasisDocumentation
Account provisioningContract performanceN/ATerms of Service
Service deliveryContract performanceN/ATerms of Service
Customer supportContract performanceLegitimate interestSupport terms
Billing and collectionsContract performanceLegal obligationTerms of Service
Security monitoringLegitimate interestLegal obligationPrivacy Policy
Fraud preventionLegitimate interestLegal obligationPrivacy Policy
Product improvementLegitimate interestConsentPrivacy Policy
Marketing communicationsConsent (where required)Legitimate interestConsent records
Legal complianceLegal obligationN/ARegulatory requirements
EmploymentContract + legal obligationLegitimate interestEmployee privacy notice

4.2 Legitimate Interest Assessments

For processing based on legitimate interest, Acme Cloud conducts balancing tests:

PurposeAcme Cloud InterestData Subject ImpactSafeguardsBalance Outcome
Security monitoringProtect platform, customersMinimal (security logs)Retention limits, access controlsLegitimate interest upheld
AnalyticsImprove servicesMinimal (pseudonymized)Aggregation, opt-outLegitimate interest upheld
B2B marketingBusiness developmentLow (professional context)Opt-out, preference centerLegitimate interest upheld
Fraud detectionPrevent abuseMinimal (automated review)Human review for adverse decisionsLegitimate interest upheld

4.3 Consent Management

Where consent is the legal basis:

Consent TypeMechanismWithdrawal MethodRecord Keeping
Marketing emailsDouble opt-in checkboxUnsubscribe link, preference centerConsent timestamp, version
Non-essential cookiesCookie consent bannerCookie settings, browser controlsConsent string (TCF)
Research participationExplicit consent formWithdrawal requestSigned consent form
Testimonial useWritten authorizationWritten revocationAuthorization document

Data Processing Purposes

5.1 Primary Service Purposes

PurposeDescriptionData UsedRetention
Account managementCreating and managing customer accountsIdentity, Contact, AccountAccount lifetime
Service provisionDelivering the SaaS platform functionalityAll platform dataPer service agreement
AuthenticationVerifying user identityAccount, TechnicalSession + 90 days logs
AuthorizationEnforcing access controlsAccount, UsageSession + 90 days logs
Support deliveryResponding to customer inquiriesCommunication, Account3 years
BillingProcessing payments, invoicingTransaction, Contact7 years
Usage meteringTracking consumption for billingUsage, Technical2 years

5.2 Security and Compliance Purposes

PurposeDescriptionData UsedRetention
Security monitoringDetecting threats and anomaliesTechnical, Usage90 days hot, 1 year archive
Fraud preventionIdentifying fraudulent activityTechnical, Account, Transaction2 years
Incident investigationResponding to security incidentsAll relevant data7 years
Audit loggingMaintaining compliance recordsUsage, Technical7 years
Vulnerability managementSecuring the platformTechnical3 years
Access auditingReviewing access patternsUsage, Account7 years

5.3 Business Operations Purposes

PurposeDescriptionData UsedRetention
AnalyticsUnderstanding usage patternsUsage (aggregated)Indefinite (aggregated)
Product developmentImproving servicesUsage (pseudonymized)2 years
MarketingCommunicating about productsContact, MarketingUntil opt-out
ResearchIndustry research, benchmarksUsage (anonymized)Indefinite (anonymized)
Legal complianceMeeting regulatory obligationsAs requiredPer regulation

Data Sharing and Disclosure

6.1 Categories of Recipients

Recipient CategoryPurposeData SharedSafeguards
SubprocessorsService delivery supportAs necessaryDPA, security review
Payment processorsBilling operationsTransaction, minimal IdentityPCI DSS compliance
Analytics providersUsage analysisPseudonymized TechnicalAggregation, contracts
Security vendorsThreat detectionTechnicalSecurity assessment
Professional advisorsLegal, audit, consultingAs necessaryProfessional obligations
RegulatorsLegal complianceAs requiredLegal process
AcquirersBusiness transactionAll (with notice)Successor obligations

