International Data Transfers

CloudNexus's policies, technical controls, and legal mechanisms governing the cross-border processing of customer data.

Version: 3.1.0
Last Updated: October 15, 2025
Applicability: Global Operations

Contents

1. Overview & Commitment #

CloudNexus operates a globally distributed infrastructure to deliver low-latency performance and high availability. We recognize that cross-border data transfers are subject to stringent regulatory requirements, particularly under the EU General Data Protection Regulation (GDPR), UK GDPR, and various data localization laws.

Our commitment is to ensure that all personal and sensitive data transferred across international boundaries maintains the same level of protection and compliance as required by the origin jurisdiction. We do not rely on blanket adequacy decisions alone; instead, we employ a layered approach combining legal safeguards, technical encryption, and contractual commitments.

Note: This policy applies to all CloudNexus services, including VPS hosting, managed Kubernetes, object storage, and global CDN edge networks. Specific regional compliance details are available in our jurisdiction-specific addenda.

3. Data Residency & Regional Isolation #

CloudNexus provides data residency controls to ensure customer workloads remain within specified geographic boundaries. Our infrastructure is partitioned into isolated regions, each governed by local jurisdictional rules.

Region Primary Data Centers Compliance Frameworks Cross-Border Restrictions
EU Central Frankfurt, Paris, Amsterdam GDPR, EU SCCs, ISO 27001 Strict opt-in for non-EEA routing
UK London, Manchester UK GDPR, IDTA, Cyber Essentials Plus UK Sovereign Cloud isolation available
US Virginia, Oregon, N. Virginia EU-US DPF, SOC 2 Type II, HIPAA-ready State-level localization compliant
APAC Singapore, Sydney, Tokyo PDPA, APP, ISO 27701 Regional data sovereignty enforced

Customers can enforce data residency at the account, project, or workload level via the Control Panel or API. Enabling "Data Residency Lock" prevents automated replication or failover to non-compliant regions.

4. Technical & Organizational Safeguards #

To meet regulatory requirements and mitigate third-country surveillance risks, CloudNexus implements the following security controls for all international data transfers:

  1. Encryption in Transit: All cross-border data flows are protected via TLS 1.3 with forward secrecy. Internal backbone traffic uses IPsec tunnels or MACsec.
  2. Encryption at Rest: Data is encrypted using AES-256. Customer-Managed Keys (CMK) are supported via AWS KMS, Azure Key Vault, or CloudNexus HSM clusters. Keys never leave the source region unless explicitly configured.
  3. Tokenization & Pseudonymization: Sensitive PII can be tokenized at the edge before cross-region replication, reducing exposure during transit.
  4. Access Controls: Zero-trust architecture with hardware-backed root of trust. CloudNexus personnel access customer data only under audited, just-in-time provisioning with multi-party approval.
  5. Audit Logging: All cross-border transfer events, access attempts, and encryption key usage are logged in immutable audit trails available to customers for 365 days (extendable to 7 years).
Customer Responsibility: While CloudNexus secures the infrastructure and transit paths, customers remain responsible for classifying data, configuring residency locks, and managing application-layer encryption where required by their compliance scope.

5. Subprocessors & Third-Party Vendors #

CloudNexus engages a limited number of vetted subprocessors for specialized services (e.g., threat intelligence feeds, regional CDN peering, backup replication). All subprocessors:

No personal data is transferred to subprocessors in non-adequate countries without explicit customer consent and applicable SCCs/IDTAs in place.

6. How to Configure Transfer Controls #

CloudNexus customers can manage international data transfer settings through the following methods:

For enterprise customers requiring sovereign cloud deployments or dedicated cross-border circuit provisioning, our Professional Services team will draft architecture blueprints aligned with your DPO's requirements.

Questions About Data Transfers?

Our Data Protection Officer and compliance engineering team are available to assist with TIAs, SCC execution, or custom residency configurations.

Contact the DPO Office →