Terms of Service
Effective Date: 4 July 2026
Last Updated: 4 July 2026
These Terms of Service ("Terms") govern your access to and use of CloudExpress, including our website, file transfer service, accounts, subscriptions, upload, download, sharing, notification, branding, and related features (the "Service").
CloudExpress is operated by Radium Technologies Limited (company number 556692), trading as Cloud Express / CloudExpress, a registered business name with company number 779575 and a business address at Unit 4/5 Burton Hall Park, Burton Hall Road, Sandyford Business Park, Dublin 18, D18 A094 ("CloudExpress", "we", "us", or "our"). Based on the information currently available to us, CloudExpress is not currently VAT registered.
You can contact us at:
- Support: [email protected]
- Abuse and illegal content notices: [email protected]
- Privacy and data protection: [email protected]
- Postal address: Unit 4/5 Burton Hall Park, Burton Hall Road, Sandyford Business Park, Dublin 18, D18 A094
By creating an account, uploading files, sending or receiving a transfer, buying a plan, or otherwise using the Service, you agree to these Terms. If you use the Service on behalf of a company, organisation, or other legal entity, you confirm that you have authority to bind that entity.
If you do not agree to these Terms, do not use the Service.
1. Other Terms That Apply
These Terms incorporate the following policies and documents:
- Privacy Policy: https://www.cloudexpress.ie/privacy-policy
- Acceptable Use and Anti-Abuse Policy: https://www.cloudexpress.ie/acceptable-use
- Security and Trust information: https://www.cloudexpress.ie/security
- Any pricing, plan, order, invoice, checkout, or subscription terms shown to you when you buy or renew a plan.
- The Data Processing Addendum in Schedule 1 of these Terms, where CloudExpress processes personal data on behalf of a business customer.
If there is a conflict, the following order applies unless we expressly state otherwise: a signed written agreement with CloudExpress, an order form or plan-specific terms, the Data Processing Addendum, these Terms, then the policies listed above.
2. Definitions
In these Terms:
"Account" means a registered CloudExpress account.
"Business Customer" means a customer using the Service for business, professional, trade, charity, public sector, or organisational purposes.
"Consumer" means an individual using the Service for purposes wholly or mainly outside that individual's trade, business, craft, or profession.
"Customer Files" means files, folders, archives, messages, filenames, metadata, transfer instructions, recipient details, passwords, and other material uploaded, sent, shared, stored, or processed through the Service by you or on your behalf.
"Recipient" means a person who receives or is invited to access a transfer.
"Transfer" means an upload, hosted download page, secure link, email delivery, or other file transfer made through the Service.
"User" means a person who accesses or uses the Service, including account holders, team members, senders, and recipients.
3. The Service
CloudExpress provides a hosted file transfer service. The Service is designed to help users upload files, create secure links, send files to recipients, set available controls such as expiry dates or password protection where supported by a plan, and track certain delivery and download events.
CloudExpress is a transfer service, not a permanent storage, archive, backup, disaster recovery, legal hold, or records management service. You must keep your own original copies and backups of all Customer Files. We are not responsible for replacing, reconstructing, or recovering Customer Files after expiry, deletion, corruption, user error, account closure, suspension, or loss, except to the extent we are legally required to be responsible.
We may change, improve, limit, suspend, withdraw, or replace parts of the Service from time to time. We will try to give reasonable notice where a material change negatively affects paid users, unless urgent changes are needed for security, legal, operational, abuse-prevention, or service-integrity reasons.
4. Eligibility and Authority
You must be at least 18 years old to create an Account or buy a paid plan. If you are under 18, you may use the Service only with the involvement and consent of a parent or guardian and only where permitted by law.
If you use the Service for an organisation, you confirm that:
- you are authorised to do so;
- the organisation accepts these Terms;
- the organisation is responsible for your use and the use of its users, members, employees, contractors, agents, and recipients.
5. Accounts and Security
You must provide accurate account, billing, and contact information and keep it up to date.
You are responsible for:
- keeping your login credentials secure;
- choosing strong passwords and protecting any transfer passwords;
- controlling who can access your Account and Transfers;
- promptly telling us about suspected unauthorised access or misuse;
- all activity under your Account, unless the activity was caused by our breach of these Terms or applicable law.
You must not share login credentials except through authorised team or workspace features. We may require password resets, multi-factor authentication, email verification, or other security steps where we consider it reasonably necessary.
