Personal Data Protection Policy
This policy describes how Bunker handles personal data, both our customers' own data and the data they entrust to us. On the privacy dimension, it implements the principles of our information security policy and covers controls A.5.31, A.5.33, A.5.34, A.8.10, A.8.11, A.8.12 and A.8.33 of the Statement of Applicability.
Our controls are self-assessed, aligned with ISO/IEC 27001, not certified by a third party to date. The status of each measure below reflects that self-assessment.
Purpose and scope
This policy applies to every processing activity Bunker operates: our customers' account and billing data, for which we act as controller; the data our customers host on the platform, for which we act as processor within the meaning of Article 28 GDPR; operational logs and internal company information.
The applicable framework is the GDPR under French law, with hosting in our three datacenters located in France. The matching contractual commitments are published on the website and listed at the end of this page; this policy describes the internal measures that support them.
Principles
- Privacy by design: self-hosted analytics, no third-party tracker on our public surfaces, hosting in France.
- Minimisation: we collect only the data needed to deliver the service and to meet the legal obligations that come with it.
- Separation of roles: what our customers host belongs to them. We act on it only under the customer's documented instructions, and tenant isolation makes that separation technically effective.
- Named accountability: a named DPO, Robin Straub, is the point of contact for data subjects and for the authorities.
- No real personal data outside production: test datasets are synthetic.
Measures
| Area | Measure |
|---|---|
| Legal and contractual framework | GDPR compliance under French law: named DPO, data processing agreement (DPA), list of subprocessors, retention periods and non-EU transfer disclosure published. Record of processing (Article 30) provided on request to the DPO (A.5.31). |
| Breach notification | Personal-data breach notification procedure (Articles 33 and 34 GDPR) being formalised; the reporting channel and the on-call rotation feeding it are operational (A.5.31). |
| Protection of records | Technical protection in place: backups, replication across datacenters and encryption. An organisation-wide retention policy remains to be formalised (A.5.33). |
| Privacy by design | Self-hosted analytics, no third-party tracker, hosting in France; published privacy policy and named DPO (A.5.34). |
| Data subject rights | Mechanisms for exercising rights (access, rectification, erasure, restriction, objection) being formalised; in the meantime requests are handled by the DPO (A.5.34). |
| Information deletion | Automated deletion of ephemeral environments and build artifacts; a customer-data deletion workflow remains to be formalised (A.8.10). |
| Data masking | Masking and anonymisation planned, to be formalised (A.8.11). |
| Data leakage prevention | A dedicated DLP capability is planned, to be evaluated then deployed (A.8.12). |
| Test information | Test datasets are synthetic: no production personal data is used in test or staging environments (A.8.33). |
Responsibilities
- The DPO (Robin Straub, [email protected]) owns this policy, the record of processing, the handling of data subject requests and the relationship with the CNIL.
- The CISO (François-Guillaume Ribreau) is accountable for the technical measures protecting this data and for qualifying incidents that may amount to a personal-data breach.
- Everyone on the team reports without delay, to the DPO or to [email protected], any access, transmission or loss of personal data that should not have happened.
Status and roadmap
One control in this scope is in place, the exclusive use of synthetic test datasets (A.8.33). The legal and technical foundations are laid (named DPO, DPA, published subprocessors and retention periods, encryption, backups and replication), but four controls remain partial (A.5.31, A.5.33, A.5.34, A.8.10) and two are planned (A.8.11, A.8.12).
The roadmap covers four workstreams: formalising the breach notification procedure under Articles 33 and 34; publishing an organisation-wide retention policy; tooling the exercise of data subject rights and the customer-data deletion workflow currently handled case by case; then evaluating data masking and a DLP capability.
We would rather show these gaps than paper over them. A control declared partial is a control you can question us on.
Review
This policy is reviewed at least once a year, whenever our processing activities change significantly, and whenever the applicable regulatory framework changes.
Last reviewed: 31 August 2026.
See also
- Statement of Applicability (the status of controls A.5.31, A.5.33, A.5.34 and A.8.10 to A.8.33)
- Access Control Policy (the segmentation and need-to-know that protect this data)
- Information Security Policy (the ISMS framework this policy derives from)
- Privacy Policy (the information notice addressed to data subjects)
- Data Processing Agreement (DPA) (our processor commitments under Article 28)