Categories of Data Shared

📄 Transparency Report 🕒 Last Updated: November 15, 2025 🌍 Applies to: All CloudNexus Regions

At CloudNexus, transparency is foundational to our security model. We only share customer data when necessary to provide, secure, or improve our infrastructure services. Below is a comprehensive breakdown of the specific data categories we process, our third-party recipients, and the lawful purposes for each transfer. We do not sell customer data. All sharing is governed by strict data processing agreements (DPAs) and industry-standard encryption protocols.

Account & Identity Data

Authentication

Core identifiers used to verify user identity, manage access controls, and maintain account integrity across our platform.

Includes Name, email, org ID, MFA tokens, role assignments
Recipients IdP providers, internal support, SSO vendors
Purpose Access management, fraud prevention

Billing & Financial Information

Transactional

Payment details and usage metrics required for service provisioning, invoicing, and financial compliance.

Includes Payment tokens, invoices, usage reports, tax ID
Recipients Payment processors, tax authorities (if mandated)
Purpose Payment processing, fiscal compliance

Infrastructure & Telemetry

Operational

System performance data collected to maintain SLA guarantees, optimize resource allocation, and detect anomalies.

Includes CPU/RAM metrics, network I/O, API latency, uptime logs
Recipients Monitoring vendors, audit firms, internal SRE teams
Purpose Service optimization, SLA reporting, threat detection

Security & Access Logs

Compliance

Audit trails and authentication events essential for maintaining a secure environment and meeting regulatory requirements.

Includes Login timestamps, IP addresses, session tokens, RBAC changes
Recipients Cybersecurity partners, law enforcement (with warrant)
Purpose Incident response, audit compliance, fraud mitigation

Backup & Replication Data

Data Protection

Encrypted snapshots and replication streams used to ensure disaster recovery and geographic redundancy.

Includes DB snapshots, VM disks, object storage backups
Recipients DR partners, secondary region storage nodes
Purpose Business continuity, RPO/RTO compliance

Marketing & Communications

Opt-In

Voluntary preferences and engagement data used to deliver product updates, newsletters, and technical insights.

Includes Email preferences, survey responses, webinar attendance
Recipients Marketing automation platforms
Purpose Product education, opt-in communications

Your Control & Rights

You maintain full ownership of your data. CloudNexus provides built-in tools and formal processes to manage, export, or restrict how your information is processed. All requests are processed within 30 days in compliance with GDPR, CCPA, and international data protection standards.

🔒 Self-Service Data Export
🚫 Opt-Out of Non-Essential Sharing
📜 Data Processing Agreements (DPA)
🗑️ Right to Erasure & Correction
🌐 Cross-Border Transfer Controls
📧 Dedicated DPO Contact