6. Transfers, Recipients, and Delivery
You are responsible for entering correct sender, recipient, and transfer details. If you send a link or email to the wrong person, make Customer Files public, share passwords insecurely, set an incorrect expiry date, or choose unsuitable access settings, you are responsible for the consequences unless caused by our breach of these Terms or applicable law.
CloudExpress may show delivery, link-open, download, or event information. Such information is provided for operational visibility and may depend on email delivery systems, browser behaviour, recipient settings, network conditions, and other factors outside our control. It is not a legal proof of receipt unless we expressly agree otherwise in a signed written agreement.
We do not guarantee that every file will be uploaded, delivered, accessed, downloaded, or received by every intended recipient. Transfers may fail, expire, be blocked, be delayed, be quarantined, or be unavailable because of recipient systems, incorrect details, spam filtering, malware controls, browser or network issues, storage limits, service limits, maintenance, abuse prevention, legal requests, or other circumstances.
7. File Retention, Expiry, and Deletion
Customer Files are retained only for the period supported by the relevant plan, workspace settings, or transfer settings, unless a different period is required by law, security, dispute handling, abuse prevention, backup integrity, or an agreement with you.
Unless your plan or settings state otherwise, transfer links and files may expire and become unavailable after the expiry period shown in the Service for the relevant transfer. Paid plans may allow longer or configurable expiry periods, subject to plan limits.
After expiry, cancellation, deletion, account closure, or suspension, Customer Files may be deleted or made unavailable. Deletion from active systems may occur before deletion from backups or logs. Backup deletion follows our backup rotation and security processes.
We may retain limited metadata, logs, billing records, abuse records, security records, and legal records after files are deleted where reasonably necessary for security, accounting, legal compliance, dispute handling, service operation, fraud prevention, or enforcement of these Terms.
8. Customer Files and Your Licence to Us
You keep ownership of your Customer Files.
You grant CloudExpress and our service providers a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, process, display, format, scan, analyse, make available, delete, and otherwise use Customer Files only as reasonably necessary to:
- provide, secure, support, and improve the Service;
- send and manage Transfers;
- provide previews, download pages, notifications, event logs, and account features;
- detect, prevent, investigate, and respond to abuse, malware, spam, fraud, security incidents, illegal content, and violations of these Terms;
- comply with law, legal process, regulator requests, and enforceable government or court orders;
- protect the rights, property, safety, and security of CloudExpress, users, recipients, and third parties.
We do not claim ownership of Customer Files and we do not use Customer Files for advertising to recipients.
9. Your Responsibilities for Customer Files
You represent and warrant that:
- you have all rights, licences, permissions, consents, and lawful bases needed to upload, store, send, share, and process Customer Files through the Service;
- Customer Files and your use of the Service comply with applicable law;
- you will not upload or share unlawful, harmful, infringing, abusive, malicious, or prohibited material;
- you will not use the Service to send spam, phishing, malware, illegal content, or unsolicited bulk communications;
- you will not use the Service in a way that infringes intellectual property, confidentiality, privacy, data protection, consumer protection, export control, sanctions, or other rights or laws;
- you will comply with the Acceptable Use and Anti-Abuse Policy.
If Customer Files include personal data, you are responsible for having an appropriate lawful basis, transparency notice, consent where required, and authority to provide that personal data to CloudExpress and recipients.
If Customer Files include special category data, confidential information, regulated information, health data, financial data, children's data, criminal offence data, legally privileged material, export-controlled information, or other sensitive material, you are responsible for deciding whether the Service and your chosen settings are appropriate.
10. Prohibited Use
You must not:
- upload, send, store, or share illegal content;
- upload, send, store, or share malware, ransomware, viruses, worms, trojans, credential stealers, exploit kits, botnet tools, or harmful code;
- use the Service for phishing, impersonation, fraud, spam, harassment, doxxing, extortion, blackmail, hate, threats, exploitation, or unlawful surveillance;
- infringe copyright, trade marks, trade secrets, database rights, privacy rights, publicity rights, or other rights;
- upload or share intimate, sexual, or private images without valid consent;
- upload or share child sexual abuse material, terrorist content, or content that is illegal to possess, transmit, or make available;
- probe, scan, overload, disrupt, reverse engineer, circumvent, or compromise the Service or its security controls;
- attempt to access accounts, workspaces, transfers, files, systems, or data without authorisation;
- misrepresent your identity, sender details, affiliation, or authority;
- use the Service to build a competing service or to benchmark the Service for publication without our written consent;
- exceed or attempt to bypass plan limits, storage limits, transfer limits, rate limits, access controls, authentication requirements, or security measures.
