Data Deletion & Exit Policy β
At Cloud-IAM, you run vanilla Keycloak the open-source solution you chose precisely because it keeps you in control. Avoiding vendor lock-in is core to how we operate, you can retrieve your data and move your Keycloak deployment elsewhere whenever you need, with no barrier on our side.
This page explains what happens to your data when you leave, how long we retain it, what it costs to exit, and the guarantees we provide around GDPR compliance and contractual obligations.
For step-by-step instructions on deleting deployments, see the How-to Deletion Guide.
No vendor lock-in β
We believe customers stay with Cloud-IAM because of our reliability, operations, and support, not because they are locked in. Running Keycloak on Cloud-IAM means your technical teams no longer carry the operational burden of hosting, scaling, and maintaining it themselves, so they can focus on building rather than firefighting.
Because we provide standard, unmodified Keycloak, your deployment remains fully portable. Whether you leave for legal, technical, or operational reasons, you keep full ownership of your Keycloak configurations, users, and events, and you can move them back to your own infrastructure at any time with Export and Backups features.
Exit costs β
Retrieving your data and configuration is free and self-service. There is no exit fee for leaving Cloud-IAM.
- Exporting your data - Available 24/7 at no extra cost through the Export and Backups features. Your Keycloak configurations, users, and events are yours to retrieve whenever you want.
- Migrating off, on your own β Free. Using your exported data, you can rebuild your Keycloak deployment on your own infrastructure without our involvement. A cost only applies in one specific scenario: if you ask our team to actively run the migration for you that is, to move your Keycloak from Cloud-IAM to your infrastructure on your behalf.
This hands-on work falls under our Cloud-IAM consulting services and is billed at standard applicable rates, as stated in our Terms of Service.
In short
Getting your data out is free and self-service. A cost applies only if you want us to perform the migration for you.
Exporting your data before deletion β
Customers are responsible for exporting their data before requesting deletion.
The export method available to you depends on your plan:
- Paid plans β Use the Export feature (Keycloak-compatible JSON) and the Backups feature (full PostgreSQL database dump) for a complete copy of your deployment.
- Freemium plan β Cloud-IAM's Export and Backups features are reserved for paid plans. You can still retrieve your configuration using Keycloak's native export, which is less complete than the Cloud-IAM export but lets you recover your realm and core configuration.
Deployment closure process β
- Free-tier deployments can be deleted directly from the Cloud-IAM Console.
- Paid deployments require a formal deletion request via the Cloud-IAM support team to ensure contractual compliance and prevent accidental data loss.
Both procedures are detailed in the How-to Deletion Guide.
Retention timelines β
Cloud-IAM ensures secure and complete deletion of all your data within 30 days after cancellation.
This applies to all Managed Keycloak deployment data, including:
- Deployment data & Configuration
- Monitoring logs and metrics
- Snapshots
- Backups
Certification of deletion β
Once all data related to your deleted deployment has been irreversibly removed, Cloud-IAM sends an email confirmation.
The confirmation includes:
- Deployment name
- Deployment ID
- Official date of deletion