CloakTrack logo
Legal & compliance

Meeting GDPR Requirements

Every piece of data our scoring engine processes is tracked and accounted for. This page explains how CloakTrack supports GDPR compliance for customers and their users throughout the EU, EEA, and UK.

Last updated: June 1, 2026

01Our role under GDPR

For click-level personal data our customers submit to CloakTrack for scoring (such as an end visitor's IP address), CloakTrack acts as a data processor and the customer acts as the data controller. For account and billing data of our direct customers, CloakTrack acts as the data controller.

02Grounds for processing your data

We process personal data on the basis of contractual necessity (to provide the fraud-scoring service you signed up for), legitimate interest (such as securing our platform and improving detection accuracy), and consent where required, such as for optional marketing communications.

03Rights individuals have

Individuals in the EU/EEA and UK have the right to access, rectify, erase, restrict, or port their personal data, and to object to certain processing. Requests can be submitted to our privacy team and will be honored within one month as required by law.

  • Right of access and data portability
  • Right to rectification of inaccurate data
  • Right to erasure ('right to be forgotten')
  • Right to restrict or object to processing

04Requesting a data processing agreement

Business customers can request a Data Processing Agreement (DPA) that incorporates the EU Standard Contractual Clauses. Our standard DPA is available for self-service signature from the billing settings page.

05Sub-processors we rely on

We maintain an up-to-date list of sub-processors who may access personal data to help deliver CloakTrack, including cloud hosting, email delivery, and webhook/alerting providers. We notify customers of material sub-processor changes at least 30 days in advance.

06Transferring data across borders

Where personal data is transferred outside the EU/EEA or UK, we rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism to safeguard the transfer.

07How we handle data breaches

In the event of a personal data breach affecting customer data, we will notify affected customers without undue delay and, in any event, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.

08Reaching our data protection officer

Our Data Protection Officer can be reached directly for GDPR-related inquiries, data subject requests, or to review our current DPA and sub-processor list.

09Exercising your rights

To exercise any of the rights described above, contact our privacy team using the email below. We may need to verify your identity before processing certain requests.

Have a question about this policy?

Contact our legal & compliance team directly.

[email protected]
Support