Location and transfers
We document regions, storage, replicas, backups, external services and support paths that can involve customer data.
Nextcloud, GDPR and compliance
We configure Nextcloud to support the organisation’s data governance: declared location, proportionate access, enforceable retention, traceable activity and readable contractual responsibility.
Practical accountability
A controller needs to understand purposes, legal bases, data categories, people concerned, recipients and retention. A processor must operate within defined instructions and safeguards. We translate that framework into architecture, configuration, contracts and procedures, involving the customer’s privacy advisers in decisions that remain theirs.
We map infrastructure, copies, telemetry, email, identity, apps and integrations so stated residency reflects actual data flows. Where providers or subprocessors are involved, we make them visible within the scope; where evidence is needed, we define how to produce it without collecting unnecessary data.
Governance controls
Each safeguard is linked to a requirement, an owner and a way to verify it.
We document regions, storage, replicas, backups, external services and support paths that can involve customer data.
We clarify processing scope, instructions, contacts, subprocessors and technical measures for the applicable agreements.
We align versions, trash, accounts, shares, backup and deletion procedures with rules that are realistic and testable.
We connect groups and roles to business responsibility, with joiner, mover, leaver and periodic review processes.
We prepare procedures to locate, export, correct or erase data while respecting duties, exceptions and technical copies.
We define useful events, log retention, evidence access and reviews that demonstrate controls have been carried out.
Compliance path
Technical work remains connected to the customer’s legal and organisational decisions.
We identify content types, users, purposes, integrations, administrators, locations and dependencies.
We connect access, encryption, retention, logging, backup and incident response to relevant obligations.
Each procedure states who decides, who acts, what proof remains and how exceptions are handled.
New apps, integrations, countries, data categories and providers trigger a review of the governance scope.
No automatic badges
Compliance depends on purposes, legal bases, configuration, contracts, user behaviour and organisational procedures. We provide technical controls, operational documentation and evidence; the customer retains controller decisions and involvement of its legal advisers or DPO.
Frequently asked questions
Nextcloud provides capabilities that can help protect and control data, but software is not compliant by itself. Compliance covers processing, legal bases, configuration, contracts, people and procedures. We design the service to support that framework and document the controls we operate.
We can design infrastructure, storage and backups in EU regions. A complete statement must also consider support, telemetry, email, identity providers, apps, integrations and their subprocessors; the result is fixed in the architecture and agreements.
Where Nebulas processes personal data for the customer, the relationship is covered by the applicable agreements, including a DPA where required. Roles, subject, duration, safeguards and providers depend on the actual service purchased.
We can establish technical procedures for search, export, correction and deletion, along with logs and operational documents. As controller, the customer validates identity, the basis of the request, legal exceptions and the final response.
Nextcloud is a registered trademark of Nextcloud GmbH. Nebulas Software provides independent consulting, development and managed services; available functions depend on the agreed edition, apps and architecture.
Data governance
Bring residency constraints, policies, DPAs and current data flows; we will identify gaps, responsibilities and the evidence required.
Assess your Nextcloud scope