StackLégal

Hosting and network

GDPR OVHcloud

In an indie stack, OVHcloud is used for Hosting and cloud, often chosen for a French entity. Entity cited: OVH SAS (French policy); the DPA published on the US site is concluded with OVH US LLC dba OVHcloud. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.

Translation of the French sheet. The facts do not change. The date is the date the official pages were read.

DPA OVHcloud

Yes for the US entity: public DPA. On the French side, the FAQ states that a DPA is built into the contract and available on simple request. Public URL of the French annex: not disclosed.

Read the DPA

Stated role

The French policy presents OVHcloud as controller of the processing it describes, and as processor when it processes on the customer's instruction (annex “Processing of personal data”). The US DPA: the customer is controller or processor, OVHcloud is processor or sub-processor.

Personal data

The French policy cites last name, first name, postal address, email, phone, identity documents and proof of address, customer identifier (NIC Handle), exchanges, and tickets. The US DPA covers content whose categories are determined by the customer.

Sub-processors of OVHcloud

Public URL of a sub-processor list: not disclosed.

Public URL of a list: not disclosed on this sheet.

Transfers outside the EU

Hosting / location

The US DPA states that the customer chooses where the content is stored, and that by uploading it the customer accepts access from anywhere in the world, including from the place where the content is maintained. Named list of regions on the pages consulted: not disclosed.

EU–United States Data Privacy Framework

OVH US LLC (public name OVHcloud) is registered. EU-U.S. Data Privacy Framework status: Active. This entry covers the US entity, not OVH SAS.

Data Privacy Framework sheet

Cookies

not disclosed

Typical use, written by StackLégal and not by the vendor: Hosting and cloud, often chosen for a French entity.

History

Last update: October 4, 2026.

  1. First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".

Clause to paste

Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.

Sub-processor clause

Add this vendor to your free sub-processors widget

Sources

Verified on October 4, 2026.

Frequently asked questions

Is OVHcloud a processor within the meaning of the GDPR?

The French policy presents OVHcloud as controller of the processing it describes, and as processor when it processes on the customer's instruction (annex “Processing of personal data”). The US DPA: the customer is controller or processor, OVHcloud is processor or sub-processor.

What DPA does OVHcloud publish?

Yes for the US entity: public DPA. On the French side, the FAQ states that a DPA is built into the contract and available on simple request. Public URL of the French annex: not disclosed. https://us.ovhcloud.com/legal/data-processing-agreement/

Which further sub-processors does OVHcloud publish?

Public URL of a sub-processor list: not disclosed.

Where does OVHcloud state that it processes data, including outside the EU?

The US DPA states that the customer chooses where the content is stored, and that by uploading it the customer accepts access from anywhere in the world, including from the place where the content is maintained. Named list of regions on the pages consulted: not disclosed.

Is OVHcloud registered under the EU–United States Data Privacy Framework?

OVH US LLC (public name OVHcloud) is registered. EU-U.S. Data Privacy Framework status: Active. This entry covers the US entity, not OVH SAS. https://www.dataprivacyframework.gov/participant/5716

Which personal data does OVHcloud mention?

The French policy cites last name, first name, postal address, email, phone, identity documents and proof of address, customer identifier (NIC Handle), exchanges, and tickets. The US DPA covers content whose categories are determined by the customer.

Often in the same stack

These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.

Related tools

All the sheets hosting and network

Full pack, from 39 € incl. VAT

The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.