6.2 Subprocessor Engagement

Acme Cloud engages Subprocessors under the following controls:

ControlRequirementVerification
ContractualDPA with equivalent protectionsLegal review
SecuritySecurity assessment pre-engagementQuestionnaire, SOC 2
Notification30-day advance notice to customersEmail notification
ObjectionCustomer objection processContract terms
MonitoringAnnual reassessmentCompliance review

Current subprocessor list: /subprocessor-list

6.3 Law Enforcement and Government Requests

Acme Cloud handles government requests according to these principles:

PrincipleImplementation
Legal validityRequests must be legally valid in relevant jurisdiction
Narrow scopeRequests challenged if overbroad
Customer noticeCustomers notified unless legally prohibited
TransparencyAggregate statistics published annually
PushbackNovel or concerning requests challenged legally
Request TypeReview ProcessCustomer NoticeEscalation
SubpoenaLegal review for validityYes, unless prohibitedGeneral Counsel
Court orderLegal review for validityPer order termsGeneral Counsel
Search warrantLegal review, compliance requiredPer warrant termsGeneral Counsel + CPO
National security letterLegal reviewProhibited by lawGeneral Counsel + CEO
Emergency requestUrgency verification, legal reviewAfter resolutionGeneral Counsel

International Data Transfers

7.1 Transfer Mechanisms

Acme Cloud employs the following mechanisms for international transfers:

Transfer RouteMechanismSupplementary Measures
EEA to USEU-US Data Privacy FrameworkTIA, encryption
EEA to UKUK Adequacy DecisionStandard protections
EEA to other third countriesStandard Contractual Clauses (2021)TIA, encryption
UK to USUK Extension to DPFTIA, encryption
UK to other third countriesInternational Data Transfer AgreementTIA, encryption
Other jurisdictionsLocal mechanisms + SCCs as applicableTIA, encryption

7.2 Transfer Impact Assessment (TIA)

For transfers requiring Transfer Impact Assessments:

Assessment FactorEvaluation CriteriaDocumentation
Legal frameworkSurveillance laws, access rightsLegal memo
Enforcement practicesActual access history, published dataResearch summary
Transfer circumstancesData types, volume, purposesData mapping
Supplementary measuresEncryption, access controlsTechnical measures
Contractual protectionsSCCs, additional clausesContract terms

7.3 Data Privacy Framework Certification

Acme Cloud maintains certification under the EU-US Data Privacy Framework:

Framework ComponentStatusVerification
EU-US DPFCertifiedCommerce Dept. list
UK ExtensionCertifiedCommerce Dept. list
Swiss-US DPFCertifiedCommerce Dept. list
Annual recertificationCompliantCertification records
Independent recourseJAMSArbitration agreement

Data Subject Rights

8.1 Rights Overview by Jurisdiction

RightGDPRCCPA/CPRALGPDUK GDPRApplicability
AccessYesYes (Know)YesYesAll jurisdictions
RectificationYesYes (Correct)YesYesAll jurisdictions
ErasureYesYes (Delete)YesYesAll jurisdictions
PortabilityYesYesYesYesAll jurisdictions
RestrictionYesLimitedYesYesGDPR jurisdictions
ObjectionYesYes (Opt-out)YesYesAll jurisdictions
Automated decisionsYesYes (Profiling)YesYesAll jurisdictions
Non-discriminationN/AYesYesN/ACCPA jurisdictions
Opt-out of saleN/AYesN/AN/ACCPA only
Limit sensitive useN/AYesYesN/ACPRA jurisdictions

8.2 Rights Exercise Process

Step 1: Request Submission 1.1. Data Subject submits request via privacy@acmecloud.com, in-app form, or postal mail 1.2. Request logged in DSR management system with timestamp 1.3. Acknowledgment sent within 3 business days

