Information Sharing & Disclosure Policy

Effective Date: January 15, 2025 Last Updated: February 10, 2025

Introduction

At CloudNexus, transparency is foundational to our relationship with customers, partners, and the broader technology ecosystem. This Information Sharing & Disclosure Policy outlines how we collect, process, share, and disclose information across our cloud hosting and infrastructure platform.

CloudNexus operates under a zero-trust, privacy-by-design architecture. We do not sell customer data, and we maintain strict boundaries between our operational infrastructure and your tenant environment. This policy supplements our Privacy Policy, Terms of Service, and Service Level Agreement (SLA).

🔒 Data Ownership Guarantee

You retain full legal ownership of all data, code, configurations, and logs generated or stored on CloudNexus infrastructure. We never claim rights to your data, nor do we mine it for advertising or third-party commercial use.

1. Information We Collect & Process

To deliver secure, performant, and compliant cloud infrastructure, CloudNexus collects and processes the following categories of information:

  • Account & Identity Data: Registration details, authentication credentials, SSO configurations, and role-based access controls (RBAC).
  • Infrastructure & Telemetry Data: CPU, memory, storage, and network utilization metrics; deployment logs; and health check status.
  • Network & Security Data: IP addresses, firewall rules, DDoS mitigation logs, SSL/TLS certificates, and threat detection alerts.
  • Support & Billing Data: Customer service interactions, technical tickets, payment history, and invoicing preferences.
  • Compliance & Audit Data: SOC 2 Type II, ISO 27001, GDPR, and HIPAA audit trails generated within your tenant environment.

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). We apply data minimization principles and retain information only as long as operationally or legally required.

2. How We Share Information

CloudNexus shares information only under explicit authorization, operational necessity, or legal obligation. We categorize sharing into three scopes:

2.1 Internal Sharing

Information may be shared across CloudNexus engineering, security, and support teams strictly on a need-to-know basis. Access is governed by zero-trust IAM policies and audited via our internal control framework.

2.2 Customer-Authorized Sharing

You may configure data sharing with your internal teams, third-party monitoring tools, or CI/CD pipelines via API keys, OAuth 2.0, or webhook endpoints. You maintain full visibility and revocation controls through the CloudNexus Console.

2.3 Aggregated & Anonymized Data

We may publish aggregated, anonymized infrastructure benchmarks and usage trends for industry research. No customer-identifiable information, tenant-specific metrics, or raw logs are ever included in public or partner-facing reports.

3. Third-Party Service Providers

CloudNexus engages vetted third-party vendors to support platform operations. All processors are bound by Data Processing Agreements (DPAs) and undergo annual security assessments. Categories include:

  • Infrastructure & Monitoring: Prometheus, Datadog, PagerDuty
  • Identity & Access: Okta, Auth0, AWS Cognito
  • Payment Processing: Stripe, Adyen (PCI DSS Level 1 certified)
  • Communication: SendGrid, Twilio (for transactional alerts only)

We maintain a live vendor transparency portal accessible via your dashboard. You may request a full data flow diagram for any integrated service.

5. Security Incident Disclosure

CloudNexus maintains a 24/7 Security Operations Center (SOC) and follows the NIST SP 800-61 incident response framework. In the event of a confirmed security incident affecting customer data:

  • We will notify affected parties via email, console alerts, and status page updates within 72 hours of confirmation.
  • A detailed incident report, including root cause analysis, impact scope, and remediation steps, will be provided within 14 days.
  • For critical vulnerabilities, we follow coordinated disclosure practices and assign CVE identifiers where applicable.

Our bug bounty program is managed through HackerOne and covers all CloudNexus domains and public APIs.

6. Your Rights & Choices

Depending on your jurisdiction, you may exercise the following rights regarding your information:

  • Access & Portability: Export your data via our CLI or API in JSON, CSV, or PARQUET formats.
  • Correction & Deletion: Request modifications or permanent erasure of account and personal data.
  • Opt-Out: Disable telemetry collection, marketing communications, or third-party analytics at any time.
  • Restriction: Place holds on data processing during compliance audits or legal proceedings.

All rights requests are processed within 30 calendar days. Extensions may apply for complex or large-scale requests.

7. Submitting a Disclosure Request

If you are a customer, partner, or representative submitting a formal information disclosure request, please use the following channels:

  • Customer Portal: Submit via Support Tickets → Compliance & Legal Requests
  • Legal Mailbox: legal-requests@cloudnexus.io
  • Security Disclosures: security@cloudnexus.io (PGP key available on our security page)
  • Government/Law Enforcement: law-enforcement@cloudnexus.io

All requests must include verified identity documentation and a clear description of the data scope. We reserve the right to validate requests and may require additional documentation under applicable privacy and data protection laws.

Need Clarification?

Our compliance team is available for technical, legal, or architectural consultations regarding data handling and disclosure.

Contact Compliance Team

Policy Updates

CloudNexus reserves the right to update this policy to reflect technological, regulatory, or operational changes. Material updates will be communicated via email, console notifications, and the CloudNexus Status Page. Continued use of our platform following updates constitutes acceptance of the revised terms.

For questions regarding this policy, please contact privacy@cloudnexus.io or refer to our Privacy Policy and Terms of Service.