Data Sharing Policy
1. Overview
CloudNexus recognizes that data privacy and transparency are fundamental to our relationship with customers, partners, and users. This Data Sharing Policy outlines how we collect, use, share, and protect data across our cloud infrastructure, hosting services, and enterprise solutions.
We do not sell, rent, or trade personal data to third parties for marketing purposes. All data sharing is conducted under strict contractual, technical, and legal safeguards to ensure compliance with global privacy regulations including GDPR, CCPA, and SOC 2 Type II.
2. Our Commitment to Data Privacy
At CloudNexus, data sovereignty and user control are core principles. We operate as a data processor on behalf of our customers (data controllers) for most enterprise services. Our infrastructure is designed with privacy-by-default and data minimization in mind.
Key Principle: We only share data when necessary to deliver services, fulfill legal obligations, or with explicit user consent. Every data transfer is logged, encrypted, and subject to independent audits.
3. Categories of Data We Share
We categorize shared data based on sensitivity, purpose, and recipient type:
- Operational Data: System logs, performance metrics, and infrastructure telemetry required for service delivery and maintenance.
- Account & Billing Data: Subscription details, payment processing information, and administrative contact details shared with payment providers and support teams.
- Usage Analytics: Aggregated, anonymized usage patterns used to improve platform performance and capacity planning.
- Security & Compliance Data: Threat intelligence, access logs, and audit trails shared with security partners and regulatory bodies when required.
- Customer-Provided Data: Application data, databases, and storage content that you upload to our platform. We do not access or share this data without your explicit instruction or a valid legal requirement.
4. Third-Party Service Providers (Sub-Processors)
We engage trusted third-party providers to support specific functions. Each sub-processor is bound by a Data Processing Agreement (DPA) that mandates confidentiality, security standards, and restricted use.
| Provider | Service / Purpose | Location | Category |
|---|---|---|---|
| Stripe / Adyen | Payment Processing | EU / Global | Essential |
| Cloudflare | CDN, DDoS Protection, Security | Global | Essential |
| Twilio | Multi-Factor Authentication & Alerts | US / EU | Essential |
| PagerDuty | Incident Management & Monitoring | US | Operational |
| Cloudflare / AWS S3 | Backup & Disaster Recovery | Configurable | Essential |
Sub-processors may be added or removed with 30 days' notice. Enterprise customers receive direct notifications and opt-out rights where applicable.
5. Cross-Border Data Transfers
Our infrastructure spans 50+ global regions. When data crosses international boundaries, we implement legally compliant transfer mechanisms:
- EU/UK Data: Transfers to third countries rely on EU Standard Contractual Clauses (SCCs) and adequacy decisions where applicable.
- Data Residency Controls: Enterprise customers can enforce strict data residency policies, ensuring all data remains within specified jurisdictions.
- Encryption in Transit: All cross-border transfers are protected via TLS 1.3 and mutual authentication protocols.
Compliance Note: CloudNexus is certified under the EU-US Data Privacy Framework and maintains SCCs for all international data flows involving personal data.
6. Legal Requirements & Law Enforcement
We may disclose data when required by law, court order, subpoena, or government request. Our approach ensures transparency and minimizes disclosure:
- Validation: We verify the legal validity and scope of all requests before responding.
- Notification: We will notify affected customers unless legally prohibited or in cases of imminent threat.
- Minimization: We only disclose data strictly necessary to fulfill the legal requirement.
Our transparency reports are published quarterly and available in the Compliance Center.
7. User Controls & Consent
CloudNexus provides granular controls over data sharing preferences:
- Dashboard Settings: Manage API access, third-party integrations, and data retention policies.
- Consent Management: Explicit opt-in required for non-essential analytics and marketing communications.
- Data Export & Deletion: Self-service tools to download or permanently delete account and project data.
- Role-Based Access Control (RBAC): Enterprise administrators can restrict data visibility and sharing permissions per team or project.
8. How We Protect Shared Data
All shared data is protected through industry-leading security measures:
- Encryption: AES-256 at rest, TLS 1.3 in transit, and optional customer-managed keys (BYOK/HYOK).
- Access Controls: Zero-trust architecture, multi-factor authentication, and strict least-privilege policies.
- Auditing & Monitoring: Continuous security monitoring, quarterly third-party penetration testing, and annual SOC 2 / ISO 27001 audits.
- Breach Response: 24/7 Security Operations Center (SOC) with a documented incident response plan compliant with GDPR Article 33/34.
9. Policy Updates
This policy may be updated to reflect changes in technology, regulatory requirements, or business operations. Material changes will be communicated via email and platform notifications at least 30 days prior to implementation. The "Last Updated" date at the top of this page reflects the most recent revision.
10. Contact Us
If you have questions about our data sharing practices, wish to exercise your data rights, or need assistance with data residency configurations, please contact our Data Protection team:
- Email: privacy@cloudnexus.io
- Data Protection Officer: DPO Office, CloudNexus HQ, Amsterdam, NL
- Security Portal: cloudnexus.io/security
- Support: Help Center or account dashboard