Data Privacy Policy

✓ GDPR & CCPA Compliant Last Updated: November 15, 2025

At CloudNexus, we treat your data with the same security and reliability we apply to our cloud infrastructure. This policy outlines how we collect, use, store, and protect personal information in accordance with global privacy regulations.

1. Introduction

CloudNexus ("we," "our," or "us") is committed to protecting your privacy. This Data Privacy Policy explains how we handle personal data collected through our cloud hosting, infrastructure services, websites, and related platforms. By using our services, you consent to the practices described herein.

This policy applies to:

  • Account holders and administrators
  • End-users of applications hosted on CloudNexus
  • Visitors to our marketing and documentation websites
  • Customers interacting with our sales and support teams

2. Information We Collect

We collect information necessary to deliver, secure, and improve our cloud infrastructure services. This includes:

2.1 Information You Provide

  • Account Details: Name, email, company name, billing address, and payment information
  • Technical Configuration: Server preferences, domain names, SSH keys, and API credentials
  • Support Communications: Tickets, chat logs, and email correspondence

2.2 Information Collected Automatically

  • Usage Data: API calls, deployment logs, resource utilization, and performance metrics
  • Device & Network Info: IP address, browser type, operating system, and time zone
  • Cookies & Tracking: Session management, authentication tokens, and analytics identifiers

3. How We Use Information

We use collected data strictly for operational, security, and service improvement purposes:

  • Provisioning and managing cloud resources
  • Processing payments and invoicing
  • Monitoring system health, preventing abuse, and responding to incidents
  • Delivering customer support and technical assistance
  • Improving platform performance and developing new features
  • Complying with legal obligations and enforcing terms of service

4. Data Sharing & Third Parties

We do not sell personal data. We may share information only when necessary:

  • Service Providers: Payment processors, email delivery services, and cloud networking partners operating under strict data processing agreements
  • Legal Requirements: When required by law, subpoena, or to protect rights and safety
  • Business Transfers: In the event of merger, acquisition, or asset sale, with notice and continued privacy obligations

Subprocessor Notice: CloudNexus maintains an up-to-date list of subprocessors. Customers with data residency requirements can specify geographic constraints during account setup.

5. Data Security & Protection

Security is foundational to our infrastructure. We implement industry-leading measures including:

  • AES-256 encryption for data at rest and TLS 1.3 for data in transit
  • Regular third-party penetration testing and SOC 2 Type II audits
  • Role-based access control, MFA enforcement, and zero-trust network architecture
  • Automated threat detection, DDoS mitigation, and real-time monitoring
  • Physical security controls across all 50+ global data centers

Despite these measures, no system is completely immune. We continuously evaluate and upgrade our defenses to mitigate emerging threats.

6. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

  • Access & Portability: Request a copy of your personal data in a machine-readable format
  • Correction: Update or amend inaccurate information
  • Deletion: Request erasure of data, subject to legal retention requirements
  • Restriction & Objection: Limit processing or object to specific uses (e.g., marketing)
  • Withdraw Consent: Opt out of non-essential communications at any time

To exercise these rights, contact our Data Protection Officer via the details in Section 11. We will respond within 30 days as required by applicable law.

7. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce agreements. Generally:

  • Active account data: Retained while the account is active
  • Post-cancellation: 90 days for recovery, then securely purged
  • Billing records: 7 years for tax and audit compliance
  • Support logs: 24 months, then anonymized or deleted

8. International Data Transfers

CloudNexus operates globally. Data may be processed in jurisdictions outside your country of residence. We ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs)
  • Data Processing Addendums (DPAs) for enterprise customers
  • Regional data isolation options for regulated industries

9. Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal data from children. If we learn we have inadvertently collected such data, we will promptly delete it.

10. Policy Updates

We may update this policy to reflect changes in technology, regulation, or business practices. Material changes will be communicated via email and platform notifications. Continued use after updates constitutes acceptance.

11. Contact Us

For privacy inquiries, data subject requests, or security reports:

CloudNexus Data Protection Officer

📧 privacy@cloudnexus.io
🔒 security@cloudnexus.io (for vulnerabilities)
📍 100 Cloud Avenue, Suite 400, San Francisco, CA 94105
📞 +1 (888) 555-0199 (Mon-Fri, 9AM-6PM PST)

You also have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your privacy rights have been violated.