Step 2: Identity Verification 2.1. Verify Data Subject identity to prevent unauthorized disclosure 2.2. For account holders: verify via authenticated session or account recovery 2.3. For non-account holders: verify via identifying information match 2.4. Additional verification for sensitive requests

Step 3: Request Processing 3.1. Determine applicable jurisdiction and rights 3.2. Locate all Personal Data in scope 3.3. Evaluate exemptions (e.g., legal hold, other legal obligations) 3.4. Process request according to type

Step 4: Response 4.1. Provide response within statutory timeframe 4.2. Document completion in DSR management system 4.3. Retain record for compliance

8.3 Response Timeframes and Extensions

JurisdictionInitial ResponseExtension AvailableExtension Conditions
GDPR (EU)30 days+60 daysComplex or numerous requests
UK GDPR30 days+60 daysComplex or numerous requests
CCPA/CPRA45 days+45 daysReasonably necessary
LGPD15 daysNone specifiedN/A
PIPEDA30 days+30 daysExtensions permitted

8.4 Request Handling by Type

Request TypeAcme Cloud as ControllerAcme Cloud as Processor
AccessProvide copy of Personal DataForward to Customer
RectificationCorrect inaccurate dataForward to Customer
ErasureDelete data (subject to exceptions)Forward to Customer
PortabilityProvide machine-readable exportForward to Customer
RestrictionFlag data, limit processingForward to Customer
ObjectionCease processing (assess grounds)Forward to Customer
Opt-out of saleN/A (we don't sell data)N/A

Data Retention and Deletion

9.1 Retention Schedule

Data CategoryRetention PeriodLegal BasisDeletion Method
Active account dataAccount lifetimeContractN/A until termination
Terminated account data30 days post-terminationContract, litigation holdAutomated deletion
Transaction records7 yearsLegal (tax, audit)Secure deletion
Security logs90 days hot, 1 year coldLegitimate interestAutomated rotation
Support tickets3 yearsLegitimate interestAutomated deletion
Marketing dataUntil opt-out + 30 daysConsent/legitimate interestAutomated deletion
Audit logs7 yearsLegal (compliance)Secure deletion
Employment records7 years post-terminationLegal (labor law)Secure deletion
Cookie dataPer cookie typeConsentBrowser expiration

9.2 Customer Data Deletion Process

Upon service termination:

TimelineActionVerification
Day 0Service access disabledSystem confirmation
Day 1-7Deletion grace period (customer retrieval)N/A
Day 8-14Data deletion from productionDeletion confirmation
Day 15-30Purge from backupsBackup cycle completion
Day 30+Certificate of destruction availableUpon request

9.3 Backup and Archive Retention

Backup TypeRetentionEncryptionGeographic Location
Database snapshots90 days rollingAES-256Primary + DR region
Transaction logs90 daysAES-256Primary region
Object storage versions90 daysAES-256Per data residency
Disaster recoverySynchronizedAES-256DR region
Long-term archivePer retention scheduleAES-256Per data residency

Cookies and Tracking Technologies

10.1 Cookie Categories

CategoryPurposeConsent RequiredDuration
Strictly necessaryEssential functionalityNoSession to 1 year
FunctionalPreferences, settingsYes (GDPR), No (CCPA)1 year
PerformanceAnalytics, optimizationYes2 years
TargetingAdvertising, remarketingYes2 years

10.2 Cookie Inventory

Cookie NameCategoryPurposeDurationThird Party
session_idNecessarySession managementSessionNo
csrf_tokenNecessarySecuritySessionNo
localeFunctionalLanguage preference1 yearNo
_gaPerformanceGoogle Analytics2 yearsGoogle
_gidPerformanceGoogle Analytics24 hoursGoogle
_fbpTargetingFacebook Pixel90 daysMeta
hubspotutkTargetingHubSpot tracking13 monthsHubSpot

