Privacy

ARCHIVED 2023-12-01, DATE APPROXIMATE · VERSION 20231201_rev01 · COMPARED WITH 20220704_rev01

Full text changes — 20220704_rev01 to 20231201_rev01

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

33### Privacy Policy
44
55Docker's [Privacy Policy](https://docker.com/legal/docker-privacy-policy) details the different ways personal data received from users of our website ("Website") collected via the Website, email, SMS, telephone, WAP or other means may be collected, used, and disclosed by Docker.
66
77### Data Processing Addendum
88
9The [EU General Data Protection Regulation (GDPR)](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation) came into effect on May 25, 2018. GDPR has a long reach and applies if you are based in the EU or do business in the EU. If you have any EU personal data in your Docker account, such as names, email addresses, ID numbers, or anything else that is personally identifiable, then GDPR applies. You are a Controller of personal data under GDPR, so you need to enter into GDPR-compliant data processing agreements with any online services and third party vendors you rely on, including Docker. These agreements are called a Data Processing Addendum, or DPA. The processing of EU personal data must be governed by a [GDPR-compliant data processing agreement](https://gdpr-info.eu/art-28-gdpr/). Docker provides a [standard DPA](https://docker.com/wp-content/uploads/2022/02/2022-Docker-EU-UK-SCC-Data-Processing-Agreement.pdf) to extend GDPR privacy principles, rights, and obligations regarding personal data stored in the production system/technical instance of Docker's subscriptions and/or services provided by Docker and ordered by a Docker customer.
9The [EU General Data Protection Regulation (GDPR)](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation) came into effect on May 25, 2018. GDPR has a long reach and applies if you are based in the EU or do business in the EU. If you have any EU personal data in your Docker account, such as names, email addresses, ID numbers, or anything else that is personally identifiable, then GDPR applies. You are a Controller of personal data under GDPR, so you need to enter into GDPR-compliant data processing agreements with any online services and third party vendors you rely on, including Docker. These agreements are called a Data Processing Addendum, or DPA. The processing of EU personal data must be governed by a [GDPR-compliant data processing agreement](https://gdpr-info.eu/art-28-gdpr/). Docker provides a [standard DPA](https://www.docker.com/wp-content/uploads/2022/03/2022-Docker-EU-UK-SCC-Data-Processing-Agreement.pdf) to extend GDPR privacy principles, rights, and obligations regarding personal data stored in the production system/technical instance of Docker's subscriptions and/or services provided by Docker and ordered by a Docker customer.
1010
1111### Subprocessors
1212
1313Docker uses third party subprocessors, such as cloud computing service providers and customer support software, to provide our services. We enter into a GDPR-compliant data processing agreement with each subprocessor, and require the same of them.