Legal & Compliance

COPPA Compliance Policy

Effective Date: January 15, 2025 | Last Updated: March 10, 2025

1. Scope & Applicability

This Children's Online Privacy Protection Act (COPPA) Compliance Policy outlines how CloudNexus, Inc. ("CloudNexus," "we," "us," or "our") handles personal information in compliance with the COPPA and related child privacy regulations. This policy applies to our cloud infrastructure, hosting services, API platforms, and associated management tools.

CloudNexus operates primarily as a Business-to-Business (B2B) cloud infrastructure provider. Our services are designed for developers, IT administrators, and enterprise clients, and are not directed at children under the age of 13. However, we recognize that our customers may deploy applications, websites, or services that interact with younger audiences. This policy clarifies our role, your responsibilities, and the safeguards we maintain to support a compliant ecosystem.

2. Age Requirements

CloudNexus services require users to be at least 18 years of age, or the age of legal majority in their jurisdiction, to register for an account, enter into service agreements, or access administrative features.

Important: We do not knowingly collect, maintain, or use personal information from children under 13. If you are under 18, you may use our services only under the direct supervision and approval of a parent or legal guardian.

Our registration process includes age verification mechanisms. If we discover that an account has been created by a minor without proper authorization, we will promptly suspend access and delete associated data unless required to retain it for legal or security reasons.

4. Customer Responsibilities

As a service provider, CloudNexus acts as a data processor for information hosted on our infrastructure. Customers deploying services that collect data from users under 13 retain the primary responsibility as data controllers under COPPA. You agree to:

  1. Implement appropriate age gates, parental consent workflows, and privacy notices compliant with applicable laws.
  2. Configure CloudNexus security groups, encryption, and access controls to protect sensitive data.
  3. Respond to parental requests for access, modification, or deletion of personal information.
  4. Audit third-party SDKs, analytics tools, or integrations for COPPA compliance.
  5. Notify CloudNexus immediately if a data breach or compliance incident involving minor's data occurs.

Failure to comply with COPPA obligations may result in service suspension in accordance with our Acceptable Use Policy and Terms of Service.

5. Data Security & Retention

CloudNexus maintains industry-leading security standards to protect all data hosted on our infrastructure, including any personal information related to minors:

  • Encryption: AES-256 at rest, TLS 1.3+ in transit, with optional customer-managed keys (CMK).
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and audit logging for all administrative actions.
  • Network Security: DDoS mitigation, Web Application Firewalls (WAF), and isolated tenant environments.
  • Retention & Deletion: Data is retained only as long as necessary to provide services or comply with legal obligations. Upon service termination or valid deletion request, data is cryptographically erased within 30 days.

6. Compliance Support & Tools

We are committed to empowering our customers to build child-safe digital experiences. CloudNexus offers:

  • Compliance Dashboards: Real-time visibility into data flows, access logs, and retention policies.
  • API-Driven Consent Management: Webhooks and endpoints to integrate with third-party consent management platforms (CMPs).
  • Regional Data Residency: Deploy workloads in specific geographic regions to comply with localized privacy regulations.
  • Documentation & Guidance: Technical guides on implementing age verification, data minimization, and secure storage practices.

For enterprise clients requiring dedicated compliance architecture reviews, our Trust & Safety team offers paid consultation services.

7. Policy Updates

We may update this COPPA Compliance Policy to reflect changes in legislation, technology, or our service offerings. Significant updates will be communicated via email to account administrators and posted on this page with a revised effective date. Continued use of CloudNexus services constitutes acceptance of the updated policy.

8. Contact Information

If you have questions about this policy, suspect unauthorized data collection involving minors, or wish to exercise parental rights regarding data hosted on CloudNexus infrastructure, please contact our Privacy & Compliance Team:

CloudNexus Privacy & Compliance Office

Email: coppa@cloudnexus.io
Mail: CloudNexus Inc., Attn: COPPA Compliance, 100 Cloud Drive, Suite 400, San Francisco, CA 94107, USA

Submit a Privacy Request →

For urgent compliance or safety concerns, please include "COPPA INQUIRY" in your subject line. We respond to all verified requests within 15 business days.