Compliance
The standards we hold ourselves to.
Last updated: July 15, 2026
Regulations
| Framework | Status | Evidence |
|---|---|---|
| GDPR (EU/EEA) | Supported | DPA + EU SCCs |
| UK GDPR | Supported | DPA + UK Addendum |
| Swiss FADP | Supported | DPA + Swiss addendum |
| CCPA / CPRA (California) | Supported | Privacy Policy + DPA |
| Other US state privacy laws | Supported | CCPA-equivalent practices |
| HIPAA — health data | Not supported | Refused by design |
| COPPA — children’s data | Not supported | Refused by design |
| GLBA — regulated financial data | Not supported | Refused by design |
| BIPA — biometric data | Not supported | Refused by design |
| MHMDA — consumer health data | Not supported | Refused by design |
Current certifications
None.
AlreadyBack documents the controls it operates today rather than claiming certifications it does not yet hold. When we pursue formal attestation (for example, SOC 2), we will publish it here.
The infrastructure we run on is independently certified. Our US compute runs in data-center facilities operated by NTT Global Data Centers Americas, certified to ISO/IEC 27001:2022 (Schellman, certificate 1554103-9). Encrypted backups are stored with Cloudflare R2, certified to ISO/IEC 27001 and SOC 2 Type II. Because every backup is encrypted before it leaves our systems, these providers only ever hold ciphertext.
Data we refuse by design
AlreadyBack is deliberately not built for regulated high-sensitivity data: health (HIPAA), children’s data (COPPA, or under 16 where EU law applies), biometric (BIPA), regulated-financial (GLBA), and consumer-health data must not be backed up through the Services. This is enforced in our Terms, not just discouraged.
Available documentation
Every claim on this page is backed by a document you can read now.
Compliance principles
- We document the controls we operate today.
- We collect the minimum personal data needed to run the Services.
- We process your backed-up content only on your instructions.
- We publish our sub-processors, and give notice before any change.
- We refuse the data categories we’re not designed to protect.
Enterprise and data residency
Have data-residency or deployment needs beyond our standard US and EU regions? We can discuss additional contractual or deployment requirements for enterprise customers. Talk to us about enterprise requirements.