We may remove or restrict access to Customer Files, suspend Transfers, block links, disable Accounts, preserve evidence, or notify authorities where we reasonably believe this clause has been breached or where required by law.
11. Content Moderation, Abuse Notices, and Illegal Content
CloudExpress may be a hosting service for certain Customer Files. We provide a mechanism for reporting illegal content, abuse, malware, phishing, intellectual property infringement, privacy violations, or other misuse at [email protected] or through any reporting form we make available.
A notice should include, where possible:
- the URL, transfer link, file reference, account, or other location of the material;
- a clear explanation of why the material is alleged to be illegal or abusive;
- your name and email address, except where the notice concerns child sexual abuse material or where anonymity is legally permitted;
- a statement that you believe in good faith that the information in the notice is accurate and complete.
We may review notices using manual review, automated tools, user reports, third-party signals, law enforcement notices, trusted sources, and security systems. We may restrict, remove, disable access to, or preserve material where we consider it necessary or appropriate.
Where required by law, we will provide a statement of reasons to affected users when we restrict content or accounts. We may withhold details where disclosure would be unlawful, create security risk, interfere with an investigation, reveal detection methods, expose confidential information, or increase harm.
If you believe we made a mistake, you may contact [email protected] or [email protected] with the relevant details. Repeated manifestly unfounded notices or appeals may be restricted.
12. Security
We use technical and organisational measures designed to protect the Service and Customer Files. These may include encryption in transit, access controls, operational monitoring, logging, expiry controls, password protection features, storage controls, backup controls, abuse detection, and administrative safeguards.
No online service is perfectly secure. You are responsible for using available security features appropriately, including passwords, expiry settings, authenticated download settings, recipient controls, account security, and secure sharing practices.
We may scan, analyse, quarantine, block, or remove Customer Files, links, metadata, or traffic for malware, abuse, spam, fraud, security, legal, or policy reasons. We do not promise that all harmful material will be detected or blocked.
You must tell us promptly at [email protected] or [email protected] if you discover a vulnerability, unauthorised access, suspected breach, exposed transfer, or misuse of the Service. You must not publicly disclose vulnerabilities or exploit them beyond what is necessary to demonstrate the issue responsibly.
13. Plans, Limits, and Fair Use
Plans may include limits on file size, transfer size, storage, expiry periods, branding, team members, notifications, history, bandwidth, API access, authenticated download, or other features.
Plan limits are shown on the pricing page, checkout page, in-product settings, or order documentation. We may enforce limits technically or operationally.
We may apply fair use controls to protect the Service, users, recipients, infrastructure, deliverability, and security. This may include rate limits, temporary upload blocks, storage reserve controls, bandwidth controls, recipient limits, email limits, anti-abuse blocks, and manual review.
If we materially reduce paid plan limits during a subscription term, we will try to give reasonable notice and, where required by law, provide appropriate cancellation or refund rights.
14. Fees, Billing, Renewals, and Taxes
Paid plans are billed as shown at checkout or in the relevant order. Fees may be charged monthly, annually, or on another billing cycle selected by you.
By buying a paid plan, you authorise us and our payment processors to charge your payment method for fees, taxes, renewals, upgrades, usage charges, and other amounts due.
Unless stated otherwise:
- prices are in EUR unless stated otherwise;
- prices do not include VAT because CloudExpress is not currently VAT registered, unless this changes and we state otherwise at checkout;
- subscriptions renew automatically at the end of each billing period until cancelled;
- you must cancel before the renewal date to avoid the next charge;
- plan downgrades or cancellations take effect at the end of the current billing period unless we state otherwise;
- fees are non-refundable except as required by law or expressly stated by us.
If payment fails, we may suspend, downgrade, or terminate paid features after reasonable attempts to notify you. You remain responsible for unpaid amounts.
We may change prices for future billing periods by giving notice through the Service, email, checkout flow, invoice, or website. If you do not accept a price change, you must cancel before the change takes effect.