10.3 Consent Management

JurisdictionConsent MechanismDefault StateOpt-Out Method
EU/EEACookie consent banner (TCF 2.0)All non-essential offBanner or settings
UKCookie consent bannerAll non-essential offBanner or settings
CaliforniaCCPA notice + opt-outFunctional on, targeting off"Do Not Sell" link
Other USNotice onlyAll onBrowser settings
BrazilConsent bannerAll non-essential offBanner or settings

Full cookie policy: /cookie-policy


Children's Privacy

11.1 Age Restrictions

Acme Cloud services are designed for business use and are not directed at children:

JurisdictionMinimum AgeVerificationExceptions
United States16 (COPPA: 13)Terms acceptanceNone
European Union16 (or member state minimum)Terms acceptanceNone
United Kingdom13Terms acceptanceNone
Brazil18 (or parental consent)Terms acceptanceNone

11.2 Response to Underage Data Discovery

If Acme Cloud discovers it has collected Personal Data from a child under applicable age thresholds:

1.1. Immediately cease processing the child's Personal Data 1.2. Notify parent/guardian if identifiable and required by law 1.3. Delete the child's Personal Data within 48 hours 1.4. Document the incident and remediation 1.5. Review controls to prevent recurrence


Privacy by Design and Default

12.1 Privacy Engineering Principles

PrincipleImplementationVerification
Data minimizationCollect only necessary dataDesign review checklist
Purpose limitationPurpose documented before collectionPrivacy review
Storage limitationAutomated retention enforcementTechnical controls
AccuracyCorrection mechanismsSelf-service + support
SecurityEncryption, access controlsSecurity review
AccountabilityDocumentation, auditingPrivacy assessments

12.2 Privacy Impact Assessment Process

DPIAs required for:

  • New processing activities involving sensitive data
  • Large-scale profiling or monitoring
  • New technology with privacy implications
  • Changes to high-risk existing processing
DPIA PhaseActivitiesDocumentation
InitiationScreening questionnaire, threshold assessmentScreening record
AssessmentData mapping, risk identification, consultationDPIA report
ReviewPrivacy team review, recommendationsReview memo
ApprovalCPO approval for acceptable residual riskApproval record
ImplementationControl implementation, monitoringImplementation plan

12.3 Privacy Review in Product Development

Development PhasePrivacy ActivityDeliverable
PlanningPrivacy screeningGo/no-go recommendation
DesignPrivacy reviewDesign recommendations
DevelopmentPrivacy testingTest results
LaunchFinal privacy approvalLaunch authorization
Post-launchPrivacy monitoringOngoing compliance

Breach Notification

13.1 Breach Classification

ClassificationDefinitionExampleNotification Required
Category 1High risk to individualsExfiltrated sensitive PIIRegulators + individuals
Category 2Risk to individualsLost unencrypted deviceRegulators
Category 3Low riskEncrypted data lostDocumentation only
Category 4No riskMisdirected internal emailDocumentation only

13.2 Notification Timelines

JurisdictionRegulator NotificationIndividual NotificationCustomer Notification (Processor)
GDPR (EU)72 hoursWithout undue delayWithout undue delay
UK GDPR72 hoursWithout undue delayWithout undue delay
CCPA/CPRAExpeditiousExpeditiousPer contract
LGPDReasonable timeframeReasonable timeframePer contract
US state lawsPer state (typically 30-60 days)Per statePer contract

13.3 Notification Content

ElementRegulator NoticeIndividual NoticeCustomer Notice
Nature of breachYesYesYes
Categories of dataYesYesYes
Approximate subjects affectedYesYesYes
Likely consequencesYesYesYes
Measures taken/proposedYesYesYes
DPO contactYesYesN/A
Recommendations for individualsN/AYesN/A

