Data processing
Where your data lives, who processes it, and for how long.
CloudFix processes and stores all AWS cost, usage and resource metadata in one AWS region, us-east-1. You are the controller; CloudFix is the processor, under a Data Processing Addendum you can read now.
Data residency
AWS us-east-1
N. Virginia. The single region where all customer data is processed and stored. For specific residency or transfer requirements, including UK and EEA, talk to us.
Data residency and hosting
One region, on AWS.
| Component | Location | Provider |
|---|---|---|
| Application and APIs | AWS us-east-1 (N. Virginia) | Amazon Web Services |
| Customer data storage | AWS us-east-1 (N. Virginia) | Amazon Web Services |
| Cost and Usage Report analysis | AWS us-east-1 (N. Virginia): Athena and Glue | Amazon Web Services |
| CDN and edge (dashboard only) | AWS global edge network (origin: us-east-1) | Amazon CloudFront: HTTP metadata only, no AWS cost data |
| Support platform | United States | Kayako: support ticket content only |
Data Processing Addendum
The DPA, in summary.
The DPA governs how CloudFix processes customer data. A standard version is published; an enterprise-specific version can be negotiated.
| Term | Detail |
|---|---|
| Controller | Customer (you) |
| Processor | CloudFix (Aurea, Inc.) |
| Data categories | AWS cost and usage metadata, account configuration data, resource metadata |
| Processing purposes | Cost analysis, optimization recommendations, approved fix implementation |
| Data location | US East: AWS us-east-1 |
| Retention period | Duration of contract + 30 days |
| Deletion | Automated within 30 days of contract termination |
Sub-processors
Who processes customer data, and what they see.
Notification policy: CloudFix notifies customers at least 30 days before engaging any new sub-processor, with the opportunity to object.
Amazon Web Services (AWS)
Infrastructure for the CloudFix application, data storage and compute. Also processes AWS Marketplace billing for customer subscriptions.
- Data processed
- AWS cost and usage metadata, resource configuration data, billing data
- Location
- US East (us-east-1)
- Certifications
- SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, CSA STAR, FedRAMP
Amazon CloudFront
CDN and TLS termination for the CloudFix dashboard. Part of AWS infrastructure, not a separate third party.
- Data processed
- HTTP request metadata (does not see customer AWS data)
- Location
- AWS global edge network (origin: us-east-1)
- Certifications
- SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
Amazon Route 53
DNS resolution for the CloudFix dashboard. Part of AWS infrastructure, not a separate third party.
- Data processed
- DNS query metadata (does not see customer AWS data)
- Location
- AWS global anycast network
- Certifications
- SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
AWS Shield
DDoS protection at the AWS edge. Part of AWS infrastructure, not a separate third party.
- Data processed
- Network and HTTP request metadata (does not see customer AWS data)
- Location
- AWS global edge network
- Certifications
- SOC 1/2/3, ISO 27001, PCI DSS (inherited from AWS)
PostHog
Product analytics: understanding feature usage and improving the CloudFix experience.
- Data processed
- Anonymized usage events and page views. No customer AWS data or cost data.
- Location
- US
- Certifications
- SOC 2 Type 2
Kayako
Customer support: managing support tickets and customer communications.
- Data processed
- Support ticket content, email correspondence, customer name and email
- Location
- US
- Certifications
- SOC 2 Type 2, ISO 27001
Integrations
Data transferred in integrations.
What CloudFix exchanges with an external platform (a service desk or ITSM tool) connected by webhook or API. The ITSM diagram shows the flow.
CloudFix sends (outbound, to the ITSM platform)
| Data type | Description | Personal data? |
|---|---|---|
| Recommendation metadata | AWS resource IDs, service type, estimated savings, status | No |
| Account and org identifiers | AWS account ID, account name as configured in CloudFix | No |
| Approval status updates | Approved or rejected, timestamp, approver username within CloudFix | Potentially (username) |
| Fix execution results | Success or failure status, completion timestamp | No |
CloudFix receives (inbound, from the ITSM platform through the API)
| Data type | Description | Personal data? |
|---|---|---|
| Approval decisions | Approved or rejected signal for a specific recommendation ID | No |
| Approver identity (optional) | Name or user ID of the approver in the ITSM platform, if passed | Potentially (if a name is included) |
No application or business data is transferred to the ITSM platform. Outbound payloads carry recommendation metadata only. Inside your AWS account, CloudFix reads primarily infrastructure metadata (resource IDs, configuration, cost and usage metrics); a few finders need targeted reads beyond that, each granted only when the finder is enabled. See the finder role permission model.
How data is processed
From collection to deletion.
Collection
Through IAM roles created by a CloudFormation StackSet you deploy. The finder role is read-oriented: overwhelmingly
Describe,ListandGet, plus tagging, query execution and a few finder-specific actions (such ass3:PutObjectandssm:SendCommand) present only when the finder needing them is entitled. All are enumerated on the security page and in the CloudFormation templates.Analysis
Cost and Usage Reports are queried through Amazon Athena and processed in memory. Results (optimization recommendations) are stored in CloudFix's database. Raw CUR data is not stored long-term.
Fix execution
When you approve a fix, CloudFix starts it as an AWS Systems Manager Automation runbook inside your AWS account, under
cloudfix-ssm-update-role. The change happens within your account boundary, and every execution is logged.Deletion
On contract termination all customer data is deleted automatically within 30 days: account metadata and configuration, analysis results and recommendations, fix history and audit logs. You can remove the CloudFormation stacks at any time.
Need the full DPA?
Read the standard DPA, print it to PDF, or ask for a version for your organization.