Data Processing Agreement (DPA)
1 Introduction & Parties
This Data Processing Agreement ("DPA") is entered into by and between [Customer Legal Entity Name] ("Controller") and CloudNexus, Inc., a Delaware corporation ("Processor"), collectively referred to as the "Parties".
This Agreement supplements the Master Service Agreement ("MSA") and outlines the rights and obligations of the Parties regarding the processing of personal data in accordance with applicable data protection laws, including but not limited to the EU General Data Protection Regulation (GDPR), UK GDPR, and California Consumer Privacy Act (CCPA).
2 Definitions
Capitalized terms used but not defined in this DPA shall have the meanings assigned to them in the MSA or applicable Data Protection Laws. For clarity:
- "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject").
- "Processing" means any operation performed on Personal Data, including collection, storage, encryption, alteration, or deletion.
- "Data Subject" means an individual whose Personal Data is processed.
- "Applicable Data Protection Laws" means GDPR, UK GDPR, CCPA, and any successor or substantially equivalent legislation.
3 Scope, Subject Matter & Duration
3.1 Subject Matter
The Processor shall process Personal Data on behalf of the Controller solely to provide CloudNexus infrastructure hosting, CDN, database management, and related cloud services as specified in the MSA and associated service configurations.
3.2 Duration
The processing activities shall commence on the Effective Date and continue for the duration of the MSA, unless terminated earlier in accordance with Section 14.
4 Nature & Purpose of Processing
The Processor shall process Personal Data strictly for the following purposes:
- Provision of cloud hosting, compute instances, and object storage services;
- Account management, billing, and technical support;
- Security monitoring, threat detection, and incident response;
- Service optimization, load balancing, and global content delivery;
- Compliance with legal obligations and audit requirements.
CloudNexus does not access, use, or process Customer Personal Data for its own purposes. All processing is performed under the documented instructions of the Controller.
5 Categories of Personal Data & Data Subjects
Subject to the Controller's configuration and data ingestion, the following categories may be processed:
| Category of Data Subjects | Categories of Personal Data |
|---|---|
| End Users / Consumers | Names, email addresses, IP addresses, usage logs, authentication tokens |
| Business Contacts / Admins | Full names, corporate emails, phone numbers, billing addresses, payment references |
| Technical Accounts | API keys, service account credentials, device fingerprints, session identifiers |
6 Controller's Obligations
The Controller warrants and represents that it has obtained all necessary consents, lawful bases, and disclosures required under Applicable Data Protection Laws to process Personal Data and to engage the Processor. The Controller shall:
- Provide accurate, complete, and legally sound processing instructions;
- Notify the Processor without delay of any changes in data subject categories, processing purposes, or legal constraints;
- Respond to Data Subject requests and coordinate with the Processor as required;
- Conduct Data Protection Impact Assessments (DPIAs) where required by law.
7 Processor's Obligations
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required by law;
- Ensure personnel with access to Personal Data are bound by confidentiality obligations and data protection training;
- Assist the Controller in fulfilling Data Subject rights requests (access, rectification, erasure, restriction, portability);
- Notify the Controller within 24 hours of becoming aware of a Personal Data Breach;
- Maintain detailed records of processing activities as required by Article 30 GDPR.
8 Sub-processors
The Controller grants general authorization for the Processor to engage sub-processors for core infrastructure operations, including but not limited to network transit providers, managed hardware suppliers, and security audit firms. The Processor shall maintain an up-to-date list of approved sub-processors on its Compliance Portal and notify the Controller of any new sub-processor engagement. The Processor remains fully liable for the acts and omissions of its sub-processors.
9 Data Subject Rights
The Processor shall assist the Controller in responding to Data Subject requests within the statutory timeframes. Upon lawful request, CloudNexus will:
- Facilitate data export in commonly used, machine-readable formats;
- Execute data deletion or anonymization across active services and backups (subject to technical feasibility and retention policies);
- Provide confirmation of processing scope and data mapping for transparency purposes.
10 Security Measures
CloudNexus implements industry-leading technical and organizational measures (TOMs) including:
- Encryption: AES-256 at rest, TLS 1.3 in transit, customer-managed keys (CMK) support;
- Access Control: Role-based access control (RBAC), multi-factor authentication (MFA), least-privilege principles;
- Infrastructure: Isolated tenancy, automated patching, DDoS mitigation, WAF, zero-trust networking;
- Monitoring: 24/7 SOC, SIEM integration, anomaly detection, automated incident response playbooks;
- Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, PCI DSS Level 1.
11 International Data Transfers
Personal Data may be processed in countries outside the EEA/UK where CloudNexus maintains data centers or sub-processors. Where transfers occur outside adequacy decisions, the Parties shall rely on:
- EU Standard Contractual Clauses (SCCs) (2021/914);
- UK International Data Transfer Addendum;
- Appropriate technical safeguards (encryption, pseudonymization, access restrictions).
12 Audit & Inspection Rights
Subject to reasonable prior notice and confidentiality protections, the Controller may request an annual audit of the Processor's compliance with this DPA, or request the Processor to provide third-party audit reports (e.g., SOC 2). CloudNexus may require the Controller to sign a separate NDA prior to audit execution.
13 Confidentiality
Both Parties agree to treat all Personal Data, processing instructions, and security configurations as strictly confidential. This obligation survives the termination of this Agreement for a period of five (5) years.
14 Termination & Data Return/Deletion
Upon termination or expiration of the MSA, the Processor shall, at the Controller's direction:
- Return all Personal Data in a standard, machine-readable format within 30 days; or
- Safely delete/destroy all Personal Data and provide written certification of destruction within 45 days;
- Retain data only where required by law (e.g., tax, financial, or litigation holds), in which case such data will be isolated and processed under continued confidentiality obligations.
15 Governing Law & Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of the State of Delaware, United States, without regard to conflict of law principles. The Parties consent to the exclusive jurisdiction of the state and federal courts located in Wilmington, Delaware, for disputes arising from this Agreement.
For questions regarding this DPA, data subject rights, or compliance inquiries, contact CloudNexus Trust & Compliance at dpa@cloudnexus.io.