Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Dorsa Cloud is a cloud hosting and infrastructure provider used to run websites and applications. As infrastructure it acts as a processor and does not add marketing cookies to the sites it hosts. The most important compliance question is data location: because its servers are outside the European Economic Area, hosting European personal data with it raises international transfer issues that must be addressed before use.
Dorsa Cloud is a cloud hosting and infrastructure provider that offers servers and platform services for running websites and applications. Like other hosts, it serves as the underlying infrastructure rather than a tracking technology, so its compliance profile is shaped by where data is stored and how the provider is contracted.
As infrastructure, Dorsa Cloud processes the data your application passes through it, including visitor IP addresses in server logs and any personal data your application stores. It does not add analytics or marketing cookies to hosted sites. Any cookies a visitor sees come from the application, though a strictly necessary technical cookie may exist at the server level.
Dorsa Cloud acts as a processor under Article 28 of the GDPR, but because its servers are outside the European Economic Area the bigger issue is Chapter 5 on international transfers. Storing European personal data on infrastructure in a third country without an adequacy decision requires appropriate safeguards and may expose the data to foreign access, which the controller must assess.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Hosting itself does not require visitor consent, because delivering the requested website and its strictly necessary cookies are exempt. The relevant safeguards here are contractual and organisational rather than a cookie banner, and consent obligations still apply to any analytics or marketing your application loads.
Confirm exactly where Dorsa Cloud stores your data. If the country has an adequacy decision, transfers are straightforward. If it does not, you need Standard Contractual Clauses and a transfer impact assessment with supplementary measures such as encryption, and for sensitive data an EU based host is often the safer choice.
Establish the hosting location, sign a data processing agreement and Standard Contractual Clauses if needed, carry out a transfer impact assessment, and apply encryption in transit and at rest. Document the decision, minimise the personal data hosted there, and consider an EU provider where the transfer risk is high.
Websites using Dorsa Cloud must obtain user consent under GDPR regulations.
DPIA considerations
The central concern is the transfer of personal data outside the EEA to a country that may lack an adequacy decision. Assess the exact location, whether Standard Contractual Clauses and supplementary measures are in place, the sensitivity of the data, and whether an EU host would be more appropriate.
Sample consent text
Our website is hosted on Dorsa Cloud infrastructure. Hosting uses only strictly necessary technologies to deliver the site and does not track you for marketing.
Third-party domains contacted
dorsacloud.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| dorsa_session | Functional | Session | Strictly necessary session cookie used by the hosting and control panel to deliver the service. |
| csrftoken | Functional | Session | Strictly necessary security cookie that protects forms against cross site request forgery. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
Dorsa Cloud does not add marketing or analytics cookies to the sites it hosts. Visitor facing cookies come from your application, and the server may use a strictly necessary technical cookie that does not require consent.
No, not for hosting. The relevant compliance work is contractual and about transfers, not a cookie banner. Consent still applies to any analytics or marketing tools your application loads.
As a processor under Article 28 of the GDPR, Dorsa Cloud acts on your instructions under a data processing agreement. For data leaving the EEA you also need a transfer mechanism under Chapter 5 of the GDPR.
Yes, its infrastructure is outside the European Economic Area. If the country lacks an adequacy decision, you must put Standard Contractual Clauses and supplementary measures in place, and assess whether the transfer can be justified.
A transfer impact assessment is advisable whenever European personal data is hosted in a third country without adequacy. Cover the data sensitivity, the legal regime of the destination, and the safeguards in place.
Confirm the hosting location, sign a data processing agreement and Standard Contractual Clauses, run a transfer impact assessment, and encrypt data in transit and at rest. For sensitive or large scale data, consider an EU based host instead.
For EU hosting, alternatives include Hetzner, OVH, Scaleway, and IONOS, which keep data within the European Economic Area and remove the third country transfer question for most use cases.
Name Dorsa Cloud as a hosting processor, state the country where data is stored, and describe the transfer safeguards you rely on. Because it sets no non essential cookies, it usually belongs in the privacy notice rather than the cookie banner.