Introduction
OptiCloud, operated by Solutia s.r.o., is committed to protecting the privacy and personal data of our users in full compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Czech data protection legislation.
This policy explains what personal data we collect, why we collect it, how we use it, and what rights you have regarding your data. OptiCloud is designed with privacy-by-design and privacy-by-default principles at its core.
Data Controller
Company: Solutia s.r.o.
EU Registration: CZ.01.01.02/01/24_054/0004809
Address: Czech Republic, EU
Data Protection Contact: privacy@solutia.cz
What Data We Collect
OptiCloud collects and processes the following categories of personal data:
Identity & Account Data
Name, email address, role, department — provided during account creation via Keycloak SSO. Used for authentication and RBAC.
Cloud Cost & Resource Data
Billing data, resource metadata, and usage metrics from connected cloud providers (OCI, Azure, AWS, GCP). This data may contain project names and cost center identifiers.
Application Usage Data
Actions performed within OptiCloud: service requests submitted, approvals, provisioning events. Recorded in the audit trail for compliance.
Technical & Log Data
IP addresses, browser type, session tokens, API request logs. Collected automatically for security monitoring and performance optimization.
Purpose of Data Processing
- Providing multi-cloud cost management, billing aggregation, and resource provisioning services
- Authenticating users and enforcing role-based access control (10 RBAC roles)
- Maintaining a complete audit trail for ISO/IEC 27001 compliance and regulatory requirements
- Generating cost reports, dashboards, and budget alerts for authorized users
- Monitoring system performance, security, and ensuring 99.9% SLA availability
Legal Basis for Processing
Contract Performance (Art. 6(1)(b))
Processing necessary to provide the OptiCloud service as contracted with your organization.
Legitimate Interest (Art. 6(1)(f))
Security monitoring, fraud prevention, and system performance optimization.
Legal Obligation (Art. 6(1)(c))
Maintaining audit trails and financial records as required by law.
Consent (Art. 6(1)(a))
Where applicable, for optional analytics and communication preferences.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
7 years
Audit trail & compliance logs
3 years
Cost & billing records
90 days
Technical logs & sessions
Security Measures
- All data encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Authentication via Keycloak SSO with 2FA (TOTP) for privileged roles (SuperAdmin, CloudAdmin, SecurityOfficer)
- Role-based access control with 10 configurable roles — users only see data relevant to their role
- All infrastructure hosted within the European Union (EU-hosted data centers)
- Regular security assessments, penetration testing, and vulnerability scanning
- ISO/IEC 27001 aligned security controls and incident response procedures
Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR. To exercise any of these rights, contact privacy@solutia.cz:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete data.
Right to Erasure (Art. 17)
Request deletion of your data ('right to be forgotten'), subject to legal retention requirements.
Right to Restrict Processing (Art. 18)
Request limitation of data processing in certain circumstances.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interest.
Right to Lodge a Complaint (Art. 77)
File a complaint with your national data protection authority.
International Data Transfers
OptiCloud infrastructure is hosted entirely within the European Union. When connecting to external cloud providers (OCI, Azure, AWS, GCP), only billing metadata and resource identifiers are transmitted via encrypted API calls. No personal user data is transferred outside the EU. Where cloud provider APIs involve non-EU endpoints, appropriate safeguards (Standard Contractual Clauses) are in place.
Contact & Complaints
If you have questions about this privacy policy or wish to exercise your data protection rights, please contact us:
Email: privacy@solutia.cz
Supervisory Authority: Office for Personal Data Protection of the Czech Republic (ÚOOÚ)
Last updated: March 2026