Skip to content

Compliance

The standards we hold ourselves to.

Compliance is a posture, not a checkbox. This page is the map of that posture — what we support, what we refuse, and the documents behind each answer. For security questionnaires, vendor due diligence, or documentation under NDA, get in touch.

Last updated: July 15, 2026

Regulations

Regulations AlreadyBack supports or refuses by design, with the document behind each
FrameworkStatusEvidence
GDPR (EU/EEA)SupportedDPA + EU SCCs
UK GDPRSupportedDPA + UK Addendum
Swiss FADPSupportedDPA + Swiss addendum
CCPA / CPRA (California)SupportedPrivacy Policy + DPA
Other US state privacy lawsSupportedCCPA-equivalent practices
HIPAA — health dataNot supportedRefused by design
COPPA — children’s dataNot supportedRefused by design
GLBA — regulated financial dataNot supportedRefused by design
BIPA — biometric dataNot supportedRefused by design
MHMDA — consumer health dataNot supportedRefused by design

Current certifications

None.

AlreadyBack documents the controls it operates today rather than claiming certifications it does not yet hold. When we pursue formal attestation (for example, SOC 2), we will publish it here.

The infrastructure we run on is independently certified. Our US compute runs in data-center facilities operated by NTT Global Data Centers Americas, certified to ISO/IEC 27001:2022 (Schellman, certificate 1554103-9). Encrypted backups are stored with Cloudflare R2, certified to ISO/IEC 27001 and SOC 2 Type II. Because every backup is encrypted before it leaves our systems, these providers only ever hold ciphertext.

Data we refuse by design

AlreadyBack is deliberately not built for regulated high-sensitivity data: health (HIPAA), children’s data (COPPA, or under 16 where EU law applies), biometric (BIPA), regulated-financial (GLBA), and consumer-health data must not be backed up through the Services. This is enforced in our Terms, not just discouraged.

AI and data-use governance

No customer content is ever used to train, fine-tune, or prompt any AI or machine-learning system — a commitment written into our Terms and DPA, not a policy we can quietly change.

Available documentation

Every claim on this page is backed by a document you can read now.

Compliance principles

  • We document the controls we operate today.
  • We collect the minimum personal data needed to run the Services.
  • We process your backed-up content only on your instructions.
  • We publish our sub-processors, and give notice before any change.
  • We refuse the data categories we’re not designed to protect.

Enterprise and data residency

Have data-residency or deployment needs beyond our standard US and EU regions? We can discuss additional contractual or deployment requirements for enterprise customers. Talk to us about enterprise requirements.