Privacy Governance

14.1 Privacy Organization

RoleResponsibilitiesReports To
Chief Privacy OfficerPrivacy program leadership, regulatory liaisonGeneral Counsel
Data Protection Officer (EU/UK)Independence, supervisory authority contactCPO (functionally independent)
Privacy Engineering ManagerPrivacy by design implementationCPO + CTO
Privacy Analysts (3)DSR processing, assessments, trainingCPO
Privacy Champions (per team)Embedded privacy guidanceFunctional + CPO dotted

14.2 Privacy Governance Bodies

BodyMembersMeeting CadenceResponsibilities
Privacy Steering CommitteeCPO, CLO, CISO, CTOQuarterlyStrategy, major decisions
Privacy OperationsCPO, Privacy Analysts, LegalWeeklyOperational issues, DSRs
Privacy Review BoardCPO, Privacy Eng, Security, LegalAs neededDPIA approval, exception review

14.3 Privacy Training

Training TypeAudienceFrequencyContent
General awarenessAll employeesAnnual + onboardingPrivacy principles, policies
Role-specificEngineering, Support, SalesAnnualJob-relevant privacy practices
Advanced privacyPrivacy team, LegalContinuousRegulatory updates, case studies
Incident responseIR teamAnnualPrivacy breach procedures

Framework Mapping Appendix

GDPR Article Compliance Mapping

GDPR ArticleRequirementAcme Cloud ImplementationEvidence
Art. 5Processing principlesData minimization, purpose limitationPrivacy assessments
Art. 6Lawful basisDocumented basis per activityProcessing records
Art. 7Consent conditionsConsent management platformConsent records
Art. 12-14TransparencyPrivacy policy, noticesPublished policies
Art. 15-22Data subject rightsDSR proceduresResponse records
Art. 24Controller obligationsPrivacy programDocumentation
Art. 25Privacy by designDPIA processAssessment records
Art. 28Processor requirementsDPA template, subprocessor managementContracts
Art. 30Records of processingProcessing inventoryROPA
Art. 32SecurityTechnical measuresSecurity documentation
Art. 33-34Breach notificationIncident proceduresIR records
Art. 35DPIAAssessment processDPIA records
Art. 37-39DPOAppointed DPOAppointment records
Art. 44-49International transfersTransfer mechanismsSCCs, TIAs

CCPA/CPRA Compliance Mapping

CCPA/CPRA SectionRequirementAcme Cloud ImplementationEvidence
1798.100Right to knowAccess request proceduresResponse records
1798.105Right to deleteDeletion proceduresDeletion confirmations
1798.106Right to correctCorrection proceduresResponse records
1798.110Categories disclosurePrivacy policyPublished policy
1798.115Right to opt-outN/A (no sale)Policy statement
1798.120Opt-out of saleN/A (no sale)Policy statement
1798.121Sensitive PILimit use optionConsent mechanisms
1798.125Non-discriminationEqual servicePolicy statement
1798.130Service provider contractsDPA termsContracts
1798.135Privacy linksWebsite footerSite implementation
1798.140DefinitionsPolicy alignmentPolicy language

Related Trust Center documents

cookie policy, dpa, subprocessor list, data retention, terms of service, security overview, encryption standards

Document revision history

VersionDateAuthorSummary of changes
1.02024-06-01Legal & ComplianceInitial Trust Center publication
2.02025-03-15GRC ProgramSOC 2 Type II alignment refresh; expanded subprocessors
2.52025-09-01Security EngineeringEncryption standards update; ISO 27001 mapping
3.02026-01-15Trust Center ProgramFull procurement-grade expansion; 34-document set

Contact

Acme Cloud, Inc. 1200 Market Street, Suite 400 San Francisco, CA 94103, USA

ChannelEmailUse case
Trust & procurementtrust@acmecloud.comSecurity questionnaires, trust reviews
Securitysecurity@acmecloud.comIncidents, vulnerabilities, control questions
Privacyprivacy@acmecloud.comDSRs, privacy assessments
Legallegal@acmecloud.comContractual, DPA, legal notices
Last updated: January 15, 2026
EthicPages logoEthicPages