15. Consumer Cancellation Rights
This clause applies only where you are a Consumer.
Where you buy a paid digital service online, you may have a statutory right to cancel within 14 days, unless an exception applies or you have requested immediate supply and acknowledged that cancellation rights may be affected as permitted by law.
If you want the Service to begin immediately during the cancellation period, we may ask for your express request and acknowledgement during checkout. If you cancel after we have started providing the Service, we may charge or retain an amount permitted by law for the Service supplied before cancellation, and your right to a full refund may be reduced or lost where the law allows.
Nothing in these Terms limits your statutory rights as a Consumer. If there is any conflict between these Terms and mandatory consumer law, mandatory consumer law applies.
To exercise a statutory cancellation right, contact [email protected] with your account email, order details, and a clear statement that you wish to cancel.
16. Refunds
For Business Customers, payments are non-refundable unless a written agreement says otherwise, we decide to provide a refund, or applicable law requires one.
For Consumers, statutory refund rights apply. Any voluntary refund we provide does not create a right to future refunds.
We may refuse refunds where we reasonably believe there has been abuse, fraud, breach of these Terms, excessive use, or misuse of promotional offers, subject to mandatory law.
17. Trial, Free, Beta, and Promotional Features
We may offer free plans, trials, beta features, previews, discounts, or promotional credits. These may be changed, limited, withdrawn, or terminated at any time unless stated otherwise.
Free and beta features are provided without service level commitment and may be subject to stricter limits. Beta features may be incomplete, unstable, or changed before general release.
Promotional offers may have eligibility conditions, expiry dates, and usage limits. We may withdraw offers used abusively or in breach of these Terms.
18. Intellectual Property
CloudExpress and our licensors own all rights in the Service, website, software, user interface, branding, logos, design, documentation, systems, and technology, except Customer Files and third-party materials.
You may use the Service only as permitted by these Terms. You must not copy, modify, distribute, sell, lease, sublicense, reverse engineer, decompile, scrape, or create derivative works from the Service except to the extent permitted by law.
You may submit feedback, suggestions, or ideas. We may use them without restriction or payment to you.
19. Privacy and Data Protection
Our Privacy Policy explains how we process personal data as a controller.
For Business Customers, where CloudExpress processes personal data in Customer Files on behalf of the Business Customer, the Data Processing Addendum in Schedule 1 applies unless a separate signed data processing agreement is in place.
You are responsible for ensuring that your use of the Service complies with data protection law, including providing notices to senders, recipients, employees, clients, and other data subjects where required.
You must not use the Service in a way that would cause CloudExpress to breach data protection law.
20. Confidentiality
Each party may receive confidential information from the other. Confidential information includes non-public business, technical, financial, security, product, customer, pricing, and account information, and Customer Files that are not intended to be public.
Each party will use the other's confidential information only to perform or receive the Service, exercise rights, comply with law, or enforce these Terms. Each party will protect the other's confidential information using reasonable care.
Confidentiality obligations do not apply to information that is public through no breach, already known without restriction, independently developed, lawfully received from a third party, or required to be disclosed by law. Where legally permitted, the receiving party will give reasonable notice before compelled disclosure.
21. Third-Party Services and Integrations
The Service may use or integrate with third-party services, including hosting, storage, email delivery, payments, authentication, analytics, security, and support providers.
Third-party services may be subject to their own terms and privacy notices. We are not responsible for third-party services outside our reasonable control.
If you choose to connect Google, Microsoft, or another third-party account, you authorise us to access and use information from that service as necessary to provide the integration and as described in our Privacy Policy.
22. Suspension and Termination by Us
We may suspend, restrict, remove, disable, or terminate access to the Service, Accounts, Transfers, Customer Files, or links immediately where we reasonably believe:
- you breached these Terms or the Acceptable Use and Anti-Abuse Policy;
- your use creates security, legal, operational, financial, reputational, or abuse risk;
- your payment is overdue;
- your Account is compromised or used without authorisation;
- Customer Files are illegal, harmful, infringing, malicious, or abusive;
- we are required or requested to do so by law, court order, regulator, law enforcement, payment processor, hosting provider, or other competent authority;
- continued provision of the Service would expose us, users, recipients, or third parties to risk.
Where reasonable and legally permitted, we will give notice and an opportunity to remedy. We may act without notice where necessary.
23. Cancellation and Termination by You
You may stop using the Service at any time. You may cancel paid subscriptions through account settings, by contacting support, or as otherwise described in the Service.
Cancelling a subscription does not automatically delete all Customer Files, metadata, logs, invoices, or legal records. Files may remain available until expiry or deletion according to plan settings and our retention practices.
You are responsible for exporting or downloading any information you need before cancellation, expiry, suspension, or closure.
24. Consequences of Termination
When an Account, plan, or Transfer ends:
- your right to use the relevant Service features ends;
- unpaid amounts become due;
- we may delete or disable access to Customer Files and Account data according to these Terms and our retention practices;
- clauses intended to survive will continue, including clauses on fees, Customer Files, intellectual property, confidentiality, data protection, warranties, liability, indemnities, governing law, dispute resolution, and interpretation.
25. Disclaimers
The Service is provided using reasonable skill and care. However, except as expressly stated in these Terms or required by law, the Service is provided on an "as is" and "as available" basis.
To the fullest extent permitted by law, we do not warrant that:
- the Service will be uninterrupted, error-free, secure, or always available;
- every upload, transfer, notification, email, link, or download will succeed;
- every recipient will receive, open, or download Customer Files;
- every threat, malware file, abusive file, unauthorised access, or illegal use will be detected;
- Customer Files will be preserved beyond applicable retention or expiry periods;
- the Service will meet every legal, regulatory, professional, archival, evidential, or sector-specific requirement applicable to you.
You are responsible for assessing whether the Service is suitable for your intended use.
26. Liability to Consumers
Nothing in these Terms excludes or limits liability where it would be unlawful to do so. This includes liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, wilful misconduct, and any rights or remedies that cannot be excluded or limited under applicable consumer law.
If you are a Consumer, we are responsible for losses you suffer that are a foreseeable result of our breach of these Terms or our failure to use reasonable skill and care. We are not responsible for losses that are not foreseeable.
The Service is not intended for business use by Consumers. If you use the Service for business or professional purposes, our liability to you is limited as set out for Business Customers.
27. Liability to Business Customers
This clause applies to Business Customers and business use.
Nothing in these Terms excludes or limits liability for:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- wilful misconduct;
- payment obligations;
- liability that cannot be excluded or limited by law.
Subject to the previous paragraph, CloudExpress will not be liable for:
- loss of profits, revenue, sales, business, contracts, opportunity, goodwill, reputation, anticipated savings, or wasted expenditure;
- business interruption;
- loss, corruption, deletion, disclosure, or unavailability of data, Customer Files, or records, except to the extent caused by our breach and not otherwise excluded by law;
- indirect, special, incidental, punitive, exemplary, or consequential loss;
- losses caused by incorrect recipient details, insecure sharing by you, recipient action or inaction, expired links, user error, failure to keep backups, or use contrary to these Terms;
- losses caused by third-party services, networks, email systems, browsers, devices, hosting providers, payment processors, identity providers, or recipient systems outside our reasonable control.
Subject to the exclusions above, CloudExpress's total aggregate liability to a Business Customer arising out of or in connection with the Service, these Terms, and any related claim, whether in contract, tort, negligence, breach of statutory duty, misrepresentation, restitution, or otherwise, will not exceed the greater of:
- the fees paid by that Business Customer to CloudExpress for the Service in the 12 months before the event giving rise to the claim; or
- EUR 100 where the claim relates to a free plan, free trial, free transfer, or unpaid use.
Claims must be brought within 12 months after the date on which the claimant first knew or should reasonably have known about the facts giving rise to the claim, unless a longer period is required by law.
28. Indemnity
If you are a Business Customer, you will indemnify and hold harmless CloudExpress, our affiliates, officers, directors, employees, contractors, agents, and service providers from and against claims, losses, damages, liabilities, penalties, fines, costs, and expenses, including reasonable legal fees, arising from or related to:
- Customer Files;
- your breach of these Terms;
- your unlawful, unauthorised, or negligent use of the Service;
- your violation of intellectual property, privacy, data protection, confidentiality, consumer protection, export control, sanctions, or other rights or laws;
- disputes between you and your recipients, clients, employees, contractors, or third parties;
- your failure to maintain backups or use appropriate security controls;
- your instructions to CloudExpress, where we follow them lawfully.
We will notify you of the claim where reasonably possible and allow you to participate in the defence, provided that we may control the defence where the claim could affect CloudExpress, the Service, other users, or our legal position.
29. Force Majeure
We are not liable for delay or failure caused by events beyond our reasonable control, including acts of God, extreme weather, fire, flood, power failure, internet or telecoms failure, cyberattack, malware outbreak, labour dispute, war, terrorism, civil unrest, government action, legal restrictions, supplier failure, hosting failure, payment processor failure, email provider failure, or emergency maintenance.
30. Export Controls and Sanctions
You must comply with applicable export control, trade control, and sanctions laws. You must not use the Service in or for the benefit of sanctioned countries, territories, persons, or entities, or for prohibited end uses.
We may refuse, suspend, or terminate access where we reasonably believe sanctions or export control issues may arise.
31. Changes to These Terms
We may update these Terms from time to time. We will post the updated Terms on our website and update the "Last Updated" date.
For material changes that negatively affect paid users, we will try to give reasonable advance notice by email, in-product notice, website notice, or another reasonable method. Changes may take effect immediately where needed for legal, security, abuse-prevention, operational, or regulatory reasons.
Your continued use of the Service after changes take effect means you accept the updated Terms. If you do not accept the updated Terms, you must stop using the Service and cancel any paid plan before the changes apply, subject to mandatory law.
32. Electronic Contracting and Records
You agree that contracts may be concluded electronically. Before placing an order, you will be shown the relevant plan, price, billing cycle, payment details, and available means to correct input errors.
After an online order, we or our payment processor may send an acknowledgement or receipt by email or make it available in your Account. We may retain electronic records of orders, invoices, acceptances, consents, and account activity.
These Terms are made available in a form that can be stored and reproduced.
33. Notices
We may send notices to the email address associated with your Account, through the Service, by posting on our website, or by other reasonable means.
You may send legal notices to [email protected] and by post to Unit 4/5 Burton Hall Park, Burton Hall Road, Sandyford Business Park, Dublin 18, D18 A094. Notices are deemed received when delivered, or if sent by email, when the email is sent unless the sender receives a failed delivery notice.
34. Assignment
You may not assign or transfer your rights or obligations under these Terms without our prior written consent.
We may assign or transfer our rights and obligations to an affiliate, successor, purchaser, investor, acquirer, or other entity involved in a merger, acquisition, restructuring, sale of assets, financing, or change of control, provided this does not materially reduce your rights under these Terms.
35. Severability
If any part of these Terms is found invalid, unlawful, or unenforceable, that part will be limited or removed to the minimum extent necessary, and the rest of the Terms will remain in effect.
36. No Waiver
If we do not enforce a provision of these Terms immediately, that does not mean we waive our right to enforce it later.
37. Third-Party Rights
Except where these Terms expressly say otherwise, no person other than you and CloudExpress has rights to enforce these Terms.
38. Governing Law and Disputes
These Terms and any dispute or claim arising from or related to them or the Service are governed by the laws of Ireland.
If you are a Business Customer, the courts of Ireland have exclusive jurisdiction.
If you are a Consumer, you may have rights to bring proceedings in your country of residence under mandatory consumer law. Nothing in these Terms limits those rights.
Before starting formal proceedings, each party will try to resolve the dispute in good faith by contacting the other party and giving reasonable details of the issue.
Schedule 1 - Data Processing Addendum
This Data Processing Addendum ("DPA") applies where CloudExpress processes personal data on behalf of a Business Customer as processor under GDPR or applicable data protection law.
1. Roles
For Customer Files and recipient data submitted by or on behalf of a Business Customer, the Business Customer is the controller, and CloudExpress is the processor, unless the parties agree otherwise in writing.
For account administration, billing, fraud prevention, service analytics, security, legal compliance, and CloudExpress business operations, CloudExpress may act as an independent controller as described in the Privacy Policy.
2. Processing Details
Subject matter: provision of secure file transfer, hosting, recipient delivery, download pages, transfer controls, notifications, event logs, account administration, security, support, and related services.
Duration: for the term of the Business Customer's use of the Service and thereafter as required for deletion, backup rotation, legal compliance, security, and dispute handling.
Nature and purpose: upload, storage, transmission, access control, download, logging, support, security monitoring, abuse prevention, deletion, and related processing needed to provide the Service.
Categories of data subjects: senders, recipients, account users, team members, employees, contractors, clients, suppliers, and other individuals whose personal data is included in Customer Files or transfer metadata.
Categories of personal data: names, email addresses, IP addresses, account identifiers, transfer metadata, filenames, file contents, messages, download events, audit logs, support communications, and any personal data contained in Customer Files.
Special categories: CloudExpress does not require special category data to provide the Service, but Customer Files may contain special category data if uploaded by the Business Customer. The Business Customer is responsible for ensuring a lawful basis and appropriate safeguards.
3. Customer Instructions
CloudExpress will process Customer Personal Data only on documented instructions from the Business Customer, including these Terms, product settings, transfer instructions, support requests, and written instructions, unless required by law.
If CloudExpress believes an instruction infringes data protection law, we will inform the Business Customer where legally permitted.
4. Confidentiality
CloudExpress will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
5. Security Measures
CloudExpress will implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context, and purpose of processing and the risks to individuals.
Measures may include:
- encryption in transit;
- access controls and least-privilege administrative access;
- authentication controls;
- logging and monitoring;
- transfer expiry controls;
- password-protection features where selected by users or supported by plan;
- backup and recovery controls;
- malware, abuse, or security scanning where enabled;
- vulnerability management and operational security processes;
- staff confidentiality and access procedures.
6. Subprocessors
The Business Customer authorises CloudExpress to use subprocessors to provide the Service, including hosting, storage, email delivery, payment, analytics, authentication, support, security, and infrastructure providers.
CloudExpress will maintain a list of material subprocessors and make it available on request.
CloudExpress will impose data protection obligations on subprocessors that are materially equivalent to those in this DPA. CloudExpress remains responsible for subprocessors' performance of their data protection obligations.
CloudExpress will give reasonable notice of new material subprocessors where required by law or contract. If the Business Customer objects on reasonable data protection grounds, the parties will work in good faith to resolve the concern. If it cannot be resolved, the Business Customer may stop using the affected Service and cancel the affected paid plan.
7. International Transfers
CloudExpress will not transfer Customer Personal Data outside the EEA unless an appropriate transfer mechanism is in place, such as an adequacy decision, Standard Contractual Clauses, or another lawful safeguard.
8. Assistance
Taking into account the nature of processing and information available to CloudExpress, CloudExpress will provide reasonable assistance to the Business Customer with:
- data subject requests;
- security obligations;
- personal data breach notifications;
- data protection impact assessments;
- consultations with supervisory authorities.
CloudExpress may charge reasonable fees for assistance that is extensive, unusual, or not caused by CloudExpress's breach.
9. Personal Data Breach
CloudExpress will notify the Business Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will include information reasonably available to CloudExpress to help the Business Customer meet its obligations. CloudExpress may provide information in phases as it becomes available.
Notification is not an admission of fault or liability.
10. Deletion and Return
On termination or expiry of the Service, CloudExpress will delete or return Customer Personal Data according to the Service functionality, retention settings, backup rotation, and legal requirements.
CloudExpress may retain Customer Personal Data where required by law or reasonably necessary for legal claims, security, fraud prevention, abuse prevention, accounting, or compliance, subject to continued protection.
11. Audit
CloudExpress will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, policies, summaries, third-party reports, or written responses.
Audits must be reasonable, limited to information relevant to the Service, subject to confidentiality, and must not compromise security, privacy, other customers, or trade secrets. On-site audits require reasonable prior notice and CloudExpress's written agreement.
12. Liability
Liability under this DPA is subject to the liability limits in the Terms, unless applicable law requires otherwise.
Schedule 2 - Contact and Legal Information
Service provider: Radium Technologies Limited
Trading name: Cloud Express / CloudExpress
Business structure: Body corporate
Registered business name number: 779575
Owner company number: 556692
Registered date for Cloud Express: 28 January 2026
Business activity: Computer consultancy activities
Business address: Unit 4/5 Burton Hall Park, Burton Hall Road, Sandyford Business Park, Dublin 18, D18 A094
VAT number: Not VAT registered based on the information currently available
Email: [email protected]
Abuse notices: [email protected]
Privacy notices: [email protected]
Security reports: [email protected]
Website: https://www.cloudexpress.ie
Online contract language: English
Codes of conduct: None stated
Supervisory authority for data protection: Data Protection Commission, Ireland, unless another authority has jurisdiction